Skip to main content

Posts

Showing posts with the label Cybersecurity

Skynet? Not Quite -But Closer Than You'd Think

  AI ‑ Native Malware: The Emerging Reality Behind Adaptive Cyber Threats As AI becomes woven into everyday tools and workflows, the cyber threat landscape is evolving alongside it. One of the most significant shifts is the emergence of AI ‑ native malware malicious software that doesn ’ t just use AI during development but actively integrates AI models into its runtime behaviour. This isn’t science fiction anymore. While we’re not facing a fully autonomous “Skynet” scenario, recent discoveries show that adaptive, AI ‑ driven malware is already operating in the wild. The question is no longer if AI ‑ native malware will exist, but how quickly it will mature and what that means for defenders.   What Makes Malware “AI ‑ Native ” ? AI ‑ Assisted Malware Traditional malware created with help from AI tools such as LLMs. Attackers may use AI to: • Write phishing content • Generate exploit code • Speed up reconnaissance But the malware itself behaves conventionall...

Fortinet Switches: The Patch You Can't Ignore

  Introduction Looking online this time at the hacker news a website I like for cyber security news articles. I find them to be clear and concise. Which is where   I found this article ( Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw ) on a vulnerability in Fortinet switches. The Vulnerability A vulnerability with a 9.3 out of 10 CVSS score, the CVE can be found here ( https://nvd.nist.gov/vuln/detail/CVE-2024-48887 ). A 9.3 CVSS score indicates a critical vulnerability with severe risks, including unauthorized access, system compromise, and service disruptions. Immediate action is crucial for mitigation. Prompt patch management is necessary to protect infrastructure integrity and safeguard clients and stakeholders who depend on secure and reliable services. The article identifies a vulnerability in the switches, where an attacker can alter the administrative password through a specifically crafted request. What is being done For...