81% concerned about ChatGPT security and safety risks

0
[ad_1]

ChatGPT may have already hit its public perception wall, according to a Malwarebytes survey that showed high levels of distrust and concern in the tool’s trustworthiness and safety.

Seven months after ChatGPT burst into our lives, it seems the lustre of the chatbot-that’s-going-to-change-everything is starting to fade. A new survey by Malwarebytes exposes deep reservations about ChatGPT, with optimism in startlingly short supply. Of the respondents familiar with ChatGPT:

  • 81% were concerned about possible security and safety risks.
  • 63% don’t trust the information it produces.
  • 51% would like to see work on it paused so regulations can catch up.

The concerns expressed in the survey mirror the trajectory of the news about ChatGPT since its introduction in November 2022.

ChatGPT is a type of Artificial Intelligence (AI) developed by the organization OpenAI. Trained on vast amounts of text data, it can generate human-like responses to prompts or questions. And just in case you don’t know what that means, you should know that the last sentence you read was written by ChatGPT as part of a response to a request to “Describe ChatGPT in a single paragraph.” This is the whole text it generated:

ChatGPT is a powerful language model developed by OpenAI, based on the GPT-3.5 architecture. Trained on vast amounts of text data, it can generate human-like responses to prompts or questions. With its deep learning capabilities, ChatGPT understands context and produces coherent and contextually relevant text. It can assist with various tasks such as answering questions, providing explanations, and offering suggestions. Although it’s not a human and lacks real-time awareness, ChatGPT’s ability to generate text across multiple languages makes it a versatile tool, albeit one that should be cross-verified with reliable sources for accuracy.

When people explored its capabilities in the days and weeks after its launch, it seemed almost miraculous—a wonder tool that could do everything from creating computer programs and replacing search engines, to writing students’ essays and penning punk rock songs. Its release kick-started a race to disrupt everything with AI, and integrate ChatGPT-like interfaces into every conceivable tech product.

But those that know the hype cycle know that the Peak of Inflated Expectations is quickly followed by the Trough of Disillusionment. Predictably, ChatGPT’s rapid ascent was met by an equally rapid backlash as its shortcomings became apparent.

Chief among them is ChatGPT’s propensity to “hallucinate”, the euphemism that data scientists give to untruths created by machine learning models. Perhaps the best example of just how consequential hallucinations can be is Mata v. Avianca, Inc, a court case in which a lawyer found himself in serious hot water after citing numerous non-existent legal cases hallucinated by ChatGPT when he used it as a research tool.

Against that backdrop, Malwarebytes decided to poll its vast pool of newsletter subscribers to see how they felt about ChatGPT, six months after its launch.

Despite all the hype and hooplah surrounding it, only 35% of our tech-savvy respondents agreed with the statement “I am familiar with ChatGPT,” significantly less than the 50% that disagreed.

Those who claimed to be familiar with ChatGPT did not have a rosy outlook. This is what they told us.

Not accurate or trustworthy

The first issue for ChatGPT is that our respondents don’t trust that it’s accurate or trustworthy. Only 12% agreed with the statement “The information produced by ChatGPT is accurate,” while 55% disagreed, a huge discrepancy.

Responses to "The information produced by ChatGPT is accurate" by respondents familiar with ChatGPT
Responses to “The information produced by ChatGPT is accurate” by respondents familiar with ChatGPT

The responses were similarly bleak for the statement “I trust the information produced by ChatGPT,” with only 10% agreeing and a huge 63% disagreeing.

Responses to "I trust the information produced by ChatGPT" by respondents familiar with ChatGPT
Responses to “I trust the information produced by ChatGPT” by respondents familiar with ChatGPT

A risk to security and safety

Not only was ChatGPT seen as untrustworthy, it was also perceived as a negative influence on safety and security, with few seeing it as a tool that will improve safety, and an overwhelming majority seeing it as a source of risk.

51% disagreed with the statement “ChatGPT and other AI tools will improve Internet safety,” dwarfing the tiny percentage that see it as a positive for safety.

Responses to "ChatGPT and other AI tools will improve internet safety" by respondents familiar with ChatGPT
Responses to “ChatGPT and other AI tools will improve internet safety” by respondents familiar with ChatGPT

Worse still, an extraordinary 81% were concerned about the possible security and/or safety risks.

Responses to "I am concerned about the possible security and/or safety risks posed by ChatGPT" by respondents familiar with ChatGPT
Responses to “I am concerned about the possible security and/or safety risks posed by ChatGPT” by respondents familiar with ChatGPT

They aren’t alone. In March a raft of tech luminaries signed a letter that said “We call on all AI labs to immediately pause for at least 6 months the training of AI systems more powerful than GPT-4.” The letter pulled no punches on the “profound risks” posed by “AI systems with human-competitive intelligence”:

Should we let machines flood our information channels with propaganda and untruth? Should we automate away all the jobs, including the fulfilling ones? Should we develop nonhuman minds that might eventually outnumber, outsmart, obsolete and replace us? Should we risk loss of control of our civilization?

The letter calls for the pause to be used to “jointly develop and implement a set of shared safety protocols for advanced AI design and development that are rigorously audited and overseen by independent outside experts.”

We put the idea to our respondents and 52% of those familiar with ChatGPT agreed, while less than half that number disagreed.

Responses to "Work on ChatGPT and other AI tools should be paused until regulations can catch up" by respondents familiar with ChatGPT
Responses to “Work on ChatGPT and other AI tools should be paused until regulations can catch up” by respondents familiar with ChatGPT

Conclusion

Our survey showed that an overwhelming number of respondents familiar with ChatGPT were concerned about the risks it poses to security and safety. They also don’t trust the information it produces, and would like to see a pause in development so that regulation can catch up. What remains to be seen is whether this is simply a singular moment of anxiety or a trend that will persist.

An AI revolution has been gathering pace for a very long time, and many specific, narrow applications have been enormously successful without stirring this kind of mistrust. For example, at Malwarebytes, Machine Learning and AI have been used for years to help improve efficiency, to identify malware, and improve the overall performance of many technologies.

ChatGPT is a different beast though. It is a generalized AI tool that could help or supplant humans across a broad range of knowledge work, from coding and composing songs to making malware and spreading misinformation.

The uncertainty around how ChatGPT will change our lives, and whether it will take our jobs, is compounded by the mysterious way in which it works. It is an unknown quantity to everyone, even its creators. Machine learning models like ChatGPT are “black boxes” with emergent properties that appear suddenly and unexpectedly as the amount of computing power used to create them increases.

Real world emergent properties have included the ability to perform arithmetic, take college-level exams, and identify the intended meaning of words. The ability to perform these tasks could not be predicted from smaller models, and today’s models cannot be used to predict what the next generation of larger models will be capable of.

That leaves us facing a very uncertain future, both individually and collectively. The continuum of view points held by serious commentators ranges—quite literally—from those who think AI is an existential risk to those who think it will save the world. Given the stakes, the caution of our respondents is no surprise.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

TikTok might be your next shopping platform

0
[ad_1]

TikTok has been making great strides as a video-sharing app, but it’s looking to expand. After trying to bring an online shopping experience to the States via live streams, the company is back with another e-commerce idea. According to Semafor (via Engadget) TikTok is working on bringing an online store.

The video-sharing app was able to combine e-commerce and shopping in other markets. Creators would hold live streams, and viewers would be able to buy items that they promote.

This is an interesting idea that the company was looking to bring to the States. However, it was not able to gain much traction. The company swiftly discontinued this initiative.

Now, TikTok could bring an online store

According to the report, TikTok is readying to launch a dedicated online store for the US audience. The company already has tried e-commerce initiatives in the past, but this one will be different. Before, TikTok would just link customers to other stores where they could buy products. Those stores would handle the shipping and handling of the item.

For this new TikTok store, all of that will be handled by TikTok. There is even talk about TikTok planning on developing fulfillment centers so that it could handle the products. This would put TikTok in competition with services like Amazon and eBay.

At this point, there’s still a lot of information in the air. We’re not sure what kind of items we should expect from the store. We can expect TikTok-branded merchandise, of course. While that may be the case, we can’t rule out the company partnering with different brands to sell their items on the platform. Who knows if TikTok will partner with small businesses as well?

We’re also not sure when the company is going to launch this store. The rumor has it that it could launch as soon as next month. That’s not a long time to wait seeing as it’s already June 28th.

TikTok will be launching this store on shaky ground. The company is still at war with the American government. The US is still pushing to ban the app over national security concerns. We’ll just have to wait to see how this pans out.


[ad_2]
Source link

Samsung is coursing nicely to produce 2nm chips in 2025

0
[ad_1]

Samsung has announced that it is on track to begin mass production of 2nm semiconductor chips for mobile processors in 2025. The company plans to manufacture 2nm chips for HPC (High-Performance Computing) in 2026 and automotive applications in 2027. It will also start producing 1.4nm chips in 2027.

The Korean tech giant is the world’s second-largest semiconductor foundry after TSMC. Both firms started producing 3nm chips last year and have long planned to move to 2nm solutions in 2025. At its 6th annual Samsung Foundry Forum last year, Samsung shared its semiconductor roadmap for the next five years. The roadmap included improvements for 3nm chips as well as production plans for 2nm and 1.4nm solutions.

Samsung reiterated those timelines at this year’s Samsung Foundry Forum, the US edition of which concluded recently (the company will also hold the conference in South Korea in July and expand to Europe and other major Asian markets later this year). The event was attended by over 700 industry guests, while 38 companies showcased the latest foundry technology trends to the attendees.

During the event, Samsung revealed that its 2nm process (SF2) is already promising notable improvements over its 3nm process (SF3). The company is claiming a 12 percent increase in performance, a 25 percent increase in power efficiency, and a 5 percent decrease in chip area. It isn’t yet ready to share more details about 1.4nm chips, though. Those solutions are probably still in the very early stages of development.

Samsung will also launch its 5nm RF process for 6G technology in 2025

Samsung Foundry has more big plans for 2025. The company already has a 5nm Radio Frequency (RF) process under development, which it aims to launch in the first half of 2025. The new solutions will bring a 40 percent increase in power efficiency and a 50 percent decrease in chip area compared to the 14nm process. This will come in time for 6G wireless technology.

The Korean behemoth also plans to begin foundry services for 8-inch gallium nitride (GaN) power semiconductors in 2025. Moreover, it will add automotive applications to its 8nm and 14nm RF processes. Mass production of these solutions is currently limited to mobile applications. Of course, these expansions will require a higher production capacity. To that end, Samsung is expanding its chip factories in South Korea and the US.

Samsung is building new manufacturing lines at its Pyeongtaek campus in South Korea. Line 3 will be ready for mass production of foundry products for mobile and other applications later this year. The construction of its new chip plant in Taylor, Texas, is also in full swing and going according to plan. It will be finished by the end of this year, with operations beginning in the second half of 2024. Samsung says its clean room capacity will increase by 7.3 times between 2021 and 2027.

Samsung semiconductors chips roadmap October 2022


[ad_2]
Source link

TikTok scraps TikTok Now, its BeReal-like feature

0
[ad_1]

Following BeReal’s low tide, TikTok is sending notifications to its users: it’s getting rid of its own BeReal copy: TikTok Now.

Multiple Twitter users (here and here) reported a message update from TikTok (via The Verge), which reads:

Nothing (as of the time of writing this article) can be found on the official support page, but it’s unlikely that this is some sort of hoax or bug. TikTok Now closely follows BeReal’s life timeline. The duo dynamics are like that: BeReal explodes in popularity, TikTok Now is born. Next: BeReal suffers a mass dropout… TikTok Now gets shut down!

Let’s take a closer look at their rise and fall


TikTok Now sprung in mid-September of 2022, amidst the commercial success of BeReal: an app used primarily by Gen Z audiences, which operates in quite a fashionable way. Once a day, users get a notification with exclamation mark emojis on their screen, prompting “Time to BeReal!” The objective is to post an immediate photo with both your front and rear cameras at the same time in a 2-minute time window, set by the app. Once you click on the notification, the timer counts back. If you want to see your friends’ BeReal moments, you’re not allowed until you post your own first. Talking about peer pressure…TikTok Now operates (read: operated) in a more than similar way, with minor tweaks. They include a 3-, instead of 2-minutes timeframe and the ability to post 10-second-long videos, not just photos. And Now gives you the option to show your instant posts only to your friendlist, while in BeReal you choose between that and going public to the Discovery feed.

Privacy hit a new low


Brought to fame by Zoomers claiming they want a break from the superficial, artificial major social media networks, BeReal is seen by the younger generation as a way to, well, get more real by sharing ordinary, everyday situations without rehearsal and any concept in mind.

This mindset, however, paved the way to quite the situation, where business and even state privacy was endangered. BeReal users snapped literally any and everything that was in front and behind them, whenever the app notified them to. Including laptop screen, documents, (too) personal situations, etc. You can read more about the BeReal privacy breach phenomenon here.

This was last year, though. Since then, a 61% drop in the daily active BeReal users have been reported, but app officials responded in April by saying: ‘We have 20 million daily active users’.


[ad_2]
Source link

Twitter Hacker Sentenced: A look into the 2020 Twitter Crypto Scam – Latest Hacking News

0
[ad_1]

Twitter hacker sentenced in a landmark ruling, the mastermind behind the infamous 2020 Twitter Crypto Scam. This case has sent shockwaves through the cybersecurity and social media worlds, highlighting the vulnerabilities even within major tech giants like Twitter.

The 2020 Twitter Crypto Scam

In July 2020, a massive security breach on Twitter led to several high-profile accounts being hacked. The accounts of Barack Obama, Elon Musk, and many others were used to promote a Bitcoin scam. The hacker promised to double the amount of any Bitcoin sent to a specific address, a classic scam that unfortunately still manages to trick many unsuspecting victims.

The Hacker Behind the Scam

The individual behind this audacious scam was a British hacker who was recently sentenced to five years in prison. The hacker, who was arrested in Spain, was found guilty of multiple charges, including hacking and fraud.

The Sentence

The sentence handed down to the hacker is seen as a stern warning to others who might be tempted to exploit the vulnerabilities of social media platforms for illicit gains. The five-year sentence is a clear message that cybercrime is taken seriously, and perpetrators will face severe consequences.

Implications for Cybersecurity

This case has significant implications for cybersecurity. It highlights the vulnerabilities that exist even within major tech companies like Twitter. It also underscores the need for individuals and businesses to take cybersecurity seriously and implement robust security measures to protect against such attacks.

Lessons Learned

The 2020 Twitter Crypto Scam and the subsequent sentencing of the hacker offer several important lessons. Firstly, it underscores the importance of strong cybersecurity measures. Even tech giants like Twitter are not immune to cyberattacks, and it’s crucial for all organizations, regardless of size, to invest in robust cybersecurity defenses.

Secondly, it highlights the need for constant vigilance. Cyber threats are continually evolving, and staying one step ahead requires ongoing effort and adaptation. Regular security audits, employee training, and staying updated on the latest threats are all essential components of a comprehensive cybersecurity strategy.

The Role of Law Enforcement

This case also highlights the crucial role of international cooperation in law enforcement. The hacker was arrested in Spain and extradited to the U.S., demonstrating the global nature of cybercrime and the need for cross-border collaboration in tackling these threats.

Looking Ahead

As we look to the future, it’s clear that cybersecurity will continue to be a major concern. The Twitter hacker may have been sentenced, but there are many more cybercriminals out there, and the threat of cybercrime is not going away anytime soon.

However, by learning from cases like this and taking proactive steps to enhance cybersecurity, we can hope to minimize the risk and protect against future attacks. Stay safe online, and remember – if something seems too good to be true, it probably is.


[ad_2]
Source link

Newly Surfaced ThirdEye Infostealer Targeting Windows Devices

0
[ad_1]

While the ThirdEye infostealer is now in town, researchers have already identified several of its variants, all aiming at victims’ data.

FortiGuard Labs uncovered a not-so-sophisticated but highly malicious infostealer while analyzing suspicious files during a cursory review. They named this ThirdEye Infostealer. According to the report authored by Fred Gutierrez, James Slaughter, and Shunichi Imano, researchers became suspicious after spotting an archive file in Russian titled “Табель учета рабочего времени.zip“, which means “time sheet” in the English language.

This file contained two additional files, both with double extensions, including a .exe extension and another document-related extension. One of these files is titled “CMK Правила оформления больничных листов.pdf.exe.”

The title means “QMS Rules for issuing sick leave” in the English language. Further investigation revealed traits that researchers had previously seen in ThirdEye infostealer samples they had been detecting since early April 2023.

Various Versions of ThirdEye ThirdEye Infostealer Discovered

The earliest sample of ThirdEye infostealer was discovered on 3 April 2023 at 12:36:37 GMT. This sample collected client_hash,  OS_type, host_name and user_name and sent it to C2 server “(glovatickets(.)ru/ch3ckState)” with a custom web request header: Cookie: 3rd_eye=. It was submitted to a file scanning service on 4 April 2023.

A few weeks later, researchers found a variant which had a compile timestamp of 26 April 09:56:55 GMT. This variant collected additional data, including the BIOS vendor and release date, RAM size, CPU core number, user’s desktop files list, list of registered users on the device, and network interface data. However, this version crashes in some virtual machines.

One day later, they found a new variant with just one change: it used a PDF icon. This variant used “(ohmycars(.)ru/ch3ckState)” as C2 communications.

Later, another variant was found which gathered additional data such as total and free disk space on the C drive, domain name, network ports list, list of programs and version numbers, systemUptime, CD-ROM, drive letters volume information, currently running processes list, and programs installed in the Program Files directory.

Another file in the archive WAS titled “Табель учета рабочего времени.xls.exe,” which is a ThirdEye infostealer variant capable of performing the same activities.

Newly Surfaced ThirdEye Infostealer Targeting Windows Devices
Credit: FortiGuard Labs

Functionalities of ThirdEye Infostealer

in their blog post, FortiGuard Labs’ researchers revealed that ThirdEye Infostealer can steal system data from infected devices, including BIOS and hardware information. In addition, it can enumerate folder files, running processes, and network data.

Upon execution, the infostealer quickly gathers the data and transmits it to a C2 server hosted at “shlalala(.)ru/ch3ckState.” Apart from this, ThirdEye Infostealer does not perform any other function.

While researching, an interesting feature was noted – a string named 3rd eye, from which they derived the name of this malware family. The malware decrypts this string and uses it with another hash value to identify the C2 server. ThirdEye infostealer isn’t too sophisticated; however, it is evolving fast. Some recently collected samples stole more system data than the previously discovered versions.

Moreover, researchers noted that the infostealer targets Windows-based systems with a medium severity level. There is currently no evidence that ThirdEye Infostealer has been used in attacks.

However, since it is designed to collect data from compromised devices and systems, it can come in handy for cybercriminals in launching attacks. Researchers believe that all previous and latest variants of ThirdEye Infostealer are named in Russian, so the attacker is probably eyeing Russian-speaking organizations to deploy malware.

  1. Legion: SMS Hijacking Malware Sold on Telegram
  2. New Jupyter infostealer dropped through MSI installer
  3. Malicious ChatGPT Installers Distribute RedLine Stealer
  4. Infostealer Adrozek malware hits Firefox, Chrome browser
  5. New MacStealer Malware Targeting macOS Catalina Devices

[ad_2]
Source link

This flip phone concept has an E Ink cover display

0
[ad_1]

We’ve been seeing all kinds of concept smartphones in the last couple of years, but nothing like the one we’re here to talk about. This flip phone concept has an E Ink cover display… on the bottom.

This flip phone concept has an E Ink cover display, and it looks quite unique

Yes, you read that right. It not only has an E Ink display, but it has it in the bottom portion of the phone’s body. The designer seemingly placed it there so that it can take full advantage of that portion of the phone, without having to think about the rear cameras.

The device also has flat sides all around. Even though its corners are rounded, it has a boxy feel to it. A display camera hole is included on the main display, and it’s centered. The bezels are quite thin, around the main display.

This concept device is called ‘0/1 Phone’, and it has been designed by Andrea Mangone. He says that this phone, if real, would “help people disconnect from digital distractions and regain control of their lives”.

Using this phone would surely feel different to any other foldable

The designer says that this phone is supposed to cater to both regular users, and minimalists who want to use their phones to the very minimum. When the phone is closed, the layout for minimalists emerges thanks to the E Ink display, when you open it, you get access to a regular UI.

This phone also has two cameras on the back, which are included in a round camera island. You’ll also notice an orange tag on the left side, which complements this white-colored device nicely. That tag comes in other colors too, and it’s actually there not only for design purposes, that’s also where the SIM tray lies. All you have to do is pull on it, no SIM removal tool needed.

The designer also envisioned vegan leather on the upper portion of the phone’s back, around the rear cameras.

This phone will not become a reality, of course, but it’s still nice to see. In fact, it would be interesting to see something similar to it reach the market at some point. It would surely have something different to offer.


[ad_2]
Source link

Samsung TVs, monitors get improved color vision accessibility

0
[ad_1]

Samsung has added a new accessibility feature to its 2023 TVs and monitors. The big-screen devices are getting the company’s SeeColors mode, which allows viewers with color vision deficiency (CVD) to recalibrate the display colors of their devices for the best viewing experience. It offers various color settings based on degrees and types of CVD to ensure that everyone can easily distinguish colors on the screen.

Launched in January 2017, Samsung’s SeeColors mode originally debuted as a standalone app for smartphones. The company has since expanded it to TVs and monitors, integrating the service with the accessibility menus on these devices. This helps make the service readily accessible. While its newest TVs and monitors lacked this accessibility feature out of the box, a new software update will bring it soon.

The Neo QLED, QLED, OLED, Smart Monitor, and the G95SC gaming monitor lineups will get this update. To check for updates over the internet, press the Home button on your TV’s remote control and go to Settings. Now, navigate to All Settings and select Support. Finally, click on Software Update, followed by Update Now. If Software Update is greyed out, exit and change your TV source to Live TV and repeat the steps.

SeeColors mode offers nine picture presets. Users can browse through those presets and select the one that is most suitable for them. Depending on the selected picture preset, the feature adjusts the red, green, and blue levels of the screen. This enables viewers to distinguish colors easily regardless of the type or degree of their color vision deficiency. Samsung says the SeeColors mode is a commitment to accessibility under the vision of “Screens Everywhere, Screens for All.”

Samsung SeeColors mode has obtained “Color Vision Accessibility” certification

According to Samsung, its SeeColors mode received the “Color Vision Accessibility” certification from Cologne, Germany-based globally renowned testing organization TÜV Rheinland earlier this month. The certification acknowledges that the feature can “help those with CVD better enjoy content on Samsung screens.” The feature isn’t intended for use in the diagnosis or prevention of color vision deficiency, though.

“We are thrilled to introduce additional accessibility features, including SeeColors and Relumino mode, in our 2023 TV and monitor lineup to assist individuals with color blindness and low vision,” said Seokwoo Jason Yong, Executive Vice President of Visual Display Business at Samsung. “Under the vision of ‘Screens Everywhere, Screens for All,’ we will continue to innovate and bring inclusive technologies closer to our consumers.”

Samsung SeeColors mode TVs monitors 2


[ad_2]
Source link

Twitter introduces 25,000-character tweets for its Twitter Blue users

0
[ad_1]

Tweeting, or the art of sharing snippets of your thoughts, passions, and moments in real-time in just 280 characters, is not an easy job to master. However, Twitter Blue users can now breathe easily, as their tweets can be much longer, stretching up to 25,000 characters.

According to a tweet by Twitter employee Prachi Poddar (via Android Headlines), Twitter Blue users now have the freedom to compose posts up to 25,000 characters in length. Previously, paid subscribers were limited to 10,000 characters, which can still be a very long tweet. Since Elon Musk took over the company, numerous changes have been implemented, and tweet length is just one of them.

This update, which allows Twitter Blue users to express themselves in up to 25,000 characters, is likely to appeal to writers, journalists, bloggers, and anyone eager to share more detailed news, research, or articles. It’s important to note, however, that this change might diminish one of Twitter’s unique features, as its shorter posts have set it apart from other social media platforms.


Since Musk became the owner of Twitter, he has been actively seeking ways to make the company more profitable. One of his decisions was the introduction of a paid subscription known as Twitter Blue, which was launched globally in March. To attract an increasing number of paid users, Twitter continuously updates its service by adding new features, such as tweet editing.


Currently, Twitter boasts over 80 million users in the United States alone and a global user base of approximately 353 million. Interestingly, this represents a slight decline compared to the previous year. Thus, it comes as no surprise that the company is striving to update its platform and introduce new features to attract potential paid users. Hopefully, free users will also benefit from exciting updates in the near future.


[ad_2]
Source link

IBM QRadar SIEM Flaw Leads to XSS Attack

0
[ad_1]

IBM QRadar is a popular SIEM (Security Incident and Event Management) tool organizations use to detect and monitor threats.

The IBM QRadar SIEM can be used in the form of a physical appliance, a software-only solution, or a virtual appliance.

As of 2023, It is being used by over 1130 companies worldwide as part of their SIEM.

IBM discovered three new vulnerabilities in the IBM SIEM and CVEs, and necessary fixes were also released.

These vulnerabilities were related to Cryptography, XSS, and information disclosure which was discovered by IBM’s Security Ethical Hacking team.

IBM QRadar SIEM Flaw

CVE-2023-26276: Weak Cryptographic Algorithm

This vulnerability exists due to the use of a weaker or expected cryptographic algorithm in the QRadar tool, which could allow a threat actor to decrypt highly sensitive information.

This vulnerability was given a CVSS Score of 5.9 (medium)

CVE-2023-26274: Cross-Site Scripting (XSS)

An attacker can exploit this vulnerability to embed arbitrary JS code in the Web UI that can alter the functionality that can lead to credentials disclosure through XSS on a trusted session.

This vulnerability was given a CVSS Score of 4.6 (medium).

CVE-2022-34352: Information Disclosure

This vulnerability allows a delegated Admin tenant with a specific domain security profile to see other domain data.

This vulnerability was given a CVSS Score of 6.5 (medium).

Affected Products

ProductVersionRemediation/First Fix
IBM QRadar SIEM7.5.0 7.5.0 UP6

There are no workarounds or mitigations available. IBM recommended all its users patch their IBM QRadar SIEM by upgrading it to the latest version.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link