Insights, updates, and deep dives into cybersecurity, cloud technology, and AI innovation.

According to a recent report, Apple has pledged to deliver security updates to iPhones for a minimum of five years after their release. This commitment strengthens Apple's reputation for providing long-lasting software support for its devices.

Fog, a new ransomware operation, has been targeting educational organizations in the US since early May 2024. This ransomware gains access to victim networks through compromised VPN credentials, highlighting the importance of strong VPN security.Â

European banks are facing a significant rise in ATM malware attacks. This malicious software targets ATMs, allowing criminals to steal cash directly from the machines. Security researchers have identified a specific strain called "DispenserSpitter" capable of manipulating the ATM's cash dispensing mechanism.

A new report reveals a concerning issue within the public sector: a growing security debt. This term refers to the backlog of unpatched vulnerabilities and outdated systems plaguing government agencies and critical infrastructure.

The BlackSuit ransomware gang has leaked stolen data from attacks against 53 organizations spanning a year, particularly in the education and industrial goods sectors. This targeted approach suggests they're aiming to maximize profits by hitting businesses more likely to pay high ransoms. Their success is linked, in part, to exploiting weak security measures.

GitLab recently addressed two critical security vulnerabilities. The first, patched in May 2024 (CVE-2024-4835), is a high-severity flaw in the VS code editor that allows attackers to steal sensitive information through malicious web pages.

There's a rising security risk with customer chatbots, especially those built on readily available general-purpose AI engines. While these chatbots are convenient to develop, securing them is a challenge, as a recent incident demonstrates. In January 2024, a researcher managed to manipulate a chatbot into bad-mouthing its own company.
Apple and Google are joining forces to combat unwanted Bluetooth tracking. A new feature, "Detecting Unwanted Location Trackers," has begun rolling out on iOS 17.5 and Android 6.0+ devices.

Scammers are capitalizing on DocuSign's popularity to launch phishing attacks against businesses. A black market thrives for fake DocuSign templates and login credentials, making it easier for attackers to build convincing scams. Phishing emails disguised as DocuSign requests are on the rise.