Infosecurity News

“TicTacToe Dropper” Malware Distribution Tactics Revealed
A new Fortinet analysis revealed a plethora of final-stage payloads delivered by a series of malware droppers

Prudential Financial Faces Cybersecurity Breach
The breach exposed administrative and user data from specific IT systems, but there is no evidence of customer or client data compromise

Crypto-Money Laundering Records 30% Annual Decline
Chainalysis data reveals a near-30% fall in the value of digital currency being laundered in 2023

Microsoft, OpenAI Confirm Nation-States are Weaponizing Generative AI in Cyber-Attacks
Microsoft and OpenAI found that nation-state groups are using generative AI tools to support cyber campaigns rather than developing novel attack techniques

GoldPickaxe Trojan Blends Biometrics Theft and Deepfakes to Scam Banks
Group-IB warns of new Trojan GoldPickaxe designed to bypass banking facial recognition with deepfakes

Water Hydra’s Zero-Day Attack Chain Targets Financial Traders
CVE-2024-21412 was used to evade Microsoft Defender SmartScreen and implant victims with DarkMe

PII Input Sparks Cybersecurity Alarm in 55% of DLP Events
Menlo Security’s latest report also revealed a 26% surge in security policies tailored for generative AI sites

Iranian Hackers Target Israel and US to Sway Public Opinion in Hamas Conflict
Iran-aligned adversaries have attempted to use cyber tactics to sway public opinion of the Israel-Hamas war, Google found in a new report

Cybersecurity Spending Expected to be Slashed in 41% of SMEs
JumpCloud found that 41% of SME IT professionals expect cybersecurity spending to be cut in their organization, increasing the risk of cyber-attacks

Microsoft Fixes Two Zero-Days in February Patch Tuesday
Two zero-day bugs actively exploited in the wild now have official Microsoft patches

Romantic AI Chatbots Fail the Security and Privacy Test
Mozilla warns of serious security and privacy concerns over romantic chatbots downloaded by 100 million users

Southern Water Notifies Customers and Employees of Data Breach
UK utilities firm Southern Water has informed 5-10% of its customer base that their personal data has been accessed following a ransomware attack in January

Bank of America Customers at Risk After Data Breach
A notification letter sent to the Attorney General of Maine showed 57,028 individuals were impacted

CISA Reveals JCDC’s 2024 Cybersecurity Priorities
These will focus on countering APTs, fortifying critical infrastructure and anticipating emerging risks

US, UK and India Among the Countries Most At Risk of Election Cyber Interference
Threat intelligence provider Tidal Cyber found that 64 countries holding elections in 2024 could face cyber interference threats

Notorious Bumblebee Malware Re-emerges with New Attack Methods
Proofpoint researchers observed a new Bumblebee social engineering campaign in February following a four-month absence

UK Businesses Lose £31bn to Security Breaches in a Year
Beaming data reveals the cost of UK cybersecurity breaches surged 138% over four years to £31.5bn

Stealthy “Hunter-Killer” Malware Detections Surge 333% Annually
Picus Security sees huge uptick in malware designed to detect and disrupt security tooling

Sophisticated Cyber-Attack Hits Islamic Charity in Saudi Arabia
Talos said the attacker utilized new “Zardoor” malware to establish persistence

China Targets US Hacking Ops in Media Offensive
Claims include allegations of US hacking into seismic sensors at the Wuhan Earthquake Monitoring Center



