> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
Over the weekend David Miranda, partner of Glen Greenwald - the Guardian journalist who published the first of a series of reports detailing United States and British mass surveillance programs, based on documents obtained by Edward Snowden - was detained at Heathrow for just under 9 hours – the ma...
There have been two new developments in the British lawsuit against Google for allegedly overriding Safari privacy settings to track users’ internet habits: firstly the High Court granted permission to serve on Google Inc, putting the papers into the public domain; and secondly Google responded by c...
Today we’re excited to release an open-source version of iVerify! iPhone users now have an easy way to ensure their phones are free of malware. iVerify validates the integrity of supported iOS devices and detects modifications that malware or jailbreaking would make, without the use of signatures. I...
A man was arrested in Wisconsin this week as the latest move in a long-running battle by the authorities to force him to hand over decryption keys for hard drives believed to contain child pornography.
The Washington Post yesterday issued a brief statement confirming that it had indeed been breached by SEA. At around the same time, the New York Times claimed that a brief outage on Wednesday had been caused by maintenance rather than hacking.
Les composants des systèmes d’information industriels étant mal armés pour résister à des cyber-attaques, que faut-il faire :
les rendre plus résistants en réduisant leur vulnérabilité ? (les « patcher »)
ou les mettre hors de portée des attaquants via des [...] Lire la suite
The Open Rights Group has launched a campaign for the adoption of a new HTTP 400 range status code: Error 451, designed to indicate that access to a page or website is unavailable by court order.
IBM has announced a definitive agreement to buy the Israeli firm Trusteer, which specializes in anti-financial malware and fraud software. Although terms have not been revealed, market estimates put the price at around $800-$900 million.
In filing a motion to dismiss a class action that it illegally intercepts and reads emails, Google lawyers have invoked a ruling from a 1979 court case (Smith vs Maryland) that originally referred to telephony.
Web page spoofing just got easier: One of the defenses against Domain Name System (DNS) cache poisoning and web address spoofing lies in the randomization of the IP address of the queried name server. But a newly found vulnerability in BIND, the most widely used DNS software on the internet, enables...
Considering the hyper-connected world that we live in, a good security mantra should be: if it can be connected to the web, it can be hacked. Even light bulbs. Yes, even light bulbs.
News emerged last week that a London firm had been installing wifi snooping equipment in London recycle bins, spying on the mobile phones of passers-by. But the City of London authorities have moved quickly with a cease and desist instruction.
The Dalai Lama and his supporters have been under almost continuous cyber attack for years. In a new ‘don’t go there’ announcement, a security researcher warned Monday that the Chinese language version of his website has been compromised in a new water hole attack that delivers a backdoor trojan.
Websites using the popular content management system Joomla are at risk of being hijacked for use in malware payload and phishing attacks, thanks to the discovery of a fresh vulnerability and accompanying zero-day attack.
Remember when President Obama had to get a special, encrypted version of his BlackBerry in order to continue using a smartphone post-election? It’s taken the US Department of Defense (DoD) about five years since then to support anything but restricted smartphone use (no selfsies, folks), but now a s...
Just as Bitcoin warns its users that Android-based bitcoin wallets are vulnerable to theft, so the New York Department of Financial Services subpoenas 22 digital currency companies and investors, and investigates the regulatory guidelines that should be put in place.
Following what the Greater Manchester police described as their largest ever cybercrime investigation, two polish men were arrested at a Heathrow hotel on suspicion of blackmailing a Manchester-based internet company with threats of a DDoS attack.
In a testament to the very real business threat that cybercrime represents, a remote access trojan (RAT) has drained a California escrow firm of $1.5 million, forcing it to shut its doors and lay off its nine employees – at the state’s behest.
Privacy International has sent a pre-action letter (a formal pre-cursor to legal action) to BT, Verizon Business, Vodafone Cable, Level 3, Global Crossing (now owned by Level 3), Viatel and Interoute. At issue is the telcos' involvement in GCHQ's spy program Tempora.
Mobile malware continues to escalate in volume, with security vendor Fortinet seeing a 30% increase in malicious samples in just the last six months. The firm is seeing more than 1,300 new samples per day, mostly, unsurprisingly, Android-focused. The threats range from new ransomware samples to new...