> TODAY'S SUMMARY (98 articles)
Today's cybersecurity news highlights several critical threats and trends. Z.ai faced backlash for security flaws in its ZCode coding assistant, prompting the temporary disabling of certain features. In the UK, two individuals were arrested following the disruption of the "EvilTokens" AI chatbot, which facilitated cybercriminals in account compromise for a subscription fee. Researchers revealed that stolen passwords pose significant risks to U.S. water providers, exposing critical infrastructure to potential cyberattacks. Additionally, a wave of AI-driven threats is emerging, with reports indicating that AI is increasingly aiding cybercriminals while defenders struggle to keep pace. Lastly, vulnerabilities in Zyxel switches and recent attacks exploiting deepfake technology underscore the evolving landscape of cybersecurity risks.
|
// AI-powered summary generated at 16:01
Researchers have discovered a 'Snapchat' link that provides many things – mainly advertisement-serving adware – but the one thing it doesn't deliver is Snapchat itself.
Two researchers have demonstrated that lessons have not been learned from Robin Sage, a fictitious character created on social media in 2009, who went on to collect friends in the FBI and CIA and get job offers from Google and Lockheed Martin.
Mois de la sécurité, Assises de la sécurité, révélations Snowden sur les pratiques de la NSA, failles Internet Explorer, projet de loi ANSSI : petit tour des actus de l’automne…
Il y a un paradoxe en cette fin d’année 2013 [...] Lire la suite
Mobile malware focused at Google’s Android operating system is proliferating at a prodigious rate. But increasingly, a particularly unsavory brand of malicious adware – dubbed “madware” – has been making significant inroads to Google Play. Volume-wise, it came to be present in 23% of apps in the fir...
(ISC)² has announced the recipients of its annual US Government Information Security Leadership Awards (GISLA) program, including the inaugural Lynn F. McNulty Tribute GISLA award, which went to Dr. Ronald “Ron” Ross, senior fellow at the National Institute of Standards and Technology (NIST).
A paper published this week by the Institution of Engineering and Technology (IET) demonstrates that contactless payment card data can be intercepted at more than four times the distance laid down by standards.
Finnish foreign minister Erkki Tuomioja yesterday confirmed reports that the country's government networks had been breached by hackers. Local TV station MTV3 had earlier claimed that Chinese or Russian agents may have been involved.
Legitimate SMB websites pose a greater cybersecurity threat than pornography sites, says Sian John, security strategist at Symantec.
A flaw impacting Apple iOS-based apps has been discovered that, if exploited, could allow an attacker to hijack the server URL from which mobile applications load their data, replacing the served data with his own content.
The US energy sector experienced the largest number of malware attacks of any industry in the spring and summer of 2012, with the end result being expensive outages at pipelines, oil refineries and drilling platforms. This year, brute-force attacks and botnet infestations are all alarmingly on the r...
BSIMM-V is effectively a scorecard that can be used by companies to either measure or improve their existing software development security stance. It is not a 'standard' in the regulatory sense; it more a practical description of actual best practices.
The lessons learnt from securing the digital infrastructure at the London 2012 Games have given BT a better understanding of how to do cyber defence, said Mark Hughes, CEO of BT Security in his keynote at RSA Europe today
When news of the Adobe breach emerged at the beginning of October, the company admitted that bank card and other personal information on 2.9 million users had been stolen together with usernames and passwords for an undisclosed number of customers. That number is now put at 38 million.
On April 8 2014, Microsoft will withdraw all support from the XP operating system, despite 21% of the worldwide OS marketplace still using it, and 13% of the UK. The results of the latest Microsoft SIR report prove just how vulnerable this will leave users, according to Microsoft director of Trustwo...
There are two undisputed facts in the information security marketplace: there is a severe skills shortage; and women are dramatically under-represented in the security workforce. A new Frost & Sullivan report argues that a solution to the former can be found in redressing the latter.
Cisco has issued three patches to address serious security flaws across a handful of products. Exploitation of the vulnerabilities could give an attacker a way to remotely execute arbitrary code to take over a server, or could lead to a denial-of-service (DoS) attack.
Buffer, a social media app, allows its users to schedule and automatically post updates to social media sites such as Facebook and Twitter. Over the weekend it started posting weight-loss spam tweets and posts.
LinkedIn has released a new product called Intro, which shows users' LinkedIn profiles from inside the native iPhone mail client. Members can, at-a-glance, see the profile picture of the person who’s emailing, learn more about their background, and connect on LinkedIn. It sounds like another step in...
More than two in five Americans (44%) have chosen not to sign the back of their credit or debit cards, instead writing “see ID” or leaving it blank. However, the tactic is not achieving its intended outcome, as 87% of respondents report that majority of the time they make a purchase with their cards...
Google's Safe Browsing Tool, used by Chrome, Firefox and Safari to protect users from sites serving malware, yesterday blocked php.net, home of the hugely popular open-source PHP programming language.