Menu

Blog

Page 2

Jan 15, 2025

Microsoft Uncovers macOS Vulnerability CVE-2024–44243 Allowing Rootkit Installation

Posted by in categories: cybercrime/malcode, mobile phones

Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as “root” to bypass the operating system’s System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions.

The vulnerability in question is CVE-2024–44243 (CVSS score: 5.5), a medium-severity bug that was addressed by Apple as part of macOS Sequoia 15.2 released last month. The iPhone maker described it as a “configuration issue” that could permit a malicious app to modify protected parts of the file system.

“Bypassing SIP could lead to serious consequences, such as increasing the potential for attackers and malware authors to successfully install rootkits, create persistent malware, bypass Transparency, Consent and Control (TCC), and expand the attack surface for additional techniques and exploits,” Jonathan Bar Or of the Microsoft Threat Intelligence team said.

Jan 15, 2025

Google OAuth Vulnerability Exposes Millions via Failed Startup Domains

Posted by in category: sustainability

Attackers exploit a Google OAuth flaw, recycling domains to access SaaS accounts and sensitive HR data.

Jan 15, 2025

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites

Posted by in category: cybercrime/malcode

A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data.

Researchers at webscript security company c/side discovered during an incident response engagement for one of their clients that the malicious activity uses the wp3[.]xyz domain to exfiltrate data but have yet to determine the initial infection vector.

After compromising a target, a malicious script loaded from the wp3[.]xyz domain creates the rogue admin account wpx_admin with credentials available in the code.

Jan 15, 2025

Google OAuth flaw lets attackers gain access to abandoned accounts

Posted by in category: security

A weakness in Google’s OAuth “Sign in with Google” feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms.

The security gap was discovered by Trufflesecurity researchers and reported to Google last year on September 30.

Continue reading “Google OAuth flaw lets attackers gain access to abandoned accounts” »

Jan 15, 2025

OpenAI Urges the Government to Make it Easier to Train AI

Posted by in categories: government, robotics/AI

The company also called for federal regulations and billions of dollars in investments.

Jan 14, 2025

Zuckerberg Announces Plans to Automate Facebook Coding Jobs With AI

Posted by in categories: employment, robotics/AI

Meta CEO Mark Zuckerberg said that the company will likely release an AI model that acts as a “midlevel engineer” this year.

Jan 14, 2025

Single Gene Links Autism, Epilepsy via Brain Circuit Development

Posted by in categories: genetics, neuroscience

New research uncovers how neuropilin2 gene mutations disrupt brain balance, linking inhibitory neuron migration to autism and epilepsy. Study offers insights for targeted therapies.


Source: UCR

The gene neuropilin2 encodes a receptor involved in cell-cell interactions in the brain and plays a key role in regulating the development of neural circuits.

Continue reading “Single Gene Links Autism, Epilepsy via Brain Circuit Development” »

Jan 14, 2025

New facility could allow humans to freeze their bodies and outlive an apocalypse

Posted by in categories: cryonics, life extension, robotics/AI

Imagine you could pause your life and wake up in the future.

A new groundbreaking facility could allow humans to freeze their bodies and potentially wake up in the future.

The company behind the project, TimeShift, describes itself as the world’s first AI-powered cryopreservation facility. It combines advanced AI technology with novel cryopreservation techniques.

Jan 14, 2025

How should we test AI for human-level intelligence? OpenAI’s O3 electrifies quest

Posted by in category: robotics/AI

Experimental model’s record-breaking performance on science and maths tests wows researchers.

Jan 14, 2025

Stanford scientist discovers that AI has developed an uncanny human-like ability

Posted by in categories: innovation, robotics/AI

AI models, like ChatGPT-4, can simulate human-like reasoning by solving theory of mind tasks. This breakthrough suggests AI’s potential for advanced social interactions but raises ethical concerns about trust and misuse.

Page 2 of 12,35712345678Last