Category: www.infosecurity-magazine.com

#BHUSA: Nation-State Attacks Target Hardware Supply Chains

New report warns of escalating hardware supply chain attacks, with 19% of organizations impacted and nearly all IT leaders expecting nation-state involvement This article has been indexed from www.infosecurity-magazine.com Read the original article: #BHUSA: Nation-State Attacks Target Hardware Supply Chains

US Sues TikTok For Children’s Law Violations

The US government is taking TikTok to court for alleged violations of the COPPA regulation This article has been indexed from www.infosecurity-magazine.com Read the original article: US Sues TikTok For Children’s Law Violations

EPA Told to Address Cyber Risks to Water Systems

The US Government Accountability Office has told the Environmental Protection Agency to urgently develop a strategy to tackle rising cyber-threats to the water industry This article has been indexed from www.infosecurity-magazine.com Read the original article: EPA Told to Address Cyber…

Gaming Industry Faces 94% Surge in DDoS Attacks

The rise in DDOS attacks against the gaming industry is accompanied by increasing bot activity This article has been indexed from www.infosecurity-magazine.com Read the original article: Gaming Industry Faces 94% Surge in DDoS Attacks

Cencora Confirms Patient Data Stolen in Cyber-Attack

Pharma company Cencora confirmed in an updated SEC filing that sensitive personal and health data was exfiltrated by attackers in a February 2024 incident This article has been indexed from www.infosecurity-magazine.com Read the original article: Cencora Confirms Patient Data Stolen…

E-Commerce Fraud Campaign Uses 600+ Fake Sites

The “Eriakos” info-stealing campaign is using hundreds of fake web shops to defraud victims This article has been indexed from www.infosecurity-magazine.com Read the original article: E-Commerce Fraud Campaign Uses 600+ Fake Sites

Urgent Blood Appeal Issued in US After Ransomware Attack

US non-profit OneBlood has issued an urgent appeal for donations after a ransomware attack has significantly reduced its capacity to distribute blood to hospitals This article has been indexed from www.infosecurity-magazine.com Read the original article: Urgent Blood Appeal Issued in…

New PyPI Package Zlibxjson Steals Discord, Browser Data

According to Fortinet, PyPI package Zlibxjson steals Discord tokens and browser data, including passwords and extensive user information This article has been indexed from www.infosecurity-magazine.com Read the original article: New PyPI Package Zlibxjson Steals Discord, Browser Data

DDoS Attack Triggers New Microsoft Global Outage

A global outage of Microsoft services was triggered by a DDoS attack, with an error Microsoft’s DDoS protection measures amplifying the impact This article has been indexed from www.infosecurity-magazine.com Read the original article: DDoS Attack Triggers New Microsoft Global Outage

Stolen GenAI Accounts Flood Dark Web With 400 Daily Listings

According to eSentire, around 400 GenAI account logins are sold daily on the dark web, including credentials for GPT, Quillbot, Notion and Replit This article has been indexed from www.infosecurity-magazine.com Read the original article: Stolen GenAI Accounts Flood Dark Web…

ICO Slams Electoral Commission for Basic Security Failings

The ICO found that the Electoral Commission did not have appropriate security measures in place, allowing hackers to access the personal details of 40 million UK voters This article has been indexed from www.infosecurity-magazine.com Read the original article: ICO Slams…

HealthEquity Breach Hits 4.3 Million Customers

Health savings specialist HealthEquity reveals over four million customers were impacted in a recent breach This article has been indexed from www.infosecurity-magazine.com Read the original article: HealthEquity Breach Hits 4.3 Million Customers

US Crypto Exchange Gemini Reveals Breach

Thousands of customers of cryptocurrency exchange Gemini have had personal data compromised This article has been indexed from www.infosecurity-magazine.com Read the original article: US Crypto Exchange Gemini Reveals Breach

Hacktivists Claim Leak of CrowdStrike Threat Intelligence

CrowdStrike has acknowledged the claims by the USDoD hacktivist group, which has provided a link to download the alleged threat actor list on a cybercrime forum This article has been indexed from www.infosecurity-magazine.com Read the original article: Hacktivists Claim Leak…

Despite Bans, AI Code Tools Widespread in Organizations

Despite bans on AI code generation tools, widespread use and lack of governance are creating significant security risks for organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: Despite Bans, AI Code Tools Widespread in Organizations

Ransomware and BEC Make Up 60% of Cyber Incidents

Cisco Talos found that ransomware and BEC accounted for 60% of all cyber incidents in Q2 2024, with ransomware rising by 22% compared to Q1 This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware and BEC Make…

Malware Attacks Surge 30% in First Half of 2024

SonicWall observed a surge in malware attacks in H1 2024, with strains becoming more adept at defense evasion This article has been indexed from www.infosecurity-magazine.com Read the original article: Malware Attacks Surge 30% in First Half of 2024

Most IT Leaders Say Severity of Cyber-Attacks has Increased

Appsbroker CTS found that nine in 10 IT leaders believe the severity of cyber-attacks has increased over the past year This article has been indexed from www.infosecurity-magazine.com Read the original article: Most IT Leaders Say Severity of Cyber-Attacks has Increased

Google Criticized for Abandoning Cookie Phase-Out

Google’s decision to abandon the phase out of third-party cookies on Chrome has been criticized, with the tech giant accused of neglecting user privacy This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Criticized for Abandoning Cookie…

Prolific DDoS Marketplace Shut Down by UK Law Enforcement

The UK’s National Crime Agency has infiltrated the DigitalStress marketplace, which offers DDoS capabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Prolific DDoS Marketplace Shut Down by UK Law Enforcement

Cybercriminals Exploit CrowdStrike Outage Chaos

Cybercriminals have launched phishing campaigns purporting to support organizations impacted by the global IT outage, caused by a CrowdStrike Falcon issue This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybercriminals Exploit CrowdStrike Outage Chaos

Two Russians Convicted for Role in LockBit Attacks

Two Russian nationals have pleaded guilty to charges relating to their participation in the LockBit ransomware gang This article has been indexed from www.infosecurity-magazine.com Read the original article: Two Russians Convicted for Role in LockBit Attacks

Sunburst: US Judge Dismisses Most SEC Charges Against SolarWinds

The SEC allegations against SolarWinds and its CISO over statements made after the 2020 ‘Sunburst’ hack were based on “hindsight and speculation,” said the judge This article has been indexed from www.infosecurity-magazine.com Read the original article: Sunburst: US Judge Dismisses…

CrowdStrike Fault Causes Global IT Outages

An issue related to an update to CrowdStrike’s security platform Falcon Sensor has impacted Microsoft Windows Operating Systems, causing global IT outages This article has been indexed from www.infosecurity-magazine.com Read the original article: CrowdStrike Fault Causes Global IT Outages

Nearly 13 Million Australians Affected by MediSecure Attack

MediSecure revealed that the personal and health data of approximately 12.9 million Australians has been affected by the May 2024 attack This article has been indexed from www.infosecurity-magazine.com Read the original article: Nearly 13 Million Australians Affected by MediSecure Attack

US Data Breach Victim Numbers Surge 1170% Annually

New figures reveal a massive 1170% increase in people impacted by data breaches in Q2 2024 versus a year ago This article has been indexed from www.infosecurity-magazine.com Read the original article: US Data Breach Victim Numbers Surge 1170% Annually

ICO Reprimands London Council for Mass Data Breach

The ICO said a lack of security controls led to a large-scale data breach at the London Borough of Hackney Council This article has been indexed from www.infosecurity-magazine.com Read the original article: ICO Reprimands London Council for Mass Data Breach

Understanding NullBulge, the New AI-Fighting ‘Hacktivist’ Group

The threat actor who claimed the recent Disney hack previously targeted AI-centric games and applications with commodity malware and ransomware This article has been indexed from www.infosecurity-magazine.com Read the original article: Understanding NullBulge, the New AI-Fighting ‘Hacktivist’ Group

Paris 2024 Olympics Face Escalating Cyber-Threats

Fortinet observed an 80-90% increase in darknet activity targeting the Olympics between 2023 and 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: Paris 2024 Olympics Face Escalating Cyber-Threats

Sensitive Data Sharing Risks Heightened as GenAI Surges

Netskope found that 96% of organizations use generative AI applications, with sensitive data frequently shared with these tools This article has been indexed from www.infosecurity-magazine.com Read the original article: Sensitive Data Sharing Risks Heightened as GenAI Surges

Global Police Swoop on Black Axe Cybercrime Syndicate

Interpol claims hundreds of arrests were made as police disrupted the West African Black Axe cybercrime gang This article has been indexed from www.infosecurity-magazine.com Read the original article: Global Police Swoop on Black Axe Cybercrime Syndicate

CISA: Patch Critical GeoServer GeoTools Bug Now

CISA has told federal agencies to patch a critical GeoServer GeoTools vulnerability under active exploitation This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA: Patch Critical GeoServer GeoTools Bug Now

MHTML Exploited By APT Group Void Banshee

Void Banshee targeted North American, European and Southeast Asian regions with the Atlantida stealer This article has been indexed from www.infosecurity-magazine.com Read the original article: MHTML Exploited By APT Group Void Banshee

Hacktivists Claim Leak Over 1 Terabyte of Disney Data

Disney unreleased projects and internal data are part of a data leak claimed by hacktivist group ‘NullBulge’ This article has been indexed from www.infosecurity-magazine.com Read the original article: Hacktivists Claim Leak Over 1 Terabyte of Disney Data

Half of SMEs Unprepared for Cyber-Threats

JumpCloud found that half of SME IT teams believe they lack the resources and staffing to defend their organization against cyber-threats This article has been indexed from www.infosecurity-magazine.com Read the original article: Half of SMEs Unprepared for Cyber-Threats

Kaspersky to Quit US This Weekend

Russian AV-maker Kaspersky is set to shutter its US operations from Saturday This article has been indexed from www.infosecurity-magazine.com Read the original article: Kaspersky to Quit US This Weekend

Attackers Exploit URL Protections to Disguise Phishing Links

Barracuda has observed attackers using three different URL protection services to mask their phishing URLs, bypassing email security tools This article has been indexed from www.infosecurity-magazine.com Read the original article: Attackers Exploit URL Protections to Disguise Phishing Links

Pharmacy Giant Rite Aid Hit By Ransomware

US pharmacy chain Rite Aid has confirmed a cybersecurity ‘incident’ in June This article has been indexed from www.infosecurity-magazine.com Read the original article: Pharmacy Giant Rite Aid Hit By Ransomware

Indiana County Files Disaster Declaration Following Ransomware Attack

Clay County, Indiana, said a ransomware attack has prevented the administration of critical services, leading to a disaster declaration being filed This article has been indexed from www.infosecurity-magazine.com Read the original article: Indiana County Files Disaster Declaration Following Ransomware Attack

NATO Set to Build New Cyber Defense Center

NATO members have agreed to develop a new integrated facility to help improve collective cyber-resilience This article has been indexed from www.infosecurity-magazine.com Read the original article: NATO Set to Build New Cyber Defense Center

Fraud Campaign Targets Russians with Fake Olympics Tickets

Operation Ticket Heist involves 700 web domains to sell fake Olympic Games tickets to a Russian-speaking audience, QuoIntelligence has found This article has been indexed from www.infosecurity-magazine.com Read the original article: Fraud Campaign Targets Russians with Fake Olympics Tickets

Smishing Triad Targets India with Fraud Surge

Smishing Triad’s MO involves registering fraudulent domain names that mimic legitimate organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: Smishing Triad Targets India with Fraud Surge

Ransomware Groups Prioritize Defense Evasion for Data Exfiltration

A Cisco report highlighted TTPs used by the most prominent ransomware groups to evade detection, establish persistence and exfiltrate sensitive data This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Groups Prioritize Defense Evasion for Data Exfiltration

Most Security Pros Admit Shadow SaaS and AI Use

Next DLP study finds majority of security professionals have used unauthorised apps in past year This article has been indexed from www.infosecurity-magazine.com Read the original article: Most Security Pros Admit Shadow SaaS and AI Use

Microsoft Fixes Four Zero-Days in July Patch Tuesday

Microsoft has addressed two actively exploited and two publicly disclosed zero-day bugs this month This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Fixes Four Zero-Days in July Patch Tuesday

Avast Provides DoNex Ransomware Decryptor to Victims

Researchers at Avast found a flaw in the cryptographic schema of the DoNex ransomware and have been sending out decryptor keys to victims since March 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: Avast Provides DoNex…