The beginning of an international consensus on AI governance may be emerging from Bletchley Park.

Published: Nov. 2, 2023, 8:15 p.m.

Bletchley Declaration represents a consensus starting point for AI governance. Lazarus Group prospects blockchain engineers with KANDYKORN. Boeing investigates \u2018cyber incident\u2019 affecting parts business. NodeStealer\u2019s use in attacks against Facebook accounts. Citrix Bleed vulnerability exploited in the wild. MuddyWater spearphishes Israeli targets in the interest of Hamas. India to investigate alleged attacks on iPhones. Tim Starks from the Washington Post on the SEC\u2019s case against Solar Winds. In today\u2019s Threat Vector segment David Moulton from Unit 42 is joined by Matt Kraning of the Cortex Expanse Team for a look at Attack Surface Management. And Venomous Bear rolls out some new tools.\nOn the Threat Vector segment, David Moulton, Director of Thought Leadership for Unit 42, is joined by Matt Kraning, CTO of the Cortex Expanse Team. They dive into the latest Attack Surface Management Report.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/210\n\nThreat Vector\nRead the Attack Surface Management Report.\nPlease share your thoughts with us for future Threat Vector segments by taking our brief survey.\nTo learn what is top of mind each month from the experts at Unit 42 sign up for their Threat Intel Bulletin.\xa0\n\nSelected reading.\nThe Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023 (GOV.UK)\nUS Vice President Harris calls for action on "full spectrum" of AI risks (Reuters)\xa0\nElastic catches DPRK passing out KANDYKORN (Elastic Security Labs)\nNorth Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware (The Hacker News)\nLazarus used \u2018Kandykorn\u2019 malware in attempt to compromise exchange \u2014 Elastic (Cointelegraph)\xa0\nAn info-stealer campaign is now targeting Facebook users with revealing photos (Record)\nMass Exploitation of 'Citrix Bleed' Vulnerability Underway (SecurityWeek)\nMuddyWater eN-Able spear-phishing with new TTPs | Deep Instinct Blog (Deep Instinct)\xa0\nCentre's Cyber Watchdog CERT-In To Probe iPhone "Hacking" Attempt Charges (NDTV.com)\nOver the Kazuar\u2019s Nest: Cracking Down on a Freshly Hatched Backdoor Used by Pensive Ursa (Aka Turla) (Unit 42)\nLearn more about your ad choices. Visit megaphone.fm/adchoices