Home Blog Page 278

Revolutionizing Cybersecurity and Application Security with Agentic AI

0

The Revolutionary Potential of Agentic AI in Cybersecurity

In the constantly evolving world of cybersecurity, threats are growing more sophisticated by the day, and businesses are turning to AI (AI) for bolstering their defenses. The rise of agentic AI is heralding a revolution in intelligent, flexible, and connected security products. This article delves into the revolutionary potential of AI by focusing on its application in the field of application security (AppSec) and the pioneering concept of artificial intelligence-powered automated security fixing.

Agentic AI: A New Era in Cybersecurity

Agentic AI refers to autonomous, goal-oriented systems that are able to perceive their surroundings and make choices and decisions to accomplish specific objectives. Agentic AI is different from traditional reactive or rule-based AI because it is able to adjust and learn to its surroundings, and can operate without human intervention.

The Potential of Agentic AI in Cybersecurity

The potential of agentic AI in cybersecurity is immense. Utilizing machine learning algorithms and vast amounts of data, these smart agents are able to identify patterns and correlations that human analysts may miss. They can sift through the chaos of many security threats, picking out the most critical incidents, and provide actionable information for rapid response. Agentic AI systems can be trained to develop and enhance their abilities to detect security threats and adapt themselves to cybercriminals’ constantly changing tactics.

Agentic AI and Application Security

Although agentic AI can be found in various uses across many aspects of cybersecurity, its impact on the security of applications is noteworthy. Securing applications is a priority for companies that rely increasingly on complex, interconnected software systems. AppSec tools like routine vulnerability scans and manual code reviews do not always keep up with the latest application developments.

Transforming AppSec with Agentic AI

Agentic AI can be the solution. Incorporating intelligent agents into the software development lifecycle (SDLC) could transform their AppSec processes from reactive to proactive. AI-powered software agents can continuously monitor the code repository and scrutinize each code commit for weaknesses in security. They can employ advanced methods, including static code analysis, dynamic testing, and machine learning, to detect numerous issues, from common coding mistakes to subtle vulnerabilities in injection.

Code Property Graph (CPG): The Key to Agentic AI’s Success

The link that sets agentic AI apart in AppSec is its capacity to comprehend and adapt to the specific circumstances of each app. Agentic AI is able to develop an understanding of the application’s design, data flow, and attack routes by creating a comprehensive CPG, which is a detailed representation of the connections between code elements. This understanding of context allows the AI to identify vulnerabilities based on their real-world impact and exploitability, rather than basing its decisions on generic severity scores.

Agentic AI-Powered Automated Fixing

The most exciting application of agents in AI in AppSec is the concept of automated vulnerability fix. Humans have historically been responsible for manually reviewing the code to discover vulnerabilities, understand the issue, and implement the corrective measures. This can take a lengthy time, be error-prone, and hinder the release of critical security patches.

The Power of AI-Powered Automated Fixing

With agentic AI, the game has changed. AI agents are able to identify and fix vulnerabilities automatically by leveraging CPG’s deep understanding of the codebase. They can analyze all relevant code to determine its purpose and design a fix that fixes the issue while ensuring that they do not introduce new problems.

Challenges and Considerations

It is essential to understand the threats and risks that accompany the introduction of AI agents in AppSec and cybersecurity. An important issue is the trust factor and accountability. Organizations must set clear rules to ensure that AI acts within acceptable boundaries, as AI agents develop autonomy and begin to make their own decisions. This includes implementing robust test and validation methods to check the validity and reliability of AI-generated solutions.

Problems and Considerations

Another issue is the possibility of an adversarial attack on AI. As agentic AI systems become more popular in the world of cybersecurity, adversaries could attempt to take advantage of weaknesses within the AI models or modify the data upon which they are based. This underscores the need for security-conscious AI techniques for development, such as methods like adversarial learning and model hardening.

The Future of Agentic AI in Cybersecurity

Despite the challenges that lie ahead, the future of AI for cybersecurity is incredibly hopeful. As AI techniques continue to evolve, it is possible to get even more sophisticated and efficient autonomous agents that can detect, respond to, and counter cybersecurity threats at a rapid pace and precision. In the realm of AppSec, the agentic AI technology has the potential to change how we create and secure software, enabling companies to create more secure and secure apps.

Conclusion

Agentic AI is an exciting advancement in the world of cybersecurity. It is a brand new approach to recognize, avoid, and mitigate attacks from cyberspace, as well as mitigate them. The ability of an autonomous agent, especially in automatic vulnerability fix and application security, could assist organizations in transforming their security strategies, changing from a reactive approach to a proactive one, automating processes, and transforming them from generic context-aware.

Frequently Asked Questions

Q: What is Agentic AI?

A: Agentic AI refers to autonomous, goal-oriented systems that are able to perceive their surroundings and make choices and decisions to accomplish specific objectives.

Q: How does Agentic AI work in AppSec?

A: Agentic AI uses machine learning algorithms and vast amounts of data to identify patterns and correlations that human analysts may miss, and can sift through the chaos of many security threats to provide actionable information for rapid response.

Q: What are the benefits of Agentic AI in AppSec?

A: Agentic AI can transform AppSec processes from reactive to proactive, automating processes and transforming them from generic context-aware. It can also identify and fix vulnerabilities automatically, reducing the time spent between finding vulnerabilities and remediation.

Q: What are the challenges of Agentic AI in AppSec?

A: The challenges include the trust factor and accountability, the possibility of an adversarial attack on AI, and the need for security-conscious AI techniques for development.

Physicists Tap James Webb Space Telescope to Track New Asteroids and City-Killer Rock

0

Asteroid Detection: New Method Uses James Webb Space Telescope and NVIDIA Accelerated Computing

Asteroids were responsible for extinction events hundreds of millions of years ago on Earth, providing no shortage of doomsday film plots for Hollywood. But researchers focused on asteroid tracking are on a mission to locate them for today’s real-world concerns: planetary defense.

The new and unexpected discovery tool applied in this research is NASA’s James Webb Space Telescope (JWST), which was tapped for views of these asteroids from previous research and enabled by NVIDIA accelerated computing.

Capturing Asteroid Images With Infrared JWST Driven by NVIDIA GPUs

Observatories typically look at the reflected light off asteroids to determine their size, which can be inaccurate. Using a telescope with infrared, like the JWST, can help track the thermal signals of asteroids for a more precise way at gauging their size.

Harnessing GPUs to Save the Planet From Asteroids

The 2024YR4 near-Earth asteroid — estimated as wide as 300 feet and capable of destroying a city the size of New York — has a 2.3% chance of striking Earth.

New Method for Detecting Small Asteroids

A new method for detecting small asteroids, developed by an international team of researchers, uses previous studies, asteroid synthetic movement tracking, and infrared observations. This method was applied to images of TRAPPIST-1, a star studied to search for signs of atmospheres around its seven terrestrial planets.

Conclusion

The new study used the JWST, the best-ever telescope in the infrared, on images of TRAPPIST-1, a star studied to search for signs of atmospheres around its seven terrestrial planets. The data include more than 10,000 images of the star. The researchers applied synthetic tracking methods, which doesn’t require previous information on an asteroid’s motion. Instead, it does "fully blind" search by testing possible shifts, like velocity vectors.

FAQs

Q: What is the new method for detecting small asteroids?
A: The new method uses previous studies, asteroid synthetic movement tracking, and infrared observations.

Q: What is the James Webb Space Telescope (JWST)?
A: The JWST is a space telescope that was tapped for views of these asteroids from previous research and enabled by NVIDIA accelerated computing.

Q: What is the 2024YR4 near-Earth asteroid?
A: The 2024YR4 near-Earth asteroid is estimated as wide as 300 feet and capable of destroying a city the size of New York, with a 2.3% chance of striking Earth.

Q: How does the new method detect asteroids?
A: The new method detects asteroids by using synthetic tracking methods, which doesn’t require previous information on an asteroid’s motion. Instead, it does "fully blind" search by testing possible shifts, like velocity vectors.

Q: What is the role of NVIDIA in asteroid detection?
A: NVIDIA GPUs were applied to the study, enabling the detection of small asteroids and increasing the scientific return on resources when conducting exoplanet transit-search surveys.

Mira Murati Launches Rival AI Start-up

Mira Murati Launches Rival AI Start-up

Mira Murati, the former chief technology officer of OpenAI, has launched a new artificial intelligence start-up, Thinking Machines Lab. This new venture aims to make AI systems more widely understood, customisable, and capable.

Mission Statement

According to a blog post on its website, Thinking Machines Lab’s mission is to "make AI systems more widely understood, customisable and generally capable." The company believes that knowledge of how AI systems are trained is concentrated within the top research labs, limiting both the public discourse on AI and people’s abilities to use AI effectively.

Team and Partnerships

Thinking Machines Lab has poached senior former OpenAI employees, including co-founder John Schulman, Jonathan Lachman, former head of special projects, and Barret Zoph, former vice-president. The company has also hired researchers and engineers with experience at other competitors such as Google, Meta, Mistral, and Character AI. These experts will build models focused on science and programming.

Research and Collaboration

Thinking Machines Lab believes that scientific progress is a collective effort. The company plans to publish technical blog posts, papers, and code, as it believes that sharing its work will not only benefit the public but also improve its own research culture.

History with OpenAI

Mira Murati worked at OpenAI for over six years, leading the company’s efforts to build ChatGPT as a standalone product and working on technical breakthroughs from the company’s large language models. In November 2023, OpenAI’s directors appointed Murati as interim chief executive after removing founder Sam Altman under claims he was not "sufficiently candid" with the board. Altman returned days later after protests from employees and investors.

Conclusion

Thinking Machines Lab is an exciting new development in the AI industry, with a focus on making AI systems more accessible and capable. With a team of experienced researchers and engineers, the company is poised to make a significant impact in the field. As the AI landscape continues to evolve, it will be interesting to see how Thinking Machines Lab contributes to the conversation and advancements in the field.

FAQs

Q: What is the mission of Thinking Machines Lab?
A: The mission of Thinking Machines Lab is to make AI systems more widely understood, customisable, and capable.

Q: Who is behind Thinking Machines Lab?
A: Mira Murati, the former chief technology officer of OpenAI, is the founder of Thinking Machines Lab.

Q: What is the team like at Thinking Machines Lab?
A: The team at Thinking Machines Lab includes senior former OpenAI employees, as well as researchers and engineers with experience at other competitors.

Q: What is the focus of the company’s research?
A: The company’s research will focus on science and programming, with a goal of making AI systems more widely understood and capable.

Q: What is the company’s approach to sharing knowledge?
A: Thinking Machines Lab plans to publish technical blog posts, papers, and code, believing that sharing its work will improve its own research culture and benefit the public.

Trump Admin Reverses Hydropower Layoffs that Sparked Grid Stability Fears

0

Federal Agency Cuts Spark Fears of Grid Instability, But Rehiring Efforts Underway

Deep Cuts Made to Power Marketing Administrations

This month, the Trump administration made sweeping cuts within the federal agencies in charge of power from hydroelectric dams, raising fears of grid instabilities in key data center markets. The recent layoffs slashed between 13% and 20% of the four Power Marketing Administrations’ workforces, affecting everyone from linemen to the teams that direct power on a minute-to-minute basis.

Criticism and Rehiring Efforts

However, after criticism from lawmakers and customers, the Trump administration has rehired at least some of those employees, according to a report in E&E News.

About the Power Marketing Administrations

The four power marketing administrations sell and transmit hydropower from a range of federally owned dams, including the Bonneville Dam in the Pacific Northwest and the Hoover Dam in the Southwest. These dams — and the agencies that oversee the sale and distribution of the power they produce — supply electricity to tens of millions of homes across 34 states.

Funding and Operations

The agencies are funded through the sale of that electricity and don’t rely on money from the U.S. Treasury.

Conclusion

The recent layoffs and rehiring efforts within the Power Marketing Administrations have sparked concerns about grid stability and the ability of the agencies to continue providing reliable power to millions of customers. While the situation remains uncertain, it is clear that the agencies will need to adapt to the new challenges and concerns raised by the Trump administration’s actions.

FAQs

Q: What was the extent of the layoffs within the Power Marketing Administrations?

A: The layoffs slashed between 13% and 20% of the four Power Marketing Administrations’ workforces.

Q: Who was affected by the layoffs?

A: Everyone from linemen to the teams that direct power on a minute-to-minute basis was affected by the layoffs.

Q: How are the Power Marketing Administrations funded?

A: The agencies are funded through the sale of electricity and don’t rely on money from the U.S. Treasury.

Q: What is the impact of the layoffs on the grid?

A: The layoffs have raised concerns about grid stability and the ability of the agencies to continue providing reliable power to millions of customers.

HP to Buy Humane, Maker of the AI Pin, for $116 Million

0

Humane, the ambitious start-up behind the Ai Pin device, sells to HP for $116 million

Founders’ Vision and Rise to Prominence

Humane, a technology start-up founded by Imran Chaudhri and Bethany Bongiorno, the husband-and-wife team who previously worked at Apple, aimed to revolutionize the way people interact with technology. The duo envisioned a wearable device, the Ai Pin, that would allow users to clip it to their clothes and interact with it using voice commands and a laser display projected onto their hand. The idea was to reduce the time spent staring at smartphone screens.

Challenges and Setbacks

Despite raising $240 million in funding from prominent investors, including Marc Benioff and Sam Altman, the company’s journey was marked by significant challenges. The Ai Pin, which began shipping to customers last spring, was met with criticism from reviewers, who criticized its A.I. software for often providing incorrect answers or taking a long time to respond. The device’s batteries sometimes overheated, and the company was forced to issue a recall due to the fire risk.

Sale to HP

In a surprising turn of events, Humane has agreed to sell parts of its business to HP for $116 million. The deal includes the acquisition of Humane’s A.I. capabilities, including its software platform, intellectual property, patents, and some employees. The Ai Pin will be discontinued, and customers have been notified that the device will no longer function after the end of this month. The company’s website has also announced that customer data will be deleted.

HP’s Plans for the Technology

HP, which sells an estimated 53 million PCs a year, aims to integrate Humane’s technology into its laptops to make them more useful. The company has already worked with Microsoft to develop a line of A.I.-powered computers called Copilot+ PCs. The acquisition is part of HP’s strategy to become a more "experience-led company," with a focus on building an intelligent ecosystem across its products and services.

Conclusion

Humane’s journey, marked by high hopes and significant challenges, serves as a cautionary tale for start-ups. Despite its ambitious vision, the company was unable to overcome the technical hurdles and deliver a successful product. The sale to HP marks the end of an era for Humane, but the company’s legacy will live on through its employees, who will join HP’s innovation lab, HP IQ, to focus on building an intelligent ecosystem.

Frequently Asked Questions

Q: What is the deal worth?
A: The deal is worth $116 million.

Q: What does the deal include?
A: The deal includes Humane’s A.I. capabilities, including its software platform, intellectual property, patents, and some employees.

Q: What will happen to the Ai Pin?
A: The Ai Pin will no longer function after the end of this month, and customer data will be deleted.

Q: What is HP’s plan for the technology?
A: HP aims to integrate Humane’s technology into its laptops to make them more useful and become a more "experience-led company."

HP Buys Humane’s AI Pin for $116M

0

Humane’s AI Pin Discontinued: HP Acquires Startup for $116 Million

Background

Humane, a hardware startup, announced on Tuesday that most of its assets have been acquired by HP for $116 million. The company is immediately discontinuing sales of its $499 AI Pins.

Discontinuation of AI Pins

The company has alerted customers who have already purchased the Pin that their devices will stop functioning before the end of the month – at 12 p.m. PST on February 28, 2025. After that date, the devices will no longer connect to Humane’s servers, and the devices won’t be capable of calling, messaging, AI queries/responses, or cloud access. Humane is advising AI Pin owners to transfer their important photos and data to an external device immediately.

Customer Support and Refunds

Humane plans to dissolve its customer support team for the AI Pin on February 28. The company says customers who bought an AI pin in the last 90 days are eligible for a refund, but anyone who bought a device before then is not.

History of Humane

The Bay Area startup, founded by ex-Apple employees Bethany Bongiorno and Imran Chaudhri, raised more than $230 million to create the device. Humane made a splash in April 2024 by launching its AI Pin, which it positioned as a smartphone replacement. However, the AI Pin disappointed many early reviewers and customers, creating a crisis for the company.

Acquisition by HP

HP is acquiring Humane’s engineers and product managers, and the Humane team will form the basis of a new group within HP called HP IQ, which it describes as an "AI innovation lab focused on building an intelligent ecosystem across HP’s products and services for the future of work." HP will also acquire some of Humane’s technology, including its CosmOS AI operating system, which could be used to integrate AI into HP’s personal computers and printers.

Conclusion

The acquisition marks the end of the short-lived, buzzy hardware startup, and it remains to be seen how HP will utilize the technology and talent acquired from Humane.

FAQs

Q: What is happening to the AI Pin?
A: The AI Pin will stop functioning on February 28, 2025, and will no longer connect to Humane’s servers.

Q: What about customer support?
A: Humane plans to dissolve its customer support team for the AI Pin on February 28.

Q: Am I eligible for a refund?
A: If you purchased an AI Pin in the last 90 days, you are eligible for a refund. If you purchased a device before then, you are not eligible for a refund.

Q: What is happening to Humane’s technology?
A: HP is acquiring Humane’s technology, including its CosmOS AI operating system, which could be used to integrate AI into HP’s personal computers and printers.

Musk’s AI Conundrum: Open-Source or Own?

0

Elon Musk’s xAI: The Missing Piece in Open-Source AI Development

Grok 3: A New Era in AI Reasoning

Elon Musk’s xAI, the startup that owns the X social media platform and builds AI models, has unveiled its latest innovation, Grok 3. This AI model challenges the best from OpenAI in reasoning and other tasks. The unveiling follows Musk’s hostile bid for OpenAI, Inc., the non-profit that controls OpenAI, last week.

A Shift in Focus

Musk’s statement about the bid reads, "It’s time for OpenAI to return to the open-source, safety-focused force for good it once was." However, the question remains: If Elon Musk is concerned about keeping AI development transparent and safe, why hasn’t he committed xAI to open-source Grok for all of its models starting right now, in perpetuity?

The Open-Source Debate

The term "open-source AI models" is often misused, with the historical meaning of "open source" indicating the release of a program’s source code. In the case of open-source models, including Grok 1 and Meta’s Llama AI models, no source code is released. Instead, firms release only the model "parameters," or "weights," for a model. Because a lot can be re-constructed from having access to the weights, the AI field has been willing to bend the definition of open-source. Just know that this usage is not without controversy.

The Lack of Commitment

At press time, I had not received a reply to my request for comment from xAI or to my tweet on X directed at Musk, asking why he wouldn’t commit to open-sourcing all xAI models. The first model, Grok 1, was released in November of 2023 and made open-source the following March, a four-month lag. The company quickly followed with Grok 1.5 the same month, then Grok 2 this past August, and now Grok 3. That suggests there has been ample time to make Grok 1.5 and Grok 2 open-source if the company were to follow the same cadence.

Conclusion

Musk’s lack of a firm commitment or even a vague statement of principle is odd, given his professed concern for transparency in AI for humanity’s sake. By making a hostile bid for OpenAI, Musk seems to have shifted the burden of protecting humanity outside of his own corporate interests. Perhaps not surprising, since xAI has its own for-profit investors to please.

FAQs

Q: What is the difference between open-source and open-source AI models?
A: Open-source refers to the release of a program’s source code, while open-source AI models release only the model "parameters," or "weights," for a model.

Q: Why is Elon Musk’s lack of commitment to open-sourcing xAI models surprising?
A: It is surprising given his professed concern for transparency in AI development for the benefit of humanity.

Q: Can a company maintain a balance between making available open-source models and keeping other models closed?
A: Yes, companies can maintain a balance between making available open-source models and keeping other models closed, but it is unclear why xAI is not doing so.

Q: What is the significance of the xAI’s Grok 3 model?
A: Grok 3 is a new era in AI reasoning, challenging the best from OpenAI in reasoning and other tasks.

Reddit vs. Wall Street

0

WallStreetBets’ Stocks Plummet, Prices Stay Low for Entire Trading Day

It hasn’t been a good day for WallStreetBets, as GameStop’s stock has plummeted today. AMC, the community’s other bet, dropped as well. But unlike previous dips, the stocks don’t appear to be rallying. Prices stayed low for the entire trading day, something that hasn’t happened since WallStreetBets became a household name one week ago.

GameStop’s Stock Takes a Hit

When the market closed today, the price of GameStop was $90 even, an 81 percent drop from its peak at $483, and a 58 percent drop from its price of $218 on Friday evening.

AMC’s Stock Also Drops

AMC is down too, closing today at $7.82, which is a 61 percent drop from its peak at $19.88.

Unprecedented Low Prices

It’s unusual for prices to stay low for an entire trading day, especially for stocks that have been experiencing significant fluctuations. This is a departure from previous trends, where prices would often bounce back up after a dip.

What’s Next for WallStreetBets?

As the market continues to fluctuate, it’s unclear what’s next for WallStreetBets and its community. However, one thing is certain: the community will need to adapt to these new realities and find ways to navigate the changing market.

FAQs

Q: What happened to GameStop’s stock?
A: GameStop’s stock plummeted, closing at $90 even, an 81 percent drop from its peak at $483, and a 58 percent drop from its price of $218 on Friday evening.
Q: What happened to AMC’s stock?
A: AMC’s stock also dropped, closing at $7.82, a 61 percent drop from its peak at $19.88.
Q: What’s next for WallStreetBets?
A: As the market continues to fluctuate, it’s unclear what’s next for WallStreetBets and its community. However, the community will need to adapt to these new realities and find ways to navigate the changing market.

Asan Medical Center streamlines international patient service with AI

0

Asan Medical Center Launches AI-Powered Integrated Service Platform for International Patients

How it Works

Asan Medical Center (AMC) has launched a web-based platform, AMC International Healthcare Center, which allows patients to register, share medical records, book pre-consultations, and receive remote treatment. The platform is designed for foreign patients and is available in at least eight major world languages, including English, Russian, Arabic, Vietnamese, and Mongolian.

How it Works

Patients can upload their medical records, including symptoms, photos, videos, and CT/MRI test data, which are automatically linked to AMC’s hospital information system (AMIS) for systematic data management. The medical team at AMC International Healthcare Center reviews the patient’s case and arranges a pre-consultation to refer them to the appropriate department.

Why it Matters

The AMC International Healthcare Center sees around 20,000 patients from overseas each year. In 2024 alone, approximately 19,482 international patients – mostly from the United States and the United Arab Emirates, visited the centre. The centre also offers telemedicine services to patients outside South Korea, having delivered 866 remote treatments to patients with chronic diseases from 57 countries in the past five years.

The Larger Trend

Recently, AMC was validated for Stage 7 of the new iteration of the HIMSS Infrastructure Adoption Model – the first among hospitals in Asia-Pacific. It demonstrated the use of robotic process automation to streamline operations, saving over 10,587 hours of staff hours.

FAQs

Q: What are the benefits of the new platform?
A: The platform offers patients more convenience and ease of access to AMCs services, improved data management, and enhanced patient care.

Q: How many languages is the platform available in?
A: The platform is available in at least eight major world languages, including English, Russian, Arabic, Vietnamese, and Mongolian.

Q: How many patients does AMC receive from overseas each year?
A: AMC receives around 20,000 patients from overseas each year.

Q: What are some of the challenges faced by AMC in managing patient data?
A: AMC previously faced challenges in patient data management, including a high risk of personal information exposure and language barriers.

XCSSET malware returns with new tricks

0

XCSSET Malware: A New Threat to Developers and Users

Microsoft has recently discovered a new variant of malware, known as XCSSET, which is targeting developers and users alike. This enhanced malware family has added new features to its arsenal, making it a more sophisticated and dangerous threat.

New Features and Capabilities

These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files. XCSSET contains multiple modules for collecting and exfiltrating sensitive data from infected devices.

Detection and Mitigation

Microsoft Defender for Endpoint on Mac now detects the new XCSSET variant, and it’s likely other malware detection engines will soon, if not already. Unfortunately, Microsoft didn’t release file hashes or other indicators of compromise that people can use to determine if they have been targeted. A Microsoft spokesperson said these indicators will be released in a future blog post.

Prevention and Best Practices

To avoid falling prey to new variants, Microsoft said developers should inspect all Xcode projects downloaded or cloned from repositories. The sharing of these projects is routine among developers. XCSSET exploits the trust developers have by spreading through malicious projects created by the attackers.

Conclusion

XCSSET is a formidable threat that requires immediate attention from developers and users alike. By being aware of its capabilities and taking necessary precautions, we can minimize the risk of infection and prevent data breaches. It is essential to stay vigilant and keep our systems and software up to date to ensure we can detect and mitigate this malware effectively.

FAQs

What is XCSSET?

XCSSET is a new variant of malware that targets developers and users, collecting and exfiltrating sensitive data from infected devices.

What are the new features of XCSSET?

XCSSET has added new features to its arsenal, including targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files.

How can I detect XCSSET?

Microsoft Defender for Endpoint on Mac now detects the new XCSSET variant, and it’s likely other malware detection engines will soon, if not already. However, Microsoft did not release file hashes or other indicators of compromise that people can use to determine if they have been targeted.

How can I prevent XCSSET infection?

Inspect all Xcode projects downloaded or cloned from repositories, and keep your systems and software up to date to ensure you can detect and mitigate this malware effectively.

Will XCSSET be detected by other malware detection engines?

Yes, it is likely that other malware detection engines will detect XCSSET soon, if not already. However, the exact timeline is uncertain, and it’s essential to take proactive measures to prevent infection.