> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Insurance fraud is growing. It costs the insurance company and increases insurance premiums. AXA believes that data analytics may provide the solution.
SophosLabs has recently discovered a phishing scam targeting ANZ Bank customers using a Google Docs survey form.
More evidence of malware from China attacking the US Department of Defense has been discovered by AlienVault.
The number of bootkits targeting the Microsoft Windows 64-bit platform increased rapidly last year, a trend that is likely to continue this year, according to David Harley, senior research fellow at ESET UK.
Researchers Zach Lanier and Ben Nell were able to hack into the Bridge connection between the BlackBerry PlayBook tablet and a BlackBerry handset, a connection that allows the user to access corporate email, calendars, and other data on the tablet.
A survey by Freeform Dynamics shows that more than half of small and a fifth of medium sized businesses in Europe lack a formal disaster recovery plan.
Reported fraud in the UK during 2011 increased by 50% to stand at more than £2bn. Both the number and average value of reported cases also rose.
The world is entering a “new and terribly dangerous era” in which cyberwar and information proliferation are converging to threaten critical infrastructure and personal privacy, warns Roger Thompson, chief emerging threat researcher at ICSA Labs.
Security firm Symantec has uncovered two pieces of Android malware, one spoofing a handful of popular games and another exploiting users' concerns about Carrier IQ software.
Tim Berners-Lee, father of the worldwide web, has supported a group putting pressure on the US government over the proposed PIPA Act, which aims to impose restrictions and censorship on the internet.
The US government has expelled Venezuelan diplomat Livia Acosta Noguera for allegedly assisting the Iranian government in a plot to launch cyber attacks against US nuclear power plants.
Typosquatting has led to a spam site becoming one of the highest ranking sites on the internet, according to Alexa.
“I would not be surprised to see the demise of email by the end of this decade.” This surprising but potentially realistic statement was made by Graeme Codrington, a futurist at the TomorrowToday consultancy.
Attacks against endpoints are costing the average organization around $470,000 annually, according to a survey sponsored by Symantec.
Opposition to SOPA and PIPA (the anti online piracy acts) continues to grow. Net Coalition reports on Al Gore’s reservations, while also threatening its own internet blackout.
Pastebin.com, a favorite venue for hacktivists, was shut down twice this week by distributed denial-of-service (DDoS) attacks.
Google has fixed three high-risk vulnerabilities in the latest version of its Chrome browser.
The Vietnamese Communication Security Agency has fined three individuals for stealing personal information on millions of people and selling it online, the first time fines have been issued for such activity in the country.
Ramnit is not a new worm, as it was first reported back in April 2010. Last summer it evolved into financial malware. Now its developers are specifically targeting Facebook users.
BAE Systems Detica has become a strategic partner of the Child Exploitation and Online Protection (CEOP) Centre. This is a special relationship reserved for organizations that have provided a real contribution toward CEOP’s role in protecting children online. Other strategic partners are Microsoft,...