> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
The largest retail breach in history happened at Target stores all over the country during the busy 2013 holiday shopping season, sparking 90+ lawsuits, a Congressional hearing, corporate restructuring and plummeting sales figures for the big-box retailer. But according to a report, it all could hav...
Industrial control systems (ICS) are a notorious weak link when it comes to securing mission-critical infrastructure, but progress in overhauling cyber-practices for this legacy software seems to be moving along at a snail’s pace. Case in point: yet another system, deployed in thousands of locations...
Javelin shows you how modern attackers would approach and exploit your enterprise. By simulating real-time, real-world attack techniques, Javelin identifies which employees are most likely to be targets of spearphishing campaigns, uncovers security infrastructure weaknesses, and compares overall vul...
The leader of an identity theft ring that stole more than 600 identities from US government employees and others has been sentenced to serve 12 years in prison, followed by three years of supervised release.
The latest revelations from the Snowden files, published by Glenn Greenwald's new venture The Intercept, show that NSA thinking has followed the same arguments developed by cybercriminals: if you wish to control a large number of subjects (infected computers) you need to automate the process with a...
Have you ever wanted to make a query into a native mode program asking about program locations that write a specific value to a register? Have you ever wanted to automatically deobfuscate obfuscated strings? Reverse engineering a native program involves understanding its semantics at a low level unt...
While network time protocol (NTP) amplification attacks have been a threat for many years, a new DDoS surge is ringing alarm bells: in just one month, February 2014, the number of NTP amplification attacks increased 371.43%. The average peak DDoS attack volume increased a staggering 807.48%.
More than a year ago, Kaspersky Labs analyzed dozens of modules used by Red October, an extremely sophisticated cyber-espionage operation that has been at work in dozens of high-profile targets. New analysis shows that one of its genetic progenitors is likely Agent.btz, a long-running, data-collecti...
Essen, Germany-based secunet Security Networks, which specializes in protecting classified/sensitive information, gives a sneak peak at soon-to-be-available updates to the firm’s product line
The tragic and mysterious loss of Malaysia Airlines Flight MH370 has spawned numerous dark theories, most centered around the discovery that two passengers were using stolen passports.
Penetration testing is a valuable part of any security audit. It applies a hacker mindframe to finding the vulnerabilities that hackers seek to exploit before they get to exploit them. But it suffers from two weaknesses: cost and timeframe. A third-party pentest can be expensive, and only audits sec...
LockLizard, a leading provider of document digital rights management (DRM) systems, will be addressing the holy grail of document security with the launch of a new web-based DRM solution for viewing protected PDF files
London operates a congestion charge to reduce traffic in central London. The congestion charge is enforced by 1300 automatic number plate recognition (ANPR) cameras operated by Traffic for London. Now the City of London is considering making feeds from these cameras available to the Metropolitan Pol...
There is a current scam campaign in the UK claiming that people are overdue in payment of a parking charge. An email apparently from the Ministry of Justice claims that photographic evidence of the offense is enclosed in an attachment. This, says the police ActionFraud website, "is likely to contain...
BAE Systems has released a major analysis of a long-standing cyber espionage campaign that has all the hallmarks of state-sponsored malware. The malware is sophisticated, covert and persistent, and seems to have been in operation since at least 2005. There has been a major uptick of detections durin...
If Facebook promised you naked videos of your friends, would you click? As much as you may be tempted to find out why your former 8th-grade computer lab partner is sending you a racy video selfie, beware: it is, of course, a scam.
Microsoft once again gave up only a small percentage of content data to law enforcement agencies that asked for it in the last six months of 2013. Only 2.32% of requests from police and other organizations globally resulted in disclosure of data regarding specific activities or messaging content, it...
The question repeatedly asked by the bitcoin community since Mt Gox announced that all of its bitcoins had been stolen by hackers, is where have they gone? While bitcoins do not reveal their owners, their use can be tracked via blockchains – and there has been no sign of their use.
Getty Images has a reputation for being a copyright maximalist. It has sued breaches of copyright, and lobbied Congress for stricter copyright legislation. So when the world's largest collection of photos – in excess of 80 million still images – declared that many of those images would be available...
Criminal theft of private data from public Wi-Fi hotspots is not new, but is increasing. The two most prevalent methods are traffic sniffing and man-in-the-middle attacks using a rogue, criminal-controlled hotspot. Talking to the BBC, Europol has warned the public to be ever-vigilant in public place...