Category: www.infosecurity-magazine.com

France Accuses Azerbaijan of Online Manipulation Campaigns

VIGINUM reveals that Azerbaijan state propaganda is seeking to challenge French sovereignty in French overseas territories This article has been indexed from www.infosecurity-magazine.com Read the original article: France Accuses Azerbaijan of Online Manipulation Campaigns

Corrupted Word Files Fuel Sophisticated Phishing Campaign

A new phishing attack uses corrupted Word docs to bypass security, luring victims with fake payroll and HR emails This article has been indexed from www.infosecurity-magazine.com Read the original article: Corrupted Word Files Fuel Sophisticated Phishing Campaign

Crypto.com Launches Massive $2m Bug Bounty Program

Crypto.com has launched a massive $2m bug bounty program on HackerOne, the largest ever offered on the platform, to enhance platform security This article has been indexed from www.infosecurity-magazine.com Read the original article: Crypto.com Launches Massive $2m Bug Bounty Program

Russia Arrests Prominent Ransomware Operator

Mikhail Matveev, aka WazaWaka, had worked with several ransomware groups, including Babuk, Conti, Darkside, Hive and LockBit This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia Arrests Prominent Ransomware Operator

SmokeLoader Malware Campaign Targets Companies in Taiwan

SmokeLoader malware identified targeting Taiwanese firms via phishing, exploiting Microsoft Office vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: SmokeLoader Malware Campaign Targets Companies in Taiwan

Global Police Arrest 5500 in $400m Cyber-Fraud Crackdown

Interpol’s Operation Haechi V has led to the arrest of over 5500 individuals and seizure of $400m obtained via online fraud This article has been indexed from www.infosecurity-magazine.com Read the original article: Global Police Arrest 5500 in $400m Cyber-Fraud Crackdown

Bologna FC Hit By 200GB Data Theft and Ransom Demand

Bologna FC has revealed a ransomware attack, with data on players, fans and employees thought to have been stolen This article has been indexed from www.infosecurity-magazine.com Read the original article: Bologna FC Hit By 200GB Data Theft and Ransom Demand

Malicious PyPI Package Exposes Crypto Wallets to Infostealer Code

A malicious PyPI package “aiocpa,” that stole crypto wallet data via obfuscated code, has been removed after being reported by Reversing Labs researchers This article has been indexed from www.infosecurity-magazine.com Read the original article: Malicious PyPI Package Exposes Crypto Wallets…

GodLoader Malware Infects Thousands via Game Development Tools

A new cyber-attack technique uses Godot Engine to deploy undetectable malware via GodLoader, infecting more than 17,000 devices This article has been indexed from www.infosecurity-magazine.com Read the original article: GodLoader Malware Infects Thousands via Game Development Tools

Albanian Drug Smugglers Busted After Cops Decrypt Comms

European police have arrested 21 individuals linked to a violent Albanian gang after decrypting their Sky ECC communications This article has been indexed from www.infosecurity-magazine.com Read the original article: Albanian Drug Smugglers Busted After Cops Decrypt Comms

T-Mobile Claims Salt Typhoon Did Not Access Customer Data

The CSO of T-Mobile has clarified that no customer information was stolen by Chinese hacking group Salt Typhoon This article has been indexed from www.infosecurity-magazine.com Read the original article: T-Mobile Claims Salt Typhoon Did Not Access Customer Data

Pro-Russian Hacktivists Launch Branded Ransomware Operations

A pro-Russian hacktivist collective, CyberVolk, has launched its own ransomware-as-a-service operations, SentinelLabs has found This article has been indexed from www.infosecurity-magazine.com Read the original article: Pro-Russian Hacktivists Launch Branded Ransomware Operations

Over a Third of Firms Struggling With Shadow AI

Some 35% of global organizations report challenges monitoring use of non-approved AI tools This article has been indexed from www.infosecurity-magazine.com Read the original article: Over a Third of Firms Struggling With Shadow AI

UK Scam Losses Surge 50% Annually to £11.4bn

Cifas figures reveal scammers stole over £11bn from UK consumers in the past 12 months This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Scam Losses Surge 50% Annually to £11.4bn

IoT Device Traffic Up 18% as Malware Attacks Surge 400%

Zscaler’s latest report finds 54.5% of IoT attacks target manufacturing, with the industry suffering more than three times the weekly attacks of other sectors This article has been indexed from www.infosecurity-magazine.com Read the original article: IoT Device Traffic Up 18%…

Google Deindexes Chinese Propaganda Network

Google’s threat intelligence team uncovered four Chinese PR firms operating networks of inauthentic news sites This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Deindexes Chinese Propaganda Network

ICO Urges More Data Sharing to Tackle Fraud Epidemic

The UK’s Information Commissioner’s Office argues that regulatory concerns shouldn’t prevent firms sharing data to stop scams This article has been indexed from www.infosecurity-magazine.com Read the original article: ICO Urges More Data Sharing to Tackle Fraud Epidemic

Three-Quarters of Black Friday Spam Emails Identified as Scams

Bitdefender found that 77% of Black Friday-themed spam emails in 2024 have been identified as scams, with attackers becoming more creative in their campaigns This article has been indexed from www.infosecurity-magazine.com Read the original article: Three-Quarters of Black Friday Spam…

MITRE Unveils Top 25 Most Critical Software Flaws

The 25 most dangerous software weaknesses between June 2023 and June 2024 are responsible for almost 32,000 vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: MITRE Unveils Top 25 Most Critical Software Flaws

Five Ransomware Groups Responsible for 40% of Cyber-Attacks in 2024

Corvus Insurance highlighted the growing complexity and competition within the ransomware ecosystem, with the threat level remaining elevated This article has been indexed from www.infosecurity-magazine.com Read the original article: Five Ransomware Groups Responsible for 40% of Cyber-Attacks in 2024

Manufacturing Sector in the Crosshairs of Advanced Email Attacks

Phishing attacks, business email compromise and vendor email compromise attacks on manufacturing have surged in the past 12 months This article has been indexed from www.infosecurity-magazine.com Read the original article: Manufacturing Sector in the Crosshairs of Advanced Email Attacks

Lumma Stealer Proliferation Fueled by Telegram Activity

Spreading malware via Telegram channels allows threat actors to bypass traditional detection mechanisms and reach a broad, unsuspecting audience This article has been indexed from www.infosecurity-magazine.com Read the original article: Lumma Stealer Proliferation Fueled by Telegram Activity

BianLian Ransomware Group Adopts New Tactics, Posing Significant Risk

The BianLian ransomware group has shifted exclusively to exfiltration-based extortion and is deploying multiple new TTPs for initial access and persistence This article has been indexed from www.infosecurity-magazine.com Read the original article: BianLian Ransomware Group Adopts New Tactics, Posing Significant…

Linux Malware WolfsBane and FireWood Linked to Gelsemium APT

New Linux malware WolfsBane and FireWood have been linked to Gelsemium APT, a cyber-espionage group targeting critical systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Linux Malware WolfsBane and FireWood Linked to Gelsemium APT

Suspected Phobos Ransomware Admin Extradited to US

A Russian national suspected of involvement in Phobos ransomware has appeared in court in the US This article has been indexed from www.infosecurity-magazine.com Read the original article: Suspected Phobos Ransomware Admin Extradited to US

‘ClickFix’ Cyber-Attacks for Malware Deployment on the Rise

Proofpoint researchers have observed the growing use of the ClickFix social engineering tactic, which lures people into running malicious content on their computer This article has been indexed from www.infosecurity-magazine.com Read the original article: ‘ClickFix’ Cyber-Attacks for Malware Deployment on…

Swiss Cyber Agency Warns of QR Code Malware in Mail Scam

Switzerland’s National Cyber Security Centre has warned of a new QR code scam in fake MeteoSwiss letters spreading Android malware This article has been indexed from www.infosecurity-magazine.com Read the original article: Swiss Cyber Agency Warns of QR Code Malware in…

Fake Donald Trump Assassination Story Used in Phishing Scam

A phishing email claims to be from the New York Times with a story about an assassination attempt against President-elect Donald Trump This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Donald Trump Assassination Story Used in…

FTC Records 50% Drop in Nuisance Calls Since 2021

The US Federal Trade Commission is celebrating a halving of unwanted telemarketing and scam calls since 2021 This article has been indexed from www.infosecurity-magazine.com Read the original article: FTC Records 50% Drop in Nuisance Calls Since 2021

UK Shoppers Lost £11.5m Last Christmas, NCSC Warns

The UK’s National Cyber Security Centre is urging shoppers to stay safe this Christmas after revealing they lost £11.5m to fraudsters in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Shoppers Lost £11.5m Last Christmas,…

NCSC Warns UK Shoppers Lost £11.5m Last Christmas

The UK’s National Cyber Security Centre is urging shoppers to stay safe this Christmas after revealing they lost £11.5m to fraudsters in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Warns UK Shoppers Lost £11.5m…

watchTowr Finds New Zero-Day Vulnerability in Fortinet Products

The new vulnerability was named “FortiJump Higher” due to its similarity with the “FortiJump” vulnerability discovered in October This article has been indexed from www.infosecurity-magazine.com Read the original article: watchTowr Finds New Zero-Day Vulnerability in Fortinet Products

Microsoft Power Pages Misconfiguration Leads to Data Exposure

Misconfigurations in Microsoft Power Pages granting excessive access permissions expose sensitive data, risking PII to unauthorized users This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Power Pages Misconfiguration Leads to Data Exposure

Sitting Ducks DNS Attacks Put Global Domains at Risk

Over 1 million domains are vulnerable to “Sitting Ducks” attack, which exploits DNS misconfigurations This article has been indexed from www.infosecurity-magazine.com Read the original article: Sitting Ducks DNS Attacks Put Global Domains at Risk

API Security in Peril as 83% of Firms Suffer Incidents

Over 80% of UK organizations suffered an API security incident in the past year, with each costing over £400,000 This article has been indexed from www.infosecurity-magazine.com Read the original article: API Security in Peril as 83% of Firms Suffer Incidents

Bank of England U-turns on Vulnerability Disclosure Rules

The UK’s financial regulators have discarded plans to force critical suppliers to disclose new vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Bank of England U-turns on Vulnerability Disclosure Rules

AI Threat to Escalate in 2025, Google Cloud Warns

2025 could see our biggest AI fears materialize, according to a Google Cloud forecast report This article has been indexed from www.infosecurity-magazine.com Read the original article: AI Threat to Escalate in 2025, Google Cloud Warns

Amazon MOVEit Leaker Claims to Be Ethical Hacker

An individual who posted data allegedly stolen via MOVEit from Amazon and other big-name firms claims not to be malicious This article has been indexed from www.infosecurity-magazine.com Read the original article: Amazon MOVEit Leaker Claims to Be Ethical Hacker

Phishing Tool GoIssue Targets Developers on GitHub

New phishing tool GoIssue targets GitHub, enabling mass phishing, and has been linked to the GitLoker extortion campaign This article has been indexed from www.infosecurity-magazine.com Read the original article: Phishing Tool GoIssue Targets Developers on GitHub

New Citrix Zero-Day Vulnerability Allows Remote Code Execution

watchTowr has found a flaw in Citrix’s Session Recording Manager that can be exploited to enable unauthenticated RCE against Citrix Virtual Apps and Desktops This article has been indexed from www.infosecurity-magazine.com Read the original article: New Citrix Zero-Day Vulnerability Allows…

North Korea Hackers Leverage Flutter to Deliver macOS Malware

Jamf observed North Korean attackers embedding malware within Flutter applications to target macOS devices, potentially to test a new way of weaponizing malware This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korea Hackers Leverage Flutter to…

New Remcos RAT Variant Targets Windows Users Via Phishing

The new Remcos RAT variant identified in a new phishing campaign exploits CVE-2017-0199 via malicious Excel files This article has been indexed from www.infosecurity-magazine.com Read the original article: New Remcos RAT Variant Targets Windows Users Via Phishing

Pensioners Warned Over Winter Fuel Payment Scam Texts

The UK Regional Organised Crime Unit (ROCU) Network has urged the elderly to be on the lookout for scam texts offering a winter fuel subsidy This article has been indexed from www.infosecurity-magazine.com Read the original article: Pensioners Warned Over Winter…

Man Gets 12.5 Years for Running Bitcoin Fog Crypto Mixer

Swedish-Russian national Roman Sterlingov has been jailed for 12 years and six months for operating notorious cryptocurrency mixer Bitcoin Fog This article has been indexed from www.infosecurity-magazine.com Read the original article: Man Gets 12.5 Years for Running Bitcoin Fog Crypto…

Major Oilfield Supplier Hit by Ransomware Attack

International energy solution provider Newpark Resources has confirmed it was hit by a ransomware attack that disrupted critical systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Major Oilfield Supplier Hit by Ransomware Attack

North Korean Actor Deploys Novel Malware Campaign Against Crypto Firms

SentinelLabs observed the North Korean group BlueNoroff targeting crypto firms via a multi-stage malware campaign which utilizes a novel persistence mechanism This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korean Actor Deploys Novel Malware Campaign Against…

NCSC Publishes Tips to Tackle Malvertising Threat

The UK’s National Cyber Security Centre has released malvertising guidance for brands and their ad partners This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Publishes Tips to Tackle Malvertising Threat

Defenders Outpace Attackers in AI Adoption

Trend Micro’s Robert McArdle says cybercriminals use of AI is far more limited than many realize, and pales in comparison to defenders’ use of the technology This article has been indexed from www.infosecurity-magazine.com Read the original article: Defenders Outpace Attackers…

Winos4.0 Malware Found in Game Apps, Targets Windows Users

Winos4.0 malware, derived from Gh0strat, targets Windows users via game-related applications, enabling remote control of affected systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Winos4.0 Malware Found in Game Apps, Targets Windows Users

Massive Nigerian Cybercrime Bust Sees 130 Arrested

The Nigerian police have arrested 113 foreign individuals and their 17 Nigerian collaborators for their alleged involvement in high-level cybercrimes This article has been indexed from www.infosecurity-magazine.com Read the original article: Massive Nigerian Cybercrime Bust Sees 130 Arrested

Google Cloud to Mandate Multifactor Authentication by 2025

Google wants to ensure a smooth transition towards required MFA across all Google Cloud accounts with a phased rollout running throughout 2025 This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Cloud to Mandate Multifactor Authentication by…