Infosecurity News
UK Law Enforcers Arrest 400 in Major Fraud Crackdown
British police have swooped on 400 fraud suspects and seized £19m
Only 5% of Boards Have Cybersecurity Expertise, Despite Financial Benefits
The Diligent and Bitsight report found that stronger cybersecurity measures equate to significantly higher financial performance for businesses
Portugal Forces Sam Altman's Worldcoin to Stop Collecting Biometric Data
The cryptocurrency-powered iris-scanning project led by OpenAI CEO Sam Altman must halt collecting data for 90 days in Portugal
US Targets Crypto Firms Aiding Russia Sanctions Evasion
The US Treasury has designated several Russian blockchain and virtual currency firms for sanctions evasion
CISA and FBI Urge Renewed Effort to Eliminate SQL Injection Flaws
The US government wants developers to get serious about tackling SQL injection bugs
New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns
Discovered by Sekoia in 2023, the kit is associated with Adversary-in-The-Middle (AiTM) attacks
Fake Ozempic Deals on the Rise as Experts Warn of Phishing Scams
Kaspersky's findings revealed phishing pages posing as vendors, enticing users with discounts
UK Blames China for 2021 Hack Targeting Millions of Voters' Data
The UK’s NCSC assesses that China-backed APT31 was “almost certainly” responsible for hacking the email accounts of UK parliamentarians
Police Bust Multimillion-Dollar Holiday Fraud Gang
Law enforcers have arrested nine suspected members of a prolific cyber-fraud gang
Russian Cozy Bear Group Targets German Politicians
Mandiant observes what it claims is the first ever APT29 campaign aimed at political parties
New AcidPour Wiper Targeting Linux Devices Spotted in Ukraine
SentinelLabs researchers identified the malware as a new variant of AcidRain, which shut down thousands of Viasat satellites in Ukraine and Western Europe in 2022
US Government Releases New DDoS Attack Guidance for Public Sector
The joint advisory sets out how to mitigate and respond to DDoS attacks, limiting disruption to critical services
US Treasury Targets Russian Entities in Cyber Influence Campaign
The campaign notably included attempts to impersonate legitimate media outlets
US Legislation Targets Data Sharing With Foreign Adversaries
The US House of Representatives approved the new bill with an overwhelming vote of 414-0
Security Leaders Acknowledge API Security Gaps Despite Looming Threat
Most decision-makers have experienced API security problems over the past year, yet many haven’t invested in a robust API security strategy, Fastly reveals
ICO Probes Kate Middleton Medical Record Breach
The ICO said it is assessing the reported breach of Kate Middleton’s medical records at The London Clinic
Fake Obituary Sites Send Grievers to Porn and Scareware Pages
Secureworks is warning of fake obituary sites which expose visitors to fake AV scams
Security Researchers Win Second Tesla At Pwn2Own
The Synacktiv team won its second Tesla car for finding one of 19 zero-day bugs on the first day of Pwn2Own Vancouver
CISA Warns Critical Infrastructure Leaders of Volt Typhoon
The agency has issued a fact sheet about the threat actor, emphasizing the importance of cyber-risk as a core business concern
Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands
Thales latest report also suggests less than half of organizations have a formal ransomware response plan