Infosecurity News

UK FCA Warns of Christmas Loan Fee Fraud Surge
Financial Conduct Authority claims economic hardship is making consumers more vulnerable to loan fee fraud

Disney+ Cyber Scheme Exposes New Impersonation Attack Tactics
Abnormal Security said the attackers used advanced customization techniques to deceive victims

SpyLoan Scams Target Android Users With Deceptive Apps
ESET said these apps request sensitive user information, exfiltrating it to attackers’ servers

US Federal Agencies Miss Deadline for Incident Response Requirements
20 government agencies have failed to reach the incident response maturity level required by law, the GAO found in a new report

Russian APT28 Exploits Outlook Bug to Access Exchange
Notorious Russian APT28 group is actively exploiting CVE-2023-23397 to hijack Exchange email accounts

Porn Age Checks Threaten Security and Privacy, Report Warns
Online Safety Act’s mandate for age verification to access pornography could be a security and privacy disaster, think tanks warn

Sellafield Accused of Covering Up Major Cyber Breaches
Europe’s largest nuclear site, Sellafield, is accused of consistent security failings

Cybercriminals Escalate Microsoft Office Attacks By 53% in 2023
The Kaspersky report also revealed an average detection of 411,000 malicious files per day

Rust-Based Botnet P2Pinfect Targets MIPS Architecture
Cado Security found the variant while investigating files uploaded to an SSH honeypot

EU Council and Parliament Reach Agreement on Cyber Resilience Act
The European institutions have finally resolved several contentious aspects of the Cyber Resilience Act

Staples Hit With Disruption After Cyber-Attack
Retail giant’s service lines still impacted

Russian Developer Pleads Guilty to Trickbot Conspiracy
40-year-old was extradited from South Korea

US Confirms Iranian Attacks on Water Companies
State-backed CyberAveng3rs group hits Unitronics installations

NCSC Urges UK Water Companies to Secure Control Systems
Guidance follows US incident involving Unitronics programmable logic controllers

Apple Patches Actively Exploited iOS Zero-Days
Vulnerabilities may be linked to commercial spyware operations

UK Celebrates “World-First” Anti-Fraud Deal With Big Tech
Government says tech firms have pledged to remove malicious content

North Korean Hackers Amass $3bn in Cryptocurrency Heists
Stolen cryptocurrency is converted into fiat currency using stolen identities and manipulated photos

Manufacturing Top Targeted Industry in Record-Breaking Cyber Extortion Surge
Orange Cyberdefense’s Security Navigator listed the manufacturing sector as number one for both detected cyber incidents and confirmed cyber-attacks

FjordPhantom Android Malware Targets Banks With Virtualization
Promon said one FjordPhantom attack resulted in a substantial loss of approximately $280,000

RedLine Stealer Malware Deployed Via ScrubCrypt Evasion Tool
The new ScrubCrypt obfuscation tool is designed to avoid antivirus protections



