> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
More than half of employees said they do not always follow their company’s IT security policies or are not even aware of those policies, according to a survey sponsored by McAfee and Xerox.
Another day, another lost memory stick: this one with details of a UK nuclear power station including plans and a stress test lost in India.
Le symposium S4, qui a eu lieu fin janvier à Miami, marque une nouvelle étape dans l’odyssée de Charybde à Scylla de la cybersécurité industrielle. Comme après la conférence « Black Hat » de l’été 2011, les informations présentées obligent à [...] Lire la suite
The UK Government is renewing its plans to retain internet and mobile phone traffic data on everyone for a year.
Google is again fixing flaws in its Chrome browser only a week after plugging 20 security holes with the release of version 17.
The US Central Intelligence Agency’s private sector research funding arm, In-Q-Tel (IQT), is investing in technology to analyze binary code in order to uncover malware.
Hackers likely downloaded encrypted credit card transaction information from a backup database of Steam online game distribution platform users, Valve announced recently.
Visitors to the rnbxclusive website are met with a stern rebuke from a UK LEA. Italian Windows users can receive a similar rebuke from the Polizia. Only one is genuine.
Hot on the heels of its Shockwave and Robohelp patches, Adobe has issued a patch for seven critical flaws in its Flash Player, including a zero-day universal cross-site scripting vulnerability.
The hacktivist group Anonymous launched distributed denial of service (DDoS) attacks on a number of major stock exchanges this week, continuing its reign of information security mischief.
Bangladeshi hackers have been hacking Indian sites, and Indian hackers have been hacking Bangladeshi sites. Now it is escalating as each side calls for ‘cyberwar’ against the other.
WikiLeaks has denounced UNESCO for refusing to allow it to speak at a conference being held at UNESCO HQ in Paris today and tomorrow. The conference is called 'The Media World after WikiLeaks and News of the World.'
A response to a freedom of information law request by the City of Rye, N.Y., has exposed the social security numbers of city employees.
The emergence of social media as a malware attack vector means that traditional anti-virus technologies are no longer sufficient: whitelisting must now be used to supplement traditional blacklisting.
A new report from the BBC asks whether BYOD spells the end of the traditional office PC. Are we in the midst of a complete cultural revolution?
Shylock is financial malware first detected by Trusteer last September and so named because of random excerpts from Shakespeare’s Merchant of Venice included in its binary. Trusteer now reports a significant increase in end-user infections.
Canadian telecom firm Nortel Networks, which filed for bankruptcy in 2009, was repeatedly breached by Chinese hackers for almost a decade, according to the Wall Street Journal.
“The Microsoft Store India is currently unavailable. Microsoft is working to restore access as quickly as possible. We apologize for any inconvenience this may have caused”, is the note from Microsoft's online retail outlet.
On Valentine’s Day, Microsoft is sending IT administrators a big bouquet of 21 security patches.
Fresh off its successful hack of an FBI-Scotland Yard conference call, Anonymous has claimed responsibility for taking down the US Central Intelligence Agency’s public website.