> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
Columbia University has notified 3,000 faculty members that their names, addresses, social security numbers, and bank account numbers were available on the internet for two years.
Genuine news sites publish information on events – these sites, say the Chinese authorities, promised not to publish information for a fee.
A software bug can often lead to a vulnerability that can be exploited with sophisticated exploit code. Or sometimes you can just instal a free add-on that lets you do the same thing with no effort.
In a joint exercise between between multiple law enforcement agencies, 36 websites associated with an e-commerce platform known as an automated vending cart (AVC) used to sell stolen credit cards were taken down on Wednesday.
A researcher has uncovered a backdoor in RuggedCom software used to control traffic and railroad systems that could enable a remote attacker to take control of the systems.
A hacker has posted source code for VMware’s ESX virtual machine on the internet, the company has confirmed.
Christopher Graham, the UK Information Commissioner, talks about his role as an information regulator and facilitator at Infosecurity Europe in London
A disturbing one in five Mac computers are infected by some form of malware, according to research by IT security firm Sophos.
The three companies represented on the keynote panel (G4S Secure Solutions, Steria UK, and Skipton Building Society) are very different; and their CISOs have very different views on the functioning of risk management within infosec.
The US Department of Health and Human Services, the Health Information Trust Alliance (HITRUST), and 14 healthcare organizations have set up the first Cybersecurity Incident Response and Coordination Center for the healthcare industry
Symantec has identified a social engineering scam that attempts to get users to download malware from third-party Android sites by passing itself off as part of pop icon Björk’s popular Biophilia app.
I am not a hacker, says Zarefarid. I did this to warn Iranian card holders that their accounts are in danger.
The Flashback trojan, which infected more Macs than any other malware in history, used hacked WordPress sites to get onto machines, according to Kaspersky Lab researcher Vicente Diaz.
The South Carolina Department of Health and Human Services announced this week that an employee stole personal data on 228,000 Medicaid recipients.
“The EU-US Passenger Name Record (PNR) agreement was adopted with 409 votes in favour, 226 against and 33 abstentions,” announced the EU yesterday. Opponents included “rapporteur Sophie in'T Veld, who withdrew her name from the report.”
The British Standards Institution (BSI) has recently updated its standards for information security auditing, BSI officials told Infosecurity.
The UK government's plans to allow security and police services to spy on e-mails, phone calls and internet browsing habits are dangerous, according to World Wide Web inventor, Sir Tim Berners-Lee.
Trusteer has discovered spyware being sold in underground forums for $280. It targets hospitality PoS applications.
Google is warning around 20,000 webmasters that their sites may be compromised and are carrying out “weird redirects” to malicious sites.
New statistics show that while many companies appear to understand the business threat from BYOD, many others are taking no precautions whatsoever.