> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
The total number of patient records compromised in the US increased by 97% in 2011 compared with 2010, according to a report released this week by the Redspin consulting firm.
Academics Benedikt Driessen and Ralf Hund from Ruhr University Bochum have reverse-engineered and cracked the GMR-1 and GMR-2 voice ciphers used by many satellite networks.
Apple has released massive security updates for its Lion and Snow Leopard Mac operating systems, fixing 52 vulnerabilities.
The top G-man is warning Congress that hackers will pose a greater danger to US national security than terrorists in the not-too-distant future.
The House of Commons Science and Technology Committee has today published its Malware and Cybercrime report – a recommendation to the UK government on how to tackle online threats.
Prison inmates in Maryland had access to social security numbers of patients who received treatment under the state’s Medicaid program, according to a recent state audit.
The XXX domain suffix was launched last September to provide a voluntary ‘responsible’ home for adult sites; but daily.co.uk has noted that 90% of the UK’s fastest growing companies have not yet protected their brands.
New research from M86 Labs adds further insight on the MIDI exploit first highlighted by Trend Micro last week.
More than half of policy makers and global cybersecurity experts believe that an arms race is taking place in cyberspace, according to a new report by McAfee and the Security and Defence Agenda think tank.
The FBI likely employed its CIPAV spyware to eavesdrop on Kim Dotcom and other managers of MegaUpload, according to a report by CNET.
Trymedia’s ActiveStore web-based storefront application, which processes digital game purchases made by customers on its partners’ websites, was recently breached, exposing credit card numbers and other personal information of more than 12,000 customers
A talk at the Information Exploitation Conference at the Home Office’s Security and Policing Exhibition 2012 today addresses the disconnect between user and professional, and calls for a new standard that focuses on training and awareness.
As Microsoft seeks to wean users away from the aging and insecure Internet Explorer 6, companies with IE6 legacy applications are stuck – they can’t upgrade to a newer OS because IE6 is no longer supported; and they still need IE6.
The iPhone 5 is expected to hit the market sometime this year, but scammers are looking to give you one for "free" right now.
Andrey Sabelnikov, named in Microsoft court papers as controller of the Kelihos botnet, declares his innocence in a LiveJournal post.
Trend Micro researchers are warning that a recently patched flaw in Windows Media Player is being used by remote hackers to launch malware.
A new report from the Information Security Forum (ISF) proposes the evolution from simple data defense to cyber resilience.
New research from anti-malware company ESET shows how easy it is to tailor Carberp to attack new and different targets.
Mobile operator O2 has apologized for a technical problem that resulted in subscribers' phone numbers being included in header information sent to websites they visited.
European Justice Commissioner, Viviane Reding, has unveiled the new European data privacy framework that includes a new regulation and a new directive.