Category: www.infosecurity-magazine.com

Indonesia is a Spyware Haven, Amnesty International Finds

Amnesty International found in Indonesia a murky ecosystem of surveillance suppliers, brokers and resellers that obscures the sale and transfer of surveillance technology This article has been indexed from www.infosecurity-magazine.com Read the original article: Indonesia is a Spyware Haven, Amnesty…

Android Flaw Affected Apps With 4 Billion Installs

Microsoft illustrated the severity of the issue via a case study involving Xiaomi’s File Manager This article has been indexed from www.infosecurity-magazine.com Read the original article: Android Flaw Affected Apps With 4 Billion Installs

Security Breach Exposes Dropbox Sign Users

Attackers accessed emails, usernames, phone numbers, hashed passwords and authentication information This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Breach Exposes Dropbox Sign Users

Three-Quarters of CISOs Admit App Security Incidents

Dynatrace research claims global CISOs are concerned AI is driving advanced app security threats and poor developer practices This article has been indexed from www.infosecurity-magazine.com Read the original article: Three-Quarters of CISOs Admit App Security Incidents

US and UK Warn of Disruptive Russian OT Attacks

The US and its allies claim Russian hacktivists are disruptive operations in water, energy, food and agriculture sectors This article has been indexed from www.infosecurity-magazine.com Read the original article: US and UK Warn of Disruptive Russian OT Attacks

1 in 5 US Ransomware Attacks Triggers Lawsuit

Comparitech found that 18% of ransomware incidents in the US led to a lawsuit in 2023, with 59% of completed lawsuits since 2018 proving successful This article has been indexed from www.infosecurity-magazine.com Read the original article: 1 in 5 US…

US Government Releases New Resources Against AI Threats

The US Department of Homeland Security has released new guidelines for securing critical infrastructure and CBRN from AI threats This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government Releases New Resources Against AI Threats

Ransomware Rising Despite Takedowns, Says Corvus Report

The first quarter of 2024 saw the most ransomware activity ever recorded, Corvus Insurance found in a new analysis This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Rising Despite Takedowns, Says Corvus Report

Millions of Malicious Containers Found on Docker Hub

According to JFrog, approximately 25% of all repositories lack useful functionality and serve as vehicles for spam and malware This article has been indexed from www.infosecurity-magazine.com Read the original article: Millions of Malicious Containers Found on Docker Hub

Ransom Payments Surge by 500% to an Average of $2m

Sophos found that the average ransom payment was $2m in 2023, with 63% of ransom demands $1m or more This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransom Payments Surge by 500% to an Average of $2m

Google Blocks 2.3 Million Apps From Play Store Listing

Google blocked millions of policy-violating apps from being listed on Play in 2023 and banned 333,000 bad accounts This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Blocks 2.3 Million Apps From Play Store Listing

Judge0 Sandbox Vulnerabilities Expose Systems to Takeover Risk

Tanto Security uncovered three vulnerabilities which could allow attackers to execute sandbox escapes and gain root permissions on host machines This article has been indexed from www.infosecurity-magazine.com Read the original article: Judge0 Sandbox Vulnerabilities Expose Systems to Takeover Risk

OpenAI’s ChatGPT is Breaking GDPR, Says Noyb

European non-profit Noyb has filed a complaint to the Austrian data protection authority (DSB) over OpenAI’s ChatGPT providing false personal information This article has been indexed from www.infosecurity-magazine.com Read the original article: OpenAI’s ChatGPT is Breaking GDPR, Says Noyb

New UK Smart Device Security Law Comes into Force

IoT manufacturers, retailers and importers must comply with new security legislation, the PSTI act, from today This article has been indexed from www.infosecurity-magazine.com Read the original article: New UK Smart Device Security Law Comes into Force

New UK Smart Device Security Law Comes into Force Today

IoT manufacturers, retailers and importers must comply with new security legislation, the PSTI act, from today This article has been indexed from www.infosecurity-magazine.com Read the original article: New UK Smart Device Security Law Comes into Force Today

Okta Warns Customers of Credential Stuffing Barrage

Okta has issued customers with new advice on how to block mounting credential stuffing attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: Okta Warns Customers of Credential Stuffing Barrage

Over 850 Vulnerable Devices Secured Through CISA Ransomware Program

CISA’s RVWP program sent 1754 ransomware vulnerability notifications to government and critical infrastructure entities in 2023, leading to 852 devices being secured This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 850 Vulnerable Devices Secured Through CISA…

DragonForce Ransomware Group Uses LockBit’s Leaked Builder

Cyber threat intelligence provider Cyble found that DragonForce was using a ransomware binary based on LockBit Black’s builder This article has been indexed from www.infosecurity-magazine.com Read the original article: DragonForce Ransomware Group Uses LockBit’s Leaked Builder

11% of Cybersecurity Teams Have Zero Women

A new ISC2 study highlights the lack of diversity in cybersecurity with only 4% of teams having a majority of women, while 11% have none at all This article has been indexed from www.infosecurity-magazine.com Read the original article: 11% of…

BEC and Fund Transfer Fraud Top Insurance Claims

Email-borne fraud accounted for more insurance claims than any other category in 2023, says Coalition This article has been indexed from www.infosecurity-magazine.com Read the original article: BEC and Fund Transfer Fraud Top Insurance Claims

US Congress Passes Bill to Ban TikTok

The bill that could see TikTok banned in the US has been approved by the House of Representatives and the Senate This article has been indexed from www.infosecurity-magazine.com Read the original article: US Congress Passes Bill to Ban TikTok

Fifth of CISOs Admit Staff Leaked Data Via GenAI

One in five UK organizations have had corporate data exposed via generative AI, says RiverSafe This article has been indexed from www.infosecurity-magazine.com Read the original article: Fifth of CISOs Admit Staff Leaked Data Via GenAI

Vulnerability Exploitation on the Rise as Attackers Ditch Phishing

Mandiant’s latest M-Trends report found that vulnerability exploitation was the most common initial infection vector in 2023, making up 38% of intrusions This article has been indexed from www.infosecurity-magazine.com Read the original article: Vulnerability Exploitation on the Rise as Attackers…

Vulnerability Exploitation on the Rise as Attacker Ditch Phishing

Mandiant’s latest M-Trends report found that vulnerability exploitation was the most common initial infection vector in 2023, making up 38% of intrusions This article has been indexed from www.infosecurity-magazine.com Read the original article: Vulnerability Exploitation on the Rise as Attacker…

Dependency Confusion Vulnerability Found in Apache Project

This occurs when a private package fetches a similar public one, leading to exploit due to misconfigurations in package managers This article has been indexed from www.infosecurity-magazine.com Read the original article: Dependency Confusion Vulnerability Found in Apache Project

NSA Launches Guidance for Secure AI Deployment

The new document is the first release from NSA’s Artificial Intelligence Security Center (AISC), in partnership with other government agencies in the US and other Five Eyes countries This article has been indexed from www.infosecurity-magazine.com Read the original article: NSA…

NCSC Announces PwC’s Richard Horne as New CEO

The UK’s National Cyber Security Centre will see Richard Horne take over as its new boss in the autumn This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Announces PwC’s Richard Horne as New CEO

MITRE Reveals Ivanti Breach By Nation State Actor

Non-profit MITRE says a sophisticated state group breached its network via two chained Ivanti zero-days This article has been indexed from www.infosecurity-magazine.com Read the original article: MITRE Reveals Ivanti Breach By Nation State Actor

Alarming Decline in Cybersecurity Job Postings in the US

This drop represents a direct threat to US national cybersecurity infrastructure, said CyberSN representatives in their report This article has been indexed from www.infosecurity-magazine.com Read the original article: Alarming Decline in Cybersecurity Job Postings in the US

Quishing Attacks Jump Tenfold, Attachment Payloads Halve

The figures come from Egress’s latest report, which also suggests secure email gateways lag behind tech advancements This article has been indexed from www.infosecurity-magazine.com Read the original article: Quishing Attacks Jump Tenfold, Attachment Payloads Halve

Russia’s Sandworm Upgraded to APT44 by Google’s Mandiant

Mandiant has confirmed that Sandworm is responsible for many cyber-attacks against Ukraine has close ties with a Russian hacktivist group This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia’s Sandworm Upgraded to APT44 by Google’s Mandiant

Trust in Cyber Takes a Knock as CNI Budgets Flatline

Bridewell report reveals critical infrastructure firms are losing faith in their defensive tooling This article has been indexed from www.infosecurity-magazine.com Read the original article: Trust in Cyber Takes a Knock as CNI Budgets Flatline

North Korean Group Kimsuky Exploits DMARC and Web Beacons

Proofpoint confirmed Kimsuky has directly contacted foreign policy experts since 2023 through seemingly benign email conversations This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korean Group Kimsuky Exploits DMARC and Web Beacons

US Government and OpenSSF Partner on New SBOM Management Tool

OpenSSF, in collaboration with the US Government, has developed Protobom, a open source tool designed to simplify SBOM management for organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government and OpenSSF Partner on New SBOM…

Ivanti Patches Two Critical Avalanche Flaws in Major Update

Ivanti has fixed two critical vulnerabilities in its Avalanche MDM product which could lead to remote code execution This article has been indexed from www.infosecurity-magazine.com Read the original article: Ivanti Patches Two Critical Avalanche Flaws in Major Update

Microsoft Most Impersonated Brand in Phishing Scams

New Check Point data found Microsoft was impersonated in 38% of all brand phishing attacks in Q1 2024, up from 33% in Q4 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Most Impersonated Brand in…

Russia and Ukraine Top Inaugural World Cybercrime Index

An international team of researchers published the first-ever index ranking countries by cybercrime threat level This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia and Ukraine Top Inaugural World Cybercrime Index

Palo Alto Networks Zero-Day Flaw Exploited in Targeted Attacks

Designated CVE-2024-3400 and with a CVSS score of 10.0, the flaw enables unauthorized actors to execute arbitrary code on affected firewalls This article has been indexed from www.infosecurity-magazine.com Read the original article: Palo Alto Networks Zero-Day Flaw Exploited in Targeted…

FBI Warns of Massive Toll Services Smishing Scam

The Feds have received thousands of complaints about phishing texts from fake road toll collection services This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Warns of Massive Toll Services Smishing Scam

Apple Boosts Spyware Alerts For Mercenary Attacks

The revision points out companies like NSO Group, known for surveillance tools like Pegasus This article has been indexed from www.infosecurity-magazine.com Read the original article: Apple Boosts Spyware Alerts For Mercenary Attacks

New Android Espionage Campaign Spotted in India and Pakistan

A new cyber espionage campaign, called ‘eXotic Visit,’ targeted Android users in South Asia via seemingly legitimate messaging apps This article has been indexed from www.infosecurity-magazine.com Read the original article: New Android Espionage Campaign Spotted in India and Pakistan

Raspberry Robin Distributed Through Windows Script Files

Distribution vectors of the Raspberry Robin worm now include Windows Script Files (WSF) alongside other methods like USB drives This article has been indexed from www.infosecurity-magazine.com Read the original article: Raspberry Robin Distributed Through Windows Script Files

Threat Actors Game GitHub Search to Spread Malware

Checkmarx warns of GitHub search result manipulation designed to promote malicious repositories This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actors Game GitHub Search to Spread Malware

US Data Breach Reports Surge 90% Annually in Q1

The number of publicly reported data breaches and leaks grew 90% in the first three months of the year This article has been indexed from www.infosecurity-magazine.com Read the original article: US Data Breach Reports Surge 90% Annually in Q1

LG TV Vulnerabilities Expose 91,000 Devices

The issues identified permit unauthorized access to the TV’s root system by bypassing authorization mechanisms This article has been indexed from www.infosecurity-magazine.com Read the original article: LG TV Vulnerabilities Expose 91,000 Devices

US Claims to Have Recovered $1.4bn in COVID Fraud

The DoJ says it has seized $1.4bn and charged 3500 defendants in COVID fraud cases since 2021 This article has been indexed from www.infosecurity-magazine.com Read the original article: US Claims to Have Recovered $1.4bn in COVID Fraud

Microsoft Patches 150 Flaws Including Two Zero-Days

April’s Patch Tuesday saw fixes for 150 CVEs, including two being actively exploited in the wild This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Patches 150 Flaws Including Two Zero-Days