> TODAY'S SUMMARY (7 articles)
Today's cybersecurity news highlights several significant threats and trends. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing ongoing risks in open-source software. An npm malware campaign has been discovered, wherein malicious packages evade defenses by embedding harmful code within normal runtime behaviors. In a notable incident, an AI-generated report nearly triggered a military confrontation between the U.S. and China due to incorrect intelligence. Additionally, researchers successfully escaped the OpenAI Codex sandbox, prompting the company to implement patches. Cisco has also patched a critical exploited email gateway zero-day. The ongoing evolution of these threats underscores the need for robust cybersecurity measures and vigilance.
|
// AI-powered summary generated at 20:01
The US Department of Health and Human Services (HHS) is fining Blue Cross Blue Shield of Tennessee $1.5 million related to the 2009 theft of 57 unencrypted computer hard drives containing protected health information on over one million patients.
The Tolly Group has published a new report: 'Comparison of Bit9 Advanced Threat Solution versus McAfee Endpoint Protection Suite and Symantec Endpoint Protection 12.1'. But are they apples and oranges?
Le symposium S4, qui a eu lieu fin janvier à Miami, marque une nouvelle étape dans l’odyssée de Charybde à Scylla de la cybersécurité industrielle. Comme après la conférence « Black Hat » de l’été 2011, les informations présentées obligent à [...] Lire la suite
New Zealand’s Accident Compensation Corporation (ACC), which provides personal injury insurance to New Zealand residents, admitted that a spreadsheet containing 9,000 claims with personal details on 6,000 individuals was inadvertently sent to a client.
SafeNet buys Cryptocard to offer the best of both worlds (local and cloud) in user authentication.
Security consultancy Context has produced an analysis of framesniffing, an attack technique that can data mine sensitive data through web browsers and iFrames.
The US Department of Homeland (DHS) has strengthened the sharing of federal classified information with state, local, tribal, and private sector partners.
China is suspected of being behind social engineering attacks using a bogus Facebook account of the NATO commander to steal secrets from colleagues, friends, and family.
Recent reports on the return of the Kelihos demonstrate the difficulty in keeping a good bot down.
US telecom executives came out strongly against government regulation of cybersecurity in the private sector during a House hearing this week.
A team from the French security firm Vupen has cracked a second browser during the Pwn2Own hacking contest at CanSecWest – Internet Explorer 9 – after compromising Chrome on the first day of the competition.
The Skills Framework for the Information Age (SFIA) Foundation has recognized two ISACA information security certifications as part of its IT skills framework.
Canada’s McGill University has shut down a website that published confidential data on school donors, including names, addresses, phone numbers, and the amount they donated.
GFI Software’s report for February highlights two main issues: the incidence of rogue anti-virus is continuing to increase; and the Kelihos botnet ‘taken down’ last year is resurgent.
Anonymous has vowed to do a hack every Friday, calling it the #FFF campaign. Today AntiSec defaced the New York Ironworks, a police equipment supplier that describes itself as ‘NYC's finest police equipment & tactical op’s gear store.’
Kaspersky Lab researcher Igor Soumenkov is asking for help in identifying a mystery code in the Duqu virus, the follow-on to Stuxnet uncovered last year.
The Obama administration on Wednesday simulated a cyber attack on the New York City power grid during a summer heat wave in an effort to convince US senators to pass comprehensive cybersecurity legislation.
Becrypt’s DISK Protect full-disk encryption product is the first commercial product to be granted CPA certification. By encrypting local authority laptops, it may help prevent the continuous leakage of personal data.
Trustwave, a Chicago-based security company with offices around the world, has signed a definitive agreement to acquire M86 Security, which is based in Irvine California and has international headquarters in London and R&D in California, Israel and New Zealand.
Only 34% of companies are strongly confident about quantifying the potential financial impact of a data breach, according to a report by security firm McAfee.