Category: www.infosecurity-magazine.com

#Infosec2024: How to Develop Your Future Team

Expert panel advises CISOs to look beyond pay and at career progression and work-life balance to fill skills gaps This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: How to Develop Your Future Team

New Multi-Stage Malware Targets Windows Users in Ukraine

Discovered by FortiGuard Labs, the attack leverages an Excel file embedded with a VBA macro This article has been indexed from www.infosecurity-magazine.com Read the original article: New Multi-Stage Malware Targets Windows Users in Ukraine

#Infosec24: Deepfake Expert Warns of “AI Tax Havens”

Keynote speaker Henry Ajder warns that regulatory measures may be undermined if some countries ignore global rules This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec24: Deepfake Expert Warns of “AI Tax Havens”

#Infosec2024: Conflicts Drive DDoS Attack Surge in EMEA

Akamai research found DDoS attacks in EMEA surpassed North America in Q1 2024, with ongoing conflicts helping driving a surge of incidents in the region This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: Conflicts Drive DDoS…

Ransomware Rises Despite Law Enforcement Takedowns

Ransomware activity rose in 2023, partly fueled by new groups and partnerships between groups, Mandiant has observed This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Rises Despite Law Enforcement Takedowns

Ransomware Rises Amid Law Enforcement Takedowns

Ransomware activity rose in 2023, partly fueled by new groups and partnerships between groups, Mandiant has observed This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Rises Amid Law Enforcement Takedowns

UK School Forced to Close Following Cyber-Attack

The Billericay School in Essex informed parents that it is closed to students after its IT systems were compromised and made inaccessible by a cyber-attack This article has been indexed from www.infosecurity-magazine.com Read the original article: UK School Forced to…

BBC Pension Scheme Breached, Exposing Employee Data

The BBC said that personally identifiable information of current and former employees has been breached following an incident affecting its pension scheme This article has been indexed from www.infosecurity-magazine.com Read the original article: BBC Pension Scheme Breached, Exposing Employee Data

#Infosec2024: Why Cybersecurity is Critical for the 2024 Paris Olympics

The large volume of attendees mixed with interconnected infrastructure provides opportunities for threat actors to wreak havoc during the Paris Olympics This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: Why Cybersecurity is Critical for the 2024…

Europol-Led Operation Endgame Hits Botnet, Ransomware Networks

The operation targeted several significant malware droppers, including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee This article has been indexed from www.infosecurity-magazine.com Read the original article: Europol-Led Operation Endgame Hits Botnet, Ransomware Networks

US-Led Operation Takes Down World’s Largest Botnet

A global law enforcement operation has disrupted the 911 S5 botnet, a global network of compromised devices used to facilitate criminal activity This article has been indexed from www.infosecurity-magazine.com Read the original article: US-Led Operation Takes Down World’s Largest Botnet

#Infosec2024: Why Credential-Based Attacks Need Modern Solutions

1Password’s Steve Won discusses why modern security solutions, such as passkeys, can substantially reduce the risk of credential-based attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: Why Credential-Based Attacks Need Modern Solutions

Advance Fee Fraud Targets Colleges With Free Piano Offers

Proofpoint discovered over 125,000 emails linked to this scam cluster in the past year This article has been indexed from www.infosecurity-magazine.com Read the original article: Advance Fee Fraud Targets Colleges With Free Piano Offers

Internet Archive Disrupted by Sustained and “Mean” DDoS Attack

The Internet Archive said sustained DDoS attacks have disrupted access to its preserved web pages and other historical archives This article has been indexed from www.infosecurity-magazine.com Read the original article: Internet Archive Disrupted by Sustained and “Mean” DDoS Attack

New North Korean Hacking Group Identified by Microsoft

Moonstone Sleet is a newly observed threat group targeting companies for financial and cyber espionage objectives This article has been indexed from www.infosecurity-magazine.com Read the original article: New North Korean Hacking Group Identified by Microsoft

#Infosec2024: Decoding SentinelOne’s AI Threat Hunting Assistant

SentinelOne will present a threat-hunting demonstration during which a security analyst will compete against a non-technical person using its AI assistant This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: Decoding SentinelOne’s AI Threat Hunting Assistant

Check Point Urges VPN Configuration Review Amid Attack Spike

These attacks did not exploit a vulnerability but instead leveraged weaker authentication methods This article has been indexed from www.infosecurity-magazine.com Read the original article: Check Point Urges VPN Configuration Review Amid Attack Spike

TeaBot Banking Trojan Activity on the Rise, Zscaler Observes

Researchers from Zscaler ThreatLabz observed an uptick in the TeaBot Andoird banking Trojan, also known as Anatsa This article has been indexed from www.infosecurity-magazine.com Read the original article: TeaBot Banking Trojan Activity on the Rise, Zscaler Observes

Courtroom Recording Software Vulnerable to Backdoor Attacks

Rapid7 warned that users of Justice AV Solutions (JAVS) Viewer v8.3.7 recording software are at high risk of stolen credentials and having malware installed This article has been indexed from www.infosecurity-magazine.com Read the original article: Courtroom Recording Software Vulnerable to…

#Infosec2024: What to Expect at Infosecurity Europe 2024

Get ready for Infosecurity Europe 2024 with these top five picks from Infosecurity Magazine to help you plan your visit This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: What to Expect at Infosecurity Europe 2024

#Infosec2024: Charity Bridges Digital Divide and Fuels New Cyber Talent

Every Child Online, a UK charity, tackles the digital divide and potential cybersecurity skills gap by offering free refurbished IT equipment to underprivileged children This article has been indexed from www.infosecurity-magazine.com Read the original article: #Infosec2024: Charity Bridges Digital Divide…

Fake Pegasus Spyware Strains Populate Clear and Dark Web

Actors in the clear and dark web are distributing fake source codes of the Pegasus spyware for financial gain This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Pegasus Spyware Strains Populate Clear and Dark Web

Cybercriminals Exploit Cloud Storage For SMS Phishing Scams

According to Enea, these campaigns use cloud storage platforms to host malicious websites, sending links via SMS to bypass firewalls This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybercriminals Exploit Cloud Storage For SMS Phishing Scams

Indian Election Faces Cyber-Attacks, Data Leaks on Dark Web

Resecurity reported a 300% spike in cyber-attacks post-#OpIsrael, intensifying since #OpIndia last year This article has been indexed from www.infosecurity-magazine.com Read the original article: Indian Election Faces Cyber-Attacks, Data Leaks on Dark Web

NVD Leaves Exploited Vulnerabilities Unchecked

Over half of CISA’s known exploited vulnerabilities disclosed since February 2024 have not yet been analyzed by NIST’s National Vulnerability Database This article has been indexed from www.infosecurity-magazine.com Read the original article: NVD Leaves Exploited Vulnerabilities Unchecked

National Records of Scotland Data Breached in NHS Cyber-Attack

National Records of Scotland said sensitive personal data it holds was part of information stolen and published online by ransomware attackers from NHS Dumfries and Galloway This article has been indexed from www.infosecurity-magazine.com Read the original article: National Records of…

PSNI Faces £750,000 Data Breach Fine After Spreadsheet Leak

The Police Service of Northern Ireland has been fined £750K following a serious data breach last year This article has been indexed from www.infosecurity-magazine.com Read the original article: PSNI Faces £750,000 Data Breach Fine After Spreadsheet Leak

Report Reveals 341% Rise in Advanced Phishing Attacks

This data comes from SlashNext’s mid-year State of Phishing 2024 report This article has been indexed from www.infosecurity-magazine.com Read the original article: Report Reveals 341% Rise in Advanced Phishing Attacks

UserPro Plugin Vulnerability Allows Account Takeover

The plugin is used by over 20,000 sites and enables users to create customizable community websites This article has been indexed from www.infosecurity-magazine.com Read the original article: UserPro Plugin Vulnerability Allows Account Takeover

Chinese Hackers Rely on Covert Proxy Networks to Evade Detection

Volt Typhoon and other Chinese cyber espionage actors are relying on operational relay box (ORB) networks, Mandiant has observed This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese Hackers Rely on Covert Proxy Networks to Evade Detection

Mastercard Doubles Speed of Fraud Detection with Generative AI

Mastercard said it is using generative AI-based predictive technology to double the speed at which it can detect potentially compromised cards This article has been indexed from www.infosecurity-magazine.com Read the original article: Mastercard Doubles Speed of Fraud Detection with Generative…

US Unveils $50M Program to Help Hospitals Patch Cybersecurity Gaps

The US government UPGRADE program aims to automate vulnerability management in hospital environments, ensuring minimum disruption to services This article has been indexed from www.infosecurity-magazine.com Read the original article: US Unveils $50M Program to Help Hospitals Patch Cybersecurity Gaps

Authorized Push Payment Fraud Cases Surge 12% Annually

UK Finance figures reveal romance, purchase and investment scams drove up authorised push payment fraud in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Authorized Push Payment Fraud Cases Surge 12% Annually

Russia’s DoppelGänger Campaign Manipulates Social Media

Operation Matriochka has been challenging the credibility of journalists and fact-checkers since May 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia’s DoppelGänger Campaign Manipulates Social Media

70% of CISOs Expect Cyber-Attacks in Next Year, Report Finds

Proofpoint said the shift to remote and hybrid work has expanded the attack surface for many businesses This article has been indexed from www.infosecurity-magazine.com Read the original article: 70% of CISOs Expect Cyber-Attacks in Next Year, Report Finds

70% of CISOs Expect Cyberattacks in Next Year, Report Finds

Proofpoint said the shift to remote and hybrid work has expanded the attack surface for many businesses This article has been indexed from www.infosecurity-magazine.com Read the original article: 70% of CISOs Expect Cyberattacks in Next Year, Report Finds

Ransomware and AI-Powered Hacks Drive Cyber Investment

The rise in ransomware and AI generated attacks has contributed to accelerate investment into cyber defenses, Infosecurity Europe found in a new study This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware and AI-Powered Hacks Drive Cyber…

Over 60% of Network Security Appliance Flaws Exploited as Zero Days

Rapid7 found there were more mass compromise events arose from zero-day vulnerabilities than from n-day vulnerabilities in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 60% of Network Security Appliance Flaws Exploited as Zero Days

Authorities Arrest $100m Incognito Drugs Market Suspect

US officials say the suspected owner of the prolific Incognito dark web drugs marketplace has been arrested This article has been indexed from www.infosecurity-magazine.com Read the original article: Authorities Arrest $100m Incognito Drugs Market Suspect

Critical Fluent Bit Bug Impacts All Major Cloud Platforms

A newly discovered flaw in open source utility Fluent Bit could enable widespread DoS, RCE and information leakage This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical Fluent Bit Bug Impacts All Major Cloud Platforms

Network Outages Hit 59% of Multi-Site Businesses Monthly

A new report from Kaspersky also shows that 46% of businesses experience network problems between one and three times a month This article has been indexed from www.infosecurity-magazine.com Read the original article: Network Outages Hit 59% of Multi-Site Businesses Monthly

Grandoreiro Banking Trojan is Back With Major Updates

The malware-as-a-service Grandoreiro Trojan is now targeting 1500 global banks, says IBM This article has been indexed from www.infosecurity-magazine.com Read the original article: Grandoreiro Banking Trojan is Back With Major Updates

UK Councils Warn of Data Breach After Attack on Medical Supplier

Multiple UK councils have warned that residents’ personal data may have been compromised following a ransomware attack on NRS Healthcare This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Councils Warn of Data Breach After Attack on…

Patient Data at Risk in MediSecure Ransomware Attack

Electronic prescriptions provider MediSecure said the attack originated from a third-party vendor, and has impacted individuals’ personal and health information This article has been indexed from www.infosecurity-magazine.com Read the original article: Patient Data at Risk in MediSecure Ransomware Attack

Windows Quick Assist Exploited in Ransomware Attacks

Microsoft warned Storm-1811 started vishing attacks in April to gain access to target devices This article has been indexed from www.infosecurity-magazine.com Read the original article: Windows Quick Assist Exploited in Ransomware Attacks

53,000 Employees’ Social Security Numbers Exposed in Nissan Data Breach

Car manufacturer Nissan revealed that over 53,000 of its North America employees had their social security numbers accessed by a ransomware attacker This article has been indexed from www.infosecurity-magazine.com Read the original article: 53,000 Employees’ Social Security Numbers Exposed in…

CISO Confidence in AI Security Grows as GenAI Adoption Rises

Nearly six out of ten surveyed ClubCISO members are confident AI is used securely in their organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: CISO Confidence in AI Security Grows as GenAI Adoption Rises

UK Lags Europe on Exploited Vulnerability Remediation

UK organizations are less likely than their European peers to have known exploited bugs but take longer to fix them This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Lags Europe on Exploited Vulnerability Remediation

BreachForums Hacking Marketplace Taken Down Again

The FBI claims to have seized the domain and servers of hacking forum BreachForums This article has been indexed from www.infosecurity-magazine.com Read the original article: BreachForums Hacking Marketplace Taken Down Again

PDF Exploitation Targets Foxit Reader Users

CPR said exploit builders in .NET and Python have been employed to deploy this malware This article has been indexed from www.infosecurity-magazine.com Read the original article: PDF Exploitation Targets Foxit Reader Users

Cyber-Attack Disrupts Christie’s $840M Art Auctions

Despite this setback, the auction house said bids can still be placed by phone and in-person This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber-Attack Disrupts Christie’s $840M Art Auctions

NCSC Expands Election Cybersecurity to Safeguard Candidates and Officials

The National Cyber Security Centre launches an opt-in Personal Internet Protection service to safeguard individuals from cyber threats during the upcoming election This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Expands Election Cybersecurity to Safeguard Candidates…

Santander Customer Data Compromised Following Third-Party Breach

Santander has warned that customer and employee data has been breached following unauthorized access to a database held by a third-party provider This article has been indexed from www.infosecurity-magazine.com Read the original article: Santander Customer Data Compromised Following Third-Party Breach

Current Market Forces Disincentivizing Cybersecurity, Says NCSC CTO

NCSC CTO argues current market rewards prioritize cost over security, hindering the development of secure technology This article has been indexed from www.infosecurity-magazine.com Read the original article: Current Market Forces Disincentivizing Cybersecurity, Says NCSC CTO

Microsoft Fixes Three Zero-Days in May Patch Tuesday

Microsoft has released patches for three zero-day vulnerabilities including two actively exploited in the wild This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Fixes Three Zero-Days in May Patch Tuesday

Data Breaches in US Schools Exposed 37.6M Records

Comparitech said 2023 was a record year for breaches with 954 reported, up from 139 in 2022 and 783 in 2021 This article has been indexed from www.infosecurity-magazine.com Read the original article: Data Breaches in US Schools Exposed 37.6M Records

Ebury Botnet Operators Diversify with Financial and Crypto Theft

The 15-year-old Ebury botnet is more active than ever, as ESET found 400,000 Linux servers compromised for cryptocurrency theft and financial gain This article has been indexed from www.infosecurity-magazine.com Read the original article: Ebury Botnet Operators Diversify with Financial and…

NIST Confusion Continues as Cyber Pros Complain CVE Uploads Stalled

Several software security experts have told Infosecurity that no new vulnerabilities have been added to the US National Vulnerability Database (NVD) since May 9 This article has been indexed from www.infosecurity-magazine.com Read the original article: NIST Confusion Continues as Cyber…

44% of Cybersecurity Professionals Struggle with Regulatory Compliance

Infosecurity Europe research highlights significant challenges faced by organisations in staying up to speed with increasing compliance requirements This article has been indexed from www.infosecurity-magazine.com Read the original article: 44% of Cybersecurity Professionals Struggle with Regulatory Compliance

China Presents Defining Challenge to Global Cybersecurity, Says GCHQ

GCHQ chief warns China’s cyber actions threaten global internet security, while Russia and Iran pose immediate risks This article has been indexed from www.infosecurity-magazine.com Read the original article: China Presents Defining Challenge to Global Cybersecurity, Says GCHQ

Russian Actors Weaponize Legitimate Services in Multi-Malware Attack

Recorded Future details a novel campaign that abuses legitimate internet services to deploy multiple malware variants for credential theft This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Actors Weaponize Legitimate Services in Multi-Malware Attack

UK Insurance and NCSC Join Forces to Fight Ransomware Payments

UK insurers and the National Cybersecurity Centre release new guidance to discourage ransomware payments by businesses This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Insurance and NCSC Join Forces to Fight Ransomware Payments

UK Insurance and NCSC Join Forces to Fight Ransomware Payments

UK insurers and the National Cybersecurity Centre release new guidance to discourage ransomware payments by businesses This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Insurance and NCSC Join Forces to Fight Ransomware Payments

Hackers Use DNS Tunneling to Scan and Track Victims

Palo Alto Networks warns threat actors are using DNS tunneling techniques to probe for network vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Hackers Use DNS Tunneling to Scan and Track Victims

FCC Names and Shames First Robocall Threat Actor

In a first, the FCC has designated “Royal Tiger” as a malicious robocall threat group This article has been indexed from www.infosecurity-magazine.com Read the original article: FCC Names and Shames First Robocall Threat Actor

Critical Vulnerabilities in Cinterion Modems Exposed

The flaws include CVE-2023-47610, a security weaknesses within the modem’s SUPL message handlers This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical Vulnerabilities in Cinterion Modems Exposed

Mallox Ransomware Deployed Via MS-SQL Honeypot Attack

Analyzing Mallox samples, Sekoia identified two distinct affiliates using different approaches This article has been indexed from www.infosecurity-magazine.com Read the original article: Mallox Ransomware Deployed Via MS-SQL Honeypot Attack

Ascension Ransomware Attack Diverts Ambulances, Delays Appointments

A ransomware attack on US private healthcare provider Ascension has disrupted patient care, with several hospitals currently on diversion This article has been indexed from www.infosecurity-magazine.com Read the original article: Ascension Ransomware Attack Diverts Ambulances, Delays Appointments

Black Basta Ransomware Victim Count Tops 500

Affiliates of prolific Black Basta ransomware group have breached over 500 global organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: Black Basta Ransomware Victim Count Tops 500

Threat Actor Claims Major Europol Data Breach

A threat actor known as IntelBroker claims to be selling confidential Europol data after a May breach This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actor Claims Major Europol Data Breach

RSAC: Experts Highlight Novel Cyber Threats and Tactics

Well-funded cybercriminals are adopting more sophisticated techniques, creating a need for defenders to stay informed about the evolving threat landscape This article has been indexed from www.infosecurity-magazine.com Read the original article: RSAC: Experts Highlight Novel Cyber Threats and Tactics

RSAC: How CISOs Should Protect Themselves Against Indictments

Experts at the RSA Conference discussed what CISOs can do to protect themselves against legal pressure This article has been indexed from www.infosecurity-magazine.com Read the original article: RSAC: How CISOs Should Protect Themselves Against Indictments

RSAC: Why Cybersecurity Professionals Have a Duty to Secure AI

Experts at the RSA Conference urged cyber professionals to lead the way in securing AI systems today and pave the way for AI to solve huge societal challenges This article has been indexed from www.infosecurity-magazine.com Read the original article: RSAC:…

#RSAC: Why Cybersecurity Professionals Have a Duty to Secure AI

Experts at the RSA Conference urged cyber professionals to lead the way in securing AI systems today and pave the way for AI to solve huge societal challenges This article has been indexed from www.infosecurity-magazine.com Read the original article: #RSAC:…

#RSAC: How CISOs Should Protect Themselves Against Indictments

Experts at the RSA Conference discussed what CISOs can do to protect themselves against legal pressure This article has been indexed from www.infosecurity-magazine.com Read the original article: #RSAC: How CISOs Should Protect Themselves Against Indictments

New ‘LLMjacking’ Attack Exploits Stolen Cloud Credentials

Sysdig said the attackers gained access to these credentials from a vulnerable version of Laravel This article has been indexed from www.infosecurity-magazine.com Read the original article: New ‘LLMjacking’ Attack Exploits Stolen Cloud Credentials

Mobile Banking Malware Surges 32%

Afghanistan, Turkmenistan and Tajikistan victims experienced the highest share of banking Trojans This article has been indexed from www.infosecurity-magazine.com Read the original article: Mobile Banking Malware Surges 32%