Top

Tag: Featured


Threats & Malware, Vulnerabilities

T-Mobile US exposes some customer data – but don’t call it a breach

September 25, 2023

Via: The Register

T-Mobile US has had another bad week on the infosec front – this time stemming from a system glitch that exposed customer account data, followed by allegations of another breach the carrier denied. According to customers who complained of the […]


Cyber-crime, Malware

New variant of BBTok Trojan targets users of +40 banks in LATAM

September 25, 2023

Via: Security Affairs

Check Point researchers warn of a new variant of a banking trojan, called BBTok, that is targeting users of over 40 banks in Latin America. The new malware campaign relies on new infection chains and employs a unique combination of […]


Network security, Security

Balancing cybersecurity with convenience and progress

September 25, 2023

Via: Help Net Security

Changing approaches to cybersecurity have led to slow but steady progress in defense and protection. Still, competing interests create a growing challenge for cybersecurity decision makers and practitioners, according to CompTIA. The state of cybersecurity Most business and technology professionals […]


Cyber-crime, Identity theft

TransUnion reckons big dump of stolen customer data came from someone else

September 21, 2023

Via: The Register

Days after a miscreant boasted leaking a 3GB-plus database from TransUnion containing financial information on 58,505 people, the credit-checking agency has claimed the info was actually swiped from a third party. On Sunday, a thief using the handle USDoD shared […]


Data loss, Threats & Malware

The Clorox Company admits cyberattack causing ‘widescale disruption’

September 19, 2023

Via: The Register

The Clorox Company, makers of bleach and other household cleaning products, doesn’t expect operations to return to normal until near month end as it combs over “widescale disruption to operations” caused by cyber baddies. The $2 billion turnover biz, whose […]


Threats & Malware, Virus & Malware

Cryptojackers spread their nets to capture more than just EC2

September 18, 2023

Via: The Register

As cloud native computing continues to gain popularity, so does the risk posed by criminals seeking to exploit the unwary. One newly spotted method targets services on the AWS platform, but not necessarily the ones you might think. Researchers from […]


Network security, Security

Former CIO accuses Penn State of faking cybersecurity compliance

September 18, 2023

Via: The Register

Last October, Pennsylvania State University (Penn State) was sued by a former chief information officer for allegedly falsifying government security compliance reports. The lawsuit, recently unsealed, is a qui tam complaint (in Latin “who as well,”) meaning it was filed […]


Data loss, Threats & Malware

GAO Report Reveals IRS’s Limited Control Over Taxpayer Data Handling

September 18, 2023

Via: SecureWorld

The U.S. Internal Revenue Service (IRS) is entrusted with the vital responsibility of safeguarding sensitive taxpayer information. Recent incidents of potential unauthorized access to or disclosure of this data have raised concerns and prompted a thorough review by the Government […]


Cloud security, Security

Lacework expands partnership with Snowflake to drive secure cloud growth

September 14, 2023

Via: Help Net Security

Lacework and Snowflake announced an expanded partnership that advances the future of cloud infrastructure and further automates cloud security at scale. The extended partnership empowers security teams with direct access to their Lacework cloud security data through Snowflake’s secure data […]


Network security, Security

Viavi Solutions and Google Cloud unlock new opportunities for network optimization

September 14, 2023

Via: Help Net Security

Viavi Solutions announced the availability of NITRO AIOps on Google Cloud, creating an innovative solution that leverages VIAVI network analytics solutions and Google Cloud’s native service capabilities. The collaboration aims to address critical challenges faced by Communication Service Providers (CSPs) […]


Application security, Security

CTERA Vault safeguards against risks related to data tampering

September 12, 2023

Via: Help Net Security

CTERA unveiled CTERA Vault, Write Once, Read Many (WORM) protection technology which provides regulatory compliant storage for the CTERA Enterprise Files Services Platform. CTERA Vault aids enterprises in guaranteeing the preservation and tamperproofing of their data, while also ensuring compliance […]


Application security, Security

Wing and Drata join forces to ensure a way to keep SaaS compliant

September 12, 2023

Via: Help Net Security

Wing Security has partnered with Drata to integrate SaaS security controls, robust insights, and automation in order to streamline and expedite user access reviews and vendor risk assessments for compliance frameworks and standards such as SOC 2 and ISO 27001. […]


Privacy protection, Security

Swissbit introduces iShield Archive memory card that protects sensitive information

September 12, 2023

Via: Help Net Security

With ‘iShield Archive’, Swissbit introduces a new microSD card designed for encryption and access protection of video and image records, expanding the Swissbit iShield product line for plug-and-play security solutions. The card is intended particularly for manufacturers and users for […]


Data loss, Threats & Malware

Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security Breach

September 7, 2023

Via: The Hacker News

Microsoft on Wednesday revealed that a China-based threat actor known as Storm-0558 acquired the inactive consumer signing key to forge tokens and access Outlook by compromising an engineer’s corporate account. This enabled the adversary to access a debugging environment that […]


Network security, Security

The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2024

September 7, 2023

Via: The Hacker News

By the end of 2024, the number of MSPs and MSSPs offering vCISO services is expected to grow by almost 5 fold, as can be seen in figure 1. This incredible surge reflects the growing business demand for specialized cybersecurity […]


Threats & Malware, Virus & Malware

Researchers Warn of Cyber Weapons Used by Lazarus Group’s Andariel Cluster

September 5, 2023

Via: The Hacker News

The North Korean threat actor known as Andariel has been observed employing an arsenal of malicious tools in its cyber assaults against corporations and organizations in the southern counterpart. “One characteristic of the attacks identified in 2023 is that there […]


Cyber warfare, Cyber-crime

Meta Takes Down Thousands of Accounts Involved in Disinformation Ops from China and Russia

September 5, 2023

Via: The Hacker News

Meta has disclosed that it disrupted two of the largest known covert influence operations in the world from China and Russia, blocking thousands of accounts and pages across its platform. “It targeted more than 50 apps, including Facebook, Instagram, X […]


Threats & Malware, Virus & Malware

New Python Variant of Chaes Malware Targets Banking and Logistics Industries

September 5, 2023

Via: The Hacker News

Banking and logistics industries are under the onslaught of a reworked variant of a malware called Chaes. “It has undergone major overhauls: from being rewritten entirely in Python, which resulted in lower detection rates by traditional defense systems, to a […]


Threats & Malware, Virus & Malware

Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks

August 29, 2023

Via: The Hacker News

Microsoft is warning of an increase in adversary-in-the-middle (AiTM) phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model. In addition to an uptick in AiTM-capable PhaaS platforms, the tech giant noted that existing phishing services […]


Threats & Malware, Vulnerabilities

Citrix NetScaler Alert: Ransomware Hackers Exploiting Critical Vulnerability

August 29, 2023

Via: The Hacker News

Unpatched Citrix NetScaler systems exposed to the internet are being targeted by unknown threat actors in what’s suspected to be a ransomware attack. Cybersecurity company Sophos is tracking the activity cluster under the moniker STAC4663. Attack chains involve the exploitation […]