Infosecurity News

  1. Huione Guarantee Marketplace Exposed as Front for Cybercrime

    Researchers at Elliptic claim multibillion dollar Huione Guarantee platform is enabler of scams and money laundering

  2. Smishing Triad Targets India with Fraud Surge

    Smishing Triad's MO involves registering fraudulent domain names that mimic legitimate organizations

  3. Microsoft Outlook Faced Critical Zero-Click RCE Vulnerability

    For trusted senders, the flaw is zero-click, but requires one-click interactions for untrusted ones

  4. Ransomware Groups Prioritize Defense Evasion for Data Exfiltration

    A Cisco report highlighted TTPs used by the most prominent ransomware groups to evade detection, establish persistence and exfiltrate sensitive data

  5. Russian Media Uses AI-Powered Software to Spread Disinformation

    RT leverages the Meliorator software to create fake personas on social media, US, Canadian and Dutch agencies have found

  6. Most Security Pros Admit Shadow SaaS and AI Use

    Next DLP study finds majority of security professionals have used unauthorised apps in past year

  7. Microsoft Fixes Four Zero-Days in July Patch Tuesday

    Microsoft has addressed two actively exploited and two publicly disclosed zero-day bugs this month

  8. Cyber-Attack on Evolve Bank Exposed Data of 7.6 Million Customers

    In a statement on Monday, Evolve confirmed the breach includes over 20,000 customers in Maine

  9. Eldorado Ransomware Strikes Windows and Linux Networks

    Group-IB also revealed the ransomware uses Chacha20 and RSA-OAEP for encryption

  10. Chinese State Actor APT40 Exploits N-Day Vulnerabilities “Within Hours”

    A joint government advisory warned that the Chinese state-sponsored actor APT40 is capable of immediately exploiting newly public vulnerabilities in widely used software

  11. Avast Provides DoNex Ransomware Decryptor to Victims

    Researchers at Avast found a flaw in the cryptographic schema of the DoNex ransomware and have been sending out decryptor keys to victims since March 2024

  12. Just a Fifth of Manufacturers Have Strongest Anti-Phishing Protection

    Study confirms most manufacturers with DMARC don’t have it configured to most secure policy

  13. Ticketmaster Extortion Continues, Threat Actor Claims New Ticket Leak

    Tickets to Foo Fighters, Aerosmith, Pink and Usher gigs have been leaked by a threat actor trying to extort Ticketmaster

  14. New APT CloudSorcerer Malware Hits Russian Targets

    The malware issues commands via a hardcoded charcode table and Microsoft COM object interfaces

  15. Mekotio Trojan Targets Latin American Banking Credentials

    Trend Micro said the trojan has been observed masquerading as communications from tax agencies

  16. Cisco Warns regreSSHion Vulnerability Impacts Multiple Products

    Cisco has told customers that 42 of its products are impacted by the OpenSSH regreSSHion vulnerability, with a further 51 products being investigated

  17. Russia Blocks VPN Services in Information Crackdown

    The ban comes from Russian communication watchdog Roskomnadzor, likely in a bid to control the flow of information to Russian citizens

  18. Crypto Thefts Double to $1.4 Billion, TRM Labs Finds

    Higher average token prices are the likely cause of the surge rather than a change in the crypto threat landscape

  19. 10 Billion Passwords Leaked on Hacking Forum

    A Cybernews investigation found that nearly 10 billion unique passwords have been posted on a popular hacking forum, putting users worldwide at risk of account compromises

  20. Vinted Fined €2.3m Over Data Protection Failure

    The Lithuanian data protection authority has imposed a fine of almost $2.5m on second-hand specialist Vinted for breaching GDPR

What’s hot on Infosecurity Magazine?