Category: http://www.infosecurity-magazine.com/rss/news/76/application-security/

#InfosecurityEurope: What TechUK’s New Plan Means for Cybersecurity

The British tech trade association called for more collaboration between government and industry actors to improve the security of critical sectors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: What TechUK’s New Plan Means for Cybersecurity

#InfosecurityEurope: Top Five Things to Check Out at This Year’s Event

With Infosecurity Europe just around the corner, here are four of the must-see activities happening at this year’s event This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Top Five Things to Check Out at This Year’s…

Microsoft Pays $20m to Settle Another FTC COPPA Case

Regulator alleged Microsoft knowingly collected personal information from children This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Pays $20m to Settle Another FTC COPPA Case

Ofcom Latest MOVEit Victim as Exploit Code Released

UK regulator admits hundreds of employees are impacted This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Ofcom Latest MOVEit Victim as Exploit Code Released

Historic Zacks Breach Impacts Nearly Nine Million

Stock research firm revealed more recent incident in January This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Historic Zacks Breach Impacts Nearly Nine Million

Data Flows Between UK and US to be Simplified Under New Agreement

The ‘data bridge’ is an extension to the Data Privacy Framework agreed between the US and EU last year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Data Flows Between UK and US to be Simplified Under…

Swiss Government Targeted by Series of Cyber-Attacks

A DDoS attack targeting Switzerland’s administration is the third campaign targeting the country in two weeks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Swiss Government Targeted by Series of Cyber-Attacks

Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

Investigating the ESG bug, Rapid7 assumed the presence of persistent malware hindering device wipes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

Security Experts Highlight Exploit for Patched Windows Flaw

Numen Cyber said exploiting the vulnerability does not require novel techniques This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Security Experts Highlight Exploit for Patched Windows Flaw

Google Launches Framework to Secure Generative AI

The Secure AI Framework (SAIF) is a first step to help collaboratively secure AI technology, said Alphabet’s subsidiary This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Google Launches Framework to Secure Generative AI

Minecraft Users Warned of Malware Targeting Modpacks

Bitdefender researchers warn that mods and plugins have been rigged by the infostealer malware, dubbed Fractureiser This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Minecraft Users Warned of Malware Targeting Modpacks

Pharmaceutical Giant Eisai Hit By Ransomware Incident

Several systems, including logistics systems, have been temporarily taken offline This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Pharmaceutical Giant Eisai Hit By Ransomware Incident

Microsoft Brings OpenAI Tech to US Agencies

The capabilities will expedite content generation and enhance decision-making processes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Brings OpenAI Tech to US Agencies

Lazarus Group Blamed for Atomic Wallet Heist

Notorious North Korean group pegged for recent campaign This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Lazarus Group Blamed for Atomic Wallet Heist

CISA and Partners Publish Guide For Remote Access Security

Cyber-actors are utilizing these tools for easy and broad access to victim systems This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CISA and Partners Publish Guide For Remote Access Security

Cisco Counterfeiter Pleads Guilty to $100m Scheme

Dual US/Turkish citizen ran at least 19 companies This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cisco Counterfeiter Pleads Guilty to $100m Scheme

FBI Warns of Surge in Deepfake Sextortion Attempts

Fake imagery is being used to harass and extort victims This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: FBI Warns of Surge in Deepfake Sextortion Attempts

CVEs Surge By 25% in 2022 to Another Record High

Volume of new vulnerabilities has increased three-fold in a decade This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CVEs Surge By 25% in 2022 to Another Record High

Three Vulnerabilities Discovered in Game Dev Tool RenderDoc

Qualys identified one instance of privilege escalation and two heap-based buffer overflows This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Three Vulnerabilities Discovered in Game Dev Tool RenderDoc

Exploitation of Vulnerabilities Have Soared, Unit 42 Report Finds

The Palo Alto Networks report also suggests Linux malware emerged as a growing concern last year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Exploitation of Vulnerabilities Have Soared, Unit 42 Report Finds

New ChatGPT Attack Technique Spreads Malicious Packages

Vulcan Cyber’s Voyager18 research team called the technique “AI package hallucination” This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New ChatGPT Attack Technique Spreads Malicious Packages

BEC Volumes and Ransomware Costs Double in a Year

Annual Verizon report reveals humans are still a major source of risk This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: BEC Volumes and Ransomware Costs Double in a Year

Critical Zero-Day Flaw Exploited in MOVEit Transfer

The vulnerability (CVE-2023-34362) can grant escalated privileges and unauthorized access This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Critical Zero-Day Flaw Exploited in MOVEit Transfer

Spanish Bank Globalcaja Hit By Ransomware Attack

The firm said the attack occurred last Thursday and prompted it to activate its security protocols This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Spanish Bank Globalcaja Hit By Ransomware Attack

UK Closes CCP Cyber Certification Scheme

Certified Cyber Professional will be replaced by new chartered scheme This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Closes CCP Cyber Certification Scheme

US and Korean Agencies Issue Warning on North Korean Cyber-Attacks

The advisory identifies several actors: Kimsuky, Thallium, APT43, Velvet Chollima and Black Banshee This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US and Korean Agencies Issue Warning on North Korean Cyber-Attacks

Horabot Campaign Targets Spanish-Speaking Users in the Americas

Cisco Talos said the threat actor behind the campaign is believed to be located in Brazil This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Horabot Campaign Targets Spanish-Speaking Users in the Americas

Potential Backdoor in Gigabyte PCs Exposes Supply Chain Risks

Eclypsium is working closely with Gigabyte to rectify insecure implementation of its app center This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Potential Backdoor in Gigabyte PCs Exposes Supply Chain Risks

HMRC in New Tax Credits Scam Warning

Claimants bombarded by phishing emails, phone calls and texts This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: HMRC in New Tax Credits Scam Warning

Zyxel Customers Urged to Patch Exploited Bug

Vulnerability being “widely exploited” in Mirai-based botnet attacks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Zyxel Customers Urged to Patch Exploited Bug

SpinOk Trojan Compromises 421 Million Android Devices

The Doctor Web team unveiled information about the malware in an advisory published on Monday This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: SpinOk Trojan Compromises 421 Million Android Devices

WordPress Rushes Out Jetpack Patch to Millions

Bug could allow malicious actors to manipulate files This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: WordPress Rushes Out Jetpack Patch to Millions

Human Error Fuels Industrial APT Attacks, Kaspersky Reports

OT network admins grant access to employees or contractors without sufficient security measures This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Human Error Fuels Industrial APT Attacks, Kaspersky Reports

Ransomware Gangs Adopting Business-like Practices to Boost Profits

Cyber-criminal gangs are mirroring the practices of legitimate businesses to drive efficiencies and increase profits This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Ransomware Gangs Adopting Business-like Practices to Boost Profits

Dark Web Data Leak Exposes RaidForums Members

Cybercrime site was taken down by the authorities in 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Dark Web Data Leak Exposes RaidForums Members

Nine Million MCNA Dental Customers Hit by Breach

LockBit ransomware group has claimed responsibility This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Nine Million MCNA Dental Customers Hit by Breach

New Mirai Variant Campaigns are Targeting IoT Devices

Unit 42 researchers observed that a wave of malicious campaigns, all deployed by the same threat actor, have been using IZ1H9 since November 2021 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New Mirai Variant Campaigns are…

New Russian-Linked Malware Poses “Immediate Threat” to Energy Grids

Researchers say the specialized OT malware has similarities with Industroyer, which was used to take down power in Kiev, Ukraine, in 2016 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New Russian-Linked Malware Poses “Immediate Threat” to…

Romania’s Safetech Leans into UK Cybersecurity Market

The cyber innovator sees the UK is an ideal location to realize its global ambitions as it opens a SOC at the Plexal Innovation Hub This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Romania’s Safetech Leans into…

Advanced Phishing Attacks Surge 356% in 2022

Perception Point said the increase is due to the adoption of new cloud collaboration apps This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Advanced Phishing Attacks Surge 356% in 2022

Expo Framework API Flaw Reveals User Data in Online Services

The vulnerability was discovered by Salt Security and has a CVSS score of 9.6 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Expo Framework API Flaw Reveals User Data in Online Services

AI Used to Create Malware, WithSecure Observes

The cybersecurity firm confirms that it has observed AI being used to generate malware This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: AI Used to Create Malware, WithSecure Observes

Lazarus Group Targeting Microsoft Web Servers to Launch Espionage Malware

Researchers detail the DLL side-loading technique used to deploy malware that facilitates credential theft and lateral movement This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Lazarus Group Targeting Microsoft Web Servers to Launch Espionage Malware

Backup Repositories Targeted in 93% of Ransomware Attacks

Organizations now acknowledge that having clean and recoverable backups is a critical element of a good business continuity plan This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Backup Repositories Targeted in 93% of Ransomware Attacks

Google Unveils Bug Bounty Program For Android Apps

Rewards range from $750 for certain MiTM scenarios to $30,000 for some ACE vulnerabilities This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Google Unveils Bug Bounty Program For Android Apps

ESET: Android App ‘iRecorder – Screen Recorder’ Trojanized with AhRat

With over 50,000 downloads, the screen recording app was initially legitimate, but the malicious functionality was later implemented This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: ESET: Android App ‘iRecorder – Screen Recorder’ Trojanized with AhRat

Two-Thirds of IT Leaders Say GDPR Has Reduced Consumer Trust

Increased awareness of data privacy issues has reduced trust in organizations, according to the survey This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Two-Thirds of IT Leaders Say GDPR Has Reduced Consumer Trust

China Issues Ban on US Chipmaker Products

The Chinese Communist Party has told tech operators in China to stop purchasing Micron products This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: China Issues Ban on US Chipmaker Products

Meta Fined €1.2bn for Violating GDPR

The record-breaking amount of the fine is the least important part of the story, privacy experts argued This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Meta Fined €1.2bn for Violating GDPR

UK Man Sentenced to 13 Years for Running Multi-Million Fraud Website

Confirmed global losses from iSpoof scams were £100m, with the actual figure believed to be far higher This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Man Sentenced to 13 Years for Running Multi-Million Fraud Website

Microsoft Warns of Increase in Business Email Compromise Attacks

The company’s systems currently detect and investigate an average of 156,000 BEC attacks daily This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Warns of Increase in Business Email Compromise Attacks

KeePass Flaw Exposes Master Passwords

The vulnerability (CVE-2023-32784) was discovered by security researcher Dominik Reichl This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: KeePass Flaw Exposes Master Passwords

CommonMagic Malware Implants Linked to New CloudWizard Framework

Kaspersky researchers said sections of the CloudWizard code were identical to CommonMagic This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CommonMagic Malware Implants Linked to New CloudWizard Framework

Experts Warn of Voice Cloning-as-a-Service

Dark web offerings could commoditize deep fake technology This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Experts Warn of Voice Cloning-as-a-Service

Teen Charged in DraftKings Credential Stuffing Case

Wisconsin man alleged to have stolen $600,000 from accounts This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Teen Charged in DraftKings Credential Stuffing Case

Apple’s App Store Blocks $2bn in Fraudulent Transactions

Firm also rejected 1.7 million apps for failing to meet privacy, security and content standards This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Apple’s App Store Blocks $2bn in Fraudulent Transactions

Cyber Warfare Escalates Amid China-Taiwan Tensions

Trellix report observed a surge in malicious emails targeting Taiwanese industries and government officials This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cyber Warfare Escalates Amid China-Taiwan Tensions

Apple’s App Store Blocks $2b in Fraudulent Transactions

Firm also rejected 1.7 million apps for failing to meet privacy, security and content standards This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Apple’s App Store Blocks $2b in Fraudulent Transactions