Infosecurity News

  1. Cyber-Attack Disrupts Christie’s $840M Art Auctions

    Despite this setback, the auction house said bids can still be placed by phone and in-person

  2. PDF Exploitation Targets Foxit Reader Users

    CPR said exploit builders in .NET and Python have been employed to deploy this malware

  3. NCSC Expands Election Cybersecurity to Safeguard Candidates and Officials

    The National Cyber Security Centre launches an opt-in Personal Internet Protection service to safeguard individuals from cyber threats during the upcoming election

  4. Google Expands Synthetic Content Watermarking Tool to AI-Generated Text

    Google DeepMind’s SynthID can now be used to watermark AI-generated images, audio, text and video

  5. Santander Customer Data Compromised Following Third-Party Breach

    Santander has warned that customer and employee data has been breached following unauthorized access to a database held by a third-party provider

  6. Current Market Forces Disincentivizing Cybersecurity, Says NCSC CTO

    NCSC CTO argues current market rewards prioritize cost over security, hindering the development of secure technology

  7. A Third of CISOs Have Been Dismissed “Out of Hand” by the Board

    Trend Micro research claims CISOs are often ignored or dismissed as “nagging” by their board

  8. Microsoft Fixes Three Zero-Days in May Patch Tuesday

    Microsoft has released patches for three zero-day vulnerabilities including two actively exploited in the wild

  9. Data Breaches in US Schools Exposed 37.6M Records

    Comparitech said 2023 was a record year for breaches with 954 reported, up from 139 in 2022 and 783 in 2021

  10. Ebury Botnet Operators Diversify with Financial and Crypto Theft

    The 15-year-old Ebury botnet is more active than ever, as ESET found 400,000 Linux servers compromised for cryptocurrency theft and financial gain

  11. CISA and Partners Unveil Cybersecurity Guide For Civil Society Groups

    The guide is designed to provide high-risk communities with actionable steps to bolster their cybersecurity defenses

  12. NIST Confusion Continues as Cyber Pros Complain CVE Uploads Stalled

    Several software security experts have told Infosecurity that no new vulnerabilities have been added to the US National Vulnerability Database (NVD) since May 9

  13. China Presents Defining Challenge to Global Cybersecurity, Says GCHQ

    GCHQ chief warns China's cyber actions threaten global internet security, while Russia and Iran pose immediate risks

  14. 44% of Cybersecurity Professionals Struggle with Regulatory Compliance

    Infosecurity Europe research highlights significant challenges faced by organisations in staying up to speed with increasing compliance requirements

  15. Russian Actors Weaponize Legitimate Services in Multi-Malware Attack

    Recorded Future details a novel campaign that abuses legitimate internet services to deploy multiple malware variants for credential theft

  16. UK Insurance and NCSC Join Forces to Fight Ransomware Payments

    UK insurers and the National Cybersecurity Centre release new guidance to discourage ransomware payments by businesses

  17. Hackers Use DNS Tunneling to Scan and Track Victims

    Palo Alto Networks warns threat actors are using DNS tunneling techniques to probe for network vulnerabilities

  18. FCC Names and Shames First Robocall Threat Actor

    In a first, the FCC has designated “Royal Tiger” as a malicious robocall threat group

  19. Critical Vulnerabilities in Cinterion Modems Exposed

    The flaws include CVE-2023-47610, a security weakness within the modem’s SUPL message handlers

  20. Mallox Ransomware Deployed Via MS-SQL Honeypot Attack

    Analyzing Mallox samples, Sekoia identified two distinct affiliates using different approaches

What’s hot on Infosecurity Magazine?