> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
Sweden has sometimes been called the 'Sixth Eye' – referring to the English-speaking Five Eyes SIGINT alliance – suggesting a close working relationship between Sweden's FRA and the NSA and GCHQ. New documents suggest that it has access to the XKeyscore tool, and has helped in the Quantum hacking pr...
The issue of hacked WordPress sites continues to persist, as evidenced by one victimized URL being used to host links to thousands if not millions or billions of shady pharmaceutical sites without the knowledge of the owners.
Mois de la sécurité, Assises de la sécurité, révélations Snowden sur les pratiques de la NSA, failles Internet Explorer, projet de loi ANSSI : petit tour des actus de l’automne…
Il y a un paradoxe en cette fin d’année 2013 [...] Lire la suite
Eleven Microsoft bulletins including ten critical vulnerabilities – some of which are already being actively exploited – affecting all supported versions of Windows, Office, SharePoint, Exchange, and Lync make for a busy last month of a busy year (106 bulletins all told) for sys admins.
The old adage of "if it’s too good to be true that it usually is," continues to hold water. An elaborate social engineering lure using the Affordable Care Act as bait is unfolding, with the end goal of serving up an executable file containing malware.
Ahead of the G20 summit in Russia in late summer, a group of perpetrators (who may be Chinese) carried out a targeted attack on diplomatic missions, including ministries of foreign affairs (MFA), using the crisis in Syria as social engineering bait.
SSL certificates are designed to provide trust in the internet. They are issued by trusted Certificate Authorities to prove that a site is indeed the site it claims to be. But if a certificate is forged, lost, or improperly issued, it provides false trust that can lead to man-in-the-middle cyber att...
Online gamers use false names and characters to meet, chat and interact with other people from all over the world anonymously. NSA and GCHQ began to suspect that criminals and terrorists were using these virtual worlds, such as World of Warcraft, XBox Live and Second Life to 'hide in plain site' – a...
Whether hackers are able to remotely switch on victims' webcams without the camera light giving the game away has been the subject of some debate. Now we learn that not only can it be done, it is done by the FBI.
Two months after European justice ministers agreed the principle of the 'one-stop-shop' for data protection rulings, Hubert Legal (head of legal services for the European Council; that is, the member states) declared it would be a bad outcome likely in breach of European human rights.
At least three distinct versions of the Dexter point of sale (POS) malware are making the rounds this holiday season, designed to steal credit and debit card data from unwitting shoppers.
An international cooperative effort involving Microsoft, the FBI, Europol and A10 Networks has disrupted the ZeroAccess (Sirefef) P2P ad fraud botnet. ZeroAccess is believed to use up to 800,000 out of a total of two million infected PCs at any time, mostly in the US and Europe, capable of stealing...
Amazon made headlines this week with the news that its experimenting with using airborne drones to deliver goods within 30 minutes of order. What could possibly go wrong? Infamous hacker Samy Kamkar highlights one issue with the release of SkyJack – a drone that’s meant to take over other drones.
Two alleged hackers have been arrested in Bavaria and Lower Saxony on suspicion of operating a botnet of compromised PCs to perform bitcoin mining. In related raids, the authorities discovered bitcoins currently valued at around €700,000 and evidence of other criminal activity involving copyright an...
In Beijing, UK Prime Minister David Cameron has challenged the Chinese Government to discuss its industrial-scale cyber-espionage, while in London the Guardian is under legal threat for disclosing GCHQ's own efforts in this area.
The European Network and Information Security Agency (ENISA) has published a good practice guide designed to help the critical infrastructure mitigate cyber-attacks against the industrial control systems supporting vital industry processes.
A new point-of-sale (POS) skimmer, used for lifting credit card details and PIN data at retail locations, has gone on sale for thousands of dollars on semi-private underground crime forums. The skimmer is notable in that it can be installed and removed in the blink of an eye.
This year's Cyber Monday, traditionally the start of the holiday online shopping season, marked the end of it for more than 700 websites involved in selling counterfeit merchandise – all seized in a joint operation between ICE (297), Europol (393) and Hong Kong Customs (16).
This story has been temporarily removed, due to dispute with the report the story was based on. We are awaiting amends from the report authors before re-posting an updated story.
Man-in-the-email is a variation on the man-in-the-middle attack. In this fraud the attacker takes an e-mail position between a buyer and seller, and is able to defraud the buyer out of funds and the seller out of goods. The FBI knows at least three US companies tricked by such a scam in 2013.