> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
In ArcSight’s Silicon Valley office, Rick Caccia, the infosec firm’s vice president of product marketing, tells Infosecurity’s editor, Eleanor Dallaway, that in addition to the constant tide of cybercrime, it’s huge amounts of data that are driving this industry.
Three security bulletins were released this week by Adobe outlining security updates for Flash Player, ColdFusion, and Flash Media Server.
Ever since malware writers swapped worldwide infamy for hefty profits, they have become a larger problem to deal with. And, says Ron Clarkson, senior vice president of CoreTrace Corporation, as the game of cat-and-mouse with anti-virus software programmers continues, hackers remain one step ahead of...
Veteran technology professional Jennifer Perry has announced that E-Victims.org, the charity she helped to found three years ago and which assists victims of electronic crime on the internet, is to close due to lack of funding.
McAfee has released the sixth edition of its security journal and has been fortunate enough to have a feature contribution from ex-Washington Post IT security writer Brian Krebs, who has written about his experiences in taking down ISPs and botnets that support cybercriminal activity.
Reports are coming in that the German government is becoming concerned over the security of the 'push' email features of several popular smartphones, including the RIM BlackBerry and the Apple iPhone.
In a move that could upset a few security vendors, Toshiba has announced it has developed a new technology for self-encrypted hard disk drives and protecting sensitive information.
The country’s foreign minister told the AP that Bahrain has no plans to join other Gulf states in threatening to block BlackBerry services.
Google's Android mobile operating system has been hit by its first text-based trojan, according to security firm Kaspersky Labs.
Kaspersky Lab is warning users to check their PCs for the presence of the TDSS rootkit, a nasty piece of code – now in its third iteration – that allows complete, but hidden, 'zombie' control of the host PC.
Google's Android mobile operating system has been hit by its first text-based Trojan, according to security firm Kaspersky Labs.
San Diego-based St. Bernard Software recently announced its purchase of email security firm Red Condor.
Terry Childs, a former city of San Francisco network administrator, received a four-year sentence on Friday for his earlier conviction on computer tampering charges.
There are signs that hackers are again turning to the recurring avenue of using attractive image files as a means to persuade internet users to infect their machines, through the usage of downloadable links to 'allow' users to view the files.
Reports from DefCon 2010 last weekend showed how it is possible to persuade a mobile phone to log into a rogue base station created using around $1,500 worth of hardware. And, says an IT security vendor, this highlights how the 'evil twin' hacking methodology used on WiFi networks can be redeployed...
The exploit for Adobe Reader and Acrobat unveiled by researcher Charlie Miller at last week’s Black Hat conference in Las Vegas has been confirmed by Adobe, which says it will issue an out-of-band patch for the exploit by mid-August.
Security writer Brian Krebs says he has conducted a straw poll and analysis of the top IT security applications and found that large numbers of them fail to utilize the standard security features of Microsoft Windows.
The European Commission has announced a new schedule for the revision of the European Union Data Protection Directive, delaying legislative proposals for over a year, according to the French Information Commissioner's Office, CNIL.
Security writer Brian Krebs says he has conducted a straw poll and analysis of the top IT security applications and found that large numbers of them fail to utilise the standard security features of Microsoft Windows.
Apple has advised users of all its mobile devices that run on iOS to avoid opening PDFs until a fix is released for a newly discovered flaw.