Infosecurity News

  1. US Intelligence Predicts Upcoming Cyber Threats for 2024

    The Office of the Director of National Intelligence (ODNI) has unveiled an unclassified version of its Annual Threat Assessment of the US Intelligence Community

  2. New Cloud Attack Targets Crypto CDN Meson Ahead of Launch

    Sysdig said the rise of the Meson Network in blockchain signals a new frontier for attackers

  3. Three-Quarters of Cyber Incident Victims Are Small Businesses

    Three-quarters of cyber-incidents Sophos responded to involved small businesses in 2023, with attackers’ main goal being data theft

  4. Lawmakers Slam UK Government’s “Ostrich Strategy” for Cybersecurity

    An influential parliamentary committee claims government short-termism is exposing the country to ransomware catastrophe

  5. Victims Lose $47m to Crypto Phishing Scams in February

    Some 57,000 victims lost $47m in phishing scams targeting their cryptocurrency last month

  6. Magnet Goblin Exploits Ivanti Vulnerabilities

    The threat actor uses custom Linux malware to pursue financial gain, according to Check Point Research

  7. BianLian Threat Actor Shifts Focus to Extortion-Only Tactics

    GuidePoint said the threat actor gained initial access via vulnerabilities in a TeamCity server

  8. NSA Launches Top 10 Cloud Security Mitigation Strategies

    The advisory is associated with ten companion cybersecurity information sheets detailing how to implement each strategy

  9. Third-Party Breach and Missing MFA Contributed to British Library Cyber-Attack

    A British Library report found the most likely source of the incident was the compromise of third-party account credentials and no MFA was in place to stop the attackers

  10. Russia’s Midnight Blizzard Accesses Microsoft Source Code

    Threat group APT29 is using secrets stolen in an earlier attack to compromise Microsoft’s internal systems

  11. Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing Campaign

    Darktrace reveals a novel phishing campaign where attackers leveraged legitimate Dropbox infrastructure to steal credentials before bypassing MFA

  12. UnitedHealth Sets Timeline to Restore Change Healthcare Systems After BlackCat Hit

    UnitedHealth said it expects Change Healthcare’s key systems to be restored by March 18, amid reports it paid a $22m ransom to BlackCat

  13. RATs Spread Via Fake Skype, Zoom, Google Meet Sites

    Zscaler’s ThreatLabz discovered malware spreading SpyNote RAT to Android and NjRAT/DCRat to Windows

  14. Evasive Panda Targets Tibet With Trojanized Software

    ESET researchers said the attackers strategically leveraged the Monlam Festival, targeting individuals associated with Tibetan Buddhism

  15. FBI: US Ransomware Losses Surge 74% to $59.6 Million in 2023

    Ransomware losses in the US rose by 74% to $59.6m in 2023, according to reported incidents to the FBI

  16. Governments Eye Disclosure Requirements for AI Development Labs

    AI scientist Inma Martinez predicts governments will start requiring ‘frontier’ AI labs full disclosure on the purpose of the tools they are developing

  17. Ransomware Attackers Leak Sensitive Swiss Government Documents, Login Credentials

    Sensitive data from Switzerland government departments were leaked by the Play ransomware group after an attack on Xplain, including classified documents and log in credentials

  18. Former Google Engineer Charged With Stealing AI Secrets

    Alleged Chinese spy Linwei Ding is accused of stealing proprietary IP from Google

  19. Hundreds of Rogue Users Added to Unpatched TeamCity Servers

    Security experts warn of mass exploitation of critical TeamCity vulnerability

  20. TA4903 Phishing Campaigns Evolve, Targets US Government

    Proofpoint said TA4903 adopted new tactics, including lure themes referencing confidential docs and ACH payments

What’s Hot on Infosecurity Magazine?