> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Microblogging service Twitter has decided to open source some of Whisper Systems' software, including the TextSecure text-messaging encryption for Android devices, on Github.
A Chinese group allegedly hacked into the US Chamber of Commerce networks last year and gained access to information on its three million members.
Hackers broke into pop star Lady Gaga’s Twitter account and broadcasted a link to a scam offer for free iPad 2s to her 17 million fans, whom she calls “little monsters.”
The Manhattan District Attorney has indicted 55 individuals for operating a $2 million organized cybercrime ring that relied on corrupt employees at companies and institutions to steal personal information of victims.
Nation-state-sponsored advanced persistent threats (APTs) are only going to increase in volume and sophistication over the next few years, and the US needs to take the offense in countering these threats, argues Peter George, president and chief executive officer of network security firm Fidelis.
Wisegate, a newly formed social networking site for information security professionals, has added a privacy and compliance micro-community for senior-level privacy and compliance professionals.
The CA/Browser Forum, a consortium of certificate authorities (CAs), has released the first international baseline requirements for the operation of CAs issuing SSL/TLS certificates.
The Royal Canadian Mounted Police (RCMP) is investigating a link between a data breach at the Insurance Corporation of British Columbia (ICBC) and drive-by shootings and arson in the Canadian province.
The Federal Bureau of Investigation (FBI) has arrested a hacker associated with Anonymous for a distributed denial of service (DDoS) attack against the website of Gene Simmons, front man for the band KISS and reality TV celebrity.
Ancestry.com, the online commercial genealogy service, has decided to remove from its website Social Security numbers (SSNs) of individuals deceased in the last 10 years out of security concerns.
Nonprofit advocacy group Free Press is asking the Federal Communications Commission (FCC) to investigate Verizon Wireless for blocking the Google Wallet application on the Android-powered Galaxy Nexus smartphone allegedly over security concerns.
The National Institute of Standards and Technology (NIST) has issued a revised version of its Electronic Authentication Guideline (now NIST SP 800-63-1), originally published in 2006 as NIST SP 800-63.
The recent explosion in Android malware is due to the popularity of the mobile operating system and the shift in malware distribution methods from worms to applications, according to a recent white paper by security firm McAfee.
Malware in Android apps is a growing concern among security researchers. Now Symantec has discovered 11 more malicious apps. We ask what Google should be doing.
Cyber attacks could cost lives and cause huge damage, according to Ludolf Luehmann, an IT manager for Royal Dutch Shell.
The RSA data breach tops the list of most significant cybercrime developments of the year, according to security monitoring and threat intelligence firm Vigilant.
The US Department of Homeland Security (DHS) has issued a “blueprint” that outlines measures to secure cyberspace and protect US critical infrastructure.
Since criminals always follow the crowds, it should be no surprise that GFI is warning about a new phishing campaign aimed at Christmas online shoppers.
The US Army has activated its first cyber brigade to provide a proactive cyber defense, the service announced last week.
Close to a quarter of UK organizations have suffered a security breach as a result of identity fraud linked to a lost or stolen authentication device, according to an Entrust survey.