> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
Charlie Miller, computer security researcher at Twitter, declared mobile threats “all hype” despite media headlines suggesting that they are a number one security concern.
F-Secure's Threat Report for the first half of 2013 says that threat vectors have remained similar but got worse over the first half of this year. Watering hole attacks and mobile malware are good examples.
Les conférences Black Hat et DEF CON à Las Vegas sont les événements cybersécurité de l’été aux USA, avec chaque année des douzaines d’interventions, y compris sur les systèmes industriels. Cet article analyse celles concernant la cybersécurité industrielle.
Je [...] Lire la suite
Last week Microsoft issued a warning on a new zero-day exploit being used in targeted attacks. On the same day researchers published details on the Hidden Lynx hacking group. Now new research ties the IE 0-day to those same hackers.
The low cost of Chromebooks coupled with the 'free' use of Google Apps and their in-built capacity for collaborative work threatens to revolutionize computing in schools. But SafeGov is warning that it may come at the unacceptable cost of the privacy of a vulnerable section of society: schoolchildre...
In a stinging rebuke on the concept of fingerprint security, Germany's Chaos Computer Club hacks the iPhone 5s fingerprint access and claims "that fingerprint biometrics is unsuitable as access control method and should be avoided."
A resurgence of the Shylock/Capshaw banking threat has hit banks across the EU again, as well as several top US banks. In all, Capshaw is this time being found to affect at least 24 financial institutions.
Eight leading North West businessmen, including Rob Cotton, CEO of NCC Group, celebrated an epic success this week, raising over ÂŁ210,000 to date for The Christie NHS Trust while beating the hardest stages of the Tour de France route in the process.
Market confidence in Silicon Valley is rising again. While Twitter has announced plans for an IPO, FireEye has proceeded with its own, selling more shares at a higher price than at first intended.
Last week NIST recommended that its elliptic curve specification 'no longer be used.' Now, in an email advisory sent to customers, RSA strongly recommends that developers discontinue use of Dual EC DRBG and move to a different PRNG.
Apple's new iOS 7, pre-loaded on the new iPhone 5s and 5c, is also available for download to older devices. It is said to include more than 200 new features – here we look at some of the security aspects and issues.
Tor is known as a privacy browser, favored by political dissidents, journalists and others looking to be online anonymously. But a new report shows that almost a third of its traffic is fraudulent as well, pointing to its potential status as a criminals’ haven.
A highly sophisticated “hacker for hire” group operating out of China has surfaced. Not quite a crouching tiger or a hidden dragon, but somewhere in between, the “Hidden Lynx” hacking group is a team of professionals with a strong capacity and proven ability to adapt to current security practices –...
The W3C working party tasked with defining the mechanisms that will underpin Do Not Track processes is now in serious danger of collapse following the third major defection in as many months.
The Foreign Intelligence Surveillance Court yesterday published an opinion, written on August 29 by Judge Claire Eagen, explaining the legal reasoning behind its order authorizing the NSA to collect data on all US telephone calls.
A team from universities in the US, Netherlands, Switzerland and Germany have published research demonstrating that subtle changes below the gate level of chips can alter functionality in a controlled but covert manner.
Itching to jailbreak Apple's iOS 7? Ready to root a Samsung KNOX phone? Frothing at the mouth to show vulnerabilities in the iPhone 5S fingerprint reader? And get paid for it? Well if so, you’re in luck: HP’s Zero Day Initiative (ZDI) has announced the second annual Mobile Pwn2Own competition, to be...
Trusted platform modules (TPM) have been around for more than 10 years, but adoption of them by users has been slow going. Led by Infosecurity magazine’s Drew Amorosi, a panel of industry experts came together at the Trusted Computing Conference in Orlando last week to discuss TPM adoption and the o...
While the world has been hearing about the surveillance techniques of the spy agencies in the US and UK, the capabilities available to anyone through Open Source Intelligence (OSINT) products have been quietly expanding.
The deadline for abandoning SSL certificates with less than 2048-bit keys is approaching, and as of Dec. 31 of this year will be revoked. At least one vendor is setting an earlier deadline: for Symantec, it’s Oct. 1.