Category: www.infosecurity-magazine.com

SMBs at Risk From SendGrid-Focused Phishing Tactics

Kaspersky explained the fraudulent emails prompted recipients to enable two-factor authentication This article has been indexed from www.infosecurity-magazine.com Read the original article: SMBs at Risk From SendGrid-Focused Phishing Tactics

Change Healthcare Cyber-Attack Leads to Prescription Delays

The incident has impacted numerous Change Healthcare applications, including pharmacy, medical records This article has been indexed from www.infosecurity-magazine.com Read the original article: Change Healthcare Cyber-Attack Leads to Prescription Delays

Cyber Pros Embrace AI, Over 80% Believe It Will Enhance Jobs

ISC2 found that 82% of cybersecurity professionals believe AI will improve the efficiency of their jobs This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Pros Embrace AI, Over 80% Believe It Will Enhance Jobs

Chinese Duo Found Guilty of $3m Apple Fraud Plot

Two Maryland residents have been convicted of a multimillion-dollar fraud scheme against Apple This article has been indexed from www.infosecurity-magazine.com Read the original article: Chinese Duo Found Guilty of $3m Apple Fraud Plot

Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited

Researchers warn of a “ransomware free-for-all” after ScreenConnect vulnerability is exploited This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited

Over 40% of Firms Struggle With Cybersecurity Talent Shortage

Kaspersky’s recent report said the shortage is particularly acute in Europe, Russia and Latin America This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 40% of Firms Struggle With Cybersecurity Talent Shortage

Biden Executive Order to Bolster US Maritime Cybersecurity

The White House Executive Order will give new powers to the US Coast Guard to manage cyber threats in ports and issue cybersecurity standards This article has been indexed from www.infosecurity-magazine.com Read the original article: Biden Executive Order to Bolster…

Exclusive: eSentire Confirms Rhysida Ransomware Victims

Since emerging in May 2023, the group claims to have victimized 77 companies and public institutions This article has been indexed from www.infosecurity-magazine.com Read the original article: Exclusive: eSentire Confirms Rhysida Ransomware Victims

Russian Hackers Launch Email Campaigns to Demoralize Ukrainians

ESET researchers reveal a Russian threat actor has targeted Ukrainian citizens with PYSOPs messages warning of impacts such as food and medicine shortages from the war This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Hackers Launch…

NCSC Sounds Alarm Over Private Branch Exchange Attacks

The UK’s National Cyber Security Centre has produced new guidance for smaller firms on PBX attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Sounds Alarm Over Private Branch Exchange Attacks

Attacker Breakout Time Falls to Just One Hour

It now takes threat actors on average just 62 minutes to move laterally from initial access, Crowdstrike claims This article has been indexed from www.infosecurity-magazine.com Read the original article: Attacker Breakout Time Falls to Just One Hour

New Typosquatting and Repojacking Tactics Uncovered on PyPI

ReversingLabs uncovered two suspicious packages on PyPI: NP6HelperHttptest and NP6HelperHttper This article has been indexed from www.infosecurity-magazine.com Read the original article: New Typosquatting and Repojacking Tactics Uncovered on PyPI

Linux Malware Campaign “Migo” Targets Redis For Cryptomining

Cado Security said this campaign introduces unique techniques to compromise the security of Redis servers This article has been indexed from www.infosecurity-magazine.com Read the original article: Linux Malware Campaign “Migo” Targets Redis For Cryptomining

Top UK Universities Recovering Following Targeted DDoS Attack

The attack, which has been claimed by Anonymous Sudan, has been confirmed to have impacted IT services at the universities of Cambridge and Manchester This article has been indexed from www.infosecurity-magazine.com Read the original article: Top UK Universities Recovering Following…

Initial Ransomware Demands Jump 20% to $600,000 in 2023

Arctic Wolf found that the median ransomware demand was $600,000 in 2023, a 20% rise on the previous year This article has been indexed from www.infosecurity-magazine.com Read the original article: Initial Ransomware Demands Jump 20% to $600,000 in 2023

LockBit Infrastructure Disrupted by Global Law Enforcers

UK’s National Crime Agency has led an international operation to disrupt the LockBit ransomware group This article has been indexed from www.infosecurity-magazine.com Read the original article: LockBit Infrastructure Disrupted by Global Law Enforcers

Insider Steals 80,000 Email Addresses From District Councils

A former employee at Stratford-on-Avon District Council stole residents’ emails to promote his business This article has been indexed from www.infosecurity-magazine.com Read the original article: Insider Steals 80,000 Email Addresses From District Councils

Lockbit Infrastructure Disrupted by Global Law Enforcers

UK’s National Crime Agency has led an international operation to disrupt the Lockbit ransomware group This article has been indexed from www.infosecurity-magazine.com Read the original article: Lockbit Infrastructure Disrupted by Global Law Enforcers

Anatsa Banking Trojan Resurfaces, Targets European Banks

ThreatFabric said the campaign has evolved since last year, employing sophisticated methods and mainly targeting Samsung devices This article has been indexed from www.infosecurity-magazine.com Read the original article: Anatsa Banking Trojan Resurfaces, Targets European Banks

Fake Tokens Exploit BRICS Investment Hype

Resecurity said bad actors exploited geopolitical narratives, spreading misinformation This article has been indexed from www.infosecurity-magazine.com Read the original article: Fake Tokens Exploit BRICS Investment Hype

Israeli Aircraft Survive “Cyber-Hijacking” Attempts

Hackers have attempted to divert two commercial Israeli aircraft in recent days, reports claim This article has been indexed from www.infosecurity-magazine.com Read the original article: Israeli Aircraft Survive “Cyber-Hijacking” Attempts

Fifth of British Kids Have Broken the Law Online

A new National Crime Agency study reveals 20% of 10- to 16-year-olds have violated the Computer Misuse Act This article has been indexed from www.infosecurity-magazine.com Read the original article: Fifth of British Kids Have Broken the Law Online

New Ivanti Vulnerability Observed as Widespread Security Concerns Grow

After discovering a new vulnerability impacting its Connect Secure, Policy Secure, and ZTA gateways, Ivanti is under fire for poor security practices This article has been indexed from www.infosecurity-magazine.com Read the original article: New Ivanti Vulnerability Observed as Widespread Security…

Hackers Exploit EU Agenda in Spear Phishing Campaigns

Adversaries targeting EU-based victims increasingly leverage EU affairs in spear phishing attacks, CERT-EU found This article has been indexed from www.infosecurity-magazine.com Read the original article: Hackers Exploit EU Agenda in Spear Phishing Campaigns

“TicTacToe Dropper” Malware Distribution Tactics Revealed

A new Fortinet analysis revealed a plethora of final-stage payloads delivered by a series of malware droppers This article has been indexed from www.infosecurity-magazine.com Read the original article: “TicTacToe Dropper” Malware Distribution Tactics Revealed

Prudential Financial Faces Cybersecurity Breach

The breach exposed administrative and user data from specific IT systems, but there is no evidence of customer or client data compromise This article has been indexed from www.infosecurity-magazine.com Read the original article: Prudential Financial Faces Cybersecurity Breach

Crypto-Money Laundering Records 30% Annual Decline

Chainalysis data reveals a near-30% fall in the value of digital currency being laundered in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Crypto-Money Laundering Records 30% Annual Decline

PII Input Sparks Cybersecurity Alarm in 55% of DLP Events

Menlo Security’s latest report also revealed a 26% surge in security policies tailored for generative AI sites This article has been indexed from www.infosecurity-magazine.com Read the original article: PII Input Sparks Cybersecurity Alarm in 55% of DLP Events

Cybersecurity Spending Expected to be Slashed in 41% of SMEs

JumpCloud found that 41% of SME IT professionals expect cybersecurity spending to be cut in their organization, increasing the risk of cyber-attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybersecurity Spending Expected to be Slashed in…

Microsoft Fixes Two Zero-Days in February Patch Tuesday

Two zero-day bugs actively exploited in the wild now have official Microsoft patches This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Fixes Two Zero-Days in February Patch Tuesday

Romantic AI Chatbots Fail the Security and Privacy Test

Mozilla warns of serious security and privacy concerns over romantic chatbots downloaded by 100 million users This article has been indexed from www.infosecurity-magazine.com Read the original article: Romantic AI Chatbots Fail the Security and Privacy Test

Southern Water Notifies Customers and Employees of Data Breach

UK utilities firm Southern Water has informed 5-10% of its customer base that their personal data has been accessed following a ransomware attack in January This article has been indexed from www.infosecurity-magazine.com Read the original article: Southern Water Notifies Customers…

Bank of America Customers at Risk After Data Breach

A notification letter sent to the Attorney General of Maine showed 57,028 individuals were impacted This article has been indexed from www.infosecurity-magazine.com Read the original article: Bank of America Customers at Risk After Data Breach

CISA Reveals JCDC’s 2024 Cybersecurity Priorities

These will focus on countering APTs, fortifying critical infrastructure and anticipating emerging risks This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Reveals JCDC’s 2024 Cybersecurity Priorities

Notorious Bumblebee Malware Re-emerges with New Attack Methods

Proofpoint researchers observed a new Bumblebee social engineering campaign in February following a four-month absence This article has been indexed from www.infosecurity-magazine.com Read the original article: Notorious Bumblebee Malware Re-emerges with New Attack Methods

UK Businesses Lose £31bn to Security Breaches in a Year

Beaming data reveals the cost of UK cybersecurity breaches surged 138% over four years to £31.5bn This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Businesses Lose £31bn to Security Breaches in a Year

China Targets US Hacking Ops in Media Offensive

Claims include allegations of US hacking into seismic sensors at the Wuhan Earthquake Monitoring Center This article has been indexed from www.infosecurity-magazine.com Read the original article: China Targets US Hacking Ops in Media Offensive

Malicious Campaign Impacts Hundreds of Microsoft Azure Accounts

Proofpoint has observed an ongoing campaign targeting the Microsoft Azure applications of hundreds of individuals with operational and executive roles This article has been indexed from www.infosecurity-magazine.com Read the original article: Malicious Campaign Impacts Hundreds of Microsoft Azure Accounts

US Offers $10m Reward for Hive Ransomware Leaders

The US government said it will pay up to $10m for information leading to the identification of Hive leaders, and up to $5m for information leading to the arrest of any affiliates This article has been indexed from www.infosecurity-magazine.com Read…

US Dismantles Warzone RAT Malware Operation

US authorities have seized domains and arrested individuals in connection with the Warzone RAT This article has been indexed from www.infosecurity-magazine.com Read the original article: US Dismantles Warzone RAT Malware Operation

US Consumers Lose a Record $10bn+ to Fraud Last Year

Fraud cost US adults over $10bn in 2023, a record high, says the FTC This article has been indexed from www.infosecurity-magazine.com Read the original article: US Consumers Lose a Record $10bn+ to Fraud Last Year

AI-Powered Robocalls Banned Ahead of US Election

US companies using AI-generated voices during a call without prior consent could receive fines of up to $23,000 per call This article has been indexed from www.infosecurity-magazine.com Read the original article: AI-Powered Robocalls Banned Ahead of US Election

20 Years of Facebook, but Trust in Social Media Remains Rock Bottom

Facebook and other social media companies struggle with trust, with only 6% globally comfortable sharing personal data, according to a 2024 Thales survey This article has been indexed from www.infosecurity-magazine.com Read the original article: 20 Years of Facebook, but Trust…

Raspberry Robin Evolves With Stealth Tactics, New Exploits

The findings come from Check Point researchers, who published a new analysis on Wednesday This article has been indexed from www.infosecurity-magazine.com Read the original article: Raspberry Robin Evolves With Stealth Tactics, New Exploits

Linux Devs Rush to Patch Critical Vulnerability in Shim

The flaw allows the installation of malware that operates at the firmware level This article has been indexed from www.infosecurity-magazine.com Read the original article: Linux Devs Rush to Patch Critical Vulnerability in Shim

Critical Manufacturing Vulnerabilities Surge 230% in Six Months

Nozomi Networks reveals increasingly sophisticated attacks targeting bugs and other vectors in IoT and OT environments This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical Manufacturing Vulnerabilities Surge 230% in Six Months

US Warns of Destructive Chinese Cyber-Attacks

The US claims to have discovered Chinese Volt Typhoon intrusions in multiple critical infrastructure sectors This article has been indexed from www.infosecurity-magazine.com Read the original article: US Warns of Destructive Chinese Cyber-Attacks

Governments and Tech Giants Unite Against Commercial Spyware

Over 25 governments and 14 tech companies vowed to fight against the proliferation of commercial spyware This article has been indexed from www.infosecurity-magazine.com Read the original article: Governments and Tech Giants Unite Against Commercial Spyware

Google and CSA Singapore Combat Android Fraud With New Pilot

The initiative aim to tackle mobile fraud by auto-blocking apps seeking sensitive permissions This article has been indexed from www.infosecurity-magazine.com Read the original article: Google and CSA Singapore Combat Android Fraud With New Pilot

Ransomware Payments Hit $1bn All-Time High in 2023

Chainalysis monitoring of blockchain transactions reveals ransomware payments hit a record $1bn in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Payments Hit $1bn All-Time High in 2023

Ransomware Payments Hit $1bn All-Time High Last Year

Chainalysis monitoring of blockchain transactions reveals ransomware payments hit a record $1bn in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Payments Hit $1bn All-Time High Last Year

Malware-as-a-Service Now the Top Threat to Organizations

The Darktrace report observed an increasing cross-functional adaption of many MaaS strains in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Malware-as-a-Service Now the Top Threat to Organizations

Meta’s Oversight Board Urges a Policy Change After a Fake Biden Video

A fake video showing US President Joe Biden touching his granddaughter’s chest remains on Facebook despite an Oversight Board investigation This article has been indexed from www.infosecurity-magazine.com Read the original article: Meta’s Oversight Board Urges a Policy Change After a…

Latest Ivanti Zero Day Exploited By Scores of IPs

Shadowserver Foundation spots 170 distinct IP addresses trying to exploit Ivanti zero-day CVE-2024-21893 This article has been indexed from www.infosecurity-magazine.com Read the original article: Latest Ivanti Zero Day Exploited By Scores of IPs

US Cracks Down on Spyware with Visa Restrictions

The US government will deny visas to those involved in misusing spyware This article has been indexed from www.infosecurity-magazine.com Read the original article: US Cracks Down on Spyware with Visa Restrictions

ResumeLooters Gang Raids Retail and Job Site Data

Group-IB uncovers mass data theft campaign from Chinese-speaking ResumeLooters hackers This article has been indexed from www.infosecurity-magazine.com Read the original article: ResumeLooters Gang Raids Retail and Job Site Data

Pennsylvania Courts’ Website Disrupted by DoS Attack

A number of court web systems have been taken offline in the US state of Pennsylvania following a denial of service attack This article has been indexed from www.infosecurity-magazine.com Read the original article: Pennsylvania Courts’ Website Disrupted by DoS Attack

AnyDesk Hit by Cyber-Attack and Customer Data Breach

The cyber-attack that hit the remote tool provider could have a more significant impact than initially expected This article has been indexed from www.infosecurity-magazine.com Read the original article: AnyDesk Hit by Cyber-Attack and Customer Data Breach

Clorox and Johnson Controls Reveal $76m Cyber-Attack Bill

SEC filings reveal multimillion-dollar costs of two serious 2023 cyber-attacks on Clorox and Johnson Controls This article has been indexed from www.infosecurity-magazine.com Read the original article: Clorox and Johnson Controls Reveal $76m Cyber-Attack Bill

UK Court Backlog Blocks Attempts to Fight Fraud Epidemic

KPMG research finds a similar number of high-value UK fraud cases heard in 2023 to previous year This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Court Backlog Blocks Attempts to Fight Fraud Epidemic

Romance Scam Victims Surge in 2023

New data from Lloyds found that romance scam victims increased by 22% in 2023, with the average amount lost per incident £6937 This article has been indexed from www.infosecurity-magazine.com Read the original article: Romance Scam Victims Surge in 2023

Cloudflare Suffers Breach After Failing to Rotate Stolen Okta Credentials

Cloudflare revealed suspected nation-state attackers compromised its systems and accessed source code using credentials stolen in the Okta breach This article has been indexed from www.infosecurity-magazine.com Read the original article: Cloudflare Suffers Breach After Failing to Rotate Stolen Okta Credentials

LockBit Reigns Supreme in Soaring Ransomware Landscape

The last quarter of 2023 saw an 80% year-on-year increase in ransomware victim claims, according to ReliaQuest This article has been indexed from www.infosecurity-magazine.com Read the original article: LockBit Reigns Supreme in Soaring Ransomware Landscape

Interpol-Led Initiative Targets 1300 Suspicious IPs

Global collaborative effort focused on combating the global rise of phishing, malware and ransomware This article has been indexed from www.infosecurity-magazine.com Read the original article: Interpol-Led Initiative Targets 1300 Suspicious IPs

Pump-and-Dump Schemes Make Crypto Fraudsters $240m

Chainalysis reveals that pump-and-dump schemes made Ethereum market manipulators over $240m in 2023 alone This article has been indexed from www.infosecurity-magazine.com Read the original article: Pump-and-Dump Schemes Make Crypto Fraudsters $240m

Google’s Bazel Exposed to Command Injection Threat

Cycode stressed securing software supply chains amid complex dependencies and third-party actions This article has been indexed from www.infosecurity-magazine.com Read the original article: Google’s Bazel Exposed to Command Injection Threat

Ivanti Releases Zero-Day Patches and Reveals Two New Bugs

Ivanti has finally released updates to fix two zero-day bugs and two new high-severity vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Ivanti Releases Zero-Day Patches and Reveals Two New Bugs

EU Launches First Cybersecurity Certification for Digital Products

The voluntary scheme aims to encourage ICT providers to boost the cybersecurity of products and services across the EU This article has been indexed from www.infosecurity-magazine.com Read the original article: EU Launches First Cybersecurity Certification for Digital Products

Pawn Storm’s Stealthy Net-NTLMv2 Assault Revealed

Trend Micro reported recent attacks focused on government sectors, including foreign affairs, energy, defense and transportation This article has been indexed from www.infosecurity-magazine.com Read the original article: Pawn Storm’s Stealthy Net-NTLMv2 Assault Revealed

US Senators Propose Cybersecurity Agriculture Bill

The Farm and Food Cybersecurity Act has cross-party support and aims enhance the US agriculture sector’s cyber defenses This article has been indexed from www.infosecurity-magazine.com Read the original article: US Senators Propose Cybersecurity Agriculture Bill

Sysdig Report Exposes 91% Failure in Runtime Scans

The research also revealed 69% of enterprises have yet to integrate AI into cloud environments This article has been indexed from www.infosecurity-magazine.com Read the original article: Sysdig Report Exposes 91% Failure in Runtime Scans

US Sanctions Egyptian IT Experts Aiding ISIS in Cybersecurity

The US said the two Egyptian nationals provided cybersecurity training and support to ISIS leadership and supporters, as well as helping enable the group to use cryptocurrency This article has been indexed from www.infosecurity-magazine.com Read the original article: US Sanctions…

Citibank Sued For Failing to Protect Fraud Victims

New York attorney general launches legal case against Citi for failing to reimburse or protect fraud victims This article has been indexed from www.infosecurity-magazine.com Read the original article: Citibank Sued For Failing to Protect Fraud Victims

City Cyber Taskforce Launches to Secure Corporate Finance

A new initiative led by the ICAEW and NCSC launches today to improve cybersecurity during deals and investments This article has been indexed from www.infosecurity-magazine.com Read the original article: City Cyber Taskforce Launches to Secure Corporate Finance