Cybersecurity |
Sponsored by |
|
CircleID recently interview Paul Vixie, Founder & Chairman of Internet Software Consortium (ISC), to discuss ISC's newly formed Operations, Analysis, and Research Center (OARC). OARC is launched in response to DDoS attacks at the Internet's core infrastructure and the vital requirement for a formal coordination system. OARC is also a part of US homeland security initiatives, such as the formation of Information Sharing and Analysis Centers (ISACs).
"Registries and registrars, ccTLD operators, large corporate NOCs, ISPs and ecommerce companies that host many domain names are all likely candidates. This is also a natural for law enforcement groups that are worried about attacks on the Internet." more
The Internet Corporation for Assigned Names and Numbers (ICANN) has released an "Advisory" concerning VeriSign's deployment of DNS wildcard (Site Finder) service: "Since the deployment, ICANN has been monitoring community reaction, including analysis of the technical effects of the wildcard, and is carefully reviewing the terms of the .com and .net Registry Agreements. In response to widespread expressions of concern from the Internet community about the effects of the introduction of the wildcard..." more
Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.
To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer... more
A recent study by researchers at the Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Super Computer Center (SDSC) revealed that a staggering 98% of the global Internet queries to one of the main root servers, at the heart of the Internet, were unnecessary. This analysis was conducted on data collected October 4, 2002 from the 'F' root server located in Palo Alto, California.
The findings of the study were originally presented to the North American Network Operators' Group (NANOG) on October 2002 and later discussed with Richard A. Clarke, chairman of the President's Critical Infrastructure Protection Board and Special Advisor to the U.S. President for Cyber Space Security. more
Recently, I entered my domain name in a "WHOIS" database query to test the results of the database by using WHOIS on a number of domain name registrar websites. WHOIS is a database service that allows Internet users to look up a number of matters associated with domain names, including the full name of the owner of a domain name, the name of the domain name hosting service, the Internet Protocol or I.P. number(s) corresponding to the domain name, as well as personally identifying information on those who have registered domain names. I was astonished to find... more
OpenAI paused tool-enabled work on its most capable models after a research agent bypassed sandbox Internet restrictions by using DNS to communicate with an external chatbot during reinforcement-learning training. more
African institutions are adopting AI across public services and business, but effective deployment requires governance structures that address cybersecurity, accountability, procurement, digital sovereignty, regulatory coordination and institutional capacity. more
Africa's digital transformation challenge is not a lack of strategies or research, but weak institutional learning that prevents governments from preserving project lessons, applying evidence and avoiding repeated failures across administrations and technology programs. more
The EU Cyber Resilience Act faces questions over its economic impact as third-party estimates point to substantial compliance costs, competitive pressures and unresolved concerns about whether its requirements meet established proportionality and competition norms. more
Shadow AI exposes sensitive enterprise data when employees use unsanctioned AI tools. Context-aware guardrails can reduce leakage and false positives by combining deterministic rules, contextual inspection, graduated enforcement and centralized observability. more
Rule-based container security can miss attacks that evade predefined patterns, prompting an argument for behavioral detection that models activity across Kubernetes workloads and control planes while retaining rules for known threats. more
UK, US and Dutch agencies have exposed Iranian state-linked spyware that uses personalized social engineering to compromise Windows devices and surveil dissidents, activists and journalists, capturing communications, files, audio and other sensitive data. more
Telegram says it has applied for .gram, potentially giving a billion users DNS addresses while putting its governance, abuse controls, legal exposure and infrastructure under scrutiny as ICANN prepares to reveal applications. more
Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks. more
CISOs expect social media impersonation to become their leading cybersecurity threat as attackers increasingly combine AI-enabled deception, executive impersonation, and domain abuse across multiple channels to conduct fraud and steal sensitive information. more