> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
The deadline on the apparent GCHQ code challenge, due to expire last night, has been extended by 24 hours.
Google+ has begun rolling out its “Find My Face” facial recognition feature for photos on the social networking site.
The information security market in the Central Asian nation of Azerbaijan is expected to grow 30% in 2012, according to US-based endpoint management and security firm Lumension.
Trade secrets are the most common intellectual property (IP) type stolen by malicious insiders, according to a new report by Symantec.
The holidays are a time for parties, presents, decorations, shopping, and – phishing! Here are some tips to avoid phishing scams.
A hacker who developed the Dingleberry tool to jailbreak the BlackBerry PlayBook tablet has issued a new version of the tool to circumvent a patch Research in Motion (RIM) issued this week to prevent it from working.
The European Network and Information Security Agency (ENISA) has released a new report designed to help improve the proactive detection of security incidents. It is the result of questioning a wide range of leading CERTs combined with ENISA’s own expert input. It is a report largely by national CERT...
Institute of Electrical and Electronics Engineers' (IEEE) experts have uncovered malware in more than 2,000 free smartphone applications. Free rogue applications are expected to be the most common access point for mobile hackers over the next year.
There has been a 90% increase in Android malware families in 2011 compared to 2010, while malicious iOS families only increased by 25%, according to FortiGuard Labs.
California’s Contra Costa County has informed around 4,700 residents that confidential information about debts they owed to the Health Services Department was posted online.
This is the highest penalty ever imposed by the Information Commissioner. It follows a series of data protection breaches by Powys; the latest being the release of confidential child protection information to the wrong person.
Kaspersky has resigned from the Business Software Alliance (BSA). First reports indicated that it was because of the BSA’s almost automatic support for the US Stop Online Piracy Act, or SOPA. Now Eugene Kaspersky has personally explained the reasons: ‘SOPA-Dodger – or why have we decided to withdraw...
Adobe is patching a critical zero-day vulnerability in Adobe Reader and Acrobat that could enable an attacker to take control of an affected machine.
Christmas is the annual festive period when shoppers make merry and fraudsters make money. We need to take care; but perhaps our guardians shouldn’t be over-zealous.
M86 Security has released a new version of its Web Filtering and Reporting Suite specifically aimed at schools. With pupils’ growing use of both personal and school-issued portable devices, it is becoming increasingly important that staff are aware of what’s going on in order to adequately discharge...
The 2011 Lloyd’s Risk Index has been published. While cybersecurity is only one aspect of overall business risk, it shows a surprising disparity in companies’ attitude and preparedness in information security.
Russian media outlets and an election watchdog said they were the targets of cyberattacks during the recent Russian elections.
In its latest escapade dubbed Operation Robin Hood, Anonymous is vowing to steal credit cards and use them to donate money to charities and the “99%” of people who are poor.
A feature that comes standard with Windows 7 would have prevented the hack of RSA, which compromised the SecureID tokens used by some of the biggest names in the US defense industry, wrote Qualys researcher Rodrigo Branco.
The contractor who helped install the industrial control system for the Curran-Gardner Public Water District in Springfield, Illinois, said the water pump allegedly hacked by the Russians in fact just burned out.