Category: www.infosecurity-magazine.com

NCSC Publishes Security Guidance For Cloud-Hosted SCADA

The UK’s National Cyber Security Centre wants to help organizations migrate their SCADA systems to the cloud This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Publishes Security Guidance For Cloud-Hosted SCADA

NCSC Publishes Security Guidance for Cloud-Hosted SCADA

The UK’s National Cyber Security Centre wants to help organizations migrate their SCADA systems to the cloud This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Publishes Security Guidance for Cloud-Hosted SCADA

FCC Agrees to Cyber Trust Mark for IoT Products

The voluntary FCC program will allow smart device manufacturers to demonstrate to consumers that their product has met robust cybersecurity standards This article has been indexed from www.infosecurity-magazine.com Read the original article: FCC Agrees to Cyber Trust Mark for IoT…

Three New Critical Vulnerabilities Uncovered in Argo

The flaws, identified by KTrust, enable attackers to bypass rate limits and brute force protection mechanisms This article has been indexed from www.infosecurity-magazine.com Read the original article: Three New Critical Vulnerabilities Uncovered in Argo

IMF Investigates Serious Cybesecurity Breach

The International Monetary Fund says it is still looking into a recent compromise of multiple email accounts This article has been indexed from www.infosecurity-magazine.com Read the original article: IMF Investigates Serious Cybesecurity Breach

US Government to Investigate Change Healthcare Ransomware Attack

The US government will investigate whether protected healthcare information was breached in the Change Healthcare ransomware attack, and if the firm complied with HIPAA rules This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government to Investigate…

French Employment Agency Data Breach Could Affect 43 Million People

France’s employment agency suffered a massive breach, exposing the data of users who registered over the past 20 years This article has been indexed from www.infosecurity-magazine.com Read the original article: French Employment Agency Data Breach Could Affect 43 Million People

Google Paid $10m in Bug Bounties to Security Researchers in 2023

Google revealed it paid $10m in bug bounty payments to more than 600 researchers in 2023, with the highest single payment being £113,337 This article has been indexed from www.infosecurity-magazine.com Read the original article: Google Paid $10m in Bug Bounties…

Fortinet Patches Critical Bug in FortiClient EMS

Fortinet has released security updates to fix several critical vulnerabilities in its products This article has been indexed from www.infosecurity-magazine.com Read the original article: Fortinet Patches Critical Bug in FortiClient EMS

Meta Sues Former VP After Defection to AI Startup

Meta is suing one of its former executives for stealing sensitive documents before leaving the company This article has been indexed from www.infosecurity-magazine.com Read the original article: Meta Sues Former VP After Defection to AI Startup

Investment Scams Grow, 13,000 Domains Detected in January 2024

Netcraft said the domains were found across 7000 IPs in January, a 25% increase from December 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Investment Scams Grow, 13,000 Domains Detected in January 2024

Cloud Account Attacks Surged 16-Fold in 2023

Red Canary said cloud account compromise detections rose 16-fold in 2023, becoming the fourth most prevalent technique used by threat actors This article has been indexed from www.infosecurity-magazine.com Read the original article: Cloud Account Attacks Surged 16-Fold in 2023

New Research Exposes Security Risks in ChatGPT Plugins

Salt Security discovered GPT flaws affecting plugin installation, PluginLab and OAuth This article has been indexed from www.infosecurity-magazine.com Read the original article: New Research Exposes Security Risks in ChatGPT Plugins

Google to Restrict Election-Related Answers on AI Chatbot Gemini

The new restriction to Google’s AI chatbot was first implemented in India, which holds elections in April, before being rolled across other nations This article has been indexed from www.infosecurity-magazine.com Read the original article: Google to Restrict Election-Related Answers on…

Study Reveals Top Vulnerabilities in Corporate Web Applications

Kaspersky said access control weaknesses and failures in data protection accounted for 70% of all flaws This article has been indexed from www.infosecurity-magazine.com Read the original article: Study Reveals Top Vulnerabilities in Corporate Web Applications

US Intelligence Predicts Upcoming Cyber Threats for 2024

The Office of the Director of National Intelligence (ODNI) has unveiled an unclassified version of its Annual Threat Assessment of the US Intelligence Community This article has been indexed from www.infosecurity-magazine.com Read the original article: US Intelligence Predicts Upcoming Cyber…

New Cloud Attack Targets Crypto CDN Meson Ahead of Launch

Sysdig said the rise of the Meson Network in blockchain signals a new frontier for attackers This article has been indexed from www.infosecurity-magazine.com Read the original article: New Cloud Attack Targets Crypto CDN Meson Ahead of Launch

Three-Quarters of Cyber Incident Victims Are Small Businesses

Three-quarters of cyber-incidents Sophos responded to involved small businesses in 2023, with attackers’ main goal being data theft This article has been indexed from www.infosecurity-magazine.com Read the original article: Three-Quarters of Cyber Incident Victims Are Small Businesses

Victims Lose $47m to Crypto Phishing Scams in February

Some 57,000 victims lost $47m in phishing scams targeting their cryptocurrency last month This article has been indexed from www.infosecurity-magazine.com Read the original article: Victims Lose $47m to Crypto Phishing Scams in February

Magnet Goblin Exploits Ivanti Vulnerabilities

The actor utilizes custom Linux malware to pursue financial gain, according to Check Point Research This article has been indexed from www.infosecurity-magazine.com Read the original article: Magnet Goblin Exploits Ivanti Vulnerabilities

BianLian Threat Actor Shifts Focus to Extortion-Only Tactics

GuidePoint said the threat actor gained initial access via vulnerabilities in a TeamCity server This article has been indexed from www.infosecurity-magazine.com Read the original article: BianLian Threat Actor Shifts Focus to Extortion-Only Tactics

NSA Launches Top 10 Cloud Security Mitigation Strategies

The advisory is associated with ten companion cybersecurity information sheets detailing how to implement each strategy This article has been indexed from www.infosecurity-magazine.com Read the original article: NSA Launches Top 10 Cloud Security Mitigation Strategies

Telemedicine Business Owner Faces 20 Years For $136m Fraud

Nurse practitioner pleads guilty to $136m Medicare fraud plot involving her telemedicine companies This article has been indexed from www.infosecurity-magazine.com Read the original article: Telemedicine Business Owner Faces 20 Years For $136m Fraud

Russia’s Midnight Blizzard Accesses Microsoft Source Code

Threat group APT29 is using secrets stolen in an earlier attack to compromise Microsoft’s internal systems This article has been indexed from www.infosecurity-magazine.com Read the original article: Russia’s Midnight Blizzard Accesses Microsoft Source Code

Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing Campaign

Darktrace reveals a novel phishing campaign where attackers leveraged legitimate Dropbox infrastructure to steal credentials before bypassing MFA This article has been indexed from www.infosecurity-magazine.com Read the original article: Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing…

RATs Spread Via Fake Skype, Zoom, Google Meet Sites

Zscaler’s ThreatLabz discovered malware spreading SpyNote RAT to Android and NjRAT/DCRat to Windows This article has been indexed from www.infosecurity-magazine.com Read the original article: RATs Spread Via Fake Skype, Zoom, Google Meet Sites

Evasive Panda Targets Tibet With Trojanized Software

ESET researchers said the attackers strategically leveraged the Monlam Festival, targeting individuals associated with Tibetan Buddhism This article has been indexed from www.infosecurity-magazine.com Read the original article: Evasive Panda Targets Tibet With Trojanized Software

FBI: US Ransomware Losses Surge 74% to $59.6 Million in 2023

Ransomware losses in the US rose by 74% to $59.6m in 2023, according to reported incidents to the FBI This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI: US Ransomware Losses Surge 74% to $59.6 Million in…

Governments Eye Disclosure Requirements for AI Development Labs

AI scientist Inma Martinez predicts governments will start requiring ‘frontier’ AI labs full disclosure on the purpose of the tools they are developing This article has been indexed from www.infosecurity-magazine.com Read the original article: Governments Eye Disclosure Requirements for AI…

Former Google Engineer Charged With Stealing AI Secrets

Alleged Chinese spy Linwei Ding is accused of stealing proprietary IP from Google This article has been indexed from www.infosecurity-magazine.com Read the original article: Former Google Engineer Charged With Stealing AI Secrets

TA4903 Phishing Campaigns Evolve, Targets US Government

Proofpoint said TA4903 adopted new tactics, including lure themes referencing confidential docs and ACH payments This article has been indexed from www.infosecurity-magazine.com Read the original article: TA4903 Phishing Campaigns Evolve, Targets US Government

TA4903 Phishing Campaigns Evolve, Target US Government

Proofpoint said TA4903 adopted new tactics, including lure themes referencing confidential docs and ACH payments This article has been indexed from www.infosecurity-magazine.com Read the original article: TA4903 Phishing Campaigns Evolve, Target US Government

Linux Malware Targets Docker, Apache Hadoop, Redis and Confluence

Cado said the payloads facilitated RCE attacks by leveraging common misconfigurations and known vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Linux Malware Targets Docker, Apache Hadoop, Redis and Confluence

Cyber Pros Turn to Cybercrime as Salaries Stagnate

The UK’s Chartered Institute of Information Security warns that many professionals are prepared to moonlight for cybercrime groups This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Pros Turn to Cybercrime as Salaries Stagnate

Skype, Google Meet, and Zoom Used in New Trojan Scam Campaign

A new threat actor has been observed by Zscaler distributing remote access Trojans (RATs) via online meeting lures This article has been indexed from www.infosecurity-magazine.com Read the original article: Skype, Google Meet, and Zoom Used in New Trojan Scam Campaign

US Sanctions Predator Spyware Maker Intellexa

The US Treasury has designated individuals and entities associated with Predator spyware developer, Intellexa This article has been indexed from www.infosecurity-magazine.com Read the original article: US Sanctions Predator Spyware Maker Intellexa

US Sanctions Predator Spyware-Maker Intellexa

The US Treasury has designated individuals and entities associated with Predator spyware developer, Intellexa This article has been indexed from www.infosecurity-magazine.com Read the original article: US Sanctions Predator Spyware-Maker Intellexa

GhostSec Evolves With Website Compromise Tools

Cisco Talos uncovered two new tools developed by the group: the “GhostSec Deep Scan tool” and “GhostPresser” This article has been indexed from www.infosecurity-magazine.com Read the original article: GhostSec Evolves With Website Compromise Tools

ALPHV/BlackCat Ransomware Servers Go Down

Speculations about the shut down range from a potential exit scam to a rebranding initiative This article has been indexed from www.infosecurity-magazine.com Read the original article: ALPHV/BlackCat Ransomware Servers Go Down

American Express Warns Credit Card Data Exposed in Third-Party Breach

American Express has informed customers that their credit card details may have been compromised following a breach of a third-party merchant processor This article has been indexed from www.infosecurity-magazine.com Read the original article: American Express Warns Credit Card Data Exposed…

Ukraine Claims it Hacked Russian MoD

Ukraine’s military intelligence service says it hacked and stole sensitive documents from Russia’s Ministry of Defense This article has been indexed from www.infosecurity-magazine.com Read the original article: Ukraine Claims it Hacked Russian MoD

TeamCity Users Urged to Patch Critical Vulnerabilities

JetBrains says on-premises TeamCity servers must be upgraded to mitigate two new bugs This article has been indexed from www.infosecurity-magazine.com Read the original article: TeamCity Users Urged to Patch Critical Vulnerabilities

Self-Propagating Worm Created to Target Generative AI Systems

The researchers developed a worm, dubbed “Morris II,” which targets generative AI ecosystems through the use of adversarial self-replicating prompts This article has been indexed from www.infosecurity-magazine.com Read the original article: Self-Propagating Worm Created to Target Generative AI Systems

Hacktivist Collective NoName057 Strikes European Targets

Sekoia.io observed developments in the group’s DDoS tools, including updates enhancing compatibility with different processor architectures and OS This article has been indexed from www.infosecurity-magazine.com Read the original article: Hacktivist Collective NoName057 Strikes European Targets

TA577 Exploits NTLM Authentication Vulnerability

Proofpoint warned the method could be used for data gathering and further malicious activities This article has been indexed from www.infosecurity-magazine.com Read the original article: TA577 Exploits NTLM Authentication Vulnerability

Predator Spyware Targeted Mobile Phones in New Countries

Despite being exposed to human rights violations, the Predator spyware continues to be used across the world – including in new countries This article has been indexed from www.infosecurity-magazine.com Read the original article: Predator Spyware Targeted Mobile Phones in New…

Securing Perimeter Products Must Be a Priority, Says NCSC

UK’s National Cyber Security Centre warns of dangers of insecure perimeter products This article has been indexed from www.infosecurity-magazine.com Read the original article: Securing Perimeter Products Must Be a Priority, Says NCSC

Drugs and Cybercrime Market Busted By German Cops

German police have dismantled the country’s largest underground marketplace: Crimemarket This article has been indexed from www.infosecurity-magazine.com Read the original article: Drugs and Cybercrime Market Busted By German Cops

Biden Warns Chinese Cars Could Steal US Citizens’ Data

President Biden warned that connected vehicles built in China could be used to steal sensitive data of US citizens and critical infrastructure This article has been indexed from www.infosecurity-magazine.com Read the original article: Biden Warns Chinese Cars Could Steal US…

Pharma Giant Cencora Reports Cybersecurity Breach

The breach was discovered on February 21 2024, according to an SEC filing published on the same day This article has been indexed from www.infosecurity-magazine.com Read the original article: Pharma Giant Cencora Reports Cybersecurity Breach

Dark Web Market Revenues Rebound but Sector Fragments

Chainalysis study of crypto flows reveals darknet markets made $1.7bn in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Dark Web Market Revenues Rebound but Sector Fragments

US Government Warns Healthcare is Biggest Target for BlackCat Affiliates

The US government advisory warns healthcare organizations are being targeted by BlackCat amid an ongoing cyber-incident affecting Change Healthcare This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government Warns Healthcare is Biggest Target for BlackCat Affiliates

TimbreStealer Malware Targets Mexican Victims with Tax-Related Lures

The maker of the Mispadu Trojan started distributing a new infostealer with financial lures to Mexican users, Cisco Talos found This article has been indexed from www.infosecurity-magazine.com Read the original article: TimbreStealer Malware Targets Mexican Victims with Tax-Related Lures

Biden Bans Mass Sale of Data to Hostile Nations

A new presidential executive order attempts to prevent the mass sales of personal data to countries like China and Russia This article has been indexed from www.infosecurity-magazine.com Read the original article: Biden Bans Mass Sale of Data to Hostile Nations

FBI Issues Alert on Russian Threats Targeting Ubiquiti Routers

The routers were hijacked to steal credentials, proxy traffic, and host phishing pages and custom tools This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Issues Alert on Russian Threats Targeting Ubiquiti Routers

34 Million Roblox Credentials Exposed on Dark Web in Three Years

Kaspersky reported a 231% surge in compromised accounts from 4.7 million in 2021 to 15.5 million in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: 34 Million Roblox Credentials Exposed on Dark Web in Three Years

Over Half of UK Firms Concerned About Insider Threats

Cifas claims that most business decision makers are worried about fraudsters targeting employees This article has been indexed from www.infosecurity-magazine.com Read the original article: Over Half of UK Firms Concerned About Insider Threats

Ads for Zero-Day Exploit Sales Surge 70% Annually

Group-IB research warns of rising use of zero-day threats in targeted attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: Ads for Zero-Day Exploit Sales Surge 70% Annually

Industrial Cyber Espionage France’s Top Threat Ahead of 2024 Paris Olympics

Ransomware and destabilization attacks rose in 2023, yet France’s National Cybersecurity Agency is most concerned about a diversification of cyber espionage campaigns This article has been indexed from www.infosecurity-magazine.com Read the original article: Industrial Cyber Espionage France’s Top Threat Ahead…

NIST Releases Final Version of Cybersecurity Framework 2.0

NIST has made further tweaks to Version 2.0 of its Cybersecurity Framework following feedback from the cybersecurity community This article has been indexed from www.infosecurity-magazine.com Read the original article: NIST Releases Final Version of Cybersecurity Framework 2.0

Four Million WordPress Sites Vulnerable to LiteSpeed Plugin Flaw

The flaw, discovered by Patchstack, stems from a lack of input sanitization and output escaping in the plugin’s code This article has been indexed from www.infosecurity-magazine.com Read the original article: Four Million WordPress Sites Vulnerable to LiteSpeed Plugin Flaw

Half of IT Leaders Identify IoT as Security Weak Point

The Viakoo study also said 50% firms faced IoT cyber incidents in past year, 44% of which were severe This article has been indexed from www.infosecurity-magazine.com Read the original article: Half of IT Leaders Identify IoT as Security Weak Point

Most Commercial Code Contains High-Risk Open Source Bugs

Synopsys report reveals 74% of codebases now contain risky open source components This article has been indexed from www.infosecurity-magazine.com Read the original article: Most Commercial Code Contains High-Risk Open Source Bugs

69% of Organizations Infected by Ransomware in 2023

Proofpoint found that 69% of organizations experienced a successful ransomware incident in the past year, with 60% hit on four or more occasions This article has been indexed from www.infosecurity-magazine.com Read the original article: 69% of Organizations Infected by Ransomware…

Business Logic Abuse Dominates as API Attacks Surge

Imperva finds attacks targeting API business logic increased to 27% in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Business Logic Abuse Dominates as API Attacks Surge

CISA Issues Alert on APT29’s Cloud Infiltration Tactics

Known as Midnight Blizzard, the Dukes or Cozy Bear, the group has been identified as a Russian entity likely operating under the SVR This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Issues Alert on APT29’s Cloud…

Expert Warns of Growing Android Malware Activity

Kaspersky said that in 2023, the number of mobile attacks soared to nearly 33.8 million This article has been indexed from www.infosecurity-magazine.com Read the original article: Expert Warns of Growing Android Malware Activity

LockBit Takedown: What You Need to Know about Operation Cronos

What businesses should know about Operation Cronos and LockBit, one of the largest ransomware takedowns in history This article has been indexed from www.infosecurity-magazine.com Read the original article: LockBit Takedown: What You Need to Know about Operation Cronos

Avast Faces $16.5m Fine for Unlawfully Selling User Browsing Data

The FTC order found that Avast sold browsing data to advertisers that could reveal highly sensitive insights about users, misleading them about privacy protections in the process This article has been indexed from www.infosecurity-magazine.com Read the original article: Avast Faces…

NCSC to Offer Cyber Governance Guidance to Boards

The UK’s National Cyber Security Centre is preparing a new cyber governance training pack for boards This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC to Offer Cyber Governance Guidance to Boards

U-Haul Informs Customers of Major Data Breach

Moving giant U-Haul has revealed that 67,000 customers were caught in a data breach last year This article has been indexed from www.infosecurity-magazine.com Read the original article: U-Haul Informs Customers of Major Data Breach

Operation Cronos: Who Are the LockBit Admins

Law enforcement agencies involved in Operation Cronos have announced they have been in contact with the LockBit kingpin aka LockbitSupp This article has been indexed from www.infosecurity-magazine.com Read the original article: Operation Cronos: Who Are the LockBit Admins