Category: http://www.infosecurity-magazine.com/rss/news/76/application-security/

LockBit Dominates Ransomware World, New Report Finds

LockBit becomes one of the first major ransomware operations to specifically target macOS This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit Dominates Ransomware World, New Report Finds

VPN and RDP Exploitation the Most Common Attack Technique

Initial access brokers still play a key role in threat supply chain This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: VPN and RDP Exploitation the Most Common Attack Technique

Japan in the Crosshairs of Many State-Sponsored Threat Actors New Report Finds

Rapid7 found that Vietnamese APTs have also been targeting Japanese organizations, especially competitors of Vietnam’s budding automotive industry This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Japan in the Crosshairs of Many State-Sponsored Threat Actors New Report…

US Prosecutors Line Up Charges in $2.5bn Healthcare Fraud Cases

Nearly 80 individuals accused of participating in multiple schemes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Prosecutors Line Up Charges in $2.5bn Healthcare Fraud Cases

Suncor Energy Responds to Cybersecurity Incident

Over 1500 Petro-Canada gas stations are unable to accept credit card payments This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Suncor Energy Responds to Cybersecurity Incident

ThirdEye Infostealer Poses New Threat to Windows Users

FortiGuard explained that ThirdEye can harvest BIOS and hardware data This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: ThirdEye Infostealer Poses New Threat to Windows Users

Andariel’s Mistakes Uncover New Malware in Lazarus Group Campaign

Kaspersky analyzes the group’s tactics and reveals the emergence of a new threat called EarlyRat This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Andariel’s Mistakes Uncover New Malware in Lazarus Group Campaign

Mobile Malware and Phishing Surge in 2022

Zimperium records large increase in share of compromised devices This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Mobile Malware and Phishing Surge in 2022

EncroChat Bust Leads to 6500 Arrests in Three Years

Encrypted comms platform was used by organized criminals This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: EncroChat Bust Leads to 6500 Arrests in Three Years

Experts Unconvinced by Upskill in UK Cyber Program

Its 3600 applicants will barely make a dent in overall skills shortages This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Experts Unconvinced by Upskill in UK Cyber Program

Anatsa Banking Trojan Targets Banks in US, UK and DACH Region

ThreatFabric said the ongoing campaign started in March and has witnessed over 30,000 installations This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Anatsa Banking Trojan Targets Banks in US, UK and DACH Region

Third-Party Vendor Hack Exposes Data at American, Southwest Airlines

American Airlines reported 5745 pilots and applicants affected, Southwest Airlines reported 3009 This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Third-Party Vendor Hack Exposes Data at American, Southwest Airlines

Study Reveals Alarming Gap in SIEM Detection of Adversary Techniques

CardinalOps examined 4000 detection rules, one million log sources and many unique log source types This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Study Reveals Alarming Gap in SIEM Detection of Adversary Techniques

Submarine Cables at Growing Risk of Cyber-Attacks

A report from Recorded Future highlights how digital cable management systems are vulnerable to nation-state attacks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Submarine Cables at Growing Risk of Cyber-Attacks

Over Half of UK Banks Are Exposing Customers to Email Fraud

Recommended DMARC policy only implemented by a minority This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Over Half of UK Banks Are Exposing Customers to Email Fraud

NCSC Launches Cyber Risk Management Toolbox

Security agency’s latest guidance refresh makes best practices more accessible This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: NCSC Launches Cyber Risk Management Toolbox

Payments Lobby: Anti-APP Fraud Policies Could Increase Scams

Payments Association wants social media firms to play role in crackdown This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Payments Lobby: Anti-APP Fraud Policies Could Increase Scams

Are GPT-Based Models the Right Fit for AI-Powered Cybersecurity?

Many cybersecurity vendors are integrating general-purpose large language models into their solutions. However, some experts argue that these are not the best AI algorithms for security This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Are GPT-Based Models…

Umbral Stealer Discovered in Trojanized Super Mario Installer

The discovery comes from security researchers at Cyble Research and Intelligence Labs This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Umbral Stealer Discovered in Trojanized Super Mario Installer

Millions Face RepoJacking Risk on GitHub Repositories

Aqua identified numerous high-profile targets, including organizations such as Google and Lyft This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Millions Face RepoJacking Risk on GitHub Repositories

NSA Releases Guide to Mitigate BlackLotus Bootkit Infections

Microsoft patched exploited boot loader flaw but did not revoke trust in unpatched loaders This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: NSA Releases Guide to Mitigate BlackLotus Bootkit Infections

US Authorities Seize BreachForums Domain

Questions still to be answered over why it took so long This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Authorities Seize BreachForums Domain

Twitter Celeb Hacker Jailed For Five Years

Joseph O’Connor hijacked over 100 accounts in bitcoin scam This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Twitter Celeb Hacker Jailed For Five Years

US Military Personnel Warned of Malicious Smartwatches

The smartwatches have Wi-Fi auto-connect features and possibly contain malware This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Military Personnel Warned of Malicious Smartwatches

OpenSSH Trojan Campaign Targets IoT and Linux Systems

Microsoft said attackers used a patched version of OpenSSH to gain control of compromised devices This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: OpenSSH Trojan Campaign Targets IoT and Linux Systems

USB Drives Used as Trojan Horses By Camaro Dragon

The malicious software tools were discovered by Check Point Research This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: USB Drives Used as Trojan Horses By Camaro Dragon

#InfosecurityEurope: BlackBerry Cybersecurity President Warns Against Heavy-Handed AI Regulation

BlackBerry president John Giamatteo acknowledged that governments should intervene to mitigate AI risks – and his company is willing to help them This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: BlackBerry Cybersecurity President Warns Against Heavy-Handed…

NCSC Updates Cybersecurity Guidance for the Legal Sector

Law firms remain a popular target for attack This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: NCSC Updates Cybersecurity Guidance for the Legal Sector

FBI Analyst Gets Three Years For National Security Breach

Kendra Kingsbury smuggled classified documents out on storage media This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: FBI Analyst Gets Three Years For National Security Breach

#InfosecurityEurope: Experts Highlight Evolving Attack Techniques

Experts discussed growing utilization of ChatGPT by threat actors and evolving identity-based attacks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Experts Highlight Evolving Attack Techniques

#InfosecurityEurope Case Study: Attack Surface Operations at Nationwide

Nationwide Building Society is setting up a new team tasked with monitoring and managing its attack surface This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope Case Study: Attack Surface Operations at Nationwide

Apple Addresses Exploited Security Flaws in iOS, macOS and Safari

Latest updates patch two zero-day vulnerabilities reportedly weaponized in Operation Triangulation This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Apple Addresses Exploited Security Flaws in iOS, macOS and Safari

US Justice Department Launches New National Security Cyber Section

The primary objective of NatSec Cyber is to enhance the Justice Department’s capacity to counter malicious cyber activities effectively This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Justice Department Launches New National Security Cyber Section

RedEyes Group Targets Individuals with Wiretapping Malware

The campaign was discovered by AhnLab Security Emergency Response Center (ASEC) This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: RedEyes Group Targets Individuals with Wiretapping Malware

#InfosecurityEurope: Dunelm Shifts Security to the Edge

An increased focus on security allows furnishings retailer to boost its e-commerce operations This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Dunelm Shifts Security to the Edge

#InfosecurityEurope: Angoka Named UK’s Most Innovative Cyber SME of 2023

The DSIT jury awarded the prize to the Belfast-based smart city security provider with a unanimous decision This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Angoka Named UK’s Most Innovative Cyber SME of 2023

#InfosecurityEurope: Internet of Things Continues to Pose Security Risk

The growth of IoT and connected devices is contributing to an expanding attack surface, despite upcoming legal controls This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Internet of Things Continues to Pose Security Risk

#InfosecurityEurope: From Passion to Profession, Becky Pinkard’s Dedication to Cybersecurity

Infosecurity Europe inducts Becky Pinkard, Managing Director of Global Cyber Operations at Barclays, into the Hall of Fame This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: From Passion to Profession, Becky Pinkard’s Dedication to Cybersecurity

#InfosecurityEurope Hall of Fame: Becky Pinkard, Managing Director of Global Cyber Operations, Barclays

Infosecurity Europe inducts Becky Pinkard, Managing Director of Global Cyber Operations at Barclays, into the Hall of Fame This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope Hall of Fame: Becky Pinkard, Managing Director of Global Cyber…

Supply Chain and APIs Top Security Concerns, CISO Survey Shows

Findings indicate that 89% of CISOs are grappling with risks arising from the rapid deployment of digital services This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Supply Chain and APIs Top Security Concerns, CISO Survey Shows

Security Researchers Uncover New Spyware Implant TriangleDB

Kaspersky report that the implant specifically targets iOS devices via a malicious iMessage attachment This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Security Researchers Uncover New Spyware Implant TriangleDB

#InfosecurityEurope: One in Three UK&I Workers Susceptible to Phishing

KnowBe4 report revealed that 35.2% of users with no security training were prone to clicking on suspicious links This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: One in Three UK&I Workers Susceptible to Phishing

#InfosecurityEurope: Does Pentesting Need a New Service Model?

Shortlisted as one of the UK’s Most Innovative Cyber SMEs in 2023, the startup presented its vision of PTaaS during Infosecurity Europe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Does Pentesting Need a New Service…

#InfosecurityEurope: Why API Security Could Be the Next Big Thing in Cyber

APIs have become fundamental to everyone’s digital life, yet API security continues to be overlooked, Contxt’s CEO Mayur Upadhyaya said during Infosecurity Europe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Why API Security Could Be…

#InfosecurityEurope: Security Training Needs to Nudge, Not Nag

Awareness programs should use psychology to change security culture, experts argue This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Security Training Needs to Nudge, Not Nag

#InfosecurityEurope: Certifications Are No Guarantee of Security

Despite their importance, security certifications can work against diversity and innovation, according to a CISO panel This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Certifications Are No Guarantee of Security

#InfosecurityEurope: Certifications are no guarantee of security

Despite their importance, security certifications can work against diversity and innovation, according to a CISO panel This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Certifications are no guarantee of security

#InfosecurityEurope: Digital Dependence Means Government and Industry Must Bolster Collaboration

Increasing threats should prompt organizations of all sizes to move from cyber defense to cyber resilience, argues Saj Huq This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Digital Dependence Means Government and Industry Must Bolster Collaboration

Smart Pet Feeders Expose Personal Data

Kaspersky warns of two security flaws discovered in popular smart pet feeders that could lead to data theft This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Smart Pet Feeders Expose Personal Data

Majority of Users Neglect Best Password Practices: Keeper Security

Survey found that only only 25% of respondents used solid and unique passwords This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Majority of Users Neglect Best Password Practices: Keeper Security

Over 100,000 ChatGPT Accounts Found in Dark Web Marketplaces

The discovery was made by Singapore-based cybersecurity firm Group-IB. This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Over 100,000 ChatGPT Accounts Found in Dark Web Marketplaces

#InfosecurityEurope: Ironscales Launches GPT-Powered Chat Assistant for Self-Service Threat Reporting

The email security provider launched the Beta program for Themis Co-pilot, a large language model-based chat assistant for Microsoft Outlook security This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Ironscales Launches GPT-Powered Chat Assistant for Self-Service…

#InfosecurityEurope: Netskope Sets Out to Help Enterprises Safely Use ChatGPT

Netskope’s new solution aims to enable organizations to use generative AI tools without running cybersecurity or data protection risks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Netskope Sets Out to Help Enterprises Safely Use ChatGPT

#InfosecurityEurope: Asset Visibility Gaps Jeopardize Security Compliance in NHS Trusts, Report Finds

New Armis research found that many National Health Service Trusts struggle with a lack of visibility and monitoring of their connected assets This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Asset Visibility Gaps Jeopardize Security Compliance…

US Offers $10m Reward For MOVEit Attackers

State department wants information on Clop ransomware actors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Offers $10m Reward For MOVEit Attackers

Millions of UK University Credentials Found on Dark Web

Concerns mount over security of sensitive research This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Millions of UK University Credentials Found on Dark Web

UK Pledges Millions in Cyber-Defense Aid to Ukraine

Funds will help to protect under-siege country’s critical infrastructure This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Pledges Millions in Cyber-Defense Aid to Ukraine

Russian National Arrested in Connection With LockBit Ransomware

Ruslan Magomedovich Astamirov allegedly targeted computer systems in the US, Asia, Europe and Africa This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russian National Arrested in Connection With LockBit Ransomware

New Version of Android GravityRAT Spyware Targets WhatsApp Backups

ESET said the new variant was distributed via the messaging apps BingeChat and Chatico This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New Version of Android GravityRAT Spyware Targets WhatsApp Backups

Russia-affiliated Shuckworm Intensifies Cyber-Attacks on Ukraine

Symantec said the new campaign focused on acquiring military and security intelligence This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russia-affiliated Shuckworm Intensifies Cyber-Attacks on Ukraine

Barracuda Zero-Day Exploited by Chinese Actor

Mandiant lifts the lid on new espionage campaign This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Barracuda Zero-Day Exploited by Chinese Actor

Cyber-Criminals Are Using Mining Pools to Launder Crypto

Chainalysis claims threat actors are using these services like mixers This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cyber-Criminals Are Using Mining Pools to Launder Crypto

Clop Starts MOVEit Extortion as New Bug is Discovered

Progress Software scrambles to release a new security update This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Clop Starts MOVEit Extortion as New Bug is Discovered

#InfosecurityEurope: How DORA Will Force Financial Firms to Adopt Cyber Resilience

Many discussions within the cyber community are shifting from cybersecurity to cyber resilience. The EU’s Digital Operational Resilience Act is the first regulation to embrace this concept This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: How…

CISA and NSA Publish BMC Hardening Guidelines

Vulnerabilities in Baseboard Management Controllers (BMCs) serve as entry points for malicious actors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CISA and NSA Publish BMC Hardening Guidelines

Study Reveals Ransomware as Most Popular Cybercrime Service

Kaspersky also said 24% were infostealers and 18% included botnets, loaders and backdoors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Study Reveals Ransomware as Most Popular Cybercrime Service

Microsoft Names Russian Threat Actor “Cadet Blizzard”

Microsoft believes Cadet Blizzard, formerly DEV-0586, to be associated with the Russian GRU This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Names Russian Threat Actor “Cadet Blizzard”

#InfosecurityEurope: New Study Takes a Deep Dive Into Lookalike Attacks

The latest study from Infosecurity Europe exhibitor Infoblox reveals that cyber-attacks using lookalike domains are on the rise This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: New Study Takes a Deep Dive Into Lookalike Attacks

LockBit Makes $91m From US Victims in Two Years

Allied security agencies reveal figure in new advisory This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit Makes $91m From US Victims in Two Years

LockBit Makes $91m from US Victims in Two Years

Allied security agencies reveal figure in new advisory This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit Makes $91m from US Victims in Two Years

Malicious Actors Exploit GitHub to Distribute Fake Exploits

The perpetrators went to great lengths to make their profiles appear genuine This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Malicious Actors Exploit GitHub to Distribute Fake Exploits

PII Exposed: Unauthenticated IDOR in WooCommerce Stripe Plugin

The vulnerability affects versions 7.4.0 and below of the WordPress plugin This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: PII Exposed: Unauthenticated IDOR in WooCommerce Stripe Plugin

EU Passes Landmark Artificial Intelligence Act

The European Parliament adopted the latest draft of the legislation with an overwhelming majority This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: EU Passes Landmark Artificial Intelligence Act

Researchers Uncover XSS Vulnerabilities in Azure Services

They could allow unauthorized access to sessions within the compromised Azure service iframe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Researchers Uncover XSS Vulnerabilities in Azure Services

Europol Warns of Metaverse and AI Terror Threat

Emerging technologies could help propaganda and recruitment efforts This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Europol Warns of Metaverse and AI Terror Threat

MFA Bypass Kits Account For One Million Monthly Messages

Threat actors evolve to multi-factor authentication This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: MFA Bypass Kits Account For One Million Monthly Messages

No Zero-Days but PGM Flaws Cause Patch Tuesday Concern

Microsoft issues nearly 80 CVEs this month This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: No Zero-Days but PGM Flaws Cause Patch Tuesday Concern

Fortinet Addresses Critical FortiGate SSL-VPN Vulnerability

The release notes did not initially mention the critical SSL-VPN RCE vulnerability being addressed This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Fortinet Addresses Critical FortiGate SSL-VPN Vulnerability

Crypto Wallets Under Attack By DoubleFinger Malware

The malware discovered by Kaspersky employs a multistage attack method This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Crypto Wallets Under Attack By DoubleFinger Malware