Infosecurity News
Crypto Casino Stake.com Back Online After $40m Heist
Hot wallets were compromised at firm
Mend.io SAML Vulnerability Exposed
SAML flaw in enabled rogue customers to access others’ SaaS data
Airlines Battle Surge in Loyalty Program Fraud
Group-IB said 2022 saw 30% more loyalty fraud, impacting 75+ airlines and involving 2000 malicious sources
UK Electoral Commission Fails Cybersecurity Test Amid Data Breach
Auditors cited outdated software and unsupported iPhones as key reasons for the failed test
More Schools Hit By Cyber-Attacks Before Term Begins
Highgate Wood School forced to delay new term for six days
UK National Cyber Security Centre Gets a New CTO
Industry veteran Ollie Whitehouse is confirmed
Freecycle Breach May Have Hit Millions of Users
Non-profit urges all users to reset passwords
Python Package Index Targeted Again By VMConnect
ReversingLabs uncovered three additional malevolent packages believed to be part of the campaign
New Attack Technique “MalDoc in PDF” Alarms Experts
JPCERT/CC said it can elude detection by embedding a malicious Word file within a PDF document
Medical Data Breach: Ayush Jharkhand Hacked
According to CloudSEK, the leaked database contains over 320,000 patient records
Sensitive Data about UK Military Sites Potentially Leaked by LockBit
Zaun, the UK’s only manufacturer of fencing systems, saw its IT systems being compromised in early August
Sydney University Suffers Supply Chain Breach
Blast radius appears limited to international students
Four Convicted in $18m Investment Fraud Scheme
The Brittingham Group promised outsized returns to victims
Suffolk High School Forced Offline After Cyber-Attack
Separate research warns of widespread email security failings
Smishing Triad: China-Based Fraud Network Exposed
Resecurity explained the “Smishing Triad” campaign exclusively utilizes iMessages
Open-Source Malware SapphireStealer Expands
Cisco Talos said SapphireStealer has evolved significantly, resulting in multiple variants
Sophisticated Cyber-Espionage Group Earth Estries Exposed
Trend Micro noted that “Earth Estries” employed advanced tactics to infiltrate networks
Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Although the patches for these vulnerabilities have already been released, public attacks are still occurring
BYOD Security Gap: Survey Finds 49% of European Firms Unprotected
Jamf suggested firms enroll employees in a BYOD or Mobile Device Management (MDM) program
New Research Exposes Airbnb as Breeding Ground For Cybercrime
Slashnext unveiled a disturbing arsenal of stealers, cookies and exploits