Tag: http://www.infosecurity-magazine.com/rss/news/76/application-security/

New Backdoor MQsTTang Attributed to Mustang Panda Group

Unlike the group’s usual tactics, MQsTTang only has a single stage and does not use obfuscation This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New Backdoor MQsTTang Attributed to Mustang Panda Group

CISA Warns Against Royal Ransomware in New Advisory

Malicious activity using a particular malware variant has been spotted since September 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CISA Warns Against Royal Ransomware in New Advisory

NCSC: Twitter Users Should Find MFA Alternatives

UK’s security agency warns against letting protection lapse This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: NCSC: Twitter Users Should Find MFA Alternatives

Experts Warn of “SMS Pumping” Fraud Epidemic

Small businesses are particularly vulnerable This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Experts Warn of “SMS Pumping” Fraud Epidemic

White House Launches National Cybersecurity Strategy

The Strategy provides guidelines on how companies allocate roles and responsibilities in cyber space This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: White House Launches National Cybersecurity Strategy

WH Smith Discloses Cyber-Attack, Company Data Theft

Employee data was accessed by the threat actors, including names, addresses, and more This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: WH Smith Discloses Cyber-Attack, Company Data Theft

Russian Government Bans Foreign Messaging Apps

Kremlin hunkers down as war enters its second year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russian Government Bans Foreign Messaging Apps

Public SaaS Assets Are a Major Risk For Medium, Large Firms

The findings come from DoControl’s latest SaaS Security Threat Landscape report This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Public SaaS Assets Are a Major Risk For Medium, Large Firms

Record Number of Mobile Phishing Attacks in 2022

Endpoint security provider Lookout released its Global State of Mobile Phishing Report, which shows an unprecedented rate of mobile phishing attacks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Record Number of Mobile Phishing Attacks in 2022

Keylogger on Employee Home PC Led to LastPass 2022 Breach

Threat actors obtained credentials and keys later used to access and decrypt some storage volumes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Keylogger on Employee Home PC Led to LastPass 2022 Breach

Attacker Breakout Time Drops to Just 84 Minutes

Every second counts as threat actors accelerate lateral movement This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Attacker Breakout Time Drops to Just 84 Minutes

Dish Network Confirms Ransomware Outage

Satellite TV provider comes clean in SEC filing This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Dish Network Confirms Ransomware Outage

Ransomware Attack Hits US Marshals Service

Drew Wade, chief of the Marshals Service public affairs office, made the announcement on Monday This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Ransomware Attack Hits US Marshals Service

Phone Attacks and MFA Bypass Drive Phishing in 2022

Proofpoint reveals surge in direct financial losses from attacks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Phone Attacks and MFA Bypass Drive Phishing in 2022

London Honeypots Attacked 2000 Times Per Minute

Insurer records 91 million attacks in total in January This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: London Honeypots Attacked 2000 Times Per Minute

News Corp Reveals Two-Year-Long Breach

A threat actor accessed business documents and emails between February 2020 and January 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: News Corp Reveals Two-Year-Long Breach

ChromeLoader Malware Poses as Steam, Nintendo Game Mods

Asec said the malicious activity observed relied on VHD disk image files This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: ChromeLoader Malware Poses as Steam, Nintendo Game Mods

Governments Targeted by Discord-Based Threat Campaign

Threat actor delivers multiple malware types via PureCrypter This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Governments Targeted by Discord-Based Threat Campaign

EU Commission Bans TikTok on Corporate Devices

The move aims to protect the Commission against cybersecurity threats This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: EU Commission Bans TikTok on Corporate Devices

Russian IT “Brain Drain” Decentralizes Cybercrime

Recorded Future claims war in Ukraine is having a major impact This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russian IT “Brain Drain” Decentralizes Cybercrime

Investment Scams Drive $9bn in Fraud in 2022

FTC says consumer fraud is up 30% on the previous year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Investment Scams Drive $9bn in Fraud in 2022

Firms Who Pay Ransom Subsidise 10 New Attacks: Report

Trend Micro urges victim organizations to resist extorters demands This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Firms Who Pay Ransom Subsidise 10 New Attacks: Report

WinorDLL64 Backdoor Linked to Lazarus Group

The Wslink loader can reportedly serve other connecting clients and load additional payloads This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: WinorDLL64 Backdoor Linked to Lazarus Group

Dozens of Malicious ‘HTTP’ Libraries Found on PyPI

ReversingLabs cybersecurity researchers spotted 41 malicious PyPI packages This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Dozens of Malicious ‘HTTP’ Libraries Found on PyPI

Hackers Use S1deload Stealer to Target Facebook, YouTube Users

The malicious software employs DLL sideloading techniques to run its malicious components This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Hackers Use S1deload Stealer to Target Facebook, YouTube Users

Russian Invasion Sparks Global Wiper Malware Surge

Fortinet detected a 50% increase in destructive attacks in H2 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russian Invasion Sparks Global Wiper Malware Surge

Phishing Sites and Apps Use ChatGPT as Lure

Campaigns designed to steal card information and install malware This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Phishing Sites and Apps Use ChatGPT as Lure

Open Source Flaws Found in 84% of Codebases

The figures come from Synopsys’ new Open Source Security and Risk Analysis report This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Open Source Flaws Found in 84% of Codebases

Hydrochasma Group Targets Asian Medical and Shipping Sectors

The hackers appear to have a possible interest in industries connected with COVID-19 treatments This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Hydrochasma Group Targets Asian Medical and Shipping Sectors

Npm Packages Used to Distribute Phishing Links

The malicious packages were reportedly created using automated processes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Npm Packages Used to Distribute Phishing Links

Putin Speech Interrupted by DDoS Attack

Outage impacts Russian state media websites This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Putin Speech Interrupted by DDoS Attack

Time Taken to Deploy Ransomware Drops 94%

Extortion found to be most common impact from cyber-attacks in 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Time Taken to Deploy Ransomware Drops 94%

New Privilege Escalation Bug Class Found on macOS and iOS

The new class of privilege escalation bugs is based on the ForcedEntry attack This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New Privilege Escalation Bug Class Found on macOS and iOS

Researchers Uncover New Information Stealer ‘Stealc’

Stealc is a fully featured stealer, whose development relied on Vidar, Raccoon, Mars and Redline This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Researchers Uncover New Information Stealer ‘Stealc’

City Fund Managers Jailed for $8m Fraud

Trio get 12 years behind bars This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: City Fund Managers Jailed for $8m Fraud

Fifth of Brits Have Fallen Victim to Online Scammers

Many don’t have any security controls in place, says F-Secure This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Fifth of Brits Have Fallen Victim to Online Scammers

Frebniis Malware Exploits Microsoft IIS Feature

The malware was used by a previously unknown threat actor against targets in Taiwan This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Frebniis Malware Exploits Microsoft IIS Feature

FBI “Contains” Cyber-Incident on its Network

Question marks remain over what happened at New York field office This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: FBI “Contains” Cyber-Incident on its Network

Norway Seizes Millions in North Korean Crypto

Funds were taken in attack on Ronin Network This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Norway Seizes Millions in North Korean Crypto

Police Bust $41m Email Scam Gang

Criminal network comprises French and Israeli gangsters This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Police Bust $41m Email Scam Gang

EU Cybersecurity Agency Warns Against Chinese APTs

The document directly mentions APT27, APT30, APT31, Ke3chang, Gallium and Mustang Panda This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: EU Cybersecurity Agency Warns Against Chinese APTs

Google Report Reveals Russia’s Elaborate Cyber Strategy in Ukraine

One year after the invasion of Ukraine, Google and Mandiant analyzed the cyber strategy of Russia-backed threat actors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Google Report Reveals Russia’s Elaborate Cyber Strategy in Ukraine

Armenia and Azerbaijan Hackers Use OxtaRAT to Monitor Conflict

The newest version of OxtaRAT is a polyglot file combining a compiled AutoIT script and an image This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Armenia and Azerbaijan Hackers Use OxtaRAT to Monitor Conflict

UK NCSC Launches Recommendations on Supply Chain Mapping

The UK National Cybersecurity Centre’s new guidance breaks down the essentials of a good supply chain mapping (SCM) list This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK NCSC Launches Recommendations on Supply Chain Mapping

Hackers Fake Emsisoft Certificate to Hide Attack

Attempt to trick network defenders into allow-listing remote access app This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Hackers Fake Emsisoft Certificate to Hide Attack

Data Leak Hits Thousands of NHS Workers

Email snafu affects staff at Liverpool University Hospital Foundation Trust This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Data Leak Hits Thousands of NHS Workers

BEC Groups Target Firms With Multilingual Impersonation Attacks

Combined, the two groups have launched BEC campaigns in at least 13 different languages This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: BEC Groups Target Firms With Multilingual Impersonation Attacks

Hackers Leverage PayPal to Send Malicious Invoices

The phishing email warned users that there had been fraud on the account This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Hackers Leverage PayPal to Send Malicious Invoices

Quarter of Crypto Tokens Linked to Pump-and-Dump

Scammers made an estimated $30m in profits in 2022 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Quarter of Crypto Tokens Linked to Pump-and-Dump

Experts Warn of Surge in Multipurpose Malware

The average malware variant now utilizes 11 TTPs This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Experts Warn of Surge in Multipurpose Malware

UK Policing Riddled with Chinese CCTV Cameras

Security and ethical concerns raised by surveillance commissioner This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Policing Riddled with Chinese CCTV Cameras

Google Launches Privacy Sandbox Beta on Android 13 Devices

It is an initiative designed to limit user data sharing in digital advertising This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Google Launches Privacy Sandbox Beta on Android 13 Devices

LockBit and Royal Mail Ransomware Negotiation Leaked

It shows the threat actor trying to convince Royal Mail to pay the ransom using various techniques This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit and Royal Mail Ransomware Negotiation Leaked

Crypto-Stealing Campaign Deploys MortalKombat Ransomware

The attacks mainly targeted victims in the US but also in the UK, Turkey, and the Philippines This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Crypto-Stealing Campaign Deploys MortalKombat Ransomware

Threat Analysis: VMware ESXi Attacks Soared in 2022

Recorded Future analyzed how threat actors have been exploiting VMware ESXi vulnerabilities over the past three years This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Threat Analysis: VMware ESXi Attacks Soared in 2022

Microsoft Patches Three Zero-Day Bugs This Month

February Patch Tuesday contains updates for over 70 CVEs This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Patches Three Zero-Day Bugs This Month

SideWinder APT Attacks Regional Targets in New Campaign

Indian threat group conducts hundreds of operations in a short time-span This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: SideWinder APT Attacks Regional Targets in New Campaign

Chinese Hackers Infiltrate South American Diplomatic Networks

The group previously targeted government agencies and think tanks in Asia and Europe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Chinese Hackers Infiltrate South American Diplomatic Networks

Hackers Breach Pepsi Bottling Ventures’ Network

Experts say the delay in notifying customers left data potentially open to compromise This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Hackers Breach Pepsi Bottling Ventures’ Network

Spanish Police Bust €5m Phishing Gang

Group laundered funds via 100 bank accounts This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Spanish Police Bust €5m Phishing Gang

Cybersecurity Experts Warn Against Valentine’s Day Romance Scams

Victim losses associated with online romance scams nationwide totaled approximately $5.9bn in 2021 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cybersecurity Experts Warn Against Valentine’s Day Romance Scams

Group-IB Blocks Attack By Chinese Tonto Team Hackers

The threat actors used phishing to deliver malicious files created with the Royal Road Weaponizer This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Group-IB Blocks Attack By Chinese Tonto Team Hackers

Researchers Uncover 700+ Malicious Open Source Packages

Latest npm and PyPI finds should be kept out of build environments This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Researchers Uncover 700+ Malicious Open Source Packages

MoneyGram Fraud Victims Get $115m in Compensation

Money transfer firm failed to crack down on scam agents This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: MoneyGram Fraud Victims Get $115m in Compensation

Namecheap Customers Flooded with Phishing Emails

Domain registrar blames upstream provider This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Namecheap Customers Flooded with Phishing Emails

UK Politician’s Email Hacked by Suspected Russian Threat Actors

The SNP MP revealed details of the incident, in which he clicked on a malicious file purportedly about the military situation in Ukraine This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Politician’s Email Hacked by Suspected…

Reddit Hit By Phishing Attack, Source Code Stolen

Reddit said there was “no indication” of a breach of the company’s primary production systems This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Reddit Hit By Phishing Attack, Source Code Stolen

US Warns Critical Sectors Against North Korean Ransomware Attacks

The latest iteration of the document is now analyzing activity by the Maui and H0lyGh0st groups This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Warns Critical Sectors Against North Korean Ransomware Attacks

Malicious Npm Package Uses Typosquatting, Downloads Malware

Reversing Labs said aabquerys was able to download second- and third-stage malware payloads This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Malicious Npm Package Uses Typosquatting, Downloads Malware

Fifth of ICS Bugs Have No Patch Available

Some industrial systems have been exposed for three years This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Fifth of ICS Bugs Have No Patch Available