Infosecurity News

Russia’s APT29 Targets Embassies With Ngrok and WinRAR Exploit
Threat group may be looking for intel on Azerbaijan

NCSC Announces New Standard For Indicators of Compromise
Security agency authors first RFC document for IETF

Black Friday: Scammers Exploit Luxury Brands to Lure Victims
Check Point Research say these latest luxury brand scams are a wake-up call for shoppers to stay vigilant online

FBI Lifts the Lid on Notorious Scattered Spider Group
Security advisory details TTPs of prolific threat actors

Royal Mail to Spend £10m on Ransomware Remediation
Postal service was breached in January 2023

British Library: Ransomware Recovery Could Take Months
Famed institution warns of ongoing disruption

CSA Launches First Zero Trust Certification
The CCZT program incorporates foundational principles from leading sources such as CISA and NIST

Cyber-Criminals Exploit Gaza Crisis With Fake Charity
Attackers sought crypto donations of $100-$5000 using Bitcoin, Litecoin and Ethereum addresses

Russian Hacking Group Sandworm Linked to Unprecedented Attack on Danish Critical Infrastructure
A report described the coordinated attack, in which 22 critical infrastructure firms were targeted

Black Friday: Malwarebytes Warns of Credit Card Skimming Surge
Skimming threat actors ramp up their activity just in time for the holiday season

Half of Ransomware Groups Operating in 2023 Are New
WithSecure report highlights widespread code reuse

BlackCat Ransomware Group Reports Victim to SEC
ALPHV/BlackCat tries unusual extortion technique

European Police Take Down $9m Vishing Gang
Fraudsters operated from Ukrainian call centers

US Government Unveils First AI Roadmap For Cybersecurity
The initiative aligns with President Biden’s recent Executive Order

BlackCat Ransomware Gang Targets Businesses Via Google Ads
Nitrogen serves as initial-access malware, using obfuscated Python libraries for stealth

UK Privacy Regulator Issues Black Friday Smart Device Warning
Consumers urged to think before they buy connected technology

Microsoft Fixes Five Zero-Day Vulnerabilities
Patch Tuesday includes fixes for three actively exploited bugs

US Dismantles IPStorm Botnet Proxy Service
Russian-Moldovan national faces maximum 30-year jail stretch

Python Package Index Faces Security Crisis With Validated Leaks
2922 projects contained at least one unique secret, including from AWS, Redis and Google

82% of Attacks Show Cyber-Criminals Targeting Telemetry Data
Sophos report based on 232 IR cases across 25 sectors from January 1 2022 to June 30 2023



