Infosecurity News

  1. Webcams and DVRs Vulnerable to HiatusRAT, FBI Warns

    The FBI has issued a warning about the Hiatus RAT malware targeting Xiongmai and Hikvision web cameras and DVRs, urging users isolate these devices from networks

  2. CISA Urges Encrypted Messaging After Salt Typhoon Hack

    The US Cybersecurity and Infrastructure Security Agency recommended users turn on phishing-resistant MFA and switch to Signal-like apps for messaging

  3. Ransomware Attackers Target Industries with Low Downtime Tolerance

    A Dragos report observed 23 new ransomware groups targeting industrial organizations in Q3 2024

  4. US Organizations Still Using Kaspersky Products Despite Ban

    Bitsight found that 40% of US organizations who used Kaspersky products before the government ban came into effect still appear to be using them

  5. EU Opens Door for AI Training Using Personal Data

    The EU Data Protection Board (EDPB) published a long-awaited opinion on how GDPR should apply to AI models

  6. New Malware Can Kill Engineering Processes in ICS Environments

    Forescout identified a new type of malware capable of terminating engineering processes, used to target Siemens engineering workstations

  7. Crypto-Hackers Steal $2.2bn as North Koreans Dominate

    Mainly North Korean hackers stole over $2bn from crypto platforms in 2024, says Chainalysis

  8. Recorded Future CEO Calls Russia’s “Undesirable” Listing a “Compliment”

    Cybersecurity firm Recorded Future has been listed as an “undesirable” organization by the Prosecutor General's Office of the Russian Federation

  9. Vulnerability Exploit Assessment Tool EPSS Exposed to Adversarial Attack

    A Morphisec researcher showed how an attacker could manipulate FIRST’s Exploit Prediction Scoring System (EPSS) using AI

  10. Interpol Calls for an End to “Pig Butchering” Terminology

    Interpol wants to change the term “pig butchering” to “romance baiting”

  11. US Government Issues Cloud Security Requirements for Federal Agencies

    A CISA Directive sets out actions all US federal agencies must take to identify and secure cloud tenants in their environments

  12. Phishing Attacks Double in 2024

    SlashNext reports a 202% increase in overall phishing messages and a 703% surge in credential-based phishing attacks in 2024

  13. New Attacks Exploit VSCode Extensions and npm Packages

    Malicious campaigns targeting VSCode extensions have recently expanding to npm, risking software supply chains

  14. Attacker Distributes DarkGate Using MS Teams Vishing Technique

    Trend Micro highlighted a case where an attacker posed as a client on an MS Teams call to distribute DarkGate malware

  15. Nigeria Cracks Down on Cryptocurrency Investment Fraud and Romance Scams

    The suspects were apprehended in a surprise operation at their hideout in Lagos following intelligence received by Nigeria's Economic and Financial Crimes Commission

  16. Meta Hit with Massive $263m GDPR Fine

    The Irish Data Protection Commission has fined Meta $263m for a 2018 data breach impacting 29 million Facebook accounts

  17. European Commission Opens TikTok Election Integrity Probe

    The European Commission is investigating whether TikTok allowed foreign actors to influence voters during recent Romanian elections

  18. Sophisticated TA397 Malware Targets Turkish Defense Sector

    Sophisticated phishing attack targeting Turkey’s defense sector revealed TA397’s advanced tactics

  19. Texas Tech University Data Breach Impacts 1.4 Million

    The breach has affected 650,000 individuals at TTUHSC’s Lubbock campus and 815,000 at its El Paso branch

  20. Cybercriminals Exploit Google Calendar to Spread Malicious Links

    Check Point research reveals cybercriminals are using Google Calendar and Drawings to send malicious links, bypassing traditional email security

What’s hot on Infosecurity Magazine?