> TODAY'S SUMMARY (9 articles)
Today's cybersecurity landscape reveals several critical threats and vulnerabilities. AI models like Claude Opus 5 are exposing significant security flaws, with researchers successfully exploiting these to access OpenAI accounts. SolarWinds has issued patches for a severe flaw in its Access Rights Manager that could allow unauthenticated remote code execution. Additionally, a critical vulnerability in the Orkes Conductor Workflow Platform is actively being exploited in the wild. On the open-source front, CrowdSec reported a breach involving the copying of 170 private GitHub repositories via a former employee's account. Furthermore, CISA has flagged three Linux kernel vulnerabilities that are being actively exploited. The situation underscores an ongoing vulnerability explosion amid rapid AI development and exploitation.
|
// AI-powered summary generated at 12:00
Two pilot programs from Microsoft have been established in an effort to share pre-update information and aid in protecting critical infrastructure.
Security software group Symantec is to acquire VeriSign's identity and authentication business in a $1.28bn (ÂŁ89.1m) cash deal.
Fake anti-virus applications have been around for a few years now, but there are signs that hackers are deploying the scareware apps more and more and, according to Rik Ferguson, Trend Micro's solutions architect, the economics of fear are what drives this type of malware
Microsoft has issued a security advisory for a canonical display driver (cdd.dll) vulnerability affecting Windows 7 and Windows Server 2008 R2.
A former night-shift security guard pleaded guilty to two counts of transmitting malicious code for his role in hacking into computers at a Dallas area medical facility.
Microsoft is to pay $200m in settlement of a patent infringement case brought by VirnetX.
PandaLabs has warned internet users to be aware of a new type of phishing attack, following its investigation of a clone of the Navy Federal company's website, which is being used by criminals to harvest user credentials.
Around 30 000 new malicious and potentially undesirable programmes appear every day, according to security researchers at Kaspersky Lab.
Microsoft is to pay $200m in settlement of a patent infringement case brought by VirnetX.
Google has admitted that it mistakenly collected data sent over WiFi networks using its Street View cars gathering images for Google's controversial Street View service.
Reports are coming in that Facebook has identified the self-proclaimed hacker who was offering to sell batches of 1000 Facebook accounts – up to 1.5 million in total – and it appears that the Russian hacker was wildly overstating the account numbers.
Reports are coming in that Facebook has identified the self-proclaimed hacker who was offering to sell batches of 1000 Facebook accounts - up to 1.5 million in total - and it appears that the Russian hacker was wildly overstating the account numbers.
Facebook is once again in the news, as large numbers of users are being hit by a prank video posted to their Facebook walls.
The New Mexico Human Services Department informed users of its Salud! Medicaid plan that an unencrypted laptop containing personal health information was stolen back in March.
Earlier this week a San Diego jury convicted a Chinese national for attempting to smuggle communications equipment out of the country, including encryption devices used by the US military and NATO.
Cybercriminals are using Google Groups to distribute rogue anti-virus software and other malware, according to researchers at security firm eSoft.
Earlier this month the co-founders of anti-virus software vendor Sophos agreed to sell a majority stake in the company to private equity group Apax Partners in a deal worth $300 million.
Mikko Hypponen, F-Secure's chief research officer, says he applauds the actions of law enforcement offices around the world in bring increasing volumes of cybercrminals to justice in the first four months of 2010.
German enterprise software maker SAP has agreed to acquire US database and mobility software producer Sybase for $5.8bn.
Microsoft issued two security bulletins on Tuesday for what the company called “critical” patches to the Windows OS, Office suite, and Visual Basic.