Toggle light / dark theme

Organizations that rely solely on interactive sign-in monitoring are likely blind to these attacks and its risks, which include account takeovers, business disruption, lateral movement, multifactor authentication (MFA) invasion, and conditional access policies (CAP) bypass potential.

“For organizations heavily reliant on Microsoft 365, this attack is a wake-up call,” said Darren Guccione, CEO and co-founder at Keeper Security, in an emailed statement to Dark Reading. “Robust cybersecurity isn’t just about having MFA — it’s about securing every authentication pathway. A password manager enforces strong, unique credentials while minimizing exposure to credential-based attacks. For noninteractive authentication, privileged access management (PAM) is essential, ensuring least-privilege access, regular credential rotation, and real-time monitoring of service accounts.”

As for the threat actors, the researchers believe that it is likely a Chinese-affiliated group, though this theory remains unconfirmed.

In today’s AI news, Meta, the parent company of Facebook, and other leading social media platforms, is looking to raise as much as $35 Billion to build data centers in the US. Apollo Global Management Inc., an alternative asset manager has discussed providing a major part of the financing, said the people, who asked not to be identified. KKR & Co. is also a part of the investor group.

In other advancements, With so much software now getting written by AI, having a window into its security can be a challenge. That’s the premise of Archipelo, a San Francisco-based cybersecurity startup that is today emerging from stealth with $12 Million in funding. Archipelo’s pitch is that it has a platform for “Developer Security Posture Management” (DevSPM).

S integration with Suno, you can turn simple, creative requests into songs. ‘ + And, In its annual letter, payments giant Stripe declared that it was “seeing an AI boom” with its data, revealing that artificial intelligence startups are growing more rapidly than traditional SaaS companies have historically. In a chart, Stripe showed that the top 100 AI companies were able to achieve $5 million in annualized revenue in 24 months in 2024 compared to the top 100 SaaS companies taking 37 months.

In videos, ever wondered how to enhance your AI performance? IBM’s Susan Eickhoff shows how to boost AI performance using an ensemble of models, combining traditional AI and large language models. Learn structured data analysis and dynamic prediction methods.

And, since its launch in 2020, Project Aria has propelled research across the world to advance the state of the art in machine perception and AI, through access to cutting-edge research hardware and open-source datasets, models, and tooling. Today, Meta is excited to announce the next step in this journey: the introduction of Aria Gen 2 glasses.

Scientists in Switzerland have developed a new method to improve internet security against quantum computing attacks, using quantum-resistant encryption and a new type of hardware.

Maybe it’s a life hack or a liability, or a little of both. A surprising result in a new MIT study may suggest that people and animals alike share an inherent propensity to keep updating their approach to a task even when they have already learned how they should approach it, and even if the deviations sometimes lead to unnecessary error.

The behavior of “exploring” when one could just be “exploiting” could make sense for at least two reasons, says Mriganka Sur, senior author of the study published Feb. 18 in Current Biology. Just because a task’s rules seem set one moment doesn’t mean they’ll stay that way in this uncertain world, so altering behavior from the optimal condition every so often could help reveal needed adjustments. Moreover, trying new things when you already know what you like is a way of finding out whether there might be something even better out there than the good thing you’ve got going on right now.

“If the goal is to maximize reward, you should never deviate once you have found the perfect solution, yet you keep exploring,” says Sur, the Paul and Lilah Newton Professor in The Picower Institute for Learning and Memory and the Department of Brain and Cognitive Sciences at MIT. “Why? It’s like food. We all like certain foods, but we still keep trying different foods because you never know, there might be something you could discover.”

An Android malware app called SpyLend has been downloaded over 100,000 times from Google Play, where it masqueraded as a financial tool but became a predatory loan app for those in India.

The app falls under a group of malicious Android applications called “SpyLoan,” which pretend to be legitimate financial tools or loan services but instead steal data from devices for use in predatory lending.

These apps lure users with promises of quick and easy loans, often requiring little documentation and offering attractive terms. However, upon installation, they request excessive permissions, allowing the apps to steal personal data such as contacts, call logs, SMS messages, photos, and device location.