> TODAY'S SUMMARY (9 articles)
Today's cybersecurity landscape reveals several critical threats and vulnerabilities. AI models like Claude Opus 5 are exposing significant security flaws, with researchers successfully exploiting these to access OpenAI accounts. SolarWinds has issued patches for a severe flaw in its Access Rights Manager that could allow unauthenticated remote code execution. Additionally, a critical vulnerability in the Orkes Conductor Workflow Platform is actively being exploited in the wild. On the open-source front, CrowdSec reported a breach involving the copying of 170 private GitHub repositories via a former employee's account. Furthermore, CISA has flagged three Linux kernel vulnerabilities that are being actively exploited. The situation underscores an ongoing vulnerability explosion amid rapid AI development and exploitation.
|
// AI-powered summary generated at 12:00
Research published today claims to show that business attitudes towards Web 2.0 – the new generation of internet services – have charged markedly in the last three years.
Trusteer says it has detected a completely new version of the Zeus password stealing trojan that has been designed to steal online banking credentials.
The United Nations has rejected a Russia-backed proposal for a treaty on cybercrime, despite widespread agreement that closer international co-operation is vital in a world more closely connected by global computer networks.
The hackers responsible for the Operation Aurora attack against Google also managed to compromise its single sign-on password system, according to a report in the New York Times this week. The attack, which happened in December, targeted a highly secretive system operated by the search engine giant...
Anti-malware company Avira has reported an extortion scam designed to scare torrent site users into giving their credit card information to a phishing site.
Research just published by Blockmaster Security claims to show that 42% of employees grossly underestimate the potential fines associated with a data breach.
Businesses need to take note of the increase in malicious cyber activity in emerging countries, particularly those offshore and outsourced operations, says Symantec.
Administrators at Pennsylvania-based Harriton High School downloaded over 400 screenshots and webcam pictures of student Blake Robbins rather than the one or two previously estimated, according to a new motion filed in the court case between Robbins' family and the lower Merion School District. They...
A trojan has appeared posing as an extension to the Google Chrome browser. Delivered via email, the invitation to install the software tempts users with promises of a function to access documents from emails.
Israel has banned Apple's iPad from entering the country from the US and has threatened to confiscate the newly released devices from passengers at airports.
A report just released claims to show that the UK and French internet user community are leading the way when it comes to online security but are less bothered about data protection issues.
A Daily Telegraph third-party website is the latest high-profile site to be defaced by hackers apparently unhappy about the news organisation referring to Romanians as gypsies.
Ultra-secure encryption of sensitive data sent by banks, hospitals and government organisations could be a reality within three to five years, says Toshiba Research Europe.
Porn sites are still the most likely online destinations to be compromised with malware, in spite of increasing attacks on legitimate non-porn websites, according to a report released by security company Commtouch this week.
A former National Security Agency senior executive has been indicted for retaining classified information, obstructing justice and making false statements.
A pair of security researchers have identified a way to use security tools within Internet Explorer 8 to compromise a website. The attack uses cross-site scripting filters implemented in the latest version of the Microsoft browser to execute cross-site scripting attacks on sites that would normally...
A Websense researcher has released a forensics tool designed to identify malicious web content from within the Firefox browser. Called Fireshark, the plug-in was released on Wednesday at the Black Hat security conference by Stephan Chenette, a principal security researcher at Websense.
The website for the open source Apache Web server at Apache.org was compromised this month by a targeted attack, said the Apache Software Foundation, which has provided a detailed blow-by-blow account of the hack.
The latest monthly malware and vulnerability statistics released by Kaspersky Lab claims to show that the exploitation of vulnerability in Internet Explorer was the most significant cybercrime threat during the month of March.
Detailed figures just released by the Ministry of Defence show that the military arm of the government had a total of 347 data loss incidents in 2009, with 71 further losses of confidential information in January plus February of this year alone.