Menu

Blog

Archive for the ‘security’ category: Page 35

May 12, 2023

New Linux kernel NetFilter flaw gives attackers root privileges

Posted by in categories: computing, security

A new Linux NetFilter kernel flaw has been discovered, allowing unprivileged local users to escalate their privileges to root level, allowing complete control over a system.

The CVE-2023–32233 identifier has been reserved for the vulnerability, but a severity level is yet to be determined.

The security problem stems from Netfilter nf_tables accepting invalid updates to its configuration, allowing specific scenarios where invalid batch requests lead to the corruption of the subsystem’s internal state.

May 9, 2023

‘Everybody is worried’: China raids offices of consultancy firm Capvision in widening industry crackdown

Posted by in category: security

China’s state security authorities raided multiple offices of international advisory firm Capvision, state media reported Monday, part of a broader crackdown on the consulting industry as Beijing tightens control over what it considers sensitive information related to national security.

Officers raided Capvision’s office in the eastern city of Suzhou, questioned its employees and searched office devices, a Jiangsu provincial television station reported Monday. The company was a so-called expert network, which connected its clients with people who provided specialist knowledge, largely in mainland China.

The report did not give an exact date of the raid, but said it was part of a coordinated, nationwide operation carried out simultaneously targeting the company’s branches in cities including Beijing, Shenzhen as well as Shanghai, where Capvision was founded in 2006.

May 8, 2023

Threat level AI: NSA encourages use of AI to keep up with foreign adversaries

Posted by in categories: internet, privacy, robotics/AI, security

The intelligence community is mulling over how AI can pose a threat to national security.

The world is captivated by the rise of artificial intelligence (AI) tools like ChatGPT. And they have proved their worth in providing human-like answers to complex questions or even writing a research paper. While there are issues like ‘hallucination’ or grabbing and spouting out incorrect information from the internet, nations are concerned with a more significant issue when it comes to AI.

The intelligence agencies are now mulling over how AI can pose a threat to national security.

Continue reading “Threat level AI: NSA encourages use of AI to keep up with foreign adversaries” »

May 7, 2023

Google is testing a Chrome browser that adds post-quantum encryption

Posted by in categories: encryption, quantum physics, security

Google is using its enormous Chrome browser testing base to help examine the prospect of continuing the security of the digital age into the uncertainty of the quantum one.

May 7, 2023

Quantum lidar prototype acquires real-time 3D images while fully submerged underwater

Posted by in categories: engineering, particle physics, quantum physics, security

For the first time, researchers have demonstrated a prototype lidar system that uses quantum detection technology to acquire 3D images while submerged underwater. The high sensitivity of this system could allow it to capture detailed information even in extremely low-light conditions found underwater.

“This technology could be useful for a wide range of applications,” said research team member Aurora Maccarone, a Royal Academy of Engineering research fellow from Heriot-Watt University in the United Kingdom. “For example, it could be used to inspect underwater installations, such as underwater wind farm cables and the submerged structure of the turbines. Underwater can also be used for monitoring or surveying submerged archaeology sites and for security and defense applications.”

Continue reading “Quantum lidar prototype acquires real-time 3D images while fully submerged underwater” »

May 6, 2023

Dr. Kathryn Huff, Ph.D. — Assistant Secretary, Office of Nuclear Energy, U.S. Department of Energy

Posted by in categories: economics, engineering, government, nuclear energy, physics, policy, security, supercomputing

Advancing Nuclear Energy Science And Technology For U.S. Energy, Environmental And Economic Needs — Dr. Katy Huff, Ph.D. — Assistant Secretary, U.S. Department of Energy Office of Nuclear Energy, U.S. Department of Energy.


Dr. Kathryn Huff, Ph.D. (https://www.energy.gov/ne/person/dr-kathryn-huff) is Assistant Secretary, Office of Nuclear Energy, U.S. Department of Energy, where she leads their strategic mission to advance nuclear energy science and technology to meet U.S. energy, environmental, and economic needs, both realizing the potential of advanced technology, and leveraging the unique role of the government in spurring innovation.

Continue reading “Dr. Kathryn Huff, Ph.D. — Assistant Secretary, Office of Nuclear Energy, U.S. Department of Energy” »

May 5, 2023

Lockheed Martin announces reorganization of its space business

Posted by in categories: business, security, space

WASHINGTON — Lockheed Martin announced May 4 it is consolidating several businesses focused on space into three sectors: Commercial civil space, national security space, and strategic and missile defense.

“With an eye toward the future and building on our current business momentum, these changes position us to deliver end-to-end solutions for today’s mission demands and well into the future,” said Robert Lightfoot, executive vice president of Lockheed Martin Space.

May 4, 2023

Finding XSS in a million websites (cPanel CVE-2023–29489)

Posted by in category: security

Application security issues found by Assetnote.

May 2, 2023

How To Use FinOps As A Tool In The Fight Against Rising Cloud Costs

Posted by in categories: economics, security

Scott Sellers is the co-founder and CEO of Azul, with 30 years of experience as an entrepreneur and executive in the technology industry.

For the first time in a decade, controlling cloud costs has surpassed security as the top cloud management challenge facing IT professionals, according to a survey by Flexera. An Andreessen Horowitz study also said that up to $1 trillion in market capitalization is weighed down by overspending in the cloud. Today, challenging economic conditions, rising costs, increasingly stringent performance SLAs and the need for more resources are squeezing organizations that want to remain in the cloud without overspending.

Many organizations still struggle to connect the dots between the value they deliver via the cloud and the costs required to deliver that value. Without a clear understanding of that basic relationship, it is difficult for teams to hold productive conversations about costs. Engineering departments don’t know what to prioritize; cloud architects lack a direction on designing, developing and managing solutions; product managers face difficulties pricing their solutions; and executives wonder where all the money is going.

Apr 27, 2023

Three ways AI chatbots are a security disaster

Posted by in categories: robotics/AI, security

Greshake hid a prompt on a website that he had created. He then visited that website using Microsoft’s Edge browser with the Bing chatbot integrated into it. The prompt injection made the chatbot generate text so that it looked as if a Microsoft employee was selling discounted Microsoft products. Through this pitch, it tried to get the user’s credit card information. Making the scam attempt pop up didn’t require the person using Bing to do anything else except visit a website with the hidden prompt.

In the past, hackers had to trick users into executing harmful code on their computers in order to get information. With large language models, that’s not necessary, says Greshake.

Page 35 of 148First3233343536373839Last