> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
As (ISC)² celebrates its 25th anniversary, the global non-profit is well underway to conducting the most extensive overhaul of the CISSP certification exam in its history. Infosecurity catches up with its executive director at the RSA Conference in San Francisco for a retrospective, and what to expe...
The Council on Cybersecurity (CCS) has launched the 2014 US Cyber Challenge, calling on the industry and government to “get serious” about the workforce problem. The initiative aims to find 10,000 bright students and turn them into cybersecurity professionals.
Javelin shows you how modern attackers would approach and exploit your enterprise. By simulating real-time, real-world attack techniques, Javelin identifies which employees are most likely to be targets of spearphishing campaigns, uncovers security infrastructure weaknesses, and compares overall vul...
The BBC reported yesterday that energy companies "are being refused insurance cover for cyber-attacks because their defenses are perceived as weak." Before cover is offered, applicants must undergo a security audit by the insurance companies, but "the majority of applicants were turned away because...
In October 2013 the UK's National Crime Agency announced that a 28-year old Briton, simultaneously identified by the FBI as "Lauri Love, 28, of Stradishall, England," was arrested on suspicion of hacking into US Army, US military and US government computers. Yesterday the FBI further charged him wit...
Have you ever wanted to make a query into a native mode program asking about program locations that write a specific value to a register? Have you ever wanted to automatically deobfuscate obfuscated strings? Reverse engineering a native program involves understanding its semantics at a low level unt...
A new variant of ransomware dubbed BitCrypt has been smashed open by a pair of French researchers.
The US is not unique among nations when it comes to its intelligence gathering abilities. “We are just better” at it than most countries, according to Richard Clarke, the former presidential counter-terrorism adviser.
In his keynote at the RSA Conference in San Francisco, February 25 2014, Scott Charney, VP of Microsoft’s Trustworthy Computing Group, insisted that Microsoft has not compromised its principles in order to work with the NSA
In the opening keynote at the RSA Conference 2014 in San Francisco, Art Coviello, Executive Chairman of RSA, gave his first public comments about RSA’s relationship with the NSA.
Last month, Trustwave's Neal Hindocha wondered whether cybercriminals could adapt to changes in user habits. In the PC world, a major tool for cyberthieves is the keylogger, used to capture passwords as they are entered at the keyboard. But users are switching to phones and tablets that have no keyb...
It has become increasingly obvious in recent months that routers are being targeted by attackers – even the NSA uses this attack vector as part of its Quantum Injection program. Now a new survey suggests that as much as 80% of the best-selling SOHO routers include vulnerabilities.
Global IT association ISACA has issued the first of more than 30 audit programs that will align with the COBIT 5 business framework, which helps enterprises govern and manage their information and technology.
Tinder is a very popular mobile dating app. It is designed to allow people to 'meet' virtually before deciding whether they would like to meet for real. Unfortunately, Tinder has a history of allowing one user to physically locate another, even if the approach has been rejected.
The latest Cenzic report on application vulnerability trends shows that things aren't getting any better. All software has bugs, and almost all of them have bugs that are security vulnerabilities. In fact, on average, they have 14 separate vulnerabilities – a quarter of which are cross-site scriptin...
Microsoft has paid out its second $100,000 bug bounty since launching its reward program in mid-2013. The award brings total payouts for the program to $253,000 in under a year.
A new variant of the notorious Zeus banking trojan is making the rounds, with a new approach that uses steganography, a technique that allows it to disguise data inside of an existing file without damaging it.
CNN Money described Shodan as "The scariest search engine on the Internet." Forbes called it a "terrifying search engine." Unlike Google, Shodan searches for internet-connected devices (which could have known vulnerabilities) rather than information. For those who believe this is scary, it just got...
Rapid7's Metasploit researchers have developed a new exploit for an old vulnerability that remains pervasive in the Android ecosystem some 9 months after it was patched by Google. With this new code, 70% of all Android users are vulnerable to a little social engineering and a remote takeover.
An analysis of compromised credentials posted to Pastebin suggests that hundreds of millions of passwords are being compromised by cybercriminals every year.