Category: www.infosecurity-magazine.com

New APT CloudSorcerer Malware Hits Russian Targets

The malware issues commands via a hardcoded charcode table and Microsoft COM object interfaces This article has been indexed from www.infosecurity-magazine.com Read the original article: New APT CloudSorcerer Malware Hits Russian Targets

Cisco Warns regreSSHion Vulnerability Impacts Multiple Products

Cisco has told customers that 42 of its products are impacted by the OpenSSH regreSSHion vulnerability, with a further 51 products being investigated This article has been indexed from www.infosecurity-magazine.com Read the original article: Cisco Warns regreSSHion Vulnerability Impacts Multiple…

Russia Blocks VPN Services in Information Crackdown

The ban comes from Russian communication watchdog Roskomnadzor, likely in a bid to control the flow of information to Russian citizens This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia Blocks VPN Services in Information Crackdown

Crypto Thefts Double to $1.4 Billion, TRM Labs Finds

Higher average token prices are the likely cause of the surge rather than a change in the crypto threat landscape This article has been indexed from www.infosecurity-magazine.com Read the original article: Crypto Thefts Double to $1.4 Billion, TRM Labs Finds

10 Billion Passwords Leaked on Hacking Forum

A Cybernews investigation found that nearly 10 billion unique passwords have been posted on a popular hacking forum, putting users worldwide at risk of account compromises This article has been indexed from www.infosecurity-magazine.com Read the original article: 10 Billion Passwords…

Vinted Fined €2.3m Over Data Protection Failure

The Lithuanian data protection authority has imposed a fine of almost $2.5m on second-hand specialist Vinted for breaching GDPR This article has been indexed from www.infosecurity-magazine.com Read the original article: Vinted Fined €2.3m Over Data Protection Failure

Gamers’ Data Exposed in RPG Platform Roll20 Breach

Roll20 confirmed its administrative website account was accessed by a “bad actor,” leaving its users’ personal information exposed This article has been indexed from www.infosecurity-magazine.com Read the original article: Gamers’ Data Exposed in RPG Platform Roll20 Breach

New Ransomware Group Phones Execs to Extort Payment

Researchers claim the Volcano Demon ransomware group personally phone victims to pressure them into paying This article has been indexed from www.infosecurity-magazine.com Read the original article: New Ransomware Group Phones Execs to Extort Payment

UK’s NCA Leads Major Cobalt Strike Takedown

Global law enforcers have share intelligence leading to the takedown of hundreds of IP addresses hosting Cobalt Strike This article has been indexed from www.infosecurity-magazine.com Read the original article: UK’s NCA Leads Major Cobalt Strike Takedown

Cyber Extortion Soars: SMBs Hit Four Times Harder

Orange Cyberdefense’s latest Cy-Xplorer report shows a 77% rise in cyber extortion, with SMBs impacted 4.2 times more often than large enterprises This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Extortion Soars: SMBs Hit Four Times…

APP Fraud Singled Out as Biggest Financial Crime Threat

Payments professionals have highlighted authorized push payment (APP) fraud as the top threat facing businesses and consumers This article has been indexed from www.infosecurity-magazine.com Read the original article: APP Fraud Singled Out as Biggest Financial Crime Threat

Dozens of Arrests Disrupt €2.5m Vishing Gang

Police have arrested 54 suspected members of a vishing group who stole the life savings of scores of victims This article has been indexed from www.infosecurity-magazine.com Read the original article: Dozens of Arrests Disrupt €2.5m Vishing Gang

Ransomware Attack Demands Reach a Staggering $5.2m in 2024

Comparitech calculated that the average ransom demand was over $5.2m in the first six months of 2024, with 421 confirmed incidents during this period This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Attack Demands Reach a…

Health Tech Execs Get Jail Time For $1bn Fraud Scheme

The former CEO and COO of a health startup will spend years in jail after conducting a large-scale fraud scheme This article has been indexed from www.infosecurity-magazine.com Read the original article: Health Tech Execs Get Jail Time For $1bn Fraud…

Meta’s ‘Pay or Consent’ Data Model Breaches EU Law

The EU Commission said Meta’s pay or consent model means users cannot freely consent to their personal data being collected for advertising purposes This article has been indexed from www.infosecurity-magazine.com Read the original article: Meta’s ‘Pay or Consent’ Data Model…

Critical OpenSSH Flaw Enables Full System Compromise

A newly discovered RCE vulnerability, which can lead to full system compromise, has put over 14 million OpenSSH server instances are potentially at risk, according to Qualys This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical OpenSSH…

Google Thwarts Over 10,000 Attempts by Chinese Influence Operator

Google warned of high levels of activity from Chinese influence operator Dragon Bridge, which is increasingly experimenting with generative AI tools to create content This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Thwarts Over 10,000 Attempts…

Majority of Critical Open Source Projects Contain Memory Unsafe Code

A CISA analysis in collaboration with international partners concluded most critical open source projects potentially contain memory safety vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Majority of Critical Open Source Projects Contain Memory Unsafe Code

US Charges Russian Individual for Pre-Invasion Ukraine Hack

The US government is offering up to $10m for information on Amin Timovich Stigal’s location or his malicious cyber activity This article has been indexed from www.infosecurity-magazine.com Read the original article: US Charges Russian Individual for Pre-Invasion Ukraine Hack

IT Leaders Split on Using GenAI For Cybersecurity

Corelight study claims many IT leaders see benefit of GenAI but similar share are concerned about data exposure This article has been indexed from www.infosecurity-magazine.com Read the original article: IT Leaders Split on Using GenAI For Cybersecurity

Progress Discloses Two New Vulnerabilities in MOVEit Products

Two authentication bypass vulnerabilities affect Progress Software’s MOVEit Transfer SFTP service in a default configuration and MOVEit Gateway This article has been indexed from www.infosecurity-magazine.com Read the original article: Progress Discloses Two New Vulnerabilities in MOVEit Products

Novel Banking Malware Targets Customers in Southeast Asia

A novel malware strain, Snowblind, bypasses security measures in banking apps on Android, leading to financial losses and fraud, according to Promon This article has been indexed from www.infosecurity-magazine.com Read the original article: Novel Banking Malware Targets Customers in Southeast…

Cyber Attackers Turn to Cloud Services to Deploy Malware

A growing number of malware operators have turned to cloud-based command and control servers to deploy malicious campaigns, Fortinet researchers found This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Attackers Turn to Cloud Services to Deploy…

Fake Law Firms Con Victims of Crypto Scams, Warns FBI

The FBI has urged cryptocurrency scam victims to be on the alert for fraudsters posing as lawyers This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Law Firms Con Victims of Crypto Scams, Warns FBI

Dark Web Sees 230% Rise in Singapore Identity Theft

According to Resecurity, a significant portion of the stolen data was found on the XSS underground forum This article has been indexed from www.infosecurity-magazine.com Read the original article: Dark Web Sees 230% Rise in Singapore Identity Theft

Cloud Breaches Impact Nearly Half of Organizations

A Thales report found that 44% of organizations have experienced a cloud data breach, with human error and misconfigurations the leading root causes This article has been indexed from www.infosecurity-magazine.com Read the original article: Cloud Breaches Impact Nearly Half of…

Modular Malware Boolka’s BMANAGER Trojan Exposed

The group has been observed exploiting vulnerabilities through SQL injection attacks since 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: Modular Malware Boolka’s BMANAGER Trojan Exposed

China-Based RedJuliett Targets Taiwan in Cyber Espionage Campaign

The likely Chinese state-sponsored group ran espionage campaigns against Taiwan’s government, academia and diplomacy from Fuzhou, China This article has been indexed from www.infosecurity-magazine.com Read the original article: China-Based RedJuliett Targets Taiwan in Cyber Espionage Campaign

US Bans Kaspersky Over Alleged Kremlin Links

Kaspersky “poses an undue or unacceptable risk to national security,” according to the US Commerce Department’s Bureau of Industry and Security This article has been indexed from www.infosecurity-magazine.com Read the original article: US Bans Kaspersky Over Alleged Kremlin Links

Synnovis Attackers Publish NHS Patient Data Online

Ransomware group Qilin has reportedly published nearly 400GB of data stolen following the attack on NHS provider Synnovis in early June This article has been indexed from www.infosecurity-magazine.com Read the original article: Synnovis Attackers Publish NHS Patient Data Online

LockBit Most Prominent Ransomware Actor in May 2024

The LockBit ransomware group returned the fold to launch 176 attacks in May 2024 following a law enforcement takedown, NCC Group found This article has been indexed from www.infosecurity-magazine.com Read the original article: LockBit Most Prominent Ransomware Actor in May…

Threat Actor Claims AMD and Apple Breaches

Notorious threat actor IntelBroker is claiming to have stolen data from Apple and AMD This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actor Claims AMD and Apple Breaches

G7 to Develop Cybersecurity Framework for Energy Sector

The G7 nations agree to develop a cybersecurity framework for key technologies used to operate electricity, oil and natural gas systems This article has been indexed from www.infosecurity-magazine.com Read the original article: G7 to Develop Cybersecurity Framework for Energy Sector

Cybersecurity Burnout Costing Firms $700m+ Annually

Hack The Box research claims employee burnout could be costing hundreds of millions in lost productivity This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybersecurity Burnout Costing Firms $700m+ Annually

Fake Meeting Software Spreads macOS Infostealer

Recorded Future has found that Vortax, a purported virtual meeting software, is actually malicious software spreading three information stealers This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Meeting Software Spreads macOS Infostealer

VMware Discloses Critical Vulnerabilities, Urges Immediate Remediation

VMware has disclosed critical vulnerabilities impacting its VMware vSphere and VMware Cloud Foundation products, with patches available for customers This article has been indexed from www.infosecurity-magazine.com Read the original article: VMware Discloses Critical Vulnerabilities, Urges Immediate Remediation

Quarter of Firms Suffer an API-Related Breach

Salt Security study finds 23% of organizations suffered a breach via production APIs in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Quarter of Firms Suffer an API-Related Breach

Los Angeles Public Health Department Discloses Large Data Breach

Los Angeles County Department of Public Health revealed a data breach impacting more than 200,000 individuals, with personal, medical and financial data potentially stolen This article has been indexed from www.infosecurity-magazine.com Read the original article: Los Angeles Public Health Department…

Meta Pauses European GenAI Development Over Privacy Concerns

Meta has delayed plans to train its LLMs using public content shared by adults on Facebook and Instagram following a request by Ireland’s data protection regulator This article has been indexed from www.infosecurity-magazine.com Read the original article: Meta Pauses European…

Ascension Attack Caused by Employee Downloading Malicious File

Healthcare firm Ascension said that ransomware attackers gained access to its systems after an employee accidently downloaded a malicious file This article has been indexed from www.infosecurity-magazine.com Read the original article: Ascension Attack Caused by Employee Downloading Malicious File

Cyber Insurance Claims Hit Record High in North America

Insurance firm Marsh received over 1800 cyber claim reports from clients in the US and Canada in 2023, higher than any other year This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Insurance Claims Hit Record High…

Chinese Hackers Leveraging ‘Noodle RAT’ Backdoor

The ELF backdoor, initially thought to be a variant of existing malware, has a Windows and a Linux version This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese Hackers Leveraging ‘Noodle RAT’ Backdoor

Chinese FortiGate Espionage Campaign Snares 20,000+ Victims

Dutch authorities reveal that a cyber-espionage campaign using novel “Coathanger” malware was much more extensive than first thought This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese FortiGate Espionage Campaign Snares 20,000+ Victims

Threat Actor Breaches Snowflake Customers, Victims Extorted

Mandiant warns that a financially-motivated threat actor stole a significant volume of customer data from Snowflake, and is extorting many of the victims This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actor Breaches Snowflake Customers, Victims…

NVIDIA and Arm Urge Customers to Patch Bugs

Chip giants NVIDIA and Arm have released details of new vulnerabilities including a zero-day bug This article has been indexed from www.infosecurity-magazine.com Read the original article: NVIDIA and Arm Urge Customers to Patch Bugs

EmailGPT Exposed to Prompt Injection Attacks

The flaw enables attackers to gain control over the AI service by submitting harmful prompts This article has been indexed from www.infosecurity-magazine.com Read the original article: EmailGPT Exposed to Prompt Injection Attacks