Infosecurity News

  1. Global Campaign Targets PlugX Malware with Innovative Portal

    Sekoia’s innovative PlugX malware disinfection campaign removed active threats across ten countries

  2. New DoubleClickjacking Attack Bypasses Protections

    DoubleClickjacking bypasses X-Frame-Options and SameSite cookies in double-click sequences, exposing UI authentication flaws

  3. HIPAA Rules Update Proposed to Combat Healthcare Data Breaches

    The US government has set out proposals to increase security obligations on healthcare providers to protect patient data amid surging cyber-attacks in the sector

  4. Hackers Leak Rhode Island Citizens' Data on Dark Web

    The State of Rhode Island has confirmed that cybercriminals have begun publishing data stolen from its social services portal, the RIBridges system

  5. Dozens of Chrome Browser Extensions Hijacked by Data Thieves

    Over 2.5 million end users are at risk as researchers discover 36 compromised Chrome extensions

  6. US Treasury Computers Accessed by China in Supply Chain Attack

    Chinese hackers appear to have compromised Treasury machines via a trusted third party

  7. Majority of UK SMEs Lack Cybersecurity Policy

    Insurance firm Markel Direct found that 69% of UK SMEs lack a cybersecurity policy, with a significant lack of basic cybersecurity measures in place across these firms

  8. CISA's 2024 Review Highlights Major Efforts in Cybersecurity Industry Collaboration

    The US Cybersecurity and Infrastructure Security Agency’s 2024 Year in Review marks Jen Easterly’s final report before resignation

  9. Infostealers Dominate as Lumma Stealer Detections Soar by Almost 400%

    The vacuum left by RedLine’s takedown will likely lead to a bump in the activity of other a infostealers

  10. US and Japan Blame North Korea for $308m Crypto Heist

    A joint US-Japan alert attributed North Korean hackers with a May 2024 crypto heist worth $308m from Japan-based company DMM

  11. Spyware Maker NSO Group Liable for WhatsApp User Hacks

    A US judge has ruled in favor of WhatsApp in a long-running case against commercial spyware-maker NSO Group

  12. Major Biometric Data Farming Operation Uncovered

    Researchers at iProov have discovered a dark web group compiling identity documents and biometric data to bypass KYC checks

  13. Ransomware Attack Exposes Data of 5.6 Million Ascension Patients

    US healthcare giant Ascension revealed that 5.6 million individuals have had their personal, medical and financial information breached in a ransomware attack

  14. Critical Vulnerabilities Found in WordPress Plugins WPLMS and VibeBP

    The vulnerabilities, now patched, posed significant risks, including unauthorized file uploads, privilege escalation and SQL injection attacks

  15. Cryptomining Malware Found in Popular Open Source Packages

    Cryptomining malware hits popular npm packages rspack and vant, posing risks to open source tools

  16. Interpol Identifies Over 140 Human Traffickers in New Initiative

    A new digital operation has enabled Interpol to identify scores of human traffickers operating between South America and Europe

  17. ICO Warns of Mobile Phone Festive Privacy Snafu

    The Information Commissioner’s Office has warned that millions of Brits don’t know how to erase personal data from their old devices

  18. Italy’s Data Protection Watchdog Issues €15m Fine to OpenAI Over ChatGPT Probe

    OpenAI must also initiate a six-month public awareness campaign across Italian media, explaining how it processes personal data for AI training

  19. Ukraine's Security Service Probes GRU-Linked Cyber-Attack on State Registers

    The Security Service of Ukraine has accused Russian-linked actors of perpetrating a cyber-attack against the state registers of Ukraine

  20. LockBit Admins Tease a New Ransomware Version

    The LockBitSupp persona said LockBit 4.0 will be launched in February 2025

What’s hot on Infosecurity Magazine?