Cybernews researchers found that 72% of analyzed Android AI apps contained at least one hardcoded secret, with an average of 5.1 secrets leaked per app.
Security researcher Jatin Banga said that certain private Instagram profiles, when accessed from specific mobile devices, embedded links to private photos and their captions within the HTML response.
NTLM, a legacy authentication protocol, has been a persistent vulnerability, susceptible to attacks like NTLM relay, pass-the-hash, PetitPotam, and ShadowCoerce.
New research from BlackFog indicates a widespread adoption of shadow AI among employees, with a significant portion admitting to using unapproved or publicly available AI tools for work.
Linwei Ding, 38, was found guilty on 14 counts, including economic espionage and trade secret theft, for illicitly acquiring confidential data concerning Google's Tensor Processing Units (TPUs), Graphics Processing Units (GPUs), and SmartNIC network interface cards.
FedScoop reports that the Department of Veterans Affairs Office of Inspector General found that the Veterans Health Administration's national cancer testing program had at least one project that did not comply with required security and privacy procedures.
Widely used online dating app Bumble had 30 GB of data claimed to have been stolen by the ShinyHunters hacking group, most of which were internal files obtained from the firm's Google Drive and Slack accounts, according to Cybernews.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.