Category: www.infosecurity-magazine.com

US Government and OpenSSF Partner on New SBOM Management Tool

OpenSSF, in collaboration with the US Government, has developed Protobom, a open source tool designed to simplify SBOM management for organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government and OpenSSF Partner on New SBOM…

Ivanti Patches Two Critical Avalanche Flaws in Major Update

Ivanti has fixed two critical vulnerabilities in its Avalanche MDM product which could lead to remote code execution This article has been indexed from www.infosecurity-magazine.com Read the original article: Ivanti Patches Two Critical Avalanche Flaws in Major Update

LeakyCLI Flaw Exposes AWS and Google Cloud Credentials

Orca Security said the issue mirrors a previously identified vulnerability in Azure CLI This article has been indexed from www.infosecurity-magazine.com Read the original article: LeakyCLI Flaw Exposes AWS and Google Cloud Credentials

Cybersecurity Pros Urge US Congress to Help NIST Restore NVD Operation

An open letter signed by 50 cybersecurity practitioners requires the US Congress to support NIST in restoring operations at the National Vulnerability Database This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybersecurity Pros Urge US Congress to…

Microsoft Most Impersonated Brand in Phishing Scams

New Check Point data found Microsoft was impersonated in 38% of all brand phishing attacks in Q1 2024, up from 33% in Q4 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Most Impersonated Brand in…

Open Source Leaders Warn of XZ Utils-Like Takeover Attempts

Two open source organizations have revealed attempts to socially engineer project takeovers This article has been indexed from www.infosecurity-magazine.com Read the original article: Open Source Leaders Warn of XZ Utils-Like Takeover Attempts

Russia and Ukraine Top Inaugural World Cybercrime Index

An international team of researchers published the first-ever index ranking countries by cybercrime threat level This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia and Ukraine Top Inaugural World Cybercrime Index

New LockBit Variant Exploits Self-Spreading Features

Kaspersky also uncovered the use of the SessionGopher script to extract saved passwords This article has been indexed from www.infosecurity-magazine.com Read the original article: New LockBit Variant Exploits Self-Spreading Features

Palo Alto Networks Zero-Day Flaw Exploited in Targeted Attacks

Designated CVE-2024-3400 and with a CVSS score of 10.0, the flaw enables unauthorized actors to execute arbitrary code on affected firewalls This article has been indexed from www.infosecurity-magazine.com Read the original article: Palo Alto Networks Zero-Day Flaw Exploited in Targeted…

Chipmaker Giant Nexperia Confirms Cyber-Attack Amid Ransomware Group Claims

Nexperia confirmed its IT servers were accessed by attackers, with the Dunghill ransomware group claiming to have stolen chip designs and other sensitive documents This article has been indexed from www.infosecurity-magazine.com Read the original article: Chipmaker Giant Nexperia Confirms Cyber-Attack…

FBI Warns of Massive Toll Services Smishing Scam

The Feds have received thousands of complaints about phishing texts from fake road toll collection services This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Warns of Massive Toll Services Smishing Scam

Police Swoop on €645m Cannabis Investment Fraud Gang

Nine arrests and millions of euros seized in bid to bust JuicyFields investment scammers This article has been indexed from www.infosecurity-magazine.com Read the original article: Police Swoop on €645m Cannabis Investment Fraud Gang

CISA Urges Immediate Credential Reset After Sisense Breach

The breach affecting business analytics provider Sisense could lead to a wide-scale supply chain attack This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Urges Immediate Credential Reset After Sisense Breach

Apple Boosts Spyware Alerts For Mercenary Attacks

The revision points out companies like NSO Group, known for surveillance tools like Pegasus This article has been indexed from www.infosecurity-magazine.com Read the original article: Apple Boosts Spyware Alerts For Mercenary Attacks

Data Breach Exposes 300k Taxi Passengers’ Information

These records belonged to Dublin-based iCabbi, a dispatch and fleet management technology provider This article has been indexed from www.infosecurity-magazine.com Read the original article: Data Breach Exposes 300k Taxi Passengers’ Information

New Android Espionage Campaign Spotted in India and Pakistan

A new cyber espionage campaign, called ‘eXotic Visit,’ targeted Android users in South Asia via seemingly legitimate messaging apps This article has been indexed from www.infosecurity-magazine.com Read the original article: New Android Espionage Campaign Spotted in India and Pakistan

Raspberry Robin Distributed Through Windows Script Files

Distribution vectors of the Raspberry Robin worm now include Windows Script Files (WSF) alongside other methods like USB drives This article has been indexed from www.infosecurity-magazine.com Read the original article: Raspberry Robin Distributed Through Windows Script Files

Threat Actors Game GitHub Search to Spread Malware

Checkmarx warns of GitHub search result manipulation designed to promote malicious repositories This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actors Game GitHub Search to Spread Malware

US Data Breach Reports Surge 90% Annually in Q1

The number of publicly reported data breaches and leaks grew 90% in the first three months of the year This article has been indexed from www.infosecurity-magazine.com Read the original article: US Data Breach Reports Surge 90% Annually in Q1

Rhadamanthys Malware Deployed By TA547 Against German Targets

Proofpoint said it is the first time this threat actor has been seen using LLM-generated PowerShell scripts This article has been indexed from www.infosecurity-magazine.com Read the original article: Rhadamanthys Malware Deployed By TA547 Against German Targets

LG TV Vulnerabilities Expose 91,000 Devices

The issues identified permit unauthorized access to the TV’s root system by bypassing authorization mechanisms This article has been indexed from www.infosecurity-magazine.com Read the original article: LG TV Vulnerabilities Expose 91,000 Devices

Women Experience Exclusion Twice as Often as Men in Cybersecurity

A WiCyS report detailed the causes of disparities in the experiences of women working in cybersecurity compared to men, including respect and exclusion This article has been indexed from www.infosecurity-magazine.com Read the original article: Women Experience Exclusion Twice as Often…

US Claims to Have Recovered $1.4bn in COVID Fraud

The DoJ says it has seized $1.4bn and charged 3500 defendants in COVID fraud cases since 2021 This article has been indexed from www.infosecurity-magazine.com Read the original article: US Claims to Have Recovered $1.4bn in COVID Fraud

Microsoft Patches 150 Flaws Including Two Zero-Days

April’s Patch Tuesday saw fixes for 150 CVEs, including two being actively exploited in the wild This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Patches 150 Flaws Including Two Zero-Days

Hackers Use Malware to Hunt Software Vulnerabilities

Palo Alto Networks observed growing malware-initiated vulnerability scanning activity This article has been indexed from www.infosecurity-magazine.com Read the original article: Hackers Use Malware to Hunt Software Vulnerabilities

Change Healthcare Hit By Cyber Extortion Again

RansomHub has surfaced threatening to expose stolen data unless another ransom is paid This article has been indexed from www.infosecurity-magazine.com Read the original article: Change Healthcare Hit By Cyber Extortion Again

Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto

Sysdig stated that by deploying multiple miners, the group decreased attack time and detection risk This article has been indexed from www.infosecurity-magazine.com Read the original article: Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto

Foreign Interference Drives Record Surge in IP Theft

DTEX claims industrial espionage and IP theft are at an all-time high thanks to malicious insiders This article has been indexed from www.infosecurity-magazine.com Read the original article: Foreign Interference Drives Record Surge in IP Theft

Over 90,000 D-Link NAS Devices Are Under Attack

Threat actors are targeting a high severity vulnerability in close to 100,000 legacy D-Link devices This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 90,000 D-Link NAS Devices Are Under Attack

Why Identity Management is Key in a Cyber Resilience Strategy

For the fourth edition of Identity Management Day, the Identity Defined Security Alliance shared staggering numbers on the boom of identity-related cyber incidents This article has been indexed from www.infosecurity-magazine.com Read the original article: Why Identity Management is Key in…

US Federal Data Privacy Law Introduced by Legislators

Two US lawmakers have published a draft federal data privacy law, dubbed the American Privacy Rights Act, which aims to provide protections for the personal information of all US citizens This article has been indexed from www.infosecurity-magazine.com Read the original…

New Malware “Latrodectus” Linked to IcedID

The malware, discovered by Proofpoint and Team Cymru, was mainly utilized by initial access brokers This article has been indexed from www.infosecurity-magazine.com Read the original article: New Malware “Latrodectus” Linked to IcedID

Byakugan Infostealer Capabilities Revealed

Fortinet said the malware functions identified include screen monitoring, screen capturing, cryptomining and more This article has been indexed from www.infosecurity-magazine.com Read the original article: Byakugan Infostealer Capabilities Revealed

Famous YouTube Channels Hacked to Distribute Infostealers

The AhnLab Security Intelligence Center discovered new infostealer distribution campaigns leveraging legitimate YouTube channels This article has been indexed from www.infosecurity-magazine.com Read the original article: Famous YouTube Channels Hacked to Distribute Infostealers

UK Retailers Lost £11.3bn to Fraud in 2023

Research from Ayden and the CEBR found that 35% of UK retailers fell victim to fraudulent activity, cyber-attacks or data leaks over the past 12 months This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Retailers Lost…

Hospital IT Helpdesks Targeted By Voice Fraudsters, Warns HHS

Threat actors are socially engineering healthcare IT helpdesk staff to steal money, the government has warned This article has been indexed from www.infosecurity-magazine.com Read the original article: Hospital IT Helpdesks Targeted By Voice Fraudsters, Warns HHS

Veterinary Giant CVS Reveals Major Cyber-Attack

Veterinary services provider CVS Group today notified markets of a security breach last week This article has been indexed from www.infosecurity-magazine.com Read the original article: Veterinary Giant CVS Reveals Major Cyber-Attack

Chinese Threat Actors Deploy New TTPs to Exploit Ivanti Vulnerabilities

Mandiant research details how Chinese espionage groups are deploying new tools post-exploitation of recently patched Ivanti vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese Threat Actors Deploy New TTPs to Exploit Ivanti Vulnerabilities

China Using AI-Generated Content to Sow Division in US, Microsoft Finds

A Microsoft report found that China-affiliated actors are publishing AI-generated content on social media to amplify controversial domestic issues in the US This article has been indexed from www.infosecurity-magazine.com Read the original article: China Using AI-Generated Content to Sow Division…

Jackson County IT Systems Hit By Ransomware Attack

A state of emergency was declared, caused by operational inconsistencies across digital infrastructure This article has been indexed from www.infosecurity-magazine.com Read the original article: Jackson County IT Systems Hit By Ransomware Attack

New JSOutProx Malware Targets Financial Firms in APAC, MENA

First found in 2019, JSOutProx combines JavaScript and .NET functionalities to infiltrate systems This article has been indexed from www.infosecurity-magazine.com Read the original article: New JSOutProx Malware Targets Financial Firms in APAC, MENA

Leicester Council Confirms Confidential Documents Leaked in Ransomware Attack

Leicester City Council confirmed around 25 sensitive documents have been leaked online, including personal ID information, following claims by the Inc Ransom gang This article has been indexed from www.infosecurity-magazine.com Read the original article: Leicester Council Confirms Confidential Documents Leaked…

Threat Actor Claims Classified Five Eyes Data Theft

Threat actor IntelBroker claims to have classified intelligence stolen from US government tech supplier Acuity This article has been indexed from www.infosecurity-magazine.com Read the original article: Threat Actor Claims Classified Five Eyes Data Theft

Firms Must Work Harder to Guard Children’s Privacy, Says UK ICO

UK privacy regulator, the ICO, urges social media and video sharing firms to do more to protect children’s data This article has been indexed from www.infosecurity-magazine.com Read the original article: Firms Must Work Harder to Guard Children’s Privacy, Says UK…

Prudential Financial Notifies 36,000 Individuals of Data Breach

The compromised data includes names or other identifying information in combination with driver’s license numbers This article has been indexed from www.infosecurity-magazine.com Read the original article: Prudential Financial Notifies 36,000 Individuals of Data Breach

Infostealers Prevalent in Retail Sector Cybercrime Trends

The findings from Netskope also show a shift in the retail sector’s use of cloud applications This article has been indexed from www.infosecurity-magazine.com Read the original article: Infostealers Prevalent in Retail Sector Cybercrime Trends

UK and US to Build Common Approach on AI Safety

The UK and the US have signed a partnership to coordinate the work of their respective AI Safety Institutes This article has been indexed from www.infosecurity-magazine.com Read the original article: UK and US to Build Common Approach on AI Safety

RDP Abuse Present in 90% of Ransomware Breaches

Sophos reveals “unprecedented” levels of RDP compromise in ransomware attacks in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: RDP Abuse Present in 90% of Ransomware Breaches

YouTube Video Game ‘Hacks’ Contain Malware Links

Proofpoint has spotted a new infostealer campaign using malicious links in YouTube video descriptions This article has been indexed from www.infosecurity-magazine.com Read the original article: YouTube Video Game ‘Hacks’ Contain Malware Links

Researchers Report Sevenfold Increase in Data Theft Cases

Kaspersky said cybercriminals harvested 50.9 login credentials per infected device in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Researchers Report Sevenfold Increase in Data Theft Cases

Impersonation Scams Net Fraudsters $1.1bn in a Year

FTC figures reveal a three-fold increase in losses from impersonation scams over the past three years This article has been indexed from www.infosecurity-magazine.com Read the original article: Impersonation Scams Net Fraudsters $1.1bn in a Year

US Treasury Urges Financial Sector to Address AI Cybersecurity Threats

The US Treasury report sets out recommendations for financial institutions on addressing immediate AI-related operational risk, cybersecurity and fraud challenges This article has been indexed from www.infosecurity-magazine.com Read the original article: US Treasury Urges Financial Sector to Address AI Cybersecurity…

17 Billion Personal Records Exposed in Data Breaches in 2023

Flashpoint recorded a 34.5% rise in reported data breaches in 2023, with ransomware a major driver of this increase This article has been indexed from www.infosecurity-magazine.com Read the original article: 17 Billion Personal Records Exposed in Data Breaches in 2023

Half of British SMEs Have Lost Data in Past Five Years

Beaming research reveals that nearly half of UK SMEs have lost data since 2019, costing billions This article has been indexed from www.infosecurity-magazine.com Read the original article: Half of British SMEs Have Lost Data in Past Five Years

Calls to Incident Response Helpline Double in a Year

A rising volume of calls to the Scottish Cyber and Fraud Centre highlights surging threat levels This article has been indexed from www.infosecurity-magazine.com Read the original article: Calls to Incident Response Helpline Double in a Year

Only 3% of Businesses Resilient Against Modern Cyber Threats

Cisco scored just 3% of organizations as having a ‘mature’ level of readiness to cyber threats, a significant decline from the previous year This article has been indexed from www.infosecurity-magazine.com Read the original article: Only 3% of Businesses Resilient Against…

Chinese Hackers Target ASEAN Entities in Espionage Campaign

Palo Alto Networks’ Unit 42 observed two Chinese-affiliated APT groups recently conducting cyber espionage campaigns targeting ASEAN organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese Hackers Target ASEAN Entities in Espionage Campaign

Only 5% of Boards Have Cybersecurity Expertise, Despite Financial Benefits

The Diligent and Bitsight report found that stronger cybersecurity measures equate to significantly higher financial performance for businesses This article has been indexed from www.infosecurity-magazine.com Read the original article: Only 5% of Boards Have Cybersecurity Expertise, Despite Financial Benefits

US Targets Crypto Firms Aiding Russia Sanctions Evasion

The US Treasury has designated several Russian blockchain and virtual currency firms for sanctions evasion This article has been indexed from www.infosecurity-magazine.com Read the original article: US Targets Crypto Firms Aiding Russia Sanctions Evasion

New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns

Discovered by Sekoia in 2023, the kit is associated with Adversary-in-The-Middle (AiTM) attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns

UK Blames China for 2021 Hack Targeting Millions of Voters’ Data

The UK’s NCSC assesses that China-backed APT31 was “almost certainly” responsible for hacking the email accounts of UK parliamentarians This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Blames China for 2021 Hack Targeting Millions of Voters’…

Police Bust Multimillion-Dollar Holiday Fraud Gang

Law enforcers have arrested nine suspected members of a prolific cyber-fraud gang This article has been indexed from www.infosecurity-magazine.com Read the original article: Police Bust Multimillion-Dollar Holiday Fraud Gang

Russian Cozy Bear Group Targets German Politicians

Mandiant observes what it claims is the first ever APT29 campaign aimed at political parties This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Cozy Bear Group Targets German Politicians

New AcidPour Wiper Targeting Linux Devices Spotted in Ukraine

SentinelLabs researchers identified the malware as a new variant of AcidRain, which shut down thousands of Viasat satellites in Ukraine and Western Europe in 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: New AcidPour Wiper Targeting…

US Government Releases New DDoS Attack Guidance for Public Sector

The joint advisory sets out how to mitigate and respond to DDoS attacks, limiting disruption to critical services This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government Releases New DDoS Attack Guidance for Public Sector

Security Leaders Acknowledge API Security Gaps Despite Looming Threat

Most decision-makers have experienced API security problems over the past year, yet many haven’t invested in a robust API security strategy, Fastly reveals This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Leaders Acknowledge API Security Gaps…

ICO Probes Kate Middleton Medical Record Breach

The ICO said it is assessing the reported breach of Kate Middleton’s medical records at The London Clinic This article has been indexed from www.infosecurity-magazine.com Read the original article: ICO Probes Kate Middleton Medical Record Breach

Security Researchers Win Second Tesla At Pwn2Own

The Synacktiv team won its second Tesla car for finding one of 19 zero-day bugs on the first day of Pwn2Own Vancouver This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Researchers Win Second Tesla At Pwn2Own

CISA Warns Critical Infrastructure Leaders of Volt Typhoon

The agency has issued a fact sheet about the threat actor, emphasizing the importance of cyber-risk as a core business concern This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Warns Critical Infrastructure Leaders of Volt Typhoon

Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands

Thales latest report also suggests less than half of organizations have a formal ransomware response plan This article has been indexed from www.infosecurity-magazine.com Read the original article: Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands

White House Convenes States to Discuss Water Sector Breaches

The Biden administration is inviting state representatives to urgently discuss the security of the water sector This article has been indexed from www.infosecurity-magazine.com Read the original article: White House Convenes States to Discuss Water Sector Breaches