Infosecurity News

  1. LeakyCLI Flaw Exposes AWS and Google Cloud Credentials

    Orca Security said the issue mirrors a previously identified vulnerability in Azure CLI

  2. Cybersecurity Pros Urge US Congress to Help NIST Restore NVD Operation

    An open letter signed by 50 cybersecurity practitioners requires the US Congress to support NIST in restoring operations at the National Vulnerability Database

  3. Microsoft Most Impersonated Brand in Phishing Scams

    New Check Point data found Microsoft was impersonated in 38% of all brand phishing attacks in Q1 2024, up from 33% in Q4 2024

  4. Open Source Leaders Warn of XZ Utils-Like Takeover Attempts

    Two open source organizations have revealed attempts to socially engineer project takeovers

  5. Bad Bots Drive 10% Annual Surge in Account Takeover Attacks

    Malicious bots now represent a third of all internet traffic, says Imperva

  6. Russia and Ukraine Top Inaugural World Cybercrime Index

    An international team of researchers published the first-ever index ranking countries by cybercrime threat level

  7. New LockBit Variant Exploits Self-Spreading Features

    Kaspersky also uncovered the use of the SessionGopher script to extract saved passwords

  8. Palo Alto Networks Zero-Day Flaw Exploited in Targeted Attacks

    Designated CVE-2024-3400 and with a CVSS score of 10.0, the flaw enables unauthorized actors to execute arbitrary code on affected firewalls

  9. Chipmaker Giant Nexperia Confirms Cyber-Attack Amid Ransomware Group Claims

    Nexperia confirmed its IT servers were accessed by attackers, with the Dunghill ransomware group claiming to have stolen chip designs and other sensitive documents

  10. FBI Warns of Massive Toll Services Smishing Scam

    The Feds have received thousands of complaints about phishing texts from fake road toll collection services

  11. Police Swoop on €645m Cannabis Investment Fraud Gang

    Nine arrests and millions of euros seized in bid to bust JuicyFields investment scammers

  12. CISA Urges Immediate Credential Reset After Sisense Breach

    The breach affecting business analytics provider Sisense could lead to a wide-scale supply chain attack

What’s hot on Infosecurity Magazine?