> TODAY'S SUMMARY (115 articles)
Today's cybersecurity landscape reveals several significant threats and trends. A critical CVSS 9.8 vulnerability in libheif, used by many servers for processing HEIC images, could lead to file disclosure and code execution risks. The Gyazo data breach has compromised 23 million user records due to a server vulnerability, while North Korean hackers have exploited fake job interviews to infect over 30,000 devices. Notably, AI-generated exploits are emerging, with researchers successfully using AI to hack into OpenAI employee accounts. Additionally, multiple vulnerabilities were disclosed across platforms like WordPress, Linux, and Check Point, highlighting ongoing risks in widely used software. Lastly, the FBI reported that impersonation scams have cost victims $1.6 billion, underscoring the financial impact of social engineering attacks.
|
// AI-powered summary generated at 20:00
A security lapse on Facebook has made large libraries of private photographs, including one of Paris Hilton, available for all users to access. Exploiting a recent upgrade to the networking site’s privacy settings, a Canadian hacker was able to view pictures that were intended as private.
US lawmakers are asking why a stolen laptop, which had medical test results for 2,500 patients in a National Institute of Health study, was not encrypted.
The US National Security Agency (NSA) and Sun Microsystems have agreed to jointly work within the OpenSolaris community to develop new security mechanisms for the operating system.
Fourteen airports in the US, Canada and Asia, are using open or poorly secured wireless networks, according to a study by Gartner Mobile and wireless provider AirTight Networks.
Despite some progress, many US federal agencies continue to experience significant information security control deficiencies, according to a new report.
Police are investigating a possible Home Office security breach after the discovery of an encrypted laptop containing a scrambled disc with the words ‘Home Office, highly confidential’ written on it. The laptop was found in a computer shop near Bolton, after a customer had taken it in for repair. Th...
A US Department of Homeland Security-funded research program will help deliver Endeavor Security’s new method of targeting botnet and malware attacks before hosts are infected.
Identity theft and fraud in the US fell by 12% in 2007 as it fraudsters apparently relied on offline channels for their attacks.
With a key deadline rapidly approaching, will there be rapprochement between the Federal Government and a group of individual states over the implementation of the Real ID Act?
Data broker ChoicePoint has agreed to pay $10 million to settle a class-action lawsuit brought against it over the three-year old data breach which exposed 163 000 personal information records.
The potential damage to a brand justifies the high cost of Payment Card Industry Data Security Standard (PCI-DSS) security compliance work, a major payment card operator told a gambling conference.
The US Central Intelligence Agency (CIA) says criminals hacked into the computer systems of utilities, cutting the power to several international cities.
Most database administrators do not apply the Critical Patch Updates (CPUs) that Oracle issues on a quarterly basis, a new study finds.
A Federal Aviation Administration (FAA) document warns that Boeing’s new 787 passenger jet flight control systems may result in security vulnerabilities as it connects the passenger network with the flight-safety, control and navigation network.