> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
Demand for IT staff continues to rise, resulting in shortages in some software skills, according to the latest research.
The advent of sophisticated new malware such as Stuxnet could hamper the development of cloud computing and consequently economic development, Microsoft CEO Steve Ballmer said on Tuesday.
The police cybercrime unit can tackle only 11% of the 6000 known organised criminal gangs that regularly use computers for illegal purposes, the head of the Metropolitan Police admitted at the weekend.
Symantec has published an in-depth report on the Stuxnet malware in which it notes that, whilst the worm was first discovered in July, it is known to have existed at least one year prior and likely even before.
A survey of more than 9000 adults in the UK, US, Europe and Canada, has revealed that internet users in the UK feel more at risk from banking fraud than ever before.
Just like the Greek god that is its namesake, Zeus is the king of bank fraud trojan viruses, having been used by thousands of criminals to scam perhaps hundreds of millions of dollars from banking customers around the world for years. The recent busts of Zeus fraudsters in the US and the UK are just...
The European Commission has proposed a new directive on attacks against information systems to replace current, outdated frameworks.
Stuxnet, the computer worm considered to be the world's first cyber weapon, has hit millions of computers in China.
Adobe plans to release updates on October 5 for Adobe Reader 9.3.4 for Windows, Mac and UNIX, Adobe Acrobat 9.3.4 for Windows and Mac, and Adobe Reader 8.2.4 and Acrobat 8.2.4 for Windows and Mac to resolve critical security issues.
In the days of dial-up modems, malware authors developed trojans and other black code that dialled premium rate numbers in the background and so generating revenues for their criminal gangs. Today, thanks to the arrival of landline broadband, the process of background premium rate calls – driven by...
Barclays Bank plans to rewrite its software applications so they can communicate with one another using encryption to lessen the likelihood of fraudsters finding a way into its systems
The German government's new national ID card – which will start being issued this November – has been publicly hacked on TV by members of the infamous Chaos Computer Club.
Tomorrow is the day that the new PCI DSS 1.2 rules kick in, requiring all level one merchants – defined as firms processing more than 6 million transactions per year – to adhere to the v1.2 security guidelines, or face possible action by their card processor.
Hard on the heels of the spate of Twitter attacks comes news that LinkedIn members are being targeted by carefully crafted fake connection requests that route users to the ZeuS data-downloading malware.
Virtualisation is the key to better information security in cloud computing, says Eric Baize, a board member at cross-industry security initiative, SAFECode.
A number of insurance agents have recently been fined by states for not having a written information security plan in place, and some large insurance firms have reported data breaches involving clients’ personal information. To help address this problem, the Independent Agents and Brokers of America...
The Spamit.com spam affiliate programme, which is responsible for the promotion of spam via a number of outlets worldwide using financial incentives, is to close at the end of this month.
The Stuxnet worm, which has reportedly been successfully targeted at Iranian nuclear plants, is being widely reported as originating from a government agency or well-funded source with political intent. The CEO of Kaspersky Lab, however, says that, whilst there is insufficient evidence to point the...
HP has announced it has completed its acquisition of security firm Fortify Software.
Hackers are using an increasing variety of sophisticated attack vectors to infect internet users PCs, and it seems that infected spam HTML is now being used as a carrier. In its latest attack vector analysis, Barracuda Networks claims that it is now seeing more than a million instances a day of unwa...