Category: www.infosecurity-magazine.com

Rust Payloads Exploiting Ivanti Zero-Days Linked to Sophisticated Sliver Toolkit

After analyzing the 12 Rust payloads exploiting Ivanti ConnectSecure vulnerabilities, Synacktiv found they all enabled a sophisticated post-exploitation toolkit This article has been indexed from www.infosecurity-magazine.com Read the original article: Rust Payloads Exploiting Ivanti Zero-Days Linked to Sophisticated Sliver Toolkit

FBI: Scammers Are Sending Couriers to Collect Cash From Victims

The FBI is warning the public not to fall for scams where they are urged to liquidate assets and hand them to couriers for ‘safekeeping’ This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI: Scammers Are Sending…

Phobos Ransomware Family Expands With New FAUST Variant

FortiGuard said the variant was found in an Office document using a VBA script This article has been indexed from www.infosecurity-magazine.com Read the original article: Phobos Ransomware Family Expands With New FAUST Variant

Nigerian ‘Yahoo Boys’ Behind Social Media Sextortion Surge in the US

Nigeria-based cybercriminals known as Yahoo Boys are the main drivers of a financial sextortion increase on TikTok, Instagram and Snapchat, targeting English-speaking teenagers This article has been indexed from www.infosecurity-magazine.com Read the original article: Nigerian ‘Yahoo Boys’ Behind Social Media…

Microsoft Provides Defense Guidance After Nation-State Compromise

Microsoft said the Russian nation-state group Midnight Blizzard obfuscated its attack through the use of an OAuth application This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Provides Defense Guidance After Nation-State Compromise

Dark Web Drugs Vendor Forfeits $150m After Guilty Plea

Drug trafficker Banmeet Singh made $150m in cryptocurrency from dark web sales This article has been indexed from www.infosecurity-magazine.com Read the original article: Dark Web Drugs Vendor Forfeits $150m After Guilty Plea

CI/CD at Risk as Exploits Released For Critical Jenkins Bug

Customers are urged to patch now after exploits are released for critical vulnerability in Jenkins This article has been indexed from www.infosecurity-magazine.com Read the original article: CI/CD at Risk as Exploits Released For Critical Jenkins Bug

Ukraine Arrests Hacker for Assisting Russian Missile Strikes

Ukraine’s security services said that the IT specialist from Kharkiv targeted government websites and provided intelligence to Russia to carry out missile strikes This article has been indexed from www.infosecurity-magazine.com Read the original article: Ukraine Arrests Hacker for Assisting Russian…

New Leaks Expose Web of Iranian Intelligence and Cyber Companies

Recorded Future analyzed leaks describing the close relationship between the Iranian government and Iran-aligned APT groups This article has been indexed from www.infosecurity-magazine.com Read the original article: New Leaks Expose Web of Iranian Intelligence and Cyber Companies

North Korea Hacks Crypto: More Targets, Lower Gains

A global drop in DeFi hacking gains prompted North Korean threat actors to diversify and extend their victim portfolio, Chainalysis found This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korea Hacks Crypto: More Targets, Lower Gains

Southern Water Confirms Data Breach Following Black Basta Claims

Southern Water confirmed a data breach had occurred after the Black Basta ransomware group purportedly published personal information held by the firm This article has been indexed from www.infosecurity-magazine.com Read the original article: Southern Water Confirms Data Breach Following Black…

Pwn2Own Contest Unearths Dozens of Zero-Day Vulnerabilities

The Zero Day Initiative’s first Pwn2Own Automotive competition has handed out over $1m for 24 zero-days This article has been indexed from www.infosecurity-magazine.com Read the original article: Pwn2Own Contest Unearths Dozens of Zero-Day Vulnerabilities

HPE Says SolarWinds Hackers Accessed its Emails

Hewlett Packard Enterprise reveals that Russian state APT29 hackers stole data from corporate mailboxes This article has been indexed from www.infosecurity-magazine.com Read the original article: HPE Says SolarWinds Hackers Accessed its Emails

ChatGPT Cybercrime Surge Revealed in 3000 Dark Web Posts

Kaspersky said cybercriminals are exploring schemes to implement ChatGPT in malware development This article has been indexed from www.infosecurity-magazine.com Read the original article: ChatGPT Cybercrime Surge Revealed in 3000 Dark Web Posts

Browser Phishing Threats Grew 198% Last Year

Finding comes from Menlo Security’s recently released 2023 State of Browser Security Report This article has been indexed from www.infosecurity-magazine.com Read the original article: Browser Phishing Threats Grew 198% Last Year

Why Bulletproof Hosting is Key to Cybercrime-as-a-Service

As a critical infrastructure service for cybercriminals, bulletproof hosting should be tracked and blocked by defenders, Intel471 argued in a new blog post This article has been indexed from www.infosecurity-magazine.com Read the original article: Why Bulletproof Hosting is Key to…

X Makes Passkeys Available for US-Based Users

X (formerly Twitter) has announced that passkeys are available as a login option for US-based users on iOS following a spate of high-profile account hijacks This article has been indexed from www.infosecurity-magazine.com Read the original article: X Makes Passkeys Available…

Exploit Code Released For Critical Fortra GoAnywhere Bug

Researchers have released exploit code for a critical bug in managed file transfer software Fortra GoAnywhere This article has been indexed from www.infosecurity-magazine.com Read the original article: Exploit Code Released For Critical Fortra GoAnywhere Bug

AI Set to Supercharge Ransomware Threat, Says NCSC

The National Cyber Security Centre claims in a new report that AI will increase volume and impact of ransomware attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: AI Set to Supercharge Ransomware Threat, Says NCSC

Hackers Target Atlassian Confluence With RCE Exploits

Shadowserver reported over 39,000 exploitation attempts from 600 unique IP addresses, mainly Russian This article has been indexed from www.infosecurity-magazine.com Read the original article: Hackers Target Atlassian Confluence With RCE Exploits

French Watchdog Slams Amazon with €32m Fine for Spying on Workers

The French CNIL has fined Amazon France Logistique $35m for an “excessively intrusive” surveillance system set up to monitor the performance of its staff This article has been indexed from www.infosecurity-magazine.com Read the original article: French Watchdog Slams Amazon with…

Australia Sanctions Russian Hacker Behind Medibank Breach

The Australian government has sanctioned Russian national Aleksandr Ermakov for his role in the Medibank data breach This article has been indexed from www.infosecurity-magazine.com Read the original article: Australia Sanctions Russian Hacker Behind Medibank Breach

Mega-Breach Database Exposes 26 Billion Records

A haul of 26 billion records found online was compiled from historic breaches This article has been indexed from www.infosecurity-magazine.com Read the original article: Mega-Breach Database Exposes 26 Billion Records

SEC Confirms SIM Swap Attack Behind X Account Takeover

The Securities and Exchange Commission says hackers hijacked its X account in a SIM swap attack after MFA was disabled This article has been indexed from www.infosecurity-magazine.com Read the original article: SEC Confirms SIM Swap Attack Behind X Account Takeover

LoanDepot Data Breach Hits 16.6 Million Customers

The US loan giant confirmed 16.6 million customers had “sensitive personal” information stolen in a cyber-attack This article has been indexed from www.infosecurity-magazine.com Read the original article: LoanDepot Data Breach Hits 16.6 Million Customers

LoanDepot Data Breach Hits 16.6 Customers

The US loan giant confirmed 16.6 million customers had “sensitive personal” information stolen in a cyber-attack This article has been indexed from www.infosecurity-magazine.com Read the original article: LoanDepot Data Breach Hits 16.6 Customers

Thai Court Blocks 9near.org to Avoid Exposure of 55M Citizens

Thailand’s data breaches fell in 2022-2023, but Resecurity is warning of rising cyber-threats This article has been indexed from www.infosecurity-magazine.com Read the original article: Thai Court Blocks 9near.org to Avoid Exposure of 55M Citizens

New macOS Malware Targets Cracked Apps

Kaspersky said the malware targeted macOS Ventura 13.6 and newer versions This article has been indexed from www.infosecurity-magazine.com Read the original article: New macOS Malware Targets Cracked Apps

CISA Emergency Directive Demands Action on Ivanti Zero-Days

US security agency CISA orders all civilian federal agencies to take immediate steps to mitigate two Ivanti zero-day flaws This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Emergency Directive Demands Action on Ivanti Zero-Days

Russian Spies Brute Force Senior Microsoft Staff Accounts

Russian intelligence hackers compromise emails of senior Microsoft leadership with simple password spray attacks This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Spies Brute Force Senior Microsoft Staff Accounts

Russian Coldriver Hackers Deploy Malware to Target Western Officials

Google has warned that the Russia-linked Coldriver has expanded its targeting of Western officials by deploying malware to exfiltrate sensitive data This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Coldriver Hackers Deploy Malware to Target Western…

Experts Urge Clearer Direction in South Africa’s Cyber Strategy

South Africa’s cyber defenses have been lacking direction and resources for too long, researchers from the Carnegie Endowment for International Peace argued This article has been indexed from www.infosecurity-magazine.com Read the original article: Experts Urge Clearer Direction in South Africa’s…

TA866 Resurfaces in Targeted OneDrive Campaign

Proofpoint said it thwarted a large-scale campaign on January 11 primarily targeting North America This article has been indexed from www.infosecurity-magazine.com Read the original article: TA866 Resurfaces in Targeted OneDrive Campaign

New Malware Campaign Exploits 9hits in Docker Assault

Discovered by Cado Security, the campaign deploys two containers to vulnerable Docker instances This article has been indexed from www.infosecurity-magazine.com Read the original article: New Malware Campaign Exploits 9hits in Docker Assault

Iranian Phishing Campaign Targets Israel-Hamas War Experts

Microsoft said the social engineering campaign aims to steal sensitive data from experts deemed to be able to influence intelligence and policies relating to the Israel-Hamas War This article has been indexed from www.infosecurity-magazine.com Read the original article: Iranian Phishing…

Illicit Cryptocurrency Flows Drop 39% in 2023

Chainalysis data shows major drop in value of funds received into underground crypto addresses in 2023, to $24.2bn This article has been indexed from www.infosecurity-magazine.com Read the original article: Illicit Cryptocurrency Flows Drop 39% in 2023

NCSC Builds New “Cyber League” Threat Tracking Community

The UK’s National Cyber Security Centre has launched a Cyber League to monitor emerging cyber-threats This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Builds New “Cyber League” Threat Tracking Community

AI, Gaming, FinTech Named Major Cybersecurity Threats For Kids

Kaspersky also noted smart home device popularity and malicious apps as threats to children in 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: AI, Gaming, FinTech Named Major Cybersecurity Threats For Kids

OpenAI Announces Plans to Combat Misinformation Amid 2024 Elections

OpenAI will implement a provenance standard into DALL-E 3 and link ChatGPT to an authoritative election website in the US This article has been indexed from www.infosecurity-magazine.com Read the original article: OpenAI Announces Plans to Combat Misinformation Amid 2024 Elections

75% of Organizations Hit by Ransomware in 2023

Veeam found that 75% of organizations suffered at least one ransomware attack last year, with 26% hit four or more times This article has been indexed from www.infosecurity-magazine.com Read the original article: 75% of Organizations Hit by Ransomware in 2023

US Government Urges Action to Mitigate Androxgh0st Malware Threat

An advisory from the FBI and CISA says threat actors are deploying the Androxgh0st malware for victim identification and exploitation in target networks This article has been indexed from www.infosecurity-magazine.com Read the original article: US Government Urges Action to Mitigate…

Majorca Tourist Hotspot Hit With $11m Ransom Demand

Municipality of Calvià on the Spanish island of Majorca was hit by a ransomware attack last weekend This article has been indexed from www.infosecurity-magazine.com Read the original article: Majorca Tourist Hotspot Hit With $11m Ransom Demand

GitHub Rotates Credentials and Patches New Bug

GitHub urges customers to apply a new patch and take action if impacted by credential rotation This article has been indexed from www.infosecurity-magazine.com Read the original article: GitHub Rotates Credentials and Patches New Bug

Phemedrone Stealer Targets Windows Defender Flaw Despite Patch

The malware targets browsers, steals crypto wallet and messaging app data, and collects system information This article has been indexed from www.infosecurity-magazine.com Read the original article: Phemedrone Stealer Targets Windows Defender Flaw Despite Patch

New Tool Identifies Pegasus and Other iOS Spyware

Kaspersky experts developed the tool after analyzing Shutdown.log, a file retaining reboot information This article has been indexed from www.infosecurity-magazine.com Read the original article: New Tool Identifies Pegasus and Other iOS Spyware

Email Nightmare: 94% of Firms Hit by Phishing Attacks in 2023

In its latest Email Security Risk Report, Egress found that businesses were 10% more negatively affected by phishing attacks in 2023 than in 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: Email Nightmare: 94% of Firms…

Ivanti Zero-Days Exploited By Multiple Actors Globally

Volexity detects 1700 compromised Ivanti VPN devices following publication of two zero-days last week This article has been indexed from www.infosecurity-magazine.com Read the original article: Ivanti Zero-Days Exploited By Multiple Actors Globally

Researchers Uncover Major Surge in Global Botnet Activity

Netscout found a spike from 10,000 to 143,957 devices in scans between December 2023 and early January 2024 This article has been indexed from www.infosecurity-magazine.com Read the original article: Researchers Uncover Major Surge in Global Botnet Activity

Senators Demand Probe into SEC Hack After Bitcoin Price Spike

US senators have accused the SEC of failing to properly secure its social media accounts after hackers comprised its X account and posted a fake Bitcoin announcement This article has been indexed from www.infosecurity-magazine.com Read the original article: Senators Demand…

Python-Based Tool FBot Disrupts Cloud Security

Discovered by the SentinelLabs team, FBot targets web servers, cloud services and SaaS platforms This article has been indexed from www.infosecurity-magazine.com Read the original article: Python-Based Tool FBot Disrupts Cloud Security

Environmental Websites Hit by DDoS Surge in COP28 Crossfire

Content delivery provider Cloudflare observed a staggering surge in DDoS attacks against environmental services during COP28 This article has been indexed from www.infosecurity-magazine.com Read the original article: Environmental Websites Hit by DDoS Surge in COP28 Crossfire

British Library Catalogue Back Online After Ransomware Attack

The main British Library catalogue will be back online on Monday, January 15, as the institution continues its technical rebuild following the ransomware attack last year This article has been indexed from www.infosecurity-magazine.com Read the original article: British Library Catalogue…

Security Experts Urge IT to Lock Down GitHub Services

A new Recorded Future report warns of growing abuse of GitHub and recommends blocking risky services This article has been indexed from www.infosecurity-magazine.com Read the original article: Security Experts Urge IT to Lock Down GitHub Services

CISA Urges Critical Infrastructure to Patch Urgent ICS Vulnerabilities

CISA’s advisory provides mitigations for vulnerabilities in ICS products used in critical infrastructure industries like energy, manufacturing and transportation This article has been indexed from www.infosecurity-magazine.com Read the original article: CISA Urges Critical Infrastructure to Patch Urgent ICS Vulnerabilities

Waiting for Your Pay Raise? Cofense Warns Against HR-Related Scams

Email security provider Cofense outlined some of the most common HR-related scams and phishing campaigns it has observed This article has been indexed from www.infosecurity-magazine.com Read the original article: Waiting for Your Pay Raise? Cofense Warns Against HR-Related Scams

Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise

Bitdefender researchers revealed the vulnerability allows an attacker to send commands to the thermostat and replace its firmware This article has been indexed from www.infosecurity-magazine.com Read the original article: Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise

Mandiant’s X Account Was Hacked in Brute-Force Password Attack

Mandiant has shared its findings following X account hijacking, firm blames misconfigured 2FA and X’s policy change This article has been indexed from www.infosecurity-magazine.com Read the original article: Mandiant’s X Account Was Hacked in Brute-Force Password Attack

NCSC Publishes Practical Security Guidance For SMBs

The UK’s National Cyber Security Centre has launched a new online security guide to help smaller organizations better manage risk This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Publishes Practical Security Guidance For SMBs

Two Ivanti Zero-Days Actively Exploited in the Wild

Ivanti has released mitigation steps after reports of active exploitation of Connect Secure and Policy Secure vulnerabilities This article has been indexed from www.infosecurity-magazine.com Read the original article: Two Ivanti Zero-Days Actively Exploited in the Wild

Cyber Insecurity and Misinformation Top WEF Global Risk List

Cyber-attacks and misinformation top WEF’s list of global risks, with cybercrime poised to exploit tech advancements and AI dominance raising concerns about vulnerability This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Insecurity and Misinformation Top WEF…

Malware Takedowns Show Progress, But Fight Against Cybercrime Not Over

Law enforcement operations on cybercriminal infrastructure have proven efficient at hindering malware activity but are far from being a silver bullet, according to Recorded Future This article has been indexed from www.infosecurity-magazine.com Read the original article: Malware Takedowns Show Progress,…

Cyber Insurance Market to be Worth Over $90bn by 2033

Market.Us found that the global cyber insurance market will be worth $90.6bn by 2033, driven by increasing cyber-threats and growing regulations This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber Insurance Market to be Worth Over $90bn…

Ukrainian “Blackjack” Hackers Take Out Russian ISP

State-backed Ukrainian hacking group Blackjack has launched a destructive attack against a Moscow-based ISP in retaliation for Kyivstar attack This article has been indexed from www.infosecurity-magazine.com Read the original article: Ukrainian “Blackjack” Hackers Take Out Russian ISP

Microsoft Fixes 12 RCE Bugs in January Patch Tuesday

Critical Hyper-V flaw one of 12 remote code execution vulnerabilities fixed this Patch Tuesday This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Fixes 12 RCE Bugs in January Patch Tuesday

82% of Companies Struggle to Manage Security Exposure

The figure comes from XM Cyber’s 2024 State of Security Posture Report, exploring how organizations approach cybersecurity challenges This article has been indexed from www.infosecurity-magazine.com Read the original article: 82% of Companies Struggle to Manage Security Exposure

Cybersecurity Deals Boom as Investment Dips, Pinpoint Reports

2023 saw an increased number of deals in the cybersecurity industry, but the overall investment in the sector dropped, Pinpoint revealed This article has been indexed from www.infosecurity-magazine.com Read the original article: Cybersecurity Deals Boom as Investment Dips, Pinpoint Reports

New Decryption Key Available for Babuk Tortilla Ransomware Victims

Cisco Talos announced that a decryption key for the Babuk Tortilla ransomware variant is available for victims to download This article has been indexed from www.infosecurity-magazine.com Read the original article: New Decryption Key Available for Babuk Tortilla Ransomware Victims

Nigerian Gets 10 Years For Laundering Scam Funds

A Nigerian national has been sentenced to a decade behind bars for his role in romance and BEC scam This article has been indexed from www.infosecurity-magazine.com Read the original article: Nigerian Gets 10 Years For Laundering Scam Funds

LoanDepot Confirms Ransomware Attack in SEC Filing

Mortgage lender LoanDepot has revealed a ransomware breach resulting in stolen and encrypted data This article has been indexed from www.infosecurity-magazine.com Read the original article: LoanDepot Confirms Ransomware Attack in SEC Filing

New Research: Tackling .NET Malware With Harmony Library

New research from Check Point explores the significance of code manipulation in malware analysis This article has been indexed from www.infosecurity-magazine.com Read the original article: New Research: Tackling .NET Malware With Harmony Library

Anti-Hezbollah Groups Hack Beirut Airport Screens

AP said departure and arrival screens displayed a message accusing Hezbollah of jeopardizing Lebanon This article has been indexed from www.infosecurity-magazine.com Read the original article: Anti-Hezbollah Groups Hack Beirut Airport Screens

Turkish APT Sea Turtle Resurfaces, Spies on Dutch IT Firms

Turkey-aligned espionage group Sea Turtle has been conducting campaigns targeting Dutch telecommunication and media organizations This article has been indexed from www.infosecurity-magazine.com Read the original article: Turkish APT Sea Turtle Resurfaces, Spies on Dutch IT Firms

North Korean Hackers Stole $600m in Crypto in 2023

North Korean hackers remain effective in stealing cryptocurrency despite growing international law enforcement action This article has been indexed from www.infosecurity-magazine.com Read the original article: North Korean Hackers Stole $600m in Crypto in 2023

Merck Settles With Insurers Over $700m NotPetya Claim

Pharma giant Merck has reached a settlement with cyber-insurers that refused to pay out for “acts of war” This article has been indexed from www.infosecurity-magazine.com Read the original article: Merck Settles With Insurers Over $700m NotPetya Claim

19 xDedic Cybercrime Market Users and Admins Face Prison

The dark web site’s infrastructure was taken down in 2019 following an international law enforcement operation This article has been indexed from www.infosecurity-magazine.com Read the original article: 19 xDedic Cybercrime Market Users and Admins Face Prison

Cyber-Attacks Drain $1.84bn from Web3 in 2023

A Certik report found there was $1.84bn in losses across 751 cybersecurity incidents targeting Web3 in 2023 This article has been indexed from www.infosecurity-magazine.com Read the original article: Cyber-Attacks Drain $1.84bn from Web3 in 2023

23andMe Blames User “Negligence” for Data Breach

A 23andMe letter sent to a legal firm representing victims of the data breach claims that users were at fault for recycling passwords This article has been indexed from www.infosecurity-magazine.com Read the original article: 23andMe Blames User “Negligence” for Data…

LastPass Enforces 12-Character Master Passwords

Password manager provider LastPass has started implementing stricter password measures for its customers This article has been indexed from www.infosecurity-magazine.com Read the original article: LastPass Enforces 12-Character Master Passwords

Ukraine Blames Russian Sandworm Hackers for Kyivstar Attack

Ukraine’s security service says Sandworm accessed Kyivstar’s system at least six months before launching the attack This article has been indexed from www.infosecurity-magazine.com Read the original article: Ukraine Blames Russian Sandworm Hackers for Kyivstar Attack