> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
In a move designed to offer genuine hands-on security experience to EMEA’s different security initiatives, professional body (ISC)² has launched a new Advisory Board for Europe, the Middle East and Africa (EAB).
Spammers have their sites on Verizon Wireless customers after targeting those of AT&T Wireless earlier this month.
Darkmegi, malware that uses a kernel rootkit component to infect computers, has begun exploiting a flaw in Java to conduct drive-by attacks, according to McAfee Labs.
Khosrow Zarefarid found and reported a flaw in the Iranian POS system. He reported it, but was ignored – so he used it and hacked 3 million Iranian debit card details.
In a move that will be monitored by the UK’s music industry association (BPI), its Dutch equivalent BREIN (translates as ‘Brain’) has obtained a court injunction forcing the political party, the Pirate Party, to take down the proxy site that was allowing users to continue using the blocked Pirate Ba...
Los Alamos National Laboratory, the government lab responsible for the security of the US nuclear stockpile, recently conducted a vigorous cyber exercise involving more 100 participants from a number of federal agencies.
After suffering a series of cyberattacks, the interim Tunisian government is taking steps to solidify the security of government email accounts and websites.
The complete Facebook account of Philip Markoff, in hard copy and including friend IDs, was given by the Boston Police to the Boston Phoenix newspaper.
“For the reasons given in this Notice...”, says an FSA Decision Notice, "...the FSA has decided to impose on Mr Ian Charles Hannam a financial penalty of £450,000.”
The Dirt Jumper distributed denial of service (DDoS) bot family has evolved into over 300 varieties of bot packages, explained Curt Wilson of Arbor Networks.
The International Organization for Standardization (ISO) has published new standards for interorganizational and intersector communications, including data exchanges for critical infrastructure.
The US plans to fast-track the development of cyber weapons to give it the ability to create the means to attack specific targets within months, and even days.
A zero-day security flaw has been identified in the latest version of BackTrack Linux, a version used by security professionals for penetration testing. The vulnerability was discovered by a student in the InfoSec Institute’s ethical hacking class.
ISACA, the not-for-profit IT security association, has issued COBIT 5, the latest version of its IT security reference guide.
Research from by Altimeter Group, Bloor Research and Trend Micro shows that the ‘consumer marketing’ legacy of many smartphones makes them ill-equipped to meet enterprise security demands.
In a project that started from law enforcement agencies' request to the US Department of Homeland Security (DHS), which was then farmed out to the US Navy, Obscure Technologies of California has been awarded a contract to find ways of hacking game consoles.
More than half of small and medium-sized businesses (SMBs) are most concerned about SQL injection attacks against their databases, according to a survey of 6,000 SMBs users of GreenSQL’s database security product.
Adobe has shipped updates for Reader and Acrobat that fix four security holes that could cause the application to crash and allow an attacker to take control of an affected system.
Anonymous claimed credit for launching distributed denial-of-service attacks (DDoS) against a number of high-tech trade groups in retaliation for their support of the Cyber Intelligence Sharing and Protection Act (CISPA).
Google has released an update for Chrome that fixes a problem with the SSL certificate when users attempt to connect to sites over HTTPS.