Infosecurity News

NCSC Urges UK Water Companies to Secure Control Systems
Guidance follows US incident involving Unitronics programmable logic controllers

Apple Patches Actively Exploited iOS Zero-Days
Vulnerabilities may be linked to commercial spyware operations

UK Celebrates “World-First” Anti-Fraud Deal With Big Tech
Government says tech firms have pledged to remove malicious content

North Korean Hackers Amass $3bn in Cryptocurrency Heists
Stolen cryptocurrency is converted into fiat currency using stolen identities and manipulated photos

Manufacturing Top Targeted Industry in Record-Breaking Cyber Extortion Surge
Orange Cyberdefense’s Security Navigator listed the manufacturing sector as number one for both detected cyber incidents and confirmed cyber-attacks

FjordPhantom Android Malware Targets Banks With Virtualization
Promon said one FjordPhantom attack resulted in a substantial loss of approximately $280,000

RedLine Stealer Malware Deployed Via ScrubCrypt Evasion Tool
The new ScrubCrypt obfuscation tool is designed to avoid antivirus protections

Booking.com Customers Scammed in Novel Social Engineering Campaign
The sophisticated campaign has led to customers having their money stolen by cybercriminals

Thousands of Dollar Tree Staff Hit By Supplier Breach
Incident at Zeroed-In Technologies happened in August

Okta Admits All Customer Support Users Impacted By Breach
Exposure is limited to names and emails for most

Black Basta Ransomware Group Makes $100m Since 2022
Researchers identify scores of cryptocurrency payments

GoTitan Botnet and PrCtrl RAT Exploit Apache Vulnerability
Fortiguard Labs identified multiple threat actors leveraging CVE-2023-46604

DeleFriend Weakness Puts Google Workspace Security at Risk
Hunters’ Team Axon said the flaw could lead to the unauthorized access of emails in Gmail and more

AI Boosts Malware Detection Rates by 70%
New research has found that AI is significantly more accurate than traditional techniques at detecting malicious malware

A Fifth of UK SMBs Can’t Spot Scams
Many are failing UK Finance’s new fraud quiz

Hackers Exploit Critical Vulnerability in ownCloud
Zero-day bug could allow remote control of servers

Google Fixes Sixth Chrome Zero-Day Bug of the Year
Critical vulnerability is being exploited in the wild

Undetected Android Trojan Expands Attack on Iranian Banks
Zimperium’s latest findings include the identification of 245 new app variants

Ardent Health Services Grapples With Ransomware Disruption
Non-urgent procedures are being rescheduled, emergency room patients redirected to other hospitals

Deepfake Digital Identity Fraud Surges Tenfold, Sumsub Report Finds
AI-powered tools are among the top fraud techniques used by threat actors in 2023, according to Sumsub’s third annual Identity Fraud Report



