Latest Cybersecurity News and Articles
06 October 2023
Semiconductor companies in East Asia are being targeted by a China-linked threat actor using a backdoor called HyperBro to deploy Cobalt Strike beacons. The attack chain includes the use of social engineering techniques, such as decoy PDF documents.
06 October 2023
Jeremy Rahn was hired as Director of Data Governance, IT and Security Operations Team at DataDelivers. Rahn has 15 years of cybersecurity experience.
06 October 2023
As much as $7 billion in cryptocurrency has been illicitly laundered through cross-chain crime, with the North Korea-linked Lazarus Group linked to the theft of roughly $900 million of those proceeds between July 2022 and July of this year.
"As traditional entities such as mixers continue to be subject to seizures and sanctions scrutiny, the crypto crime displacement to chain- or asset-hopping
06 October 2023
A global cybercriminal operation called BadBox has infected the firmware of more than 70,000 Android smartphones, CTV boxes, and tablets with the Triada malware.
The post Android Devices With Backdoored Firmware Found in US Schools appeared first on SecurityWeek.
06 October 2023
The data obtained by the attacker may include personal information, genetic ancestry results, and potential relatives' details of 23andMe customers who opted-in to the "DNA Relatives" service.
06 October 2023
According to Microsoft, ransomware gangs are evolving their tactics, with an increase in data exfiltration attacks and the targeting of smaller organizations and less well-known software.
06 October 2023
A new survey reveals that Canadian organizations are unprepared to handle and recover from new cyber threats including artificial intelligence.
06 October 2023
The attackers are using a Remote Management System (RMS) executable to trick victims into downloading malware disguised as banned applications like ExpressVPN, WeChat, and Skype.
06 October 2023
The Royal Women's Hospital in Melbourne has experienced a data breach, potentially compromising the personal information of 192 patients. The breach occurred when cybercriminals gained unauthorized access to a staff member's private email account.
06 October 2023
Qakbot malware operators have continued their malicious activities, distributing Ransom Knight ransomware and the Remcos backdoor via phishing emails, despite the recent infrastructure takedown.
06 October 2023
A new survey reveals 39% of participants express frustration and 37% feel intimidated by the process of staying secure online.
06 October 2023
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says.
The post Microsoft Releases New Report on Cybercrime, State-Sponsored Cyber Operations appeared first on SecurityWeek.
06 October 2023
Researchers have discovered a new Android Trojan called GoldDigger that can primarily target users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets. GoldDigger's reach may extend beyond Vietnam. Countering them demands client-side fraud protection solutions that emphasize real-time protection, adaptability, and a focus on behavioral indicators.
06 October 2023
The breach involved health information, Social Security numbers, and financial data of donors and clients, prompting Blackbaud to pay a ransom to the intruder in exchange for deleting the stolen data.
06 October 2023
Builders Mutual Insurance Co. experienced a data breach that compromised the personal information of over 64,000 customers and employees, including sensitive data like Social Security numbers and medical information.
06 October 2023
Threat actors have been observed targeting semiconductor companies in East Asia with lures masquerading as Taiwan Semiconductor Manufacturing Company (TSMC) that are designed to deliver Cobalt Strike beacons.
The intrusion set, per EclecticIQ, leverages a backdoor called HyperBro, which is then used as a conduit to deploy the commercial attack simulation software and post-exploitation toolkit.
06 October 2023
The CISA is focusing on the growing threat activity from China, which has become the top nation-state cyber adversary to the U.S., particularly targeting critical infrastructure like rail transportation and energy sectors.
06 October 2023
Noteworthy stories that might have slipped under the radar: cybersecurity funding increases, new laws, and government’s illegal use of smartphone location data.
The post In Other News: Funding Increase, Abuse of Smartphone Location Data, Legal Matters appeared first on SecurityWeek.
06 October 2023
The Electronic Privacy Information Center (EPIC) has filed a complaint urging the FTC to investigate Grindr for potentially illegally storing and disclosing users' sensitive data, including HIV and vaccination status.
06 October 2023
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations.
The post Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA appeared first on SecurityWeek.