The UK’s National Cyber Security Centre (NCSC) is keen to bring in fresh blood to its Vulnerability Research Initiative, including across AI. Contrary to a flurry of press releases from excited cybersecurity vendors hitting The Stack’s inbox this week, the VRI is not new and has been running
"Your key databases are still running on VMs, your SAP systems, your enterprise ERP systems, your security products..."
"Massive questions that we are grappling with, from the balcony all the way down to the dance floor"
The bug is in the SPNEGO Extended Negotiation Security Mechanism – which essentially allows a client and server to negotiate the choice of security mechanism that they use.
In earlier SafePay attacks the group has actively gone after backups and deleted Volume Shadow Copies (VSC) in an effort to inhibit recovery activities.