Patagonia accused of privacy violations related to AI use
Patagonia, a U.S. outdoor recreation clothing retailer, was hit by a class action lawsuit alleging California privacy law violations stemming from its usage of services from artificial intelligence-powered customer service provider Talkdesk.
Microsoft slammed for improperly crediting MSHTML bug
While Microsoft dubbed the flaw as a high-severity spoofing bug, such an issue was disclosed by ZDI to be a remote code execution vulnerability that requires a higher severity rating.
Another regreSSHion-like bug identified in OpenSSH
Despite being both remote code execution and race condition flaws, CVE-2024-6409 poses a "lower" immediate impact due to the issues being present in the privsep child process with fewer privileges.
Python repositories threatened by inadvertently exposed GitHub token
PyPi has immediately moved to revoke the authentication token, which had been given to PyPI Admin EE Durbin before March 3, 2023, reported JFrog researchers.
Cytactic Focuses on Stakeholder Communication to Boost Incident Response
The new cybersecurity startup is focused on helping companies prepare and respond to a "cyber crisis" by consolidating the three Rs: readiness, response, and recovery.