Infosecurity News
CNI Firms: Climate Tech is Increasing Cyber Risk
UK’s critical infrastructure sector concerned over expanding attack surface
Estee Lauder Breached by Two Ransomware Groups
Cosmetics giant confirms data was taken
Chinese APT41 Linked to WyrmSpy and DragonEgg Surveillanceware
Lookout attributed WyrmSpy and DragonEgg to APT41 due to overlapping Android signing certificates
Critical API Security Gaps Found in Financial Services
The Salt Security report also notes a 244% surge in unique attackers between H1 and H2 2022
How Cyber Threat Intelligence Practitioners Should Leverage Automation and AI
The Cyber Threat Intelligence Summit discussed how automation and generative AI could help CTI practitioners tackle the overload of data they have to process
Biden-Harris Administration Unveils Smart Device Cyber Program
The criteria for certification are set to be based on cybersecurity guidelines published by NIST
Industry Experts Urge CISA to Update Secure by Design Guidance
A letter authored by industry experts says that CISA should include specific details on how to implement security-by-design through threat modeling
Scam Job Offers Target Uni Students
Threat actors exploit high cost of living
NCA: Nation States Using Cybercrime Groups as Proxies
Crime agency chief warns of surging online threat
Norwegian Giant Tomra Suffers “Extensive” Attack
Employees forced to work from home after IT outage
New Vulnerabilities Found in Adobe ColdFusion
Rapid7 has observed that some vulnerabilities in Adobe ColdFusion were still being exploited several days after the patches were published
CISA Unveils Guide to Aid Firms Transition to Cloud Security
It mentions the CSET, SCuBAGear, Untitled Goose Tool, Decider and Memory Forensic on Cloud
drIBAN Fraud Operations Target Corporate Banking Customers
The web injects allow cyber-criminals to manipulate legitimate web pages' content in real time
JumpCloud Confirms Data Breach By Nation-State Actor
The attack vector was identified as data injection into the firm's commands framework
Suspected Scareware Fraudster Arrested After Decade on the Run
Ukrainian said to have caused victim losses of $70m
WooCommerce Bug Exploited in Targeted WordPress Attacks
Wordfence claims over 157,000 sites have been hit so far
IT Security Pro Jailed for Attempted Extortion
Hertfordshire man pleaded guilty in May
BreachForums Admin Pleads Guilty to Hacking Charges
The guilty plea also covered a separate count of possession of child pornography
Ukraine's CERT-UA Exposes Gamaredon's Rapid Data Theft Methods
The group utilize malware like GAMMASTEEL to rapidly exfiltrate files within 30-50 minutes
Sorillus RAT and Phishing Attacks Exploit Google Firebase Hosting
eSentire found the threat after detecting suspicious code in a manufacturing customer's network