0

Microsoft Threat Report: How Russia’s War on Ukraine Is Impacting the Global Cybersecurity Community

Thứ Tư, 31 tháng 1, 2024
The Russians are engaged in widespread influence operations designed to erode trust, increase polarization, and threaten democratic processes around the globe.
0

Johnson Controls Ransomware Cleanup Costs Top $27M and Counting

JCI's latest SEC filing notes that its smart-factory installations weren't compromised, allaying physical security fears.
0

More Ivanti VPN Zero-Days Fuel Attack Frenzy as Patches Finally Roll

Both China-backed APTs and ordinary cyberattackers have seized on a pair of Ivanti VPN bugs for global exploitation.
0

Looted RIPE Credentials for Sale on the Dark Web

A monitoring exercise identified user details in 716 compromised RIPE NCC accounts, plus other valuable credentials belonging to those victims.
0

Cohesity Research Reveals Most Companies Pay Millions in Ransoms

Thứ Ba, 30 tháng 1, 2024
0

Forcepoint Federal Rebrands As Everfox to Reflect New Era of Defense-Grade Cybersecurity

0

Feds Reportedly Try to Disrupt 'Volt Typhoon' Attack Infrastructure

The China-linked threat actor's attacks on US critical infrastructure organizations have alarmed American intelligence officials, Reuters says.
0

PoC Exploits Heighten Risks Around Critical New Jenkins Vuln

Thứ Hai, 29 tháng 1, 2024
The arbitrary file-read flaw can lead to remote code execution.
0

SolarWinds Files Motion to Dismiss SEC Lawsuit

Responding to SEC charges, SolarWinds fired back with a detailed defense of how a Russian-backed cyber espionage attack on its system was handled.
0

New Jersey School District Shut Down by Cyberattack

Sunday night, Freehold Township district officials notified its staff and parents that school would not be in session Monday due to technical difficulties caused by a cyber incident.
0

Israeli Government: Smallest of SMBs Hit Hardest in Cyberattacks

Companies with fewer than 20 employees suffered the largest number of attacks among small to midsize businesses, according to Israel's Small and Medium Business Agency.
0

Bastille Raises $44M Series C Investment Led by Goldman Sachs Asset Management

Thứ Sáu, 26 tháng 1, 2024
0

Newly ID'ed Chinese APT Hides Backdoor in Software Updates

The threat actor went more than half a decade before being discovered — thanks to a remarkable backdoor delivered in invisible adversary-in-the-middle attacks.
0

Microsoft Shares New Guidance in Wake of 'Midnight Blizzard' Cyberattack

Threat actors created and abused OAuth apps to access Microsoft's corporate email environment and remain there for weeks.
0

Series of Cyberattacks Hit Ukrainian Critical Infrastructure Organizations

It's unclear if the attacks — which hit oil and gas, postal service, transport safety, and railway organizations in the nation — were related.
0

Abu Dhabi Investment Firm Warns About Scam Efforts

Thứ Năm, 25 tháng 1, 2024
A top financial entity warned that its brand is being used to spread cyber scams, as fraud efforts persist throughout the country.
0

Google Kubernetes Clusters Suffer Widespread Exposure to External Attackers

Misunderstanding the permissions of an authentication group in Google Kubernetes Engine (GKE) opens millions of containers to anyone with a Google account.
0

CISA's Water Sector Guide Puts Incident Response Front & Center

Thứ Tư, 24 tháng 1, 2024
As cyberattackers increasingly target water suppliers and wastewater utilities, the US federal government wants to help limit the impact of destructive attacks.
0

AI Learning Initiative Launches for UAE Women

The effort will train 100 women in technology and cybersecurity around artificial intelligence concepts.
0

Kasseika Ransomware Linked to BlackMatter in BYOVD Attack

An emerging actor is the latest to deploy a tactic that terminates AV processes and services before deploying its payload; the campaign is part of a bigger "bring your own vulnerable driver" trend.
0

Subway Puts a LockBit Investigation on the Menu

Thứ Ba, 23 tháng 1, 2024
The foot-long sandwich purveyor is looking into LockBit 3.0 claims that it stole reams of data from the proprietary "SBS" network.
0

SEC Says SIM Swap to Blame for Breached X Account

Crypto hackers gained control of a phone number associated with the government agency's account after MFA was disabled in July.
0

Millions at Risk As 'Parrot' Web Server Compromises Take Flight

The cyberattackers behind the traffic redirection system (TDS) inject websites with malicious scripts, have control over thousands of servers worldwide, and have ramped up efforts to avoid detection.
0

CISA Director Jen Easterly Targeted in Swatting Incident

A phone call to authorities claimed that a shooting had taken place on Easterly's block.
0

Microsoft Falls Victim to Russia-Backed 'Midnight Blizzard' Cyberattack

Thứ Hai, 22 tháng 1, 2024
Russian state-sponsored threat actor Nobelium used a basic password-spray attack to breach Microsoft corporate email accounts, including for execs.
0

German IT Consultant Fined Thousands for Reporting Security Failing

The company, Modern Solutions, had misconfigured a cloud database, but argues the contractor could only have found the password through insider knowledge.
0

Israel, Czech Republic Reinforce Cyber Partnership Amid Hamas War

The agreement to enable future sharing of information and experience is part of a spate of inter-country threat intelligence agreements that Israel is signing, as war-related attacks ramp up.
0

Battling Misinformation During Election Season

Dissemination of false information, often with the intent to deceive, has become a pervasive issue amplified by artificial intelligence (AI) tools.
0

Survey Shows a Surge in (Artificial) Intelligence

A new Omdia survey shows a rapid increase in generative AI adoption for security
0

AI Gives Defenders the Advantage in Enterprise Defense

Thứ Sáu, 19 tháng 1, 2024
A panel of CISOs acknowledged that artificial intelligence has boosted the capabilities of threat actors, but enterprise defenders are actually benefiting more from the technology.
0

CISOs Struggle for C-Suite Status Even As Expectations Skyrocket

An IANS survey shows that CISOs shoulder more and more legal and regulatory liability for data breaches, but few are getting the recognition or support they need.
0

Microsoft: Iran's Mint Sandstorm APT Blasts Educators, Researchers

The Charming Kitten-related cyber-espionage group is posing as legitimate journalists and researchers to get intel on the Israel-Hamas war.
0

Missing the Cybersecurity Mark With the Essential Eight

Australia's Essential Eight Maturity Model still doesn't address key factors needed to protect today's cloud and SaaS environments.
0

Citrix Discovers 2 Vulnerabilities, Both Exploited in the Wild

Thứ Năm, 18 tháng 1, 2024
These vulnerabilities are the second and third for Citrix but are not expected to be as detrimental as "CitrixBleed."
0

Cybercrooks Target Docker Containers With Novel Pageview Generator

Cyberattackers are exploiting Docker instances to drop the bot-tastic 9hits Web traffic generator and "earn" valuable credits that can be turned into cash.
0

With Attacks on the Upswing, Cyber-Insurance Premiums Poised to Rise Too

Insurers doubled premiums in late 2021 to offset losses from ransomware claims. With attacks rising again, organizations can anticipate a new round of increases.
0

'Punchmade Dev' Cybercrime Rapper Launches Cash-Scamming Web Shop

Thứ Tư, 17 tháng 1, 2024
For a small sum, users can reportedly buy Cash App credentials already loaded with thousands of dollars.
0

CISA: AWS, Microsoft 365 Accounts Under Active 'Androxgh0st' Attack

Cyberattackers are targeting Apache webservers and websites using the popular Laravel Web application framework in order to steal credentials for the apps.
0

Q&A: How One Company Gauges Its Employees' Cybersecurity 'Fluency'

Cybersecurity compliance training is commonplace, but one Jordan-based company has taken an extra step in testing.
0

Ivanti Zero-Day Exploits Skyrocket Worldwide; No Patches Yet

Thứ Ba, 16 tháng 1, 2024
Anyone who hasn't mitigated two zero-day security bugs in Ivanti VPNs may already be compromised by a Chinese nation-state actor.
0

Bosch Smart Thermostat Feels the Heat From Firmware Bug

The vulnerability in a popular hospitality industry gadget allows attackers to take over the device, pivot into the user's network, or brick the device entirely, rendering HVAC unusable.
0

Africa, Middle East Lead Peers in Cybersecurity, But Lag Globally

Both regions score above average compared to similar sized economies, but investing in updated technologies and patching processes would help cyber resilience globally.
0

UAE Cyber Security Council, Khalifa University Launch Abu Dhabi Academy

The university will also join the Emirates' National Cybersecurity Center of Excellence.
0

Anti-Ransomware Coalition Bound to Fail Without Key Adjustments

International pledge to reject ransomware demands misses the most important way to combat cybercrime: prevention.
0

As Enterprise Cloud Grows, So Do Challenges

Thứ Hai, 15 tháng 1, 2024
Parenting teaches many lessons, including that difficulties get more complicated as you grow. Here's what to look for in a partner to share the "big-kid problems" of distributed cloud.
0

Zero Trust, AI, Capital Markets Drive Consolidation in Cloud Security

Companies that quickly shifted to cloud-native operations are looking for greater visibility and protection — and AI benefits — while an uncertain economic future has VCs looking toward safety.
0

Name That Toon: Cast Adrift

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0

CISA Adds 9.8 'Critical' Microsoft SharePoint Bug to its KEV Catalog

Thứ Sáu, 12 tháng 1, 2024
It's a tale as old as time: an old, long-since patched vulnerability that remains actively exploited.
0

GitLab Releases Updates to Address Critical Vulnerabilities

Two vulnerabilities are critical, and three others are determined to be of high, medium, and low severity.
0

Hyundai MEA X Account Hacked, Followed by Crypto Promotion

Attackers hit more X accounts to promote Overworld Bitcoin registration.
0

Cybersecurity Incidents Consistently Increase in UAE

Malicious insider threats are increasingly becoming a cause for concern among businesses in the United Arab Emirates.
0

CES 2024: Will the Coolest New AI Gadgets Protect Your Privacy?

Thứ Tư, 10 tháng 1, 2024
Consumer electronics manufacturers are innovating fast. Regulators are slow to keep up. Data privacy is in the balance.
0

Bitcoin Prices Spike After SEC X Account Hack

A fraudulent post was taken down in less than 20 minutes, but that didn't stop it from gaining over 1 million views in that short period of time.
0

Adapting Security to Protect AI/ML Systems

AI/ML libraries create much larger attack surfaces, and traditional IT security lacks several key capabilities for protecting them.
0

Has the Investment Bubble Burst in Israeli Cybersecurity?

Start-up funding for new Israeli cybersecurity companies has plummeted — and market-watchers expect that to continue throughout 2024.
0

Path Traversal Bug Besets Popular Kyocera Office Printers

Thứ Ba, 9 tháng 1, 2024
A printer bug could lead to much worse, in IT networks without proper segmentation.
0

Ransomware Gang Gives Toronto Zoo the Monkey Business

As the investigation continues, the zoo reports that it does not store the credit card information of its guests.
0

Delinea Acquires Authomize to Strengthen Extended PAM

0

Turkish APT 'Sea Turtle' Resurfaces to Spy on Kurdish Opposition

Thứ Hai, 8 tháng 1, 2024
An old state-aligned threat actor is back on the radar, thanks to recent EMEA espionage campaigns against a minority ethnic group.
0

US, Israel Used Dutch Spy to Launch Stuxnet Malware Against Iran

Report says US and Israel spent $1 billion to develop the infamous Stuxnet virus, built to sabotage Iran's nuclear program in 2008.
0

Beirut Airport Cyberattack Targets Hezbollah

In addition to posting messages criticizing the group, the cyberattackers disrupted flight information and baggage handling systems.
0

Protecting Critical Infrastructure Means Getting Back to Basics

Critical infrastructure organizations need to recognize that the technology and cybersecurity landscapes have changed.
0

Iranian Crypto Exchange Misstep Exposes User Details

Iranian citizens' personal details were left visible online due to a misconfigured storage system.
0

North Korea Debuts 'SpectralBlur' Malware Amid macOS Onslaught

Thứ Sáu, 5 tháng 1, 2024
The post-exploitation backdoor is the latest in a string of custom tools aimed at spying on Apple users.
0

Cyber-Focused FBI Agents Deploy to Embassies Globally

The bureau is adding six new positions placed in locations that include New Delhi and Rome.
0

Dubai-US Deal Aims to Secure Medical, IoT Devices in the Middle East

IoT surge across the Middle East spawns demand for more secure devices in business, healthcare, and energy.
0

Apache ERP Zero-Day Underscores Dangers of Incomplete Patches

Thứ Năm, 4 tháng 1, 2024
Apache fixed a vulnerability in its OfBiz enterprise resource planning (ERP) framework last month, but attackers and researchers found a way around the patch.
0

Russia Kyivstar Hack Should Alarm West, Ukraine Security Chief Warns

If Ukraine's core telephone network can be taken out, organizations in the West could easily be next, Ukraine's SBU chief says.
0

Administrator Account For Middle East Internet Registry Hacked

The compromise reportedly led to corruption in the routing of a Spanish telecom provider's network.
0

Mandiant's X (Twitter) Account Hacked to Promote Crypto Scam

The hours-long breach — since resolved — directed users to a suspicious website as attackers posing as crypto-wallet service Phantom took over the feed of the Google subsidiary.
0

Cybercriminals Flood Dark Web With X (Twitter) Gold Accounts

Thứ Tư, 3 tháng 1, 2024
Verified accounts for celebs and organizations deliver a deep vein of cybercrime riches for crooks.
0

Pilfered Data From Iranian Insurance and Food Delivery Firms Leaked Online

Online food ordering service and insurance firms hit by mystery hackers using the moniker "irleaks."
0

Cybercriminals Share Millions of Stolen Records During Holiday Break

Thứ Ba, 2 tháng 1, 2024
The "Leaksmus" event on the Dark Web exposed some 50 million records containing sensitive information from people all around the world.
0

Cyberattackers Target Nuclear Waste Company via LinkedIn

The hackers were unsuccessful in their attempt, but this is not the first time the company has experienced this kind of attack.
0

Attackers Abuse Google OAuth Endpoint to Hijack User Sessions

Infostealers such as Lumma and Rhadamanthys have integrated the generation of persistent Google cookies through token manipulation.
0

Localization Mandates, AI Regs to Pose Major Data Challenges in 2024

With more than three-quarters of countries adopting some form of data localization and, soon, three-quarters of people worldwide protected by privacy rules, companies need to take care.
0

Startups Scramble to Build Immediate AI Security

AI may be inherently insecure, but only a handful of startups have put forward real visions to mitigate AI's threats and keep data private.
0

10 Years After Yahoo Breach, What's Changed? (Not Much)

Yahoo customers suffered the largest data breaches in history by some measures. But a decade on, experts warn, we still haven't learned our lesson.