> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
The EC Data Retention Directive is already in force in the UK as a Statutory Instrument – The Data Retention (EC Directive) Regulations 2009. A proposed new bill will now force ISPs and telecommunications providers to make this data available to law enforcement in real time.
Global Payments, an Atlanta-based credit and debit card processor for banks and merchants, has suffered a security breach that has exposed information on at least 50,000 cardholders, the Wall Street Journal reported.
ESET has reported on the latest version of the Blackhole exploit kit, noting that it has been updated to include a recent Java vulnerability.
Hotfile is being sued by Warner Bros (and others) – the MPAA – for copyright infringement; Hotfile is countersuing for bogus copyright infringement claims.
Do-Not-Track (DNT) is the evolving standard that will provide internet users with greater control over their privacy on the internet. “Yahoo websites worldwide will comply with visitors’ Do-Not-Track preferences starting later this year,” said the company on Wednesday.
The discovery of the Mediyes trojan using a valid digital signature has raised concerns about the need for proper key management, noted John Grimm with Thales e-Security.
The US government has evidence that Chinese hackers were responsible for the breach of RSA last year that compromised the company’s “underlying software” and required the replacement of hundreds of SecurID tokens, a top national security official told Congress this week.
Chris Aragon, one of the leaders of the ID theft and fraud forum known as the Carders Market, has pled guilty to stealing thousands of personal identities and counterfeiting credit cards to buy high-end goods that were resold on eBay and craigslist.
The US Federal Trade Commission (FTC) has reached a settlement with the social gaming site RockYou over charges it failed to protect the privacy of its users, enabling hackers to access personal information on 32 million users in 2009.
Organized digital crime is growing – but we still know little about the structure of organized digital crime groups. A new report from BAE Detica Systems and the John Grieve Centre for Policing and Security at London Metropolitan University seeks to change this.
The Australian government has blocked China’s Huawei Technologies from participating in the country’s AUS$36 billion national broadband network (NBN) project because of cybersecurity concerns.
A Belarusian named Dmitry Naskovets has been sentenced to 33 months in federal prison for operating CallService.biz, an online site that helped over 2,000 identity thieves commit fraud, federal authorities announced on Friday.
The General Accounting Office (GAO) is warning that insecurity in the global IT supply chain is putting US national security agencies at risk.
The MilitarySingles.com website has apparently been hacked by LulzSec Reborn, exposing user information on 170,000 members.
In a major action against the banking trojan Zeus, Microsoft with FS-ISAC and NACHA and research from Kyrus Tech and F-Secure have succeeded in disrupting a number of the most harmful Zeus botnets in “in an unprecedented, proactive cross-industry action.”
The US government has issued new counterterrorism guidelines that allow for the retention of intelligence on US citizens for five years, rather than the current 180 days.
Managed health care consortium Kaiser Permanente has notified thousands of current and former employees that their personal information was found on an external hard drive purchased in a second-hand store in California.
PwC and Iron Mountain have joined together to develop a risk maturity index for European SMEs; and finds them generally lacking.
Encrypted searching should become available by default for all Firefox users within a few months – a big win for privacy.
On the same day that the Sunday Times reported Indian workers offering UK finance details for sale at as little as 0.02p, the Observer reported that IBM contractors in India will have access to the data of 43 million UK drivers held by the DVLA.