> TODAY'S SUMMARY (9 articles)
Today's cybersecurity landscape reveals several critical threats and vulnerabilities. AI models like Claude Opus 5 are exposing significant security flaws, with researchers successfully exploiting these to access OpenAI accounts. SolarWinds has issued patches for a severe flaw in its Access Rights Manager that could allow unauthenticated remote code execution. Additionally, a critical vulnerability in the Orkes Conductor Workflow Platform is actively being exploited in the wild. On the open-source front, CrowdSec reported a breach involving the copying of 170 private GitHub repositories via a former employee's account. Furthermore, CISA has flagged three Linux kernel vulnerabilities that are being actively exploited. The situation underscores an ongoing vulnerability explosion amid rapid AI development and exploitation.
|
// AI-powered summary generated at 12:00
One of the least-reported areas of IT security in recent times is the topic of firewalls but, according to Gabi Reish, head of network security with Check Point, the technology is now into its fifth generation, largely as a result of the rise of the internet.
Brazilian malware writers are making use of a long-available feature within most modern browsers to launch attacks that redirect victims to malicious websites without their knowledge. The feature, known as proxy auto config, is turning up in banking trojans, according to researchers from Kaspersky.
Games console in the workplace pose an increasingly serious threat to enterprise security, according to new research from Sunbelt Software. The anti-malware vendor said that almost 4 in 10 respondents to the survey had no idea about any of the documented threats relating to online console gaming.
Federal agencies are lagging behind in the implementation of the Federal Desktop Core Configuration (FDCC) requirements, according to the US Government Accountability Office.
Web hosting company Network Solutions has deployed a massive fix for a configuration flaw that led to hundreds of WordPress blogs being compromised.
Numbers from IT advocacy group TechServe Alliance show that IT job growth declined month-over-month in March, putting a halt to the uptick the industry has experienced since December of last year.
Infosecurity reviews the week's security news
EviGator has released TAG Examiner, a tool for examining large quantities of image files to recover metadata.
A Manhattan resident was sentenced last week for his part in an international money laundering and data theft scheme that hacked into accounts at brokerage firm Charles Schwab.
The Consumer's Association has launched a publicity campaign against the law firms generating large numbers of copyright actions against alleged internet filesharers, and it appears to have paid off.
A new Windows Mobile game - apparently being offered free of charge - has a nasty surprise hidden inside; a trojan that makes very expensive international phone calls.
RootKitAnalytics has made a tool available for discovering hidden alternate data streams. Called StreamArmor, it is designed to analyze a feature of the Windows file system that allows hidden data to be embedded in files.
Nearly half of US IT professionals surveyed by ISACA said they believe that the security risks of cloud computing outweigh the potential benefits.
Protegrity, the Stamford, Connecticut-based enterprise data security specialist, is quietly making its presence felt in the UK and Europe, largely thanks to a growing network of resellers handling the firm's products.
Research just released from Arbor Networks makes the interesting assertion that a new family of distributed denial of service (DDoS) botnets has arrived on the hacker scene.
Seventy people were arrested in Romania this week as part of an investigation of three organised criminal groups connected with cybercrime.
Kaspersky has successfully patented technology that enables analysts to trace the activity of software code without infringing upon intellectual property.
Content watermarking firm Civolution has signed an expanded long-term agreement with online music database firm Gracenote to jointly market an audio and video content identification platform that lets content owners and service providers filter and monitor content.
McAfee has signed a deal with IT performance optimisation company Riverbed Technology to embed its firewall technology in the Riverbed Steelhead WAN optimisation appliance.
This week sees the introduction of new penalties for breaches of the Data Protection Act. Regulated and enforced by the Information Commissioner's Office (ICO), the maximum fine for an organisation found to be in breach of the act rises from just £5000 to a hefty £500 000.