> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Hackers, possibly from abroad, attacked a Pacific Northwest railway company’s computer system, disrupting railway signals in December, according to the US Transportation Security Administration (TSA).
UK mobile operator O2 is investigating claims it is putting customer security at risk by sending their phone numbers as header information to websites they visit.
The National Institute of Standards and Technology (NIST) has issued its first set of guidelines for managing security and privacy issues in the public cloud.
More than half of organizations expect to increase their information security spending in 2012, some by 8% of more, according to a survey by the Enterprise Strategy Group (ESG).
Viruses infect executables. Worms are executables. So viruses can, and are, infecting worms. The result, claims anti-virus company BitDefender, is a new category of threat: Frankenmalware.
The Open Digital Policy Organization reports that the Norwegian Data Inspectorate has effectively declared use of Google Apps in Norway to be illegal.
Two New York power companies, which have 1.8 million customers, have disclosed that customers' personal information, including social security numbers, dates of birth, and financial account data, may have been compromised by third-party unauthorized access.
The MegaUpload take-down is one of the hottest stories on the net, involving the FBI, illegal file-sharing, hackers’ revenge, the specter of SOPA and more. But don’t be too curious...
CyberSource, a payment management company working in e-commerce and providing a fraud management system to e-commerce merchants, has published its latest report: UK Online Fraud Report 2012.
Facebook scammers are offering a “free” $500 Amazon.com gift card as part of a premium rate mobile phone service and affiliate marketing site scheme.
Last September, Microsoft and Kaspersky Labs took down the Kelihos botnet. While Kaspersky now has control of the botnet, in a court filing in Virginia, Microsoft yesterday named Andrey Sabelnikov as the owner and operator of Kelihos.
The US National Security Agency (NSA) has released a secure version of Google’s Android platform, dubbed secure enhanced (SE) Android, which is based on an application-level permissions model.
Andrew Crossley was the solicitor behind the ACS:Law scandal. His firm sent out some 20,000 speculative letters to ‘illegal file sharers’ demanding payment of £500 in reparation to his rightsholder clients (in this case MediaCAT, which represented the individual copyright owners).
Recent months have seen the arrival of a new type of ransomware based on a legal threat from supposed law enforcement agencies.
A secret file said to contain security plans for the London Olympics was apparently left on a London train by a policeman.
This is the conclusion of a joint study by Opus and ValidSoft, a company that specializes in telecommunications-based authentication and transaction verification for financial services and government organizations.
The breach of the database containing details of 24 million customers of Amazon-owned online shoe retailer Zappos has once again raised fears over the security of e-commerce.
It is ten years since Bill Gates distributed his internal ‘Trustworthy computing’ memo to Microsoft staff: “We must lead the industry to a whole new level of Trustworthiness in computing.” Has Microsoft delivered?
The move to high-speed 4G mobile networks poses challenges for carriers and vendors to deploy security products that can handle those high speeds and data volumes, a challenge that the European Advanced Networking Test Center (EANTC) recently put to the test.
Zappos, an online shoe and clothing retailer, is warning 24 million customers that a security breach has exposed their personal information, including partial credit card data.