> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Insecure internet-connected home security cameras are a warning that the Internet of Things will require more than just computer security â this is a warning of things to come.
An Australian broadcaster asks why Symantec is guarded over the Norton AV and pcAnywhere source code that was lost to the hacker Yamatough and the Lords of Dharmaraja, while a US researcher fears he may know the reason.
Le symposium S4, qui a eu lieu fin janvier Ă Miami, marque une nouvelle Ă©tape dans lâodyssĂ©e de Charybde Ă Scylla de la cybersĂ©curitĂ© industrielle. Comme aprĂšs la confĂ©rence « Black Hat » de lâĂ©tĂ© 2011, les informations prĂ©sentĂ©es obligent Ă [...] Lire la suite
A bipartisan group of senators who authored cybersecurity legislation last year plan to introduce a compromise cybersecurity bill that will be examined at a hearing next Thursday.
Bank of America has informed affected credit card customers that their information may have been compromised by a breach at an unidentified merchant.
A federal jury in Texas has declared invalid patents for interactive web technology claimed by Michael Doyle and his patent holding company Eolas.
Security researcher Joshua Rubin has published details of his research showing a vulnerability in the Google Wallet near field communication payments system for Android.
A hacker associated with an Anonymous affiliate has released source code for Symantecâs pcAnywhere security software onto the Pirate Bay file-sharing website after an apparent attempt to extort $50,000 from the security vendor.
The commercialization of cybercrime continues, with Trusteer describing what it calls âFactory Outletsâ for the sale of stolen user credentials.
With âprivacyâ such an emotive and complex issue, Canadian companies should note that an action for tort (civil action) for âintrusion upon seclusionâ has been recognized by the Ontario Appeal Court.
The hacktivist group Anonymous apparently gained control over the Boston Police Department's community policing website in retaliation for the police crackdown on the Occupy Boston protests.
The volume of cybersecurity job ads declined in the fourth quarter in the US, compared to a four-year high in the third-quarter of 2011, according to a survey by WANTED Analytics.
Two US lawsuits, both involving producers of adult content, raise interesting questions: is the owner of an unsecured WiFi responsible for all downloaded material, and can you copyright pornography?
Spammers are targeting QuickBooks users in a tax-related scam that links to a BlackHole exploit kit.
Australiaâs central bank is seeking help from information security providers to beef up its protection against distributed denial of service (DDoS) attacks.
Adobe has announced the release of a beta version of a Protected Mode (sandboxed) Flash Player for Firefox running on Windows Vista and Windows 7.
Rootkits are on the rise and traditional security software will not protect you, warns a Symantec white paper.
In response to Androidâs growing reputation of being a âmalware cesspoolâ, Google has unveiled the Bouncer automated application scanning service to root out malware on the Android Market.
The Anonymous hacktivist group was apparently able to listen in on a conference call between the FBI and Scotland Yard by hacking into a participantâs email account and obtaining the conference call number and access code, according to security analysts.
Hackers target the most widely used file formats; and there is none more widely used than PDF. A new paper from Adobe discusses the problems and solutions to PDF security.