> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
The Utah Department of Health (UDOH) is now admitting that social security numbers of up to 280,000 individuals were stolen from the Department of Technology Services server, a 10-fold increase from the original estimate.
Twitter is usually described as a micro-blogging social network. To many who monitor its ‘trending topics’ it is also an early warning news service, frequently pointing users to breaking news before the traditional news media reports it.
Companies that monitor the end point behavior of their remote workers will have to start monitoring their (internet) behavior in bed. That at least is the inference to be drawn from a new street survey conducted by Infosecurity Europe.
Cybercriminals are sending spam to AT&T Wireless customers with huge bills in order to trick recipients into clicking on a link to malicious websites, according to Commtouch.
New variants of Darkshell, a distributed denial of service (DDoS) botnet targeting Chinese websites, have been detected by McAfee Labs.
Baylor Law School sent out an email to the incoming class informing them of an extension to the deadline for “seat deposits” along with a spreadsheet containing GPAs and LSAT scores on all class members.
Swiss industrial conglomerate ABB does not plan to patch an arbitrary code execution vulnerability in components of itsWebWare Server application, used in various industrial systems, because it is a legacy product nearing the end of its lifecycle.
The UK faction of Anonymous has announced a campaign against the Home Office in protest against extradition arrangements with the US, and the European Arrest Warrant (EAW). It is timed for 9:00pm on Saturday.
In order to protect data from a disaster or cyberattack, organizations should develop a disaster recovery plan based on a cost-benefit analysis of the value of the data versus the cost of maintaining backup facilities, according to a report from Wisegate.
In an apparent about-turn over government plans to allow security and police services to spy on e-mails, phone calls and internet browsing habits, deputy prime minister Nick Clegg said the legislation will be published only as a draft.
Cybercriminals have launched a Blackhole-laden spam campaign against US Airways passengers, trying to convince them to click on a link to "view" their reservation, according to Kaspersky Lab.
The Internal Revenue Service (IRS) just can’t catch a break when it comes to its information security posture; the US Treasury’s auditors are joining the criticisms begun by the Government Accountability Office (GAO) about infosec shortcomings at the US tax collector.
Edward Pearson, aka G-Zero, has been jailed for 26 months at Southwark Crown Court for “making an article for use in fraud and two counts of possession of an article for use in fraud.”
Discussing the latest drive-by threat to Mac users that exploits an unpatched Java vulnerability known as CVE-2012-0507, Graham Cluley of Sophos blogs, “My advice is that if you have no real need for Java, remove it.”
Adobe has released a free tool that helps IT administrators classify suspicious files as malicious or benign using machine-learning algorithms.
A report issued this week by the American Civil Liberties Union (ACLU) claims that local law enforcement is engaged in pervasive warrantless tracking of cell phones.
US defense firm ManTech has acquired technology security firm HBGary, which was at the center of a controversy last year when it claimed to have infiltrated Anonymous and was then attacked by the hacktivist group.
Global Payments, a third-party payment card processor, has admitted that around 1.5 million credit card numbers may have been stolen in a massive data breach last month, up significantly from the original report of 50,000.
Computer storage devices containing personal information on 800,000 California residents were lost following a disaster recovery exercise held by IBM and Iron Mountain on behalf of the California Department of Child Support Services (DCSS).
In its latest Hacker Intelligence Initiative report, Imperva analyzes remote and local file inclusion (RFI/LFI) attacks as favored by LulzSec.