> TODAY'S SUMMARY (2 articles)
This week in cybersecurity, Cisco issued critical patches for a zero-day vulnerability in its email gateway that had been actively exploited. Additionally, the Revolut data breach came to light, revealing unauthorized access and the impersonation of a government agency as part of the attack. The incident underscores the ongoing threat of social engineering and phishing tactics. Furthermore, the latest Security Affairs newsletter highlighted various security trends and articles, emphasizing the importance of staying updated on emerging threats. Overall, organizations must prioritize patch management and employee training to mitigate risks from both technical vulnerabilities and human factors.
|
// AI-powered summary generated at 12:00
The Department of Justice (DoJ) wants to be able to prosecute international cybercriminals under a US law originally intended to take down the Mafia, a representative told a House Judiciary panel yesterday.
Video game company Valve admitted to a data breach last week that could affect the personal information of its 35 million Steam game download customers.
(ISC)², the not-for-profit IT security association, says that, against a backdrop of more and more governments recognising the need for cyber security strategies, they now need to recognize the requirement for internationally recognised skills, principals and practices to tackle what is a very sophi...
Alfred Hitchcock could not have written a better script. It seems that the Angry Birds can find out where you live simply by your downloading their app.
Barclay Simpson’s information security contract division has published its first quarterly rate card for contractors in the IT security industry, noting that technology risk consultants can earn £710 a day, ranging down to data privacy analysts who can command £475 a day.
In its annual review of the top business IT trends for the year ahead Verizon says that high-IQ networks and the enterprise cloud will foster business innovation and a borderless workstyle in 2012.
China's NetQin - in conjunction with a research team with North Carolina state university - claim to have discovered a new type of Android trojan that disguises itself as a Google Library.
Codenomicon has taken the wraps off a completely reworked version of Defensics X, its security and robustness testing application. The new version is billed as using fuzzing techniques to enhance its capabilities.
An in-depth report from AV-Test.org claims that the raft of Android anti-malware apps that have arrived in the last 12 months or so are all virtually useless.
The latest issue of Which? Computing – the magazine of the UK Consumer’s Association – has published a special report on privacy on the Facebook social network services.
Computershare, the international share dealing company – which claims to be the largest in its market – has been hit by a data theft incident from a former employee. What perhaps makes matters worse is that the staffer was an audit risk professional.
The saga of Russia’s ChronoPay electronic money operation – which has been hit by arrests and dark accusations over the last 12 months – continued this week with the revelation that an Estonian company is a key investor in the firm.
A poorly contained data breach and mishandled response could cost companies millions of dollars in lost business and damaged reputation, warns Forrester analysts.
Apple has fixed 17 vulnerabilities in Java for OS X Snow Leopard and Lion, a move that brings the Mac operating systems up to date with Oracle’s Java SE 6 update 29.
The newest version of Firefox plugs eight security holes, including five that are rated as critical and three as high.
An intermediate web certificate authority has had its trust revoked by Mozilla after it was found to issue weak and potentially compromisable certificates.
Adobe has perhaps bowed to the inevitable and, in a notice to developers, advised them that it is ceasing development of the Adobe Flash environment for smartphones and tablets, although critical security and bug fixes will be available.
Reports are coming in that officials in Estonia – arguably one of the most internet-savvy governments in the world – have taken down a massive DNS-changing cybercrime operation involving a click-fraud program that infected more than four million computers in over 100 countries.
When is a flaw not a flaw? When it's a feature of the operating system, it seems, as serial Apple Mac cracker Charlie Miller has tapped a feature of Apple's portable operating system and created an iPhone/iPad app that allows almost complete remote access to the device.
Kaspersky Lab has made the interesting discovery that there is a massive DNS poisoning attack under way in Brazil, with several ISPs in the country falling victim to the attacks.