> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
On Friday 3 January, Dutch security firm Fox-IT detected malicious activity on some of its clients' networks – with a common factor: they had all previously visited yahoo.com. Further investigation revealed malvertising on the Yahoo site – and it is possible that millions of users have been infected...
Two researchers, Andrew 'bunnie' Huang, and Sean 'xobs' Cross, gave a talk at the Chaos Computer Congress describing how the ubiquitous flash memory card can be used to deliver a MITM attack against its host system. The problem is that SD cards are simply trusted, when perhaps they should not be.
AutoIT, a flexible coding language that’s been used since 1999 for scripting in Windows, is now cropping up in next-gen malware like a Zeus variant that efficiently steals information from FTP sites and personal certificates.
Blizzard, the company behind the popular online multiplayer World of Warcraft game, has warned its gamers that a “dangerous Trojan” called Disker is being used to compromise player's accounts, even if they are using an authenticator for protection.
TAO, Tailored Access Operations, is the elite hacking group operated by the US National Security Agency. Its existence was exposed by the 'black budget' for 2013 leaked by Edward Snowden. Now Der Spiegel has published further details on the group that will play a major part in the projected infiltra...
Spook gadgets have come a long way from Maxwell Smart’s shoe phone. Reports have surfaced that the US National Security Agency can now turn iPhones into eavesdropping tools.
Customers at eight Boston-area dining establishments owned by the Briar Group may have had their credit and debit card data stolen. The mix of restaurants and Irish-style pubs are popular around the metro area, and include Anthem, City Bar, City Table, MJ O'Connor's, Ned Devine's, Solas, The Green B...
Back in August, GibsonSec warned that Snapchat's API was insecure, and offered to help. It got no response, other than Snapchat adding some security features and implying it was safe. Apparently frustrated, GibsonSec published full details on Christmas Day.
Reports have emerged this morning about a short-lived hack of Skype's Twitter and WordPress accounts by the Syrian Electronic Army. No evidence of the hack remains, although screenshots purportedly demonstrate that it happened. Unusually, it is in protest of NSA surveillance and alleged Microsoft co...
CryptoLocker, the ransomware that uses a public-private key combo to potentially lock out victims from their files forever, has been striking since mid-September. And since it made its debut, it’s managed to make off with at least $300,000, one $300-or-less ransom payment at a time.
A worldwide group of top stock exchanges have gotten together to launch the industry’s first cybersecurity committee, with a mission to aid in the protection of global capital markets.
The accusation, made Friday by Reuters, is that "RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software."
The UK’s Information Commissioner’s Office (ICO) is warning consumers to protect their personal information when downloading mobile apps, ahead of the busiest day of the year for app downloads. In tandem, it also issued guidance to help developers look after people’s information correctly and comply...
The US, originator of Black Friday holiday sales and the dubious homeland of in-store, post-Thanksgiving brawls over hot toys (remember Tickle-Me Elmo?), has been hit with the largest retail breach of credit and debit card information of 2013. In fact, at 40 million affected and counting, the securi...
In Part 3 of our week-long look at industry predictions, we examine the effect and influence of government. There are two primary aspects: the influence of government (regulations); and the effect of government (which has been shown in the latter half of 2013 to have turned the internet into its own...
Bruce Schneier, BT's security futurologist, is leaving the company after eight years. In June 2013 he joined the board of digital rights firm Electronic Frontier Foundation, and has – since the Snowden revelations began – been a fierce critic of NSA/GCHQ mass surveillance. With BT increasingly impli...
A slaving operation masquerading as a legitimate add-on for the Mozilla Firefox browser has created a 12,500-PC strong botnet army whose purpose is to find exploitable websites.
The US Department of Energy’s failure to address known cybersecurity weaknesses was a direct cause of a July 2013 data breach that affected more than 104,000 individuals, according to federal auditors.
The internet is a pretty busy place, with traffic increasing year over year exponentially. According to the Cisco Visual Networking Index, global IP traffic has increased more than fourfold in the past five years, and will increase threefold in the coming five years. Overall, IP traffic will grow at...
NSA Information Assurance Director Debora Plunkett made a remarkable accusation on CBS 60 Minutes: the NSA had spotted and foiled a plot to unleash a supervirus capable of bricking computers. "The attack would have been disguised as a request for a software update," she told CBS. "If the user agreed...