> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
Following the arrest of Eric Eoin Marques last week, websites in the darknet hidden services began to go down. A piece of javascript malware was found and posted to the internet. Researchers are now wondering if this is the first live sample of the FBI's fabled CIPAV malware.
On Friday the Irish High Court denied bail to Mr Eric Eoin Marques, arrested the day before on an extradition warrant issued in Maryland charging him with distributing and promoting child pornography on the internet.
Today we’re excited to release an open-source version of iVerify! iPhone users now have an easy way to ensure their phones are free of malware. iVerify validates the integrity of supported iOS devices and detects modifications that malware or jailbreaking would make, without the use of signatures. I...
The hacker known as Guccifer, who makes a habit of hacking the rich and powerful – the 'Illuminati' in his own terms – has struck again, this time forcing former US Secretary of State Colin Powell to deny an affair.
Just over a week ago Symantec published a note on a new spam bot that it was and is currently investigating. A Swiss researcher, however, was already on it, having trapped the first instance in his sandnet two days earlier.
Les composants des systèmes d’information industriels étant mal armés pour résister à des cyber-attaques, que faut-il faire :
les rendre plus résistants en réduisant leur vulnérabilité ? (les « patcher »)
ou les mettre hors de portée des attaquants via des [...] Lire la suite
The Comfoo trojan has been in continuous development since at least 2006. It has more than 200 variants and has been used in at least 64 different campaigns, including the RSA SecurID breach in 2010 – but little has been known about it.
Two different presentations at Black Hat Las Vegas on August 2nd 2013 called new attention to the risks posed by smart TVs increasingly found in homes and offices around the world. Researchers demonstrated how vulnerabilities in these systems can be used to steal online credentials, sensitive data a...
Self-promotion through social media is the key to improving your visibility in the information security industry Javvad Malik told an engaged audience at BSides Las Vegas on August 1st 2013.
A new community database has been launched by Verizon to help bridge the uncertainty gap in data breach information: what we know and what we need to know. Based on VERIS, it is designed to facilitate the secure sharing of incident information for the good of all.
The Guardian has released the latest of its Edward Snowden leaks – NSA training material for a system called XKeyscore that allows analysts to search through vast databases of emails, online chats and browsing histories.
Responsible zero-day vulnerability disclosure is on the increase, according to Brian Gorenc, manager of HP’s Zero Day Initiative.
As the Syrian Electronic Army (SEA) continues its hacking spree across largely Western organizations, it is worth pausing to question: what is the SEA, how does it operate, and what are its motivations?
iOS apps are worse than Android apps, and free apps are worse than paid apps – but in a study that has implications for both personal and BYOD use, as many as 83% of all apps exhibit at least one form of risky behavior.
It's a question of where to start: TalkTalk's filter provided by Huawei; more than porn will be blocked; UK's 'pornification' MP Claire Perry hacked and now sued; at least one ISP in open rebellion; and Anonymous launches op PornStorm.
Google's Chromecast, a $35 device for streaming internet video to the TV, has been rooted within days of its launch.
Caroline Criado-Perez successfully campaigned for the inclusion of women on British banknotes. But from the moment it was announced she had succeeded and that Jane Austen will appear in 2017, she has received a barrage of abuse and threats via Twitter.
A new report claims that computers from the world's largest PC manufacturer, China's Lenovo, have been banned from use within the interconnected intelligence networks of the US, UK, Australia, New Zealand and Canada.
Well-known “ATM hacker” Barnaby Jack died on Thursday in San Francisco. He passed away just ahead of the Black Hat conference where he was planning to speak on “Hacking Humans,” including a man-killing compromise of heart implants.
Four Russians and one Ukrainian were yesterday charged with conspiracy in a worldwide hacking spree that stole 160 million credit card numbers and cost the victim companies hundreds of millions of dollars.