> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Nearly three-quarters of Americans have never installed data protection applications or security software on their smartphones to protect against data loss or malware, according to a survey sponsored by the National Cyber Security Alliance (NCSA) and McAfee.
Anonymous is entering the US legislative fray by targeting Sony over its support of the Stop Online Piracy Act (SOPA) being considered by the US House.
The Peace Officers of California (POC) group is demanding a legislative investigation into the handling of an Anonymous hack of the California State Law Enforcement Association (CSLEA) website.
The lilupophilupop.com SQL injection attacks, first analyzed by the SANS Internet Storm Center in early December, have topped one million infected pages.
Indian researchers Aditya Modha and Samir Shah have uncovered a cross-site scripting (XSS) vulnerability in WordPress 3.3.
Kaspersky’s lengthy investigation into the Duqu worm concludes that it comes from the same developers as Stuxnet. This, potentially, has serious implications.
A UK lawyer has called on the government to redirect its reforms of the Regulation of Investigatory Powers Act (RIPA) away from local authorities and toward journalism.
Online community Care2 has notified its close to 18 million members that the site’s servers were attacked, resulting in a security breach.
The PrivateX hacker group breached two Philippine government websites, the Office of the Vice President (OVP) and the Philippine Nuclear Research Institute (PNRI), on New Year’s Day.
PC Recycler provides electronics recycling services to a number of US government agencies, using degaussing to wipe data from the devices before destruction.
Saudi hackers who claim they are members of Anonymous have breached the Israeli ONE sports website and leaked personal information on 400,000 subscribers.
Last month, US defense contractor Raytheon acquired two companies that supply cybersecurity products and services to the US military: Henggeler Computer Consultants and Pikewerks Corp.
Based on its assessment that cyberattacks against critical infrastructure will increase next year, McAfee advises critical infrastructure companies to upgrade their cybersecurity infrastructure.
After an extensive review, Belgian certificate authority (CA) GlobalSign said that no rogue certificates were issued and no customer data were exposed as the result of a breach disclosed in September.
Indian information security firm Paladion Networks has announced plans to set up a dedicated hub in Oman to monitor and respond to cybercrime in the sultanate.
The US Department of Homeland Security (DHS) is warning about a buffer overflow vulnerability in the Sielco Sistemi Winlog application used to control industrial systems.
The browser’s ability to block socially engineered malware, not sandboxing technology, is the most important criteria to judge browser security, argues Rob Rachwald, director of security strategy at data security firm Imperva.
On Tuesday, Mozilla released version 9 of its Firefox browser with fixes for a number of memory safety bugs in the browser engine; then, 24 hours later, it released 9.0.1 to fix a bug that caused Mac, Linux, and Windows users’ browsers to crash.
The hacktivist group Anonymous claimed this week that it took down a dozen Egyptian government websites using distributed denial of service (DDoS) attacks in retaliation for the government’s treatment of protestors.
A $16 million class-action lawsuit has been filed against the UCLA Health System for a data breach that compromised personal information of more than 16,000 patients.