Menu

Blog

Archive for the ‘cybercrime/malcode’ category: Page 147

Jul 14, 2020

Microsoft warns of critical Windows DNS Server vulnerability that’s “wormable”

Posted by in category: cybercrime/malcode

Microsoft is urging system administrators to urgently install updates to fix a 17-year-old Windows DNS Server vulnerability. Microsoft has rated the flaw at the highest level for remote code execution, but exploits haven’t yet been developed.

Jul 14, 2020

DARPA: Hack Our Hardware

Posted by in category: cybercrime/malcode

DARPA is running a bug bounty aimed at further hardening new malware-proof architectures.

Jul 9, 2020

PQShield raises $7M for quantum-ready cryptographic security solutions

Posted by in categories: cybercrime/malcode, quantum physics

A deep tech startup building cryptographic solutions to secure hardware, software, and communications systems for a future when quantum computers may render many current cybersecurity approaches useless is today emerging out of stealth mode with $7 million in funding and a mission to make cryptographic security something that cannot be hackable, even with the most sophisticated systems, by building systems today that will continue to be usable in a post-quantum future.

PQShield (PQ being short for “post-quantum”), a spin out from Oxford University, is being backed in a seed round led by Kindred Capital, with participation also Crane Venture Partners, Oxford Sciences Innovation and various angel investors, including Andre Crawford-Brunt, Deutsche Bank’s former global head of equities.

PQShield was founded in 2018, and its time in stealth has not been in vain.

Jul 9, 2020

Researchers determine how to accurately pinpoint malicious drone operators

Posted by in categories: cybercrime/malcode, drones, encryption, robotics/AI

Researchers at Ben-Gurion University of the Negev (BGU) have determined how to pinpoint the location of a drone operator who may be operating maliciously or harmfully near airports or protected airspace by analyzing the flight path of the drone.

Drones (small commercial unmanned ) pose significant security risks due to their agility, accessibility and low cost. As a result, there is a growing need to develop methods for detection, localization and mitigation of malicious and other harmful aircraft operation.

The paper, which was led by senior lecturer and expert Dr. Gera Weiss from BGU’s Department of Computer Science, was presented at the Fourth International Symposium on Cyber Security, Cryptography and Machine Learning (CSCML 2020) on July 3rd.

Jul 9, 2020

DARPA Announces First Bug Bounty Program to Hack SSITH Hardware Defenses

Posted by in categories: cybercrime/malcode, internet, mobile phones, robotics/AI

Electronic systems – from the processors powering smartphones to the embedded devices keeping the Internet of Things humming – have become a critical part of daily life. The security of these systems is of paramount importance to the Department of Defense (DoD), commercial industry, and beyond. To help protect these systems from common means of exploitation, DARPA launched the System Security Integration Through Hardware and Firmware (SSITH) program in 2017. Instead of relying on patches to ensure the safety of our software applications, SSITH seeks to address the underlying hardware vulnerabilities at the source. Research teams are developing hardware security architectures and tools that protect electronic systems against common classes of hardware vulnerabilities exploited through software.

To help harden the SSITH hardware security protections in development, DARPA today announced its first ever bug bounty program called, the Finding Exploits to Thwart Tampering (FETT) Bug Bounty. FETT aims to utilize hundreds of ethical researchers, analysts, and reverse engineers to deep dive into the hardware architectures in development and uncover potential vulnerabilities or flaws that could weaken their defenses. DARPA is partnering with the DoD’s Defense Digital Service (DDS) and Synack, a trusted crowdsourced security company on this effort. In particular, FETT will utilize Synack’s existing community of vetted, ethical researchers as well as artificial intelligence (AI) and machine learning (ML) enabled technology along with their established vulnerability disclosure process to execute the crowdsourced security engagement.

Bug bounty programs are commonly used to assess and verify the security of a given technology, leveraging monetary rewards to encourage hackers to report potential weaknesses, flaws, or bugs in the technology. This form of public Red Teaming allows organizations or individual developers to address the disclosed issues, potentially before they become significant security challenges.

Jul 9, 2020

Cyber Command will get a new version of its training platform this fall

Posted by in categories: cybercrime/malcode, health

U.S. Cyber Command’s new training platform is slated to deliver the second iteration this fall providing additional capabilities and user capacity, program officials said.

The Persistent Cyber Training Environment (PCTE) is an online client that allows Cyber Command’s warriors to log on from anywhere in the world to conduct individual or collective cyber training as well as mission rehearsal. The program is being run by the Army on behalf of the joint cyber force and Cyber Command.

Officials delivered the first version of the program to Cyber Command in February and the environment was used for the first time in Cyber Command’s premier annual tier 1 exercise Cyber Flag in June. The second version is expected to include additional capabilities, including allowing more users to conduct team or individual training.

Jul 8, 2020

Examining trapped ion technology for next generation quantum computers

Posted by in categories: biotech/medical, cybercrime/malcode, internet, quantum physics

:3333


Quantum computers (QC) are poised to drive important advances in several domains, including medicine, material science and internet security. While current QC systems are small, several industry and academic efforts are underway to build large systems with many hundred qubits.

Towards this, computer scientists at Princeton University and physicists from Duke University collaborated to develop methods to design the next generation of quantum computers. Their study focused on QC systems built using trapped ion (TI) technology, which is one of the current front-running QC hardware technologies. By bringing together computer architecture techniques and device simulations, the team showed that co-designing near-term hardware with applications can potentially improve the reliability of TI systems by up to four orders of magnitude.

Continue reading “Examining trapped ion technology for next generation quantum computers” »

Jun 29, 2020

Cynet raises $18 million for AI safeguards against cyberthreats

Posted by in categories: cybercrime/malcode, finance, robotics/AI

Cynet, a cybersecurity startup that leverages AI and machine learning to detect threats, has raised $18 million in venture capital.

Jun 29, 2020

Suspected Cyberattack Disrupts Israel Philharmonic Orchestra Virtual Gala

Posted by in category: cybercrime/malcode

A replay of the gala can be seen on YouTube.

Jun 28, 2020

Your Personal Data Is Worth Money. Andrew Yang Wants to Get You Paid

Posted by in categories: cybercrime/malcode, economics, robotics/AI

Last year’s Netflix movie The Great Hack detailed the dark side of data collection, centered around the 2016 Cambridge Analytica scandal. The movie describes how “psychometric profiles” exist for you, me, and all of our friends. The data collected from our use of digital services can be packaged in a way that gives companies insight into our habits, preferences, and even our personalities. With this information, they can do anything from show us an ad for a pair of shoes we’ll probably like to try to change our minds about which candidate to vote for in an election.

With so much of our data already out there, plus the fact that most of us will likely keep using the free apps we’ve enjoyed for years, could it be too late to try to fundamentally change the way this model works?

Continue reading “Your Personal Data Is Worth Money. Andrew Yang Wants to Get You Paid” »