Infosecurity News
Ukraine Claims it Hacked Russian MoD
Ukraine’s military intelligence service says it hacked and stole sensitive documents from Russia’s Ministry of Defense
TeamCity Users Urged to Patch Critical Vulnerabilities
JetBrains says on-premises TeamCity servers must be upgraded to mitigate two new bugs
Self-Propagating Worm Created to Target Generative AI Systems
The researchers developed a worm, dubbed “Morris II,” which targets generative AI ecosystems through the use of adversarial self-replicating prompts
Hacktivist Collective NoName057 Strikes European Targets
Sekoia.io observed developments in the group’s DDoS tools, including updates enhancing compatibility with different processor architectures and OS
TA577 Exploits NTLM Authentication Vulnerability
Proofpoint warned the method could be used for data gathering and further malicious activities
Predator Spyware Targeted Mobile Phones in New Countries
Despite being exposed to human rights violations, the Predator spyware continues to be used across the world – including in new countries
Securing Perimeter Products Must Be a Priority, Says NCSC
UK’s National Cyber Security Centre warns of dangers of insecure perimeter products
Drugs and Cybercrime Market Busted By German Cops
German police have dismantled the country’s largest underground marketplace: Crimemarket
Biden Warns Chinese Cars Could Steal US Citizens' Data
President Biden warned that connected vehicles built in China could be used to steal sensitive data of US citizens and critical infrastructure
Five Eyes Warn of Ivanti Vulnerabilities Exploitation, Detection Tools Insufficient
Government agencies from the Five Eyes coalition said that Ivanti’s own tools are not sufficient to detect compromise
UK Home Office Breached Data Protection Law with Migrant Tracking Program, ICO Finds
The Home Office failed to assess the privacy intrusion of the continuous collection of migrants’ location information in breach of UK data protection law, according to the ICO
Pharma Giant Cencora Reports Cybersecurity Breach
The breach was discovered on February 21 2024, according to an SEC filing published on the same day
Savvy Seahorse Targets Investment Platforms With DNS Scams
Infoblox said Savvy Seahorse uses fake ChatGPT and WhatsApp bots to lure victims
Dark Web Market Revenues Rebound but Sector Fragments
Chainalysis study of crypto flows reveals darknet markets made $1.7bn in 2023
US Government Warns Healthcare is Biggest Target for BlackCat Affiliates
The US government advisory warns healthcare organizations are being targeted by BlackCat amid an ongoing cyber-incident affecting Change Healthcare
TimbreStealer Malware Targets Mexican Victims with Tax-Related Lures
The maker of the Mispadu Trojan started distributing a new infostealer with financial lures to Mexican users, Cisco Talos found
Biden Bans Mass Sale of Data to Hostile Nations
A new presidential executive order attempts to prevent the mass sales of personal data to countries like China and Russia
FBI Issues Alert on Russian Threats Targeting Ubiquiti Routers
The routers were hijacked to steal credentials, proxy traffic, and host phishing pages and custom tools
34 Million Roblox Credentials Exposed on Dark Web in Three Years
Kaspersky reported a 231% surge in compromised accounts from 4.7 million in 2021 to 15.5 million in 2023
How Security Leaders Can Break Down Barriers to Enable Digital Trust
ISACA's Rob Clyde and Pam Nigro discuss how to advance digital trust in a security context