[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (122 articles)

|

// AI-powered summary generated at 20:01

> Scammers Sell Fake Kaspersky Lab Apps on Windows Phone and Google App Stores
Cybercriminals package malware inside legitimate looking security software
> Mass-Mail Spam Carries Unusual Malware Payload
A new, wide-net malware attack posing as an “important company update” is being spammed out, targeting Windows users. The campaign carries an unusual differentiator: it uses gadget files to do the dirty work.
> Using Static Analysis and Clang To Find Heartbleed
Background Friday night I sat down with a glass of Macallan 15 and decided to write a static checker that would find the Heartbleed bug. I decided that I would write it as an out-of-tree clang analyzer plugin and evaluate it on a few very small functions that had the spirit of the Heartbleed bug […]
> NIST Kicks Off Post-Snowden Crypto Standards Review
The reverberations from Edward Snowden’s disclosures regarding the National Security Agency continue, with the National Institute of Standards and Technology (NIST) announcing it has begun a review of the institute’s cryptographic standards and guidelines program.
> Adobe’s Last XP-ready Patches Cover Critical Updates for Flash, Acrobat and Reader
The software maker announces fixes for several remote code execution vulnerabilities.
> Spend on Testing Not Marketing says Fortinet
Information security vendors should spend “less on marketing and more on testing”, John Maddison, VP marketing at Fortinet told Infosecurity at Infosecurity Europe 2014
> One Direction 'Free' Tickets Scam Heats Up Facebook
Free Stones tickets? How about free One Direction tickets if you’re a little younger? A new Facebook bait-and-switch scam is spreading across friendship circles promising one or both; but users should file this one under 'too good to be true.'
> Email Attackers Switch to ‘Blitzkrieg’ Tactics to Maximize Impact
Agari TrustIndex reports cyber gangs are increasingly 'weaponizing' their malicious emails with sophisticated threats
> Iran's Operation Saffron Rose Points to Increasing Cyber-espionage Sophistication
FireEye has identified a hacking group inside Iran that is behind Operation Saffron Rose, one of the first espionage campaigns from Iran that went after US aerospace companies and Iranian opposition inside and outside of the country.
> NSA Accused of Installing Backdoors on US Tech Exports
Latest Snowden revelations hit new spy agency head Mike Rogers’ attempts to promote greater transparency
> Fresh Phishing Scam Aims at Google Account Passwords
Hackers have been stealing Google account passwords in a new and better crafted phishing attack that is hard to catch with traditional heuristic detection, warns Bitdefender. A particularity in how Google Chrome displays data using Uniform Resource Identifiers (URIs) makes Chrome users most vulnerab...
> HMRC Acted Unlawfully in Hiding Details of Spyware Investigation
Judge rules in favor of Privacy International after criticizing HMRC department for failing to reveal details of an investigation into British business Gamma International. The Andover-based firm was accused of breaking export restrictions.
> Point-of-Sale Malware Has Become Highly Sophisticated
Point-of-sale (PoS) systems that process debit and credit cards for retail stores and restaurants are in the dubious limelight these days thanks to high-profile hacks at Target and elsewhere. But PoS malware has been lurking around for a very long time, evolving and getting smarter.
> Interview: Trey Ford, Global Security Strategist, Rapid7
If you know of Trey Ford, it will probably be as former General Manager at Black Hat. But as of January 2014, he became global security strategist at Rapid7. At Infosecurity Europe, Infosecurity editor Eleanor Dallaway sat down with him to talk about the current threat landscape and the pros and con...
> Cybercrime Boss Offers Ferrari Prize for Most Lucrative Online Attack
New video highlights the problem legitimate organizations have in recruiting the best talent
> Heartbleed Bug Hits Industrial Control Systems
The Heartbleed saga continues, this time with an industrial control element. ICS vendor Digi International has identified five products that are vulnerable to the bug, where attackers could obtain user credentials and cryptographic keys used to access the devices.
> Bitly Compromised; Users Warned to Reset Accounts
Cyber-danger can be found in many places, including, apparently, basic social networking utilities. Link-shortening service Bitly has warned its users that their account credentials may have been compromised; specifically, users’ email addresses, encrypted passwords, API keys and OAuth tokens.
> Mobile Ransomware Gives Android Porn Fans the Willies
Reveton-like malware tricks users into downloading from insalubrious sites. Experts say it could presage a more sophisticated campaign targeted at mobile users.
> Spammers Target Mobile Messaging Users in New Malware Blitz
Kaspersky Lab reports increase in spam aimed at Whatsapp, Viber and Google Hangouts users
> Saudi Aramco Cyber Attacks a ‘wake-up call’, Says Former NSA Boss
Gen. Keith Alexander warns of threat to CNI systems, but experts question whether 2012 incident was a game changer.