Infosecurity News

  1. Stolen Access Tokens Lead to New Internet Archive Breach

    A threat actor claimed to get hold of an exposed GitLab configuration file containing Zendesk API access tokens

  2. 50,000 Files Exposed in Nidec Ransomware Attack

    The August ransomware attack stole 50,000+ documents from Nidec, leaked after ransom refusal

  3. Netskope Reports Possible Bumblebee Loader Resurgence

    The malware loader taken down by Europol in May 2024 could be back with a vengeance

  4. Australia's Privacy Watchdog Publishes Guidance on Commercial AI Products

    Businesses in Australia must update their privacy policies with clear and transparent information about their use of AI, said the regulator

  5. Half of Organizations Have Unmanaged Long-Lived Cloud Credentials

    Long-lived credentials in the cloud put organizations at high risk of breaches, a report from Datadog has found

  6. Internet Archive and Wayback Machine Resurrect After DDoS Wave

    Internet Archive founder confirmed the allegedly exposed data was “safe”

  7. macOS Vulnerability Could Expose User Data, Microsoft Warns

    Microsoft urges macOS users to apply a fix for the vulnerability, which it believes may be under active exploitation by the Adload malware family

  8. Instagram Rolls Out New Sextortion Protection Measures

    Instagram has announced new security features to protect users from sextortion scams, including hiding follower lists, preventing screenshots, and launching an awareness campaign

  9. Microsoft Named Most Imitated Brand in Phishing Attacks

    The Redmond-based firm was the most impersonated brand in the third quarter of 2024, while Alibaba entered the Top 10 for the first time

  10. US Arrest Man for SEC X Account Hack

    US authorities have charged a man for involvement in the SEC X account hack in January 2024, which falsely announced the approval of Bitcoin Exchange Traded Funds

  11. Cicada3301 Ransomware Targets Critical Sectors in US and UK

    Cicada3301 ransomware has targeted critical sectors in US/UK, leaking data from 30 firms in three months

  12. US Charges Anonymous Sudan Members in DDoS Cybercrime Case

    US authorities have charged two Sudanese linked to DDoS cybercrime group, Anonymous Sudan, which caused $10m in damages

  13. Iranian Hackers Target Critical Infrastructure with Brute Force Attacks

    The ongoing campaign targets multiple critical infrastructure sectors, including healthcare, government, information technology, engineering, and energy

  14. North Korea Escalates Fake IT Worker Schemes to Extort Employers

    Secureworks said it had observed a case where a fake North Korean IT contractor exfiltrated proprietary data before issuing a ransom demand to their former employer

  15. RansomHub Overtakes LockBit as Most Prolific Ransomware Group

    Symantec data reveals RansomHub claimed more attacks than any other group in Q3 2024

  16. Two-thirds of Attributable Malware Linked to Nation States

    Netskope claims 66% of malware attacks last year were backed by nation states

  17. CISA Seeks Feedback on Upcoming Product Security Flaws Guidance

    CISA is asking for feedback on future guidance outlining bad security practices in product development as part of its Secure by Design initiative

  18. NIS2 Confusion: Concerns Over Readiness as Deadline Reached

    NIS2 will be enforced as of October 17, yet many organizations and even EU member states appear completely unprepared for implementation

  19. CISA Urges Improvements in US Software Supply Chain Transparency

    CISA released the third edition of SBOM guidelines to enhance software component transparency

  20. Ethical Hackers Embrace AI Tools Amid Rising Cyber Threats

    A new Bugcrowd study shows 71% of ethical hackers now see AI boosting hacking value, up from 21% in 2023

What’s hot on Infosecurity Magazine?