Infosecurity News
North Korean Attackers Exploiting Critical CI/CD Vulnerability
Microsoft has warned organizations using JetBrains TeamCity server to take immediate steps to mitigate this threat
Hacker Group GhostSec Unveils New Generation Ransomware Implant
The ex-hacktivist group is now fully involved with the ransomware-as-a-service market
Google Play Protect Bolsters Security Against Malicious Apps
New real-time scanning feature conducts analyses of an app’s code during the installation process
AI Adoption Surges But Security Awareness Lags Behind
The ExtraHop survey involved over 1200 global security and IT leaders
ISACA CEO Hails Europe as a Lighthouse of Capability
ISACA's new CEO highlights growth of its European membership as the Association works on an aggressive growth strategy
Global Economy Could Lose $3.5trn in Systemic Cyber-Attack
A Lloyd's research found that the US alone would experience a $1.1trn loss in the “hypothetical but plausible” risk scenario
Five Eyes Warn Deep Tech Start-Ups Against Nation-State Threats
The Five Eyes intelligence agencies want start-ups dealing with cutting-edge technology to bolster their protections against nation-state threats
FBI: Hackers Are Extorting Plastic Surgery Patients
Cybercriminals are harvesting sensitive medical data from plastic surgery offices as leverage for extortion demands
Persistent Espionage Campaign Targets APAC Governments
Kaspersky said the campaign exploiting USB drives first came to light in early 2023
Fake Browser Updates Used in Malware Distribution
Proofpoint have identified at least four distinct threat clusters
Rising AI-Fueled Phishing Drives Demand for Password Alternatives
FIDO Alliance’s third Online Authentication Barometer showed that AI-powered phishing is slowly prompting users to switch passwords for multi-factor authentication methods
Cisco Warns of Critical Vulnerability in IOS XE Software
The tech giant has issued guidance to mitigate exploitation of the flaw, which has the highest severity rating
A Third of Organizations Not Ready to Comply with NIS2
A new survey found that three-quarters of organizations in the UK are yet to address the five key requirements for compliance
Ransomware Targets Unpatched WS_FTP Servers
The threat actors attempted to escalate privileges using the open-source GodPotato tool
Growing Concern Over Role of Hacktivism in Israel-Hamas Conflict
Hacktivists claim DDoS attacks against Israeli websites as cybersecurity experts urge caution in believing these cyber-criminals’ claims
Signal Disputes Alleged Zero-Day Flaw
Reports emerged over the weekend regarding a zero-day exploit in the messaging app
Healthcare Sector Warned About New Ransomware Group NoEscape
The US government highlighted the operations of the NoEscape group, which is believed to be a rebrand of Russian threat actor Avaddon
New RomCom Backdoor Targets Female Political Leaders
A new version of the RomCom backdoor was used to lure attendees of the June 2023 Women Political Leaders Summit
UK Regulator Fines Equifax £11m for 2017 Data Breach
The UK FCA held Equifax Ltd responsible for failing to protect UK consumer data held by its US-based parent company
New Phishing Campaign Uses LinkedIn Smart Links in Blanket Attack
Email security provider Cofense has unveiled a large-scale phishing campaign leveraging LinkedIn Smart Links