> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
On 25 August, the EU’s new breach notification Regulation for electronic communication service (ECS) providers came into force. The Regulation supplements an earlier Directive that instructed ECS companies to notify their competent national authority in accordance with national laws.
When it comes to locking down enterprise infrastructure, the application layer is responsible for more than 90% of all security vulnerabilities, yet more than 80% of IT security spending continues to be at the network and endpoint layer, new research has found.
Les conférences Black Hat et DEF CON à Las Vegas sont les événements cybersécurité de l’été aux USA, avec chaque année des douzaines d’interventions, y compris sur les systèmes industriels. Cet article analyse celles concernant la cybersécurité industrielle.
Je [...] Lire la suite
Rather than hack individual websites or Twitter accounts, SEA’s latest attack was on the MelbourneIT domain registrar. It was then able to redirect visitors to MelbourneIT’s customers – including the New York Times, Twitter and Huffington Post – to an SEA controlled website.
One of the world’s leading password crackers just got better and is now able to crack passwords of up to 55 characters in length and algorithms such as TrueCrypt 5.0+, LastPass and Samsung Android Password/PIN.
Today we’re excited to release an open-source version of iVerify! iPhone users now have an easy way to ensure their phones are free of malware. iVerify validates the integrity of supported iOS devices and detects modifications that malware or jailbreaking would make, without the use of signatures. I...
Facebook has now joined other major cloud service companies with its own version of a transparency report: its first Global Government Requests Report purports to show how many government requests for user data it received in the first six months of 2013.
Molerats is the term used for a hacking campaign orchestrated by the Gaza Hackers Team. Until now it had seemed that this group concentrated on using the XtremeRAT trojan. New research now suggests that that the group has also started using the Poison Ivy RAT.
The latest revelations from Edward Snowden published by Der Spiegel and Laura Poitras, the American film maker based in Berlin and visited by David Miranda before his detention at Heathrow, shows extensive and sophisticated NSA surveillance of both the EU and UN organizations in the US.
A European privacy activist is warning that Twitter monitors users' Direct Message private tweets, even to the extent of visiting URLs contained and copying the content of the web pages concerned – most likely for behavioral profiling.
Lady Gaga is…displeased. She’s blaming “hackers” for the leak of her new single, “Applause,” ahead of its scheduled release date on August 19.
China faced the largest distributed denial-of-service (DDoS) attack in its history over the weekend, leading to a two-to-four hour shutdown of swaths of IP addresses using .cn, China's country code top-level domain.
The concept of a hacker causing a heart attack by remotely compromising a pacemaker or shutting down an insulin pump on a diabetic is unfortunately not in the realm of science fiction, with very real vulnerabilities having been found in connected medical devices. The US Food and Drug Administration...
Anti-virus companies don’t just block malware – they also give their customers the option to block ‘potentially unwanted apps’ or PUAs. These aren’t strictly malware, but can violate a user’s privacy. Adware can potentially be a PUA.
The problem revolves around the upcoming Trusted Platform Module v 2.0 developed by the US-dominated Trusted Computing Group, which cannot be deactivated by the user. The concern is that this provides a back door for Microsoft, and by extension, for the NSA.
Kim Dotcom warned earlier this month that if a new bill – the Telecommunications (Interception Capability and Security) bill known as TICS – were to become law, he would move Mega’s privacy services out of New Zealand. TICS was passed yesterday in the New Zealand parliament by a vote of 61 to 59.
The cost of cybercrime is frequently used to justify the cost of security products and the implementation of new – and invariably more stringent – cyber laws. But what if those figures are wrong? Could it mean that industry, and government, gets its entire cybersecurity strategy wrong?
The contradiction behind a remote access trojan (RAT) such as Poison Ivy is that while it is easy to use and widely used, it can also indicate a sophisticated – or APT-style – attack designed to exfiltrate specific data from major organizations.
The US National Institute of Standards and Technology (NIST) has updated two of its computer security guides to help system managers protect their systems from hackers and malware.
When Microsoft announced that it would discontinue support for Windows XP starting on April 8, 2014, many companies began the long process of transitioning to modern operating systems like Windows 7 or Windows 8. But there are others that won’t – and the software giant is raising the spectre of a ze...