> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
AVG Technologies, which has carved out a name for itself as one of the most popular free anti-virus software vendors, has linked up with virtual desktop management vendor MokaFive. The move will allow AVG to move into the virtual desktop marketplace.
UK cellcos have always been hit by fraud from multiple angles, largely because of the hefty subsidies they apply to handsets, as well as the ability of criminals to set up international calling shops using fraudulently obtained SIM cards. But now the City of London police have arrested 11 people in...
Analysts debate whether spending nearly $7.7bn makes sense.
Analysts question whether spending nearly $7.7bn makes sense.
While Facebook seems to have more security holes than Swiss cheese, mainly down to the extensible code that the social networking service uses, Sophos has issued an alert about an especially nasty clickjacking worm.
Reports are coming in that blackhat SEO techniques are being used by cybercriminals to position malicious links among the top results in internet search engines.
An SQL injection hack has affected more than 500 000 websites according to recent reports, including two sites maintained by Apple to promote iTunes podcasts.
The electronic health record (EHR) certification program is no longer temporary, as the Office of the National Coordinator for Health Information Technology (ONC) has removed the ‘pending’ label from its EHR approved testing procedures, developed by the National Institute of Standards and Technology...
A digital TV software specialist, whose Sunrise digital video broadcast (DVB) firmware is found in a number of TV set top boxes, has taken the wraps off a 'deep hibernation' system for TV digiboxes that slashes standby power consumption.
The government should consider offshoring IT work to India to achieve spending cuts, according to analyst firm Ovum.
A malicious application that conceals spyware and GPS tracking behind a mobile phone game has been discovered in the Android app store.
Although the global downturn slowed security revenue to 7% growth in 2009, organizations globally have indicated their intention to give priority to security budgets, says Gartner.
Research released by credit reference agency Experian claims to show that the careless use of passwords on the internet is creating an identity theft paradise of criminals.
FaceTime Communications has unveiled a software-as-a-service (SaaS) version of its Unified Security Gateway technology, which allows enterprises to gain granular control over the use of Web 2.0 and social networking systems plus services.
The PCI Security Standards Council (SSC) has provided a preview of upcoming changes to two of its standards covering the payment card industry.
Research carried out by the University of Pennsylvania claims to show that it possible to make an intelligent guess as to a smartphone users' handset password by the density and direction of the `smudges' on the mobile's touch screen.
CESG, the national technical authority for information assurance across the public sector, has announced it is adopting the Institute of Information Security Professionals (IISP) skills framework as the basis for its own professional skills and competency programme.
A representative from the Microsoft Security Response Center said the company is investigating the security flaw disclosed earlier this week but that it will not issue a separate advisory based on current information.
In ArcSight’s Silicon Valley office, Rick Caccia, the infosec firm’s vice president of product marketing, tells Infosecurity’s editor, Eleanor Dallaway, that in addition to the constant tide of cybercrime, it’s huge amounts of data that are driving this industry.
Ever since malware writers swapped worldwide infamy for hefty profits, they have become a larger problem to deal with. And, says Ron Clarkson, senior vice president of CoreTrace, as the game of cat-and-mouse with anti-virus software programmers continues, hackers remain one step ahead of their chief...