Infosecurity News
New WikiLoader Malware Goes to Extreme Lengths to Hide
Its authors are actively and rapidly developing it
SpyNote Android Spyware Strikes Financial Institutions
Cleafy said the malware exploits Accessibility services to conduct multiple malicious activities
APT31 Implants Target Industrial Organizations
The attackers established a channel for data exfiltration, including from air-gapped systems
Biden Announces National Cyber Workforce and Education Strategy
The White House says that filling cyber job vacancies is a national security imperative
UK Military Embraces Security by Design
The initiative is designed to transform how cybersecurity is addressed in capability programs across the MoD
Ongoing STARK#MULE Attack Campaign Discovered
The campaign appears directed at Korean-speaking victims, indicating an origin in North Korea
Global Lawyers Unveil Cyber Best Practices for Execs
International Bar Association offers practical policy recommendations
Think Tank: Insurers Not Fuelling Ransomware Market
RUSI report makes recommendations for the industry
CISA: New Submarine Backdoor Used in Barracuda Campaign
Chinese threat actor used malware in attacks
Security Serious Unsung Heroes Awards 2023 Open for Nominations
Nominations are open for the eighth annual Security Serious Unsung Heroes Awards.
UK MoD Error Sends Emails to Russia’s Ally Instead of US
The MoD clarified that the incident involved fewer than 20 emails and none were top secret
New Study Reveals Forged Certificate Attack Risks
Attempts can lead to unauthorized access to important company resources
40% of Ubuntu Cloud Workloads Vulnerable to Exploits
Wiz Research said the vulnerabilities were discovered in the Linux filesystem, OverlayFS
Microsoft Accused of Negligence in Recent Email Compromise
In an open letter, Senator Ron Wyden urged federal agencies to investigate Microsoft following a Chinese campaign that compromised US government emails
Australia and US Issue Warning About Web App Threats
The advisory issues recommendations for developers and end users on reducing the prevalence of access control vulnerabilities
SSNDOB Marketplace Admin Pleads Guilty
Site was used to trade stolen data
North Korean Hackers Bag Another $100m in Crypto Heists
Two new breaches traced back to prolific Lazarus group
MOVEit Campaign Claims Millions More Victims
US government services firm is latest to reveal compromise
Security Incident Impacts CardioComm’s Operations
Several of the company’s products are affected by the outage
High Severity Vulnerabilities Discovered in Ninja Forms Plugin
The popular forms builder plugin for WordPress has over 900,000 active installations