Agregátor RSS
The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting. [...]
Europe’s evangelistic approach to insisting Apple open up personal data to competing AI services is hurting Apple users in the region. More than that, it also places its entire business sector at risk, and a newly-published Jamf survey suggests why.
Announced at WWDC 2026, Apple Intelligence/Siri AI relies on personal, contextual data to run. Europe wants that same information to be made available to third-party services for competing apps, but has not worked with Apple to protect user confidentiality. It’s an approach that places your data at risk of exfiltration using those apps because Europe is insisting Apple share personal information with the developers of other apps.
The desire to protect that data is why Apple won’t distribute Siri AI in the EU for a while.
Jamf survey exposes the IT risks of AI
It’s not as if Europe doesn’t understand the risk of data leaks in an era of AI. Just look at the bloc’s focus on things that do matter, such as sovereign AI or managed AI services like Orange Live Intelligence. These locally-produced AI services, alongside Europe’s attitude toward them, tell me the confederation understands the risks.
How real are these risks? Very. Jamf on Monday published survey results confirming the scale of that risk, telling us that one-in-five IT and security leaders in the enterprise sector has already experienced an AI-related incident involving unexpected costs, a security issue, or both. The survey also found that:
- 72.9% of organizations have already deployed AI in some form.
- 59.7% see an AI-related incident as a near-term risk.
- Organizations with deeply integrated AI are 40% more likely to report an AI-related incident than organizations still in the exploratory stage.
The implication is that AI governance is becoming an operational requirement and — as Apple has told us umpteen times in the past — the best way to maintain operational confidentiality is not to collect or share any data at all. That’s the whole point of its approach: the data doesn’t need to be shared, it just needs to be turned into another signal that promotes utility while protecting confidentiality.
Crafting trust in a crowded market
There’s another challenge to emerge. There are now multiple brands of AI, with more coming on stream all the time. That’s great in terms of finding a model that suits your needs, but challenging when it comes to ensuring all the services you or your employees use of are equally secure. You don’t want your business to become deeply reliant on any service only for that vendor to subsequently get bought out and/or shut down, nor do you want a service to be hacked or otherwise exploited to your detriment.
“AI isn’t arriving as a single application that IT can approve and move on from,” said Jamf CEO Beth Tschida. “It’s showing up in developer tools, productivity apps, autonomous agents, and other software they already run. The challenge is maintaining visibility and control as that footprint expands.”
The survey described the challenges IT faces with AI deployment: shadow IT, vendor sprawl, and the need to grapple with highly unpredictable use-based pricing models. And that’s even before considering the governance challenges of agentic and developer AI.
AI and the emerging governance nightmare
“What our survey shows is that governance must keep pace with adoption,” Tschida said. “For organizations built on Apple, the foundation is already an advantage. Apple’s privacy model and the management controls built into the platform give IT teams a strong foundation to build on and … that advantage depends on using tools built for Apple from the start.”
That’s the point of the curated, private and secured service offered by Siri AI, of course. It’s also part of what Apple is building toward with its wider ambitions toward AI on its platform. Bloomberg’s Mark Gurman discussed elements of this in his weekend newsletter, in which he suggested Apple might introduce some subscription services using AI, and that it is building an App Store for Siri Extensions, which would allow third-party chatbots to work with Siri.
There is a need for curation and management in AI
What makes that model work is the curation with which Apple surrounds it, and its determination to extend Private Cloud Compute so it can protect your data even when using third-party servers (in this case, Google’s server clusters). It makes sense to think Apple intends to use that system to protect all approved third-parry AI interactions provided across its platforms by its own routes. That’s true, even if users access services free of those safeguards using a web browser, which they currently can.
But the key thing is that if Apple can get this right, offering up a managed, curated, and controllable ecosystem for AI agents and services, it will be going a long way toward building the kind of managed AI ecosystem the Jamf survey shows our modern digital enterprises increasingly need.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to The Core.
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search.
Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Finský startup Donut Lab na veletrhu CES sliboval revoluční sodíkové baterie • Experti však odhalili, že šlo pouze o obyčejný lithium-iontový akumulátor • Firma od drobných investorů podvodem získala zhruba 25 milionů dolarů
Employees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight. Tines explores how CISOs are handling AI-driven code sprawl, shadow tooling, and governance challenges. [...]
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. [...]
Chinese government spies remained hidden in the networks of multiple North American medical and military research organizations for more than a year, deploying custom malware and snooping through Gmail inboxes and stealing sensitive data. This PRC-nexus espionage crew, which Google tracks as UNC6508, used some particularly noteworthy search terms as they were scanning for data to steal. They included such esoteric topics as drone technology and a viral disease that spreads from mosquitoes to humans. “It’s one of the most interesting grocery shopping lists of things to collect that I’ve seen from a state-sponsored actor,” Luke McNamara, deputy chief analyst at Google Threat Intelligence Group, told The Register. “We have defense-related activity, which was a significant bulk of the different terms, or emails related to defense platform systems or companies,” McNamara said. “Some of those were looking for any emails that were coming in or going out that used @ and then a big defense name. Others were specific email addresses of individuals at more niche defense companies.” While most of the terms related to defense and technology, the intruders also searched for some medical research facilities – and the very specific pathogen, “Chikungunya,” a viral disease transmitted to humans from mosquitoes that was responsible for an outbreak in China's Guangdong province in July 2025. Google won’t say how many organizations were compromised in this campaign. A Monday report said the operation targeted several national, state, and private medical entities. “These organizations comprise world-renowned clinical providers, premier academic centers, North American military health institutions, professional advocacy groups, and health regulatory bodies,” according to the report. “Their research areas span a broad spectrum of modern medicine, from molecular discovery and clinical drug trials to state-level public health policy and military readiness.” McNamara told us that the tech company’s incident responders notified all the victims they identified, “and we suspect there's probably even more.” Incident responders first detected this campaign in early 2025, but told us it dates back to at least 2023. And all of these attacks began with the digital intruders somehow exploiting externally facing REDCap (Research Electronic Data Capture) servers. These servers are primarily used by universities, hospitals, and research institutions to build and manage online databases and surveys, and to store sensitive clinical research data. The earliest known intrusion happened in September 2023, when UNC6508 compromised a REDCap server belonging to a North American medical research institution. McNamara told us that all of the intrusions followed this same pattern. Seeing (Infinite)Red After three months, the snoops silently deployed custom malware named InfiniteRed to capture legitimate REDCap login credentials. The malware includes three modular components. The first allows it to maintain persistent remote access by injecting its code into new REDCap versions after intercepting the upgrade process. Then it injects a credential harvester into the authentication system file to compromise user accounts. Finally, it functions as a backdoor with custom hooks that executes on every REDCap page load. Google’s threat intelligence team identified “multiple” US and Canada-based organizations infected with InfiniteRed, and offered assistance with removing the malware. After remaining undetected for more than a year, UNC6508 used the stolen credentials to access admin accounts and the victims’ internal network. Finally, the attackers added sneaky domain content compliance rules for data theft. All 'Patroit' themed emails sent to BebitaBarefoot774 Content compliance rules are legitimate features in many cloud-based enterprise productivity suites - like Google Workspace - to exfiltrate specific email communications. Administrators can create these rules to manage messages that contain predefined sets of words or phrases, and these rules apply to all of the users in an organizational unit. UNC6508 created a compliance rule named "Patroit" (yes, they misspelled “Patriot”) to match keywords and email address patterns in sent or received emails. These messages were then silently BCC-forwarded to an attacker-controlled Gmail address, BebitaBarefoot774[@]gmail[.]com, delivering a steady stream of geo-strategic policy, military strategy, advanced technology, and medical research emails to the PRC-linked crew. The search terms also included professional email addresses and phone numbers for members of organizations in these spaces. GTIG disabled the Gmail account to prevent further data exfiltration. “One of the questions that we've had internally around this is: We're seeing this show up primarily at medical research institutions,” McNamara said. “Why are they searching for things like unmanned drones and unmanned vehicles? Why would you expect to find that there?” One theory, he said, is that this particular threat group was tasked with collecting data across different categories of national-security-related terms and information. “Maybe they were copy-and-pasting this across multiple victims, including ones outside of this medical research space?” Plus, some of the targeted institutions were likely working on research with a military or government agency connection. “So there was a potential that they could be in correspondence with someone where one of these terms showed up, and the actors were casting a very wide net,” McNamara said.®
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod.
This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point.
Scroll through the full Monday Cybersecurity Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
A wave of malicious commits hit the Arch User Repository (AUR) over the weekend, prompting the team to disable new account registration on Monday morning while it cleans up the mess. The issue was first acknowledged on June 12, with a post stating: "We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository." The team warned that users might have issues opening new accounts, pushing package updates, and adopting or creating fresh packages. Around 400 user-submitted packages were believed compromised; that figure climbed past 1,500 over the weekend. On June 14, a more sophisticated wave of malicious packages was spotted. The Arch Linux team this morning disabled new account registration "while we are working on the cleanup." The core Arch distribution itself is unaffected. The AUR is a community-run package repo – if something isn't in the official repo, it's probably here, assuming nobody's poisoned it. The AUR is user-submitted and unsupported, so users are expected to inspect package build files themselves before installation. The malicious packages attempted to pull in hostile JavaScript dependencies, including npm packages identified in the campaign. Arch Linux is a fast, lightweight Linux distribution. It isn't for beginners – users need to pick their own display manager and desktop environment as well as their own applications. However, this makes it highly customizable. The project's website says: "Currently we have official packages optimized for the x86-64 architecture. We complement our official package sets with a community-operated package repository that grows in size and quality each and every day." Unless, of course, miscreants go wild with malicious commits, and the team has to wade in to deal with the problem. According to the AUR, there are just over 107,000 packages, with 5,586 updated and 273 packages added in the past seven days. This isn't Arch Linux's first brush with trouble. In 2025, the project was hit with a Distributed Denial of Service (DDoS) attack that disrupted its main web page, the AUR, and the project's forums. It also had to address compromised browser packages that reportedly contained a Remote Access Trojan. Both incidents highlight risks in the way the AUR is structured and maintained. It's an invaluable library of packages led by a community of smart Arch users, yet that open, community-driven model can be abused by attackers. New account creation remains disabled at the time of writing. The Arch team will no doubt be pondering how to avoid this situation in the future. ®
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]
WhatsApp se musí bezplatně otevřít cizím AI chatbotům. • Jde o předběžné opatření Evropské komise, která vede antimonopolní vyšetřování. • Metě hrozí pokuta až do výše 10 % jejího ročního obratu.
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]
Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times. [...]
Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe.
That usually means sharing a temporary "first-day" password so employees can access systems for the first time. The issue is that these passwords don't always stay temporary. They may be sent over email or SMS, reused across accounts, [email protected]
Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family.
The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Je malá, praktická a už s ní nebudete muset shánět kabel – jeden USB-C má totiž integrovaný. Powerbanka AlzaPower Urban 10000mAh Power Delivery (22,5W) se běžně prodává za 599 Kč, teď je ale bílá varianta v rámci Alza dnů o čtvrtinu levněji, stojí 449 Kč. Levněji ještě nebyla.
Abyste ...
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites.
When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger itSwati Khandelwalhttp://www.blogger.com/profile/ [email protected]
|