News
IT governance
-
May 03, 2024
03
May'24
EU calls out Fancy Bear over attacks on Czech, German governments
The European Union, alongside member states Czechia and Germany, have accused Russian government APT Fancy Bear of being behind a series of attacks on political parties and government bodies
-
May 03, 2024
03
May'24
Lords say government must ‘go beyond’ current approach to LLMs
Chair of the Lords Communications and Digital Committee has written to the UK’s digital secretary about the government’s approach to generative AI, lamenting a lack of support for copyright holders and measures to ensure competition in AI markets
-
May 02, 2024
02
May'24
NCSC updates warning over hacktivist threat to CNI
The NCSC and CISA have warned about the evolving threat from Russia-backed hacktivist threat actors targeting critical national infrastructure, after a number of American utilities were attacked
-
May 02, 2024
02
May'24
Ukrainian national sentenced over REvil ransomware spree
A 24-year-old Ukrainian man has been sentenced to more than 13 years in prison after being convicted of his role in the REvil ransomware attacks
-
May 02, 2024
02
May'24
Dropbox Sign user information accessed in data breach
Account data belonging to Dropbox Sign users was accessed by an unknown threat actor after they hacked into the organisation’s backend infrastructure
-
May 01, 2024
01
May'24
EMEA CISOs must address human factors behind cyber incidents
The 17th annual Verizon report on data breaches makes for sobering reading for security pros, urging them to do more to address the human factors involved in cyber incidents, and highlighting ongoing issues with zero-day patching
-
May 01, 2024
01
May'24
Australia’s Qantas apologises for mobile app data breach
Australian flag carrier Qantas has apologised after a glitch in its mobile application temporarily enabled some customers to view the flights and booking details of other frequent fliers on two separate occasions
-
May 01, 2024
01
May'24
Autonomous weapons reduce moral agency and devalue human life
Military technology experts gathered in Vienna have warned about the detrimental psychological effects of AI-powered weapons, arguing that implementing systems of algorithmic-enabled killing dehumanises both the user and the target
-
April 30, 2024
30
Apr'24
Persistent data breaches deny people with HIV dignity and privacy
The ICO has urged charities and healthcare organisations that work with people living with HIV to do better when it comes to protecting their personal data, after the HIV status of more than 100 people was accidentally disclosed by London’s Central ...
-
April 30, 2024
30
Apr'24
Keeper to help Williams F1 keep up with cyber challenges
Keeper Security signs up to support F1 team Williams Racing with credential management ahead of the 2024 Miami Grand Prix
-
April 30, 2024
30
Apr'24
Global majority united on multilateral regulation of AI weapons
Foreign ministers and civil society representatives say that multilateralism is key to controlling the proliferation and use of AI-powered autonomous weapons, but that a small number of powerful countries are holding back progress
-
April 26, 2024
26
Apr'24
European Parliament approves platform worker directive
The approval of the platform worker directive gives member states two years to incorporate its measures into their national legislation, which includes provisions on how to classify the employment of gig workers and deploy algorithmic ...
-
April 25, 2024
25
Apr'24
Progress being made on gender diversity in cyber
Women make up a higher percentage of new entrants to the cyber security profession, particularly among younger age groups, and are increasingly taking up leadership positions and hiring roles, but challenges still persist
-
April 24, 2024
24
Apr'24
Education will be key to good AI regulation: A view from the USA
Computer Weekly sat down with Salesforce’s vice-president of federal government affairs, Hugh Gamble, to find out how the US is forging a path towards AI regulation, and how things look from Capitol Hill
-
April 23, 2024
23
Apr'24
GooseEgg proves golden for Fancy Bear, says Microsoft
Microsoft’s threat researchers have uncovered GooseEgg, a never-before-seen tool being used by Forest Blizzard, or Fancy Bear, in conjunction with vulnerabilities in Windows Print Spooler
-
April 23, 2024
23
Apr'24
Lords split over UK government approach to autonomous weapons
During a debate on autonomous weapons systems, Lords expressed mixed opinions towards the UK government’s current position, including its reluctance to adopt a working definition and commit to international legal instruments controlling their use
-
April 22, 2024
22
Apr'24
Government provides funding to help innovators navigate regs
AI and Digital Hub, backed by almost £2m in funding, will coordinate regulatory advice across CMA, FCA, ICO and Ofcom
-
April 22, 2024
22
Apr'24
IT leaders hiring CISOs aplenty, but don’t fully understand the role
Most businesses now have a CISO, but perceptions of what CISOs are supposed to do, and confusion over the value they offer, may be holding back harmonious relations, according to a report
-
April 19, 2024
19
Apr'24
Tech companies operating with opacity in Israel-Palestine
Tech firms operating in Occupied Palestinian Territories and Israel are falling “woefully short” of their human rights responsibilities amid escalating devastation in Gaza, says Business & Human Rights Resource Centre
-
April 18, 2024
18
Apr'24
TUC publishes legislative proposal to protect workers from AI
Proposed bill for regulating artificial intelligence in the UK seeks to translate well-meaning principles and values into concrete rights and obligations that protect workers from systems that make ‘high-risk’ decisions about them
-
April 17, 2024
17
Apr'24
Mandiant formally pins Sandworm cyber attacks on APT44 group
Mandiant has formally attributed a long-running campaign of cyber attacks by a Russian state actor known as Sandworm to a newly designated advanced persistent threat group to be called APT44
-
April 16, 2024
16
Apr'24
CISOs not yet convinced to invest in AI
CISOs say their eyes are fixed firmly on threats like ransomware and supply chain attacks, and while AI is becoming a threat that needs to be dealt with, it’s not yet an immediate spending priority
-
April 15, 2024
15
Apr'24
More social engineering attacks on open source projects observed
In the wake of the recent XZ Utils scare, maintainers of another open source project have come forward to say they may have experienced similar social engineering attacks
-
April 15, 2024
15
Apr'24
EU’s AI Act fails to protect the rule of law and civic space
Analysis reveals that the AI Act is ‘riddled with far-reaching exceptions’ and its measures to protect fundamental rights are insufficient
-
April 12, 2024
12
Apr'24
Apple iPhone security alert renews spyware concerns
An Apple security alert received by users in 92 countries raises fresh fears over ongoing campaigns by users of mercenary spyware products
-
April 11, 2024
11
Apr'24
Facial recognition to play key role in UK shoplifting crackdown
UK government will fund roll-out of police facial recognition across the country as part of its crackdown on shoplifting and violence against retail staff, but civil society groups say the government is attempting to police its way out of the ...
-
April 11, 2024
11
Apr'24
Former Post Office executive’s neglect prolonged Horizon reliability myth
Executive’s failure to provide terms of reference for a controversial Post Office investigation into its own computer system resulted in a one-sided whitewash report
-
April 11, 2024
11
Apr'24
AI skills gap blocking public sector take-up
A Salesforce report claims that a lack of skills in artificial intelligence is preventing effective take-up of generative AI to enhance frontline citizen services across the public sector
-
April 11, 2024
11
Apr'24
CMA set to tackle interconnected web of strategic AI partnerships
Google, Apple, Microsoft, Meta, Amazon and Nvidia are all collaborating on AI foundation models, potentially to the detriment of fair, open and effective competition
-
April 11, 2024
11
Apr'24
Government dismisses Lords’ concerns over facial recognition
UK government is claiming police forces’ use of live facial recognition is comprehensively covered by existing laws, in response to a Lords investigation that found police lacked a clear legal basis to deploy it
-
April 10, 2024
10
Apr'24
Cyber crooks poison GitHub search to fool developers
Researchers share data on new technique whereby malicious actors are manipulating GitHub’s search function and using cleverly crafted repositories to distribute malware
-
April 10, 2024
10
Apr'24
Salesforce helps customers establish bug bounty programmes
Salesforce has added new learning content to its Trailhead platform designed to help customers develop their own bug bounty programmes
-
April 09, 2024
09
Apr'24
UK plc failing on multiple cyber measures
Government report shows 50% of businesses and 32% of charities reported a cyber attack or breach in the past 12 months and organisations across the UK are failing on multiple cyber measures
-
April 09, 2024
09
Apr'24
Public worried by police and companies sharing biometric data
More than half of the British public do not feel comfortable with police forces sharing biometric data with the private sector, including facial recognition images, to tackle crimes such as shoplifting
-
April 09, 2024
09
Apr'24
Is a cyber arms control treaty out of reach?
The world needs cyber arms control more than ever, but the challenges facing a multilateral agreement will be hard to surmount, according to researchers at Germany’s Digital Society Institute
-
April 09, 2024
09
Apr'24
Government struggles to upgrade legacy IT systems, says PAC chair
In her annual report, Public Accounts Committee chair Meg Hillier calls legacy IT one of government’s ‘big nasties’ and says money urgently needs to be spent to fix the situation
-
April 09, 2024
09
Apr'24
Greek government fined over AI surveillance in refugee camps
Greece’s Data Protection Authority has issued a €175,000 fine against the country’s migration ministry over its deployment of artificial intelligence-powered security systems in refugee camps after the watchdog’s investigation found ‘serious ...
-
April 08, 2024
08
Apr'24
UK vet network CVS hit by cyber attack
Operations at UK-based veterinary network CVS have been disrupted by a cyber incident of an as-yet undisclosed nature
-
April 08, 2024
08
Apr'24
UN adopts ‘landmark’ resolution on making AI safe and trustworthy
A UN draft resolution promoting the use of artificial intelligence in sustainable development and the protection of human rights was backed by over 120 member states
-
April 03, 2024
03
Apr'24
RDP abused in over 90% of cyber attacks, Sophos finds
Threat actors continue to see great success using simple, tried and tested methods, and many defenders are failing to do the basics
-
April 03, 2024
03
Apr'24
Fujitsu staff instructed how to bid for government contracts during self-imposed ban
Leak reveals how Fujitsu advises staff to approach UK government customers during its self-imposed bidding pause, as well as details of a multimillion-pound project to protect its reputation
-
April 02, 2024
02
Apr'24
Risks and rewards of AI in HCM
Research from Citi Commercial Bank warns of the risks associated with overusing AI in human capital management
-
April 01, 2024
01
Apr'24
Open source alert over intentionally placed backdoor
A backdoor in the open source XZ Utils data compression library could have led to widespread compromise across the Linux ecosystem - and the community is on the trail of a developer who seems to be behind it
-
March 29, 2024
29
Mar'24
Organisations getting better at spotting identity fraud
As the barriers to committing identity fraud continue to drop, organisations should consider more sophisticated technical measures to successfully up their game, according to a report
-
March 28, 2024
28
Mar'24
UK plc going backwards on cyber maturity, Cisco report claims
Fewer UK organisations believe their cyber security postures have reached a mature level than did so 12 months ago, as they struggle to keep up with new challenges and a fast-evolving threat landscape
-
March 28, 2024
28
Mar'24
Sellafield to be prosecuted over alleged cyber compliance failure
Sellafield Ltd, the organisation responsible for cleaning up and decommissioning the UK's largest nuclear waste site, is to be prosecuted over alleged cyber security failings dating back to 2019
-
March 28, 2024
28
Mar'24
Counter-eavesdropping agency unlawfully used surveillance powers to identify journalist’s source
More than 750 journalists had their communications data accessed by law enforcement and government agencies between 2018 and 2022
-
March 27, 2024
27
Mar'24
Ransomware gang leaks data stolen from Scottish NHS board
Data stolen from an earlier attack on NHS Dumfries and Galloway has been leaked by a ransomware gang that claims to be in possession of much more content
-
March 27, 2024
27
Mar'24
Cyber spies, not cyber criminals, behind most zero-day exploitation
Analysis from Google has found that zero-day vulnerabilities are much more heavily exploited for espionage purposes than for financially motivated cyber crime
-
March 27, 2024
27
Mar'24
Lord Holmes: UK cannot 'wait and see' to regulate AI
Legislation is needed to seize the benefits of artificial intelligence while minimising its risks, says Lord Holmes - but the government’s ‘wait and see’ approach to regulation will fail on both fronts