> TODAY'S SUMMARY (6 articles)
Today's cybersecurity news highlights several significant threats and trends. An ongoing campaign involving malicious npm packages, particularly the 'indexed-btree,' demonstrates how attackers can evade supply chain defenses by embedding harmful code in normal runtime behavior. In a notable incident, an AI-generated report mistakenly identified weapons on a Chinese ship, nearly escalating tensions between the US and China. Additionally, researchers successfully escaped OpenAI's Codex sandbox, exploiting vulnerabilities to execute commands on the host machine, although these have since been patched. Lastly, Cisco has addressed a 0-day vulnerability in its email gateway, while the Revolut data breach continues to unfold, involving impersonation of a government agency.
|
// AI-powered summary generated at 16:01
Nearly a quarter of organizations around the world were victims of cybercrime in the last 12 months, according PricewaterhouseCooper’s 2011 Global Economic Crime Survey.
Hackers who want a job with the UK government’s GCHQ intelligence service need to crack a code to get an interview.
Global cybersecurity spending is predicted to total $60 billion this year and to grow 10% per year for the next three to five years.
A security flaw found in, but not necessarily limited to, HP printers can be exploited by hackers to take full control of printer functions, according to researchers at Columbia University.
Research published today by Trusteer claims to show cybercriminals have widened the services they provide as a one-stop-shop to third-party fraudsters.
The Payment Card Industry Data Security Standards (PCI DSS) are basic information security practices that can be applied to the cloud environment in the same way as traditional environments, said Tabatha Greiner, executive consultant for global PCI quality assurance with Verizon.
A data breach at South Korean online gamer Nexon has exposed personal information on 13 million subscribers.
The Information Commissioner’s Office (ICO) has imposed some of its first fines against public bodies after staff with North Somerset Council and Worcestershire County Council sent highly sensitive personal information to the wrong recipients.
Lyceum Capital, a private equity firm, has increased the total amount spent on IT industry investment this year to more than ÂŁ100 million with the acquisition of data security vendor Clearswift.
The FBI has revealed that four hackers were arrested in the Philippines last week in connection with an organized attack on the clients of telecoms giant AT&T in the US. Newswire reports suggest that the hacker crew was funded by terrorists linked to an Al Qaeda group that carried out the Bali b...
The director of security research with Solera Networks has called malware authors “mal-slackers” for their “lazy repetitive malware scams” they have created for this US Thanksgiving.
Researchers at Context Information Security are playing down the level of risk to enterprises caused by the BEAST - Browser Exploit Against SSL/TLS – that was identified by researchers in late September.
Acuity has taken the wraps off a free PCI DSS compliance analysis application that can be downloaded from its web site. The software is billed as being able to identify, assess, manage and report on risks to cardholder data.
Research carried out by Kingston Technology claims to show that purchasing secure and encrypted USB sticks is no longer enough to defend data within a company environment.
The Information Security Forum (ISF) has published a new report on Federated Identity and Access Management that describes the methodology that IT security professionals need to adopt when implementing the technology into their systems.
Do you want the good news, or the bad news first? The bad news is that one-click fraud has, at long last, arrived on smartphones. The good news (unless you live in Japan) is that the frauds are focused on Japanese language users of mobile phones.
The long-held belief that the Apple iOS platform is inherently secure due to Apple’s walled garden approach to software has been holed once again, this time by a security firm that has developed a method of sending Fake iTunes and Flash updates to iPhone and iPad users.
Websense has slammed the latest ad campaign from Motorola for its Droid Razr smartphone, citing the fact that the Android platform is secure.
Mozilla is reported to be making inroads on adding a silent update mechanism to its popular Firefox desktop web browse, and plans to integrate the new service into Firefox 10 early next year, although this timeframe may slip a few months, the open source organization says.
Prolexic Technologies claims that it has successfully mitigated what it claims was the world's largest DDoS attack in packets-per-second (PPS) terms - 69 million packets-per-second and with an amazing 45 Gbps of traffic.