Infosecurity News

Ukraine Claims it “Paralyzed” Russia’s Tax System
Ukrainian Ministry of Defense says cyber-attack wiped Russian tax system servers

Widespread Security Flaws Blamed for Northern Ireland Police Data Breach
An independent review of the August 2023 PSNI data breach found major security failings in the police department’s IT systems

Ukraine's Largest Phone Operator Hack Tied to War With Russia
Kyivstar announced its mobile network had temporarily been shut down due to a major cyber-attack on its systems

Threat Actor Targets Recruiters With Malware
Recruiters are urged to educate staff about a surge in phishing attacks from threat group TA4557

Backup Migration WordPress Plugin Flaw Impacts 90,000 Sites
Users of popular WordPress plugin Backup Migration are urged to patch a new critical vulnerability

Apache Warns of Critical Vulnerability in Struts 2
Users are urged to patch critical vulnerability in Apache Struts 2 immediately

Lazarus Group Targets Log4Shell Flaw Via Telegram Bots
Cisco Talos said Operation Blacksmith leveraged the flaw in publicly facing VMWare Horizon servers

Europol Raises Alarm on Criminal Misuse of Bluetooth Trackers
The majority of reported cases involved cocaine smuggling

EU Reaches Agreement on AI Act Amid Three-Day Negotiations
The landmark bill will regulate the use of generative AI models like ChatGPT and AI systems used by governments and law enforcement

ALPHV/BlackCat Site Downed After Suspected Police Action
Notorious ransomware collective ALPHV/BlackCat may have been disrupted by law enforcement

Police Arrest Hundreds of Human Traffickers Linked to Cyber Fraud
Interpol operation leads to arrest of hundreds on suspicion of human trafficking and fraud

Two-Fifths of Log4j Apps Use Vulnerable Versions
Two years after a critical vulnerability was found in utility Log4j, 38% of apps still use buggy versions

ICO Warns of Fines for “Nefarious” AI Use
UK privacy regulator, the information commissioner, says illegal use of AI will be punished with fines

Geopolitics to Blame For DoS Surge in Europe, Says ENISA
European security agency claims “novel and massive” DDoS threat is driven by political motivation

Ransomware Surge is Driving UK Inflation, Says Veeam
Veeam research reveals that corporate victims of ransomware are more likely to increase prices and fire staff

New Report: Over 40% of Google Drive Files Contain Sensitive Info
The Metomic research also suggested 34.2% of the files were shared with external contacts

UK Government Warns of Russian Cyber Campaigns Against Democracy
The NCSC identified the threat group responsible as Star Blizzard, linked to Russia’s FSB Center 18

Cyber-Attacks More Likely Than Fire or Theft, Aviva Research Finds
YouGov and Aviva research finds that UK businesses are almost five times as likely to have experienced a cyber-attack as a fire

Liability Fears Damaging CISO Role, Says Former Uber CISO
Former Uber CISO Joe Sullivan says CISOs are thinking about themselves rather than the bigger picture due to the risk of personal liability

Ninety Percent of Energy Companies Suffer Supplier Data Breach
Forty-three of the world’s 48 largest energy companies were hit by a third-party data breach over the past year



