Tag: www.infosecurity-magazine.com

EU Sanctions Russian Cyber Actors for “Destabilizing Actions”

The EU announced sanctions against individuals and entities involved in cyber-attacks and disinformation campaigns on behalf of the Russian state This article has been indexed from www.infosecurity-magazine.com Read the original article: EU Sanctions Russian Cyber Actors for “Destabilizing Actions”

New APIs Discovered by Attackers in Just 29 Seconds

Wallarm honeypot research finds potentially exposed APIs are being discovered within half a minute This article has been indexed from www.infosecurity-magazine.com Read the original article: New APIs Discovered by Attackers in Just 29 Seconds

US Unveils New National Cyber Incident Response Plan

The draft plan is designed to help businesses understand how the government will support them during a cyber incident This article has been indexed from www.infosecurity-magazine.com Read the original article: US Unveils New National Cyber Incident Response Plan

All Major European Financial Firms Suffer Supplier Breaches

SecurityScorecard claims 100% of Europe’s top financial services companies have suffered a supply chain breach in the past year This article has been indexed from www.infosecurity-magazine.com Read the original article: All Major European Financial Firms Suffer Supplier Breaches

CISA and EPA Warn of Cyber Risks to Water System Interfaces

CISA and EPA have published guidance for operators of water and wastewater systems to protect against cyber-attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA and EPA Warn of Cyber Risks to Water System Interfaces

Fake Captcha Campaign Highlights Risks of Malvertising Networks

Large-scale campaign identified by Guardio Lans and Infoblox, exploiting malvertising and fake captchas to distribute Lumma infostealer for massive theft This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Captcha Campaign Highlights Risks of Malvertising Networks

Ofcom Issues Guidance for Tech Firms to Tackle Online Harms

New Ofcom guidance is designed to help tech companies comply with their obligations around tackling illegal online harms under the Online Safety Act This article has been indexed from www.infosecurity-magazine.com Read the original article: Ofcom Issues Guidance for Tech Firms…

YouTube Creators Targeted in Global Phishing Campaign

Over 200,000 YouTube creators have been targeted by malware-laden phishing emails with the aim of infecting their followers This article has been indexed from www.infosecurity-magazine.com Read the original article: YouTube Creators Targeted in Global Phishing Campaign

US Uncovers North Korean IT Worker Fraud, Offers $5M Bounty

The US Government is offering a $5 million reward for information leading to the disruption of financial mechanisms supporting North Korea following a six-year conspiracy This article has been indexed from www.infosecurity-magazine.com Read the original article: US Uncovers North Korean…

US Offers $5M for Info on North Korean IT Worker Fraud

The US Government is offering a $5 million reward for information leading to the disruption of financial mechanisms supporting North Korea following a six-year conspiracy This article has been indexed from www.infosecurity-magazine.com Read the original article: US Offers $5M for…

2024 Sees Sharp Increase in Microsoft Tool Exploits

Sophos found observed a significant rise in Microsoft LOLbins abused by attackers in H1 2024 compared to 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: 2024 Sees Sharp Increase in Microsoft Tool Exploits

ISC2 Survey Reveals Critical Gaps in Cybersecurity Leadership Skills

ISC2 research has found that cybersecurity leaders have limited skills and training in areas like communication, strategic mindset and business acumen This article has been indexed from www.infosecurity-magazine.com Read the original article: ISC2 Survey Reveals Critical Gaps in Cybersecurity Leadership…

UK Shoppers Frustrated as Bots Snap Up Popular Christmas Gifts

Almost three quarters of UK consumers believe bad bots are ruining Christmas by buying up popular gifts, forcing many to purchase expensive alternatives, according to Imperva research This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Shoppers…

Security Flaws in WordPress Woffice Theme Prompts Urgent Update

Two Woffice theme vulnerabilities have been identified that allow attackers to gain unauthorized access and control of unpatched websites This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Flaws in WordPress Woffice Theme Prompts Urgent Update

Remcos RAT Malware Evolves with New Techniques

Cyber-attacks involving Remcos RAT surged in Q3 2024, enabling attackers to control victim machines remotely, steal data and carry out espionage This article has been indexed from www.infosecurity-magazine.com Read the original article: Remcos RAT Malware Evolves with New Techniques

Lookout Discovers New Spyware Deployed by Russia and China

Russian-made spyware BoneSpy and PlainGnome target former Soviet states, while public security bureaus in mainland China use Chinese surveillance tool EagleMsgSpy This article has been indexed from www.infosecurity-magazine.com Read the original article: Lookout Discovers New Spyware Deployed by Russia and…

Secret Blizzard Targets Ukrainian Military with Custom Malware

Microsoft detailed how Russian espionage group Secret Blizzard is leveraging infrastructure of other threat actors to target the Ukrainian military with custom malware This article has been indexed from www.infosecurity-magazine.com Read the original article: Secret Blizzard Targets Ukrainian Military with…

Cyber Incident Disrupting Krispy Kreme Online Orders

Krispy Kreme said the incident is likely to materially affect operations and short-term financial performance This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Incident Disrupting Krispy Kreme Online Orders

Microsoft Azure MFA Flaw Allowed Easy Access Bypass

Microsoft MFA flaw exposed that allowed attackers to bypass security within an hour, putting 400m Office 365 accounts at risk This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Azure MFA Flaw Allowed Easy Access Bypass

Operation PowerOFF Takes Down DDoS Boosters

Operation PowerOFF has dismantled a network of 27 DDoS platforms, leading to the arrests of three administrators and the identification of over 300 users This article has been indexed from www.infosecurity-magazine.com Read the original article: Operation PowerOFF Takes Down DDoS…

US Sanctions Chinese Firm at Center of Global Firewall Hack

The US government has sanctioned Sichuan Silence and one of its employees for the mass compromise of firewalls which led to the deployment of malware and ransomware This article has been indexed from www.infosecurity-magazine.com Read the original article: US Sanctions…

Snowflake Pledges to Make MFA Mandatory

The multi-cloud data warehousing platform said it will completely phase out single factor authentication with passwords by November 2025 This article has been indexed from www.infosecurity-magazine.com Read the original article: Snowflake Pledges to Make MFA Mandatory

Hackers Exploit AWS Misconfigurations in Massive Data Breach

Hackers exploited AWS misconfigurations, leaking 2TB of sensitive data, including customer information, credentials and proprietary source code This article has been indexed from www.infosecurity-magazine.com Read the original article: Hackers Exploit AWS Misconfigurations in Massive Data Breach

Utility Companies Face 42% Surge in Ransomware Attacks

The utilities sector saw a 42% surge in ransomware incidents over the past year, with groups like Play focusing on targets with IT and OT systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Utility Companies Face…

Scottish Parliament TV at Risk of Deepfake Attacks

Researchers found that the broad accessibility of streams of Scottish Parliamentary proceedings make them highly susceptible to deepfake attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: Scottish Parliament TV at Risk of Deepfake Attacks

Public Reprimands, an Effective Deterrent Against Data Breaches

The UK’s ICO has published its findings following a two-year trial of its Public Sector Approach, which aimed to improve data protection compliance and deter data breaches This article has been indexed from www.infosecurity-magazine.com Read the original article: Public Reprimands,…

Phishing Scam Targets Ukrainian Defense Companies

CERT-UA has issued a warning about phishing emails targeting Ukrainian defense companies and security forces This article has been indexed from www.infosecurity-magazine.com Read the original article: Phishing Scam Targets Ukrainian Defense Companies

FCC Proposes Stricter Cybersecurity Rules for US Telecoms

The Salt Typhoon hack against US telecommunications firms has prompted the FCC to suggest stricter security rules to protect the sector from future cyber threats This article has been indexed from www.infosecurity-magazine.com Read the original article: FCC Proposes Stricter Cybersecurity…

FBI Warns GenAI is Boosting Financial Fraud

An FBI alert warned that GenAI tools are improving the believability of fraud schemes and enabling large scale attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Warns GenAI is Boosting Financial Fraud

G20 Leaders Fear Economic Over Cyber Risks

World Economic Forum data shows G20 executives are more concerned about economic risks that cyber-threats This article has been indexed from www.infosecurity-magazine.com Read the original article: G20 Leaders Fear Economic Over Cyber Risks

Pro-Russian Hacktivist Group Claims 6600 Attacks Targeting Europe

Orange Cyberdefense found that hacktivist gang Noname has almost exclusively targeted European countries since March 2022, with no attacks impacting the US This article has been indexed from www.infosecurity-magazine.com Read the original article: Pro-Russian Hacktivist Group Claims 6600 Attacks Targeting…

Ransomware Costs Manufacturing Sector $17bn in Downtime

Ransomware attacks cost manufacturing $17bn in downtime since 2018, with $1.9m daily losses, according to Comparitech This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Costs Manufacturing Sector $17bn in Downtime

Wirral Hospital Recovery Continues One Week After Cyber Incident

Wirral University Teaching Hospital is recovering from a cybersecurity incident that occurred on November 25, with some patient services still disrupted as systems are being restored This article has been indexed from www.infosecurity-magazine.com Read the original article: Wirral Hospital Recovery…

FTC Safeguards US Consumers from Location Data Misuse

In a settlement announced on Tuesday, the FTC banned Gravy Analytics and Mobilewalla from selling sensitive location data This article has been indexed from www.infosecurity-magazine.com Read the original article: FTC Safeguards US Consumers from Location Data Misuse

Liverpool Children’s Hospital Confirms Cyber-Attack

Alder Hey Children’s NHS Foundation Trust said a single attack compromised the systems of three NHS entities This article has been indexed from www.infosecurity-magazine.com Read the original article: Liverpool Children’s Hospital Confirms Cyber-Attack

German Police Shutter Country’s Largest Dark Web Market

Law enforcers in Germany have taken down dark web marketplace Crimenetwork and arrested a suspected administrator This article has been indexed from www.infosecurity-magazine.com Read the original article: German Police Shutter Country’s Largest Dark Web Market

Vodka Giant Stoli Files for Bankruptcy After Ransomware Attack

Russian vodka-maker Stoli Group has filed for bankruptcy in the US after ransomware attack and alleged persecution by the Putin regime This article has been indexed from www.infosecurity-magazine.com Read the original article: Vodka Giant Stoli Files for Bankruptcy After Ransomware…

ENISA Launches First State of EU Cybersecurity Report

The NIS2 directive requires the EU cybersecurity agency to produce a biennial report on the state of cybersecurity in the Union This article has been indexed from www.infosecurity-magazine.com Read the original article: ENISA Launches First State of EU Cybersecurity Report

Security Risks Persist in Open Source Ecosystem

An analysis by the Linux Foundation, OpenSSF and Harvard University found that there continues to be significant cybersecurity risks in open source software practices This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Risks Persist in Open…

Lumma Stealer Proliferation Fueled by Telegram Activity

Spreading malware via Telegram channels allows threat actors to bypass traditional detection mechanisms and reach a broad, unsuspecting audience This article has been indexed from www.infosecurity-magazine.com Read the original article: Lumma Stealer Proliferation Fueled by Telegram Activity

BianLian Ransomware Group Adopts New Tactics, Posing Significant Risk

The BianLian ransomware group has shifted exclusively to exfiltration-based extortion and is deploying multiple new TTPs for initial access and persistence This article has been indexed from www.infosecurity-magazine.com Read the original article: BianLian Ransomware Group Adopts New Tactics, Posing Significant…

Linux Malware WolfsBane and FireWood Linked to Gelsemium APT

New Linux malware WolfsBane and FireWood have been linked to Gelsemium APT, a cyber-espionage group targeting critical systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Linux Malware WolfsBane and FireWood Linked to Gelsemium APT

watchTowr Finds New Zero-Day Vulnerability in Fortinet Products

The new vulnerability was named “FortiJump Higher” due to its similarity with the “FortiJump” vulnerability discovered in October This article has been indexed from www.infosecurity-magazine.com Read the original article: watchTowr Finds New Zero-Day Vulnerability in Fortinet Products

Microsoft Power Pages Misconfiguration Leads to Data Exposure

Misconfigurations in Microsoft Power Pages granting excessive access permissions expose sensitive data, risking PII to unauthorized users This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Power Pages Misconfiguration Leads to Data Exposure

Sitting Ducks DNS Attacks Put Global Domains at Risk

Over 1 million domains are vulnerable to “Sitting Ducks” attack, which exploits DNS misconfigurations This article has been indexed from www.infosecurity-magazine.com Read the original article: Sitting Ducks DNS Attacks Put Global Domains at Risk

API Security in Peril as 83% of Firms Suffer Incidents

Over 80% of UK organizations suffered an API security incident in the past year, with each costing over £400,000 This article has been indexed from www.infosecurity-magazine.com Read the original article: API Security in Peril as 83% of Firms Suffer Incidents

Bank of England U-turns on Vulnerability Disclosure Rules

The UK’s financial regulators have discarded plans to force critical suppliers to disclose new vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Bank of England U-turns on Vulnerability Disclosure Rules

AI Threat to Escalate in 2025, Google Cloud Warns

2025 could see our biggest AI fears materialize, according to a Google Cloud forecast report This article has been indexed from www.infosecurity-magazine.com Read the original article: AI Threat to Escalate in 2025, Google Cloud Warns

Amazon MOVEit Leaker Claims to Be Ethical Hacker

An individual who posted data allegedly stolen via MOVEit from Amazon and other big-name firms claims not to be malicious This article has been indexed from www.infosecurity-magazine.com Read the original article: Amazon MOVEit Leaker Claims to Be Ethical Hacker

Phishing Tool GoIssue Targets Developers on GitHub

New phishing tool GoIssue targets GitHub, enabling mass phishing, and has been linked to the GitLoker extortion campaign This article has been indexed from www.infosecurity-magazine.com Read the original article: Phishing Tool GoIssue Targets Developers on GitHub

New Citrix Zero-Day Vulnerability Allows Remote Code Execution

watchTowr has found a flaw in Citrix’s Session Recording Manager that can be exploited to enable unauthenticated RCE against Citrix Virtual Apps and Desktops This article has been indexed from www.infosecurity-magazine.com Read the original article: New Citrix Zero-Day Vulnerability Allows…

North Korea Hackers Leverage Flutter to Deliver macOS Malware

Jamf observed North Korean attackers embedding malware within Flutter applications to target macOS devices, potentially to test a new way of weaponizing malware This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korea Hackers Leverage Flutter to…

New Remcos RAT Variant Targets Windows Users Via Phishing

The new Remcos RAT variant identified in a new phishing campaign exploits CVE-2017-0199 via malicious Excel files This article has been indexed from www.infosecurity-magazine.com Read the original article: New Remcos RAT Variant Targets Windows Users Via Phishing

Pensioners Warned Over Winter Fuel Payment Scam Texts

The UK Regional Organised Crime Unit (ROCU) Network has urged the elderly to be on the lookout for scam texts offering a winter fuel subsidy This article has been indexed from www.infosecurity-magazine.com Read the original article: Pensioners Warned Over Winter…

Man Gets 12.5 Years for Running Bitcoin Fog Crypto Mixer

Swedish-Russian national Roman Sterlingov has been jailed for 12 years and six months for operating notorious cryptocurrency mixer Bitcoin Fog This article has been indexed from www.infosecurity-magazine.com Read the original article: Man Gets 12.5 Years for Running Bitcoin Fog Crypto…

Major Oilfield Supplier Hit by Ransomware Attack

International energy solution provider Newpark Resources has confirmed it was hit by a ransomware attack that disrupted critical systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Major Oilfield Supplier Hit by Ransomware Attack