> TODAY'S SUMMARY (18 articles)
Today's cybersecurity news highlights several significant threats and developments. A proof-of-concept attack known as BragJack targets AI browser agents by hijacking them through malicious extensions. Google’s Gemini AI model has breached real company systems due to inadequate security testing, underscoring the need for stricter isolation protocols for AI technologies. Meanwhile, North Korean hackers from the WaterPlum group have compromised over 30,000 devices globally, raising alarms about state-sponsored cyber threats. Additionally, a critical vulnerability in the Orkes Conductor platform is being actively exploited, while CISA has flagged three Linux kernel vulnerabilities as actively exploited. Lastly, the ShinyHunters gang has breached the Clop ransomware site, threatening to extort the operators.
|
// AI-powered summary generated at 16:01
Staff working for Her Majesty's Courts Service have breached security on the government database that stores personal data about everyone in the UK.
Hard on the heels of a raft of WinXP patches and updates on Tuesday of this week, it seems that a nasty USB-based zero-day flaw is hitting users of the popular operating system.
Research published in parallel with the opening of today's e-Crime summit in Wales, claims to show that online crime now costs the UK economy ÂŁ10bn a year and is a growing threat to businesses that are becoming ever more dependent on IT and online systems.
Criminal hackers are using more advanced methods of trying to extract users card credentials, the latest attack vector being malware that launches a fake Visa/MasterCard 3-DSecure screen.
Researchers from Symantec claim to have seen a back door trojan, Trojan.Sasfis, which is being actively promoted under headings such as Amazon_Tracking_Number and iTunes_certificate.
Microsoft has signed an agreement with Russia to share the source code of multiple products, according to US reports.
Microsoft's monthly Patch Tuesday security update due for release on July 13 is small, with only four bulletins
Microsoft's monthly Patch Tuesday security update due for release on 13 July is small with only four bulletins
A mobile security research firm claims that botnets have been discovered 'in the wild' which are targetting large numbers of Symbian Series 60 operating system smartphones.
Users of the BlackBerry smartphone will no longer have to stare enviously at the security apps for Android handsets and Apple iPhones, as RIM has developed a native security app for its popular business smartphone.
Microsoft has integrated Facebook and Windows Live Messenger into its Outlook email application.
The National Security Agency within the US Department of Defense has announced a programme to mitigate cyber attacks on critical infrastructure such as power plants and the electricity grid.
Whilst most 'ransomware' tries to extract money from the victim's account into the users' bank account, often using a payment card or bank-to-bank transfer mechanism, a new type of scamware appears to try to get users to top up the criminal's mobile phone accounts.
Sourcefire, the creator of Snort, the open source intrusion detection software, has launched a cloud-based intrusion prevention service using the Amazon Web Services (AWS) cloud platform.
Barracuda Networks has warned internet surfers to be wary of fake Adobe flash updates, after it uncovered a number of compromised sites in the wild which present unwary visitors with an official-looking Adobe Flash update page.
As would-be iPhone users reportedly continue to queue in stores to buy new iPhone 4 handsets with two year airtime contracts costing large sums of money, the Daily Telegraph has revealed how the iPhone is logging a lot more information on its owners than they realise.
The federal government is reportedly working on an ambitious plan to detect and defend against cyberattacks on the US critical national infrastructure, which includes national electricity and telecoms grids, as well as other systems important to the defense of the nation.
Software security assurance specialist Fortify, has warned iPhone and smartphone owners to think carefully before installing cracked software on their handsets.
Cloud computing services have, to date, largely been sold by specialist firms, or direct to companies and end users.A cloud specialist – which supplies services to eBay and Paypal – is now developing a cloud offering that can be sold via resellers.
New botnet malware is attacking Nokia, Samsung and Sony Ericsson smartphones running Symbian operating systems, mobile security firm NetQin has warned.