> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
In an apparent effort to turn the public relations tables, China is claiming that most of the foreign cyberattacks against Chinese computers are coming from Japan, the US, and South Korea.
Two southern California men pled guilty this week to participating in a PIN-pad tampering scheme at 84 Michaels craft stores that resulted in the theft of 94,000 debit and credit card account numbers.
StubHub, an online ticket exchange, was having trouble with criminals using its open platform to verify credentials that had been stolen from other sources. The website turned to SilverTail for help, explained Robert Capps, senior manager of trust and safety at the company.
The average organizational and per capita cost of a data breach in the US declined in 2011 for the first time in the seven years that the 'US Cost of a Data Breach Study' has been compiled.
The National Institute of Standards and Technology (NIST) has released technical guidance for evaluating the usability of electronic health records (EHR), while maintaining the security and privacy of those records.
The Russian Ministry of Internal Affairs and the Federal Security Service this week arrested eight men allegedly involved in a Carberp bank fraud ring.
At a security conference organized by Null in India, Matrix Shell claimed and demonstrated the ability to hack into GSM phones and manipulate the user’s International Mobile Subscriber Identity.
Indiana University and Microsoft researchers have uncovered flaws in Web-based single sign-on (SSO) services run by Google, Paypal, Facebook, Twitter, and others that allow hackers to get access to users’ accounts.
The Russian government has appointed Andrei Krutskikh as cybersecurity coordinator under the Foreign Ministry.
Rogue anti-virus products continue to be a major source of malware. The trick for the criminal is in getting the victim to click the link; and GFI has spotted a new development.
The average cost to UK business per record lost, according to the latest Symantec/Ponemon study, has increased from ÂŁ47 in 2007 to ÂŁ79 in 2011. Had it been inflation alone, it would have increased to just over ÂŁ53.
The top security concern of IT professionals regarding public cloud computing is the lack of perimeter defenses and/or network control, according to a survey by cloud security provider CloudPassage.
(ISC)², a non-profit information security professional association, and the Information Technology Acquisition Advisory Council (IT-AAC), a non-profit organizations to improve IT acquisition standards, have formed an alliance to improve the US government’s acquisition of IT products through security...
A number of hackers have succeeded in jailbreaking the new iPad within hours of its release.
Tibetan organizations are under attack from Chinese spear phishers who were also behind the Nitro attacks that targeted Western chemical and defense firms last year, according to research by AlienVault.
The Hydraq trojan, which wreaked havoc during the Operation Aurora attacks in 2009, is back. Actually, it never went away, note Symantec researchers.
On 6 February hacktivist group Anonymous delivered a threatening email to Bashar Assad’s personal email account. On 7 February his use of that account ceased.
Consumers are taking privacy and security into account more often when making purchasing decisions, would consider leaving companies in the wake of a data breach incident, and measure corporate reputation based on these issues, according to a survey by public relations firm Edelman.
Mozilla has fixed eight vulnerabilities, a majority of them “critical”, with the release of the latest version of its web browser, Firefox 11.
The Dutch Big Brother Awards for 2011 have been announced. There are three prize categories: People, Companies and Government.