Infosecurity News
Foreign Actors Targeted 2022 US Elections, Intelligence Community Reveals
The US intelligence community found no evidence of hacking but detected foreign influence operations during the 2022 federal elections
More Than 26,000 Vulnerabilities Discovered in 2023
The Qualys report also showed over 7000 vulnerabilities had proof-of-concept exploit code
US and Australia Warn of Play Ransomware Threat
A joint advisory by US and Australian government agencies urges organizations to protect themselves against Play group’s tactics
Impact of Log4Shell Bug Was Overblown, Say Researchers
VulnCheck claims the potential impact of Log4Shell was exaggerated
Over 14 Million Mortgage Customers Hit By Mr Cooper Breach
One of America’s biggest lenders, Mr Cooper, has revealed a breach impacted 14.7 million customers
Iranian Fuel Supplies Crippled By Cyber-Attack
Iranian minister confirms cyber-attack was cause of widespread disruption at petrol stations
MOVEit Vulnerability Hits Delta Dental: 7 Million Records Exposed
Unauthorized actors breached health data, including details related to dental procedures and claims
QakBot’s Low-Volume Resurgence Targets Hospitality
Researchers observed malicious files advancing through email, PDF, URL and MSI
ALPHV Second Most Prominent Ransomware Strain Before Reported Downtime
The group was second behind only LockBit in attacks targeting North America and Europe between January 2022 and October 2023
Insurer’s UK Honeypots Attacked 17 Million Times Per Day
RDP is singled out as insurer Coalition records 17 million cyber-attacks per day in the UK in 2023
MongoDB Investigates Customer Account Data Breach
Data platform provider MongoDB has discovered a data breach impacting customers
Technology Manufacturers Urged to Eliminate Passwords
New CISA document promotes secure-by-design shift to ditch default password use
Four Charged in Connection With $80m Pig Butchering Scheme
Four men have been charged with money laundering offenses linked to a major pig butchering operation
UK Plans Tough New Security Rules For Datacenters
The British government is proposing minimum mandatory requirements for datacenter security and resilience
Over 45,000 Employees Hit By Nuclear Research Lab Breach
Idaho National Laboratory says 45,000 employees had personal information compromised in data breach
Cozy Bear Hackers Target JetBrains TeamCity Servers in Global Campaign
The FBI and CISA detected that hackers linked to the Russian foreign intelligence service (SVR) have been targeting a JetBrains TeamCity vulnerability since September 2023
Approval Phishing Scams Drain $1bn of Cryptocurrency from Victims
Romance scammers have used the technique to great effect in recent years
Vulnerabilities Now Top Initial Access Route For Ransomware
More ransomware attacks now start with vulnerability exploitation than phishing, says Corvus Insurance
GambleForce Group Targets Websites With SQL Injection
Group-IB warns of new threat actor GambleForce, which uses SQL injection attacks to steal data from websites
Microsoft Targets Prolific Outlook Fraudster Storm-1152
Microsoft disrupts Vietnam based threat group Storm-1152, which has sold 750 million fake accounts