> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
Just as a new report explains why Java vulnerabilities, despite Oracle's best efforts, remain the hackers' favored target, a Polish researcher discovers that the latest version, Java 7, is susceptible to a 10-year old attack.
Numericable is a cable TV company operating in France, Belgium and Luxembourg. Rex Mundi claimed to have stolen customer data and demanded €22,000 for its return. Numericable declined, and denied that the hackers had the data.
Les composants des systèmes d’information industriels étant mal armés pour résister à des cyber-attaques, que faut-il faire :
les rendre plus résistants en réduisant leur vulnérabilité ? (les « patcher »)
ou les mettre hors de portée des attaquants via des [...] Lire la suite
A brief statement from Tumblr late on Tuesday confirmed that its iPhone and iPad apps had been updated to patch "an issue that allowed passwords to be compromised [sniffed] in certain circumstances."
The legality of Prism in the US is a question for Congress and the US courts, says Sir Malcolm Rifkind, chairman of the UK's all-party Intelligence and Security Committee – but the acquisition of Prism data by GCHQ is done legally.
We interrupt our regularly scheduled programming to bring you an important announcement: On Thursday, June 6th, just in time for SummerCon, we will be hosting a free Ruby Security Workshop in NYC! Signups are first-come, first-serve and we only have space for 30 people. Sign up here and we will emai...
Malware authors are ever-adaptable, as evidenced by the rise of remote access tools (RAT) written in Java that are capable of running on multiple operating systems. The Android mobile operating system has made its way into the RAT crosshairs, with a new “binder” for sale in the criminal underground...
The France-based mobile security specialist will participate in Japan’s leading IT innovation trade event to demonstrate its security solutions.
Spear-phishing is an attack that attempts to ensnare a specific individual or group of victims via email; water hole attacks wait for the victim to come to the trap. Attackers – especially state-sponsored attackers – are increasingly turning to the latter as their weapon of choice.
Femtocells are nice-to-have mini-cells that boost cellular coverage indoors, to prevent consumers from going down to one, slow bar inside a house or store. Verizon Wireless offers femtocells for home use, but it turns out they can do more than supercharge one’s 3G – the $250 gadgets can also be tur...
A file infector malware recently discovered in the wild is exhibiting what security researchers are calling unusual characteristics stemming from an unexpected combination of threat techniques.
Surveys show that employees spend up to 30% of their working hours on private affairs. And all of those non-productive hours could translate to not just lost output, but actual negative equity in the form of malware attacks and hacking incidents.
Half-Life is a popular game developed by Valve and available on the Steam gaming platform. Enthusiasts of Half-Life 2 have been waiting years for the next installment; long wanted but never delivered. Despite the 'confirmation', it still isn't.
The extent and sophistication of the market for zero-day vulnerabilities is becoming better understood. It appears that governments – especially the US, UK, Israel, Russia, India and Brazil – are among the biggest customers.
The UK's Information Commissioner has fined NHS Surrey £200,000 for not ensuring that patient data was completely removed from recycled PCs. Some of those PCs ended up on an online auction site.
As the annual Def Con event prepares to launch in Las Vegas on August 1, 15,000 hackers are planning to descend onto the hot desert landscape. Organizers have however warned federal agents, government security staffers and law enforcement agents that their particular presence is not required.
Cue the Mission Impossible theme: Europeans (especially the French) really like the idea of biometrics – ultraviolet fingerprint authentication, vein topography scans and the like – when it comes to slipping into secure corridors and preventing international criminals from moving across borders. But...
Konami Digital Entertainment announced on Wednesday that it had experienced 35,252 unauthorized logins (out of 3,945,927 attempts). This occurred within days of a similar experience at Nintendo.
Trusted and popular cloud services Dropbox and Wordpress are being incorporated into sophisticated, targeted APT-style attacks by the same Chinese group thought to be behind the New York Times compromise late last year.
The Canada-based ID management specialist has unveiled a new release for its ID Management Suite, with additional features. The firm has also inked a deal with one of Europe’s leading telecommunications providers.