> TODAY'S SUMMARY (122 articles)
Today's cybersecurity landscape highlights several critical threats and trends. The Canadian regulator is investigating IDScan for potential data privacy violations, while the ransomware PAYLOAD has demonstrated a new tactic, paralyzing an organization without file encryption. Volexity reported a China-aligned threat group exploiting vulnerabilities in Chrome and Microsoft software. The hacking group ShinyHunters claims to have breached the FBI, raising significant counterintelligence concerns. Additionally, ClosedQuorum malware is leveraging AI for attack decisions, indicating a trend towards more sophisticated, autonomous threats. CISA has urged federal agencies to patch a critical Zyxel flaw actively exploited by attackers. Meanwhile, the rise of AI in cybercrime continues, with deepfakes and AI-driven bots posing increasing risks to organizations.
|
// AI-powered summary generated at 20:01
Cybercriminals package malware inside legitimate looking security software
A new, wide-net malware attack posing as an “important company update” is being spammed out, targeting Windows users. The campaign carries an unusual differentiator: it uses gadget files to do the dirty work.
Background Friday night I sat down with a glass of Macallan 15 and decided to write a static checker that would find the Heartbleed bug. I decided that I would write it as an out-of-tree clang analyzer plugin and evaluate it on a few very small functions that had the spirit of the Heartbleed bug […]
The reverberations from Edward Snowden’s disclosures regarding the National Security Agency continue, with the National Institute of Standards and Technology (NIST) announcing it has begun a review of the institute’s cryptographic standards and guidelines program.
The software maker announces fixes for several remote code execution vulnerabilities.
Information security vendors should spend “less on marketing and more on testing”, John Maddison, VP marketing at Fortinet told Infosecurity at Infosecurity Europe 2014
Free Stones tickets? How about free One Direction tickets if you’re a little younger? A new Facebook bait-and-switch scam is spreading across friendship circles promising one or both; but users should file this one under 'too good to be true.'
Agari TrustIndex reports cyber gangs are increasingly 'weaponizing' their malicious emails with sophisticated threats
FireEye has identified a hacking group inside Iran that is behind Operation Saffron Rose, one of the first espionage campaigns from Iran that went after US aerospace companies and Iranian opposition inside and outside of the country.
Latest Snowden revelations hit new spy agency head Mike Rogers’ attempts to promote greater transparency
Hackers have been stealing Google account passwords in a new and better crafted phishing attack that is hard to catch with traditional heuristic detection, warns Bitdefender. A particularity in how Google Chrome displays data using Uniform Resource Identifiers (URIs) makes Chrome users most vulnerab...
Judge rules in favor of Privacy International after criticizing HMRC department for failing to reveal details of an investigation into British business Gamma International. The Andover-based firm was accused of breaking export restrictions.
Point-of-sale (PoS) systems that process debit and credit cards for retail stores and restaurants are in the dubious limelight these days thanks to high-profile hacks at Target and elsewhere. But PoS malware has been lurking around for a very long time, evolving and getting smarter.
If you know of Trey Ford, it will probably be as former General Manager at Black Hat. But as of January 2014, he became global security strategist at Rapid7. At Infosecurity Europe, Infosecurity editor Eleanor Dallaway sat down with him to talk about the current threat landscape and the pros and con...
New video highlights the problem legitimate organizations have in recruiting the best talent
The Heartbleed saga continues, this time with an industrial control element. ICS vendor Digi International has identified five products that are vulnerable to the bug, where attackers could obtain user credentials and cryptographic keys used to access the devices.
Cyber-danger can be found in many places, including, apparently, basic social networking utilities. Link-shortening service Bitly has warned its users that their account credentials may have been compromised; specifically, users’ email addresses, encrypted passwords, API keys and OAuth tokens.
Reveton-like malware tricks users into downloading from insalubrious sites. Experts say it could presage a more sophisticated campaign targeted at mobile users.
Kaspersky Lab reports increase in spam aimed at Whatsapp, Viber and Google Hangouts users
Gen. Keith Alexander warns of threat to CNI systems, but experts question whether 2012 incident was a game changer.