Infosecurity News

  1. Critical Vulnerability in Apache OFBiz Requires Immediate Patching

    SonicWall discovered the Apache OFBiz flaw, identifying it as a critical issue enabling unauthenticated remote code execution

  2. 86% of Firms Identify Unknown Cyber-Risks as Top Concern

    50% of professionals also cited a lack of expertise as a barrier to effective cyber-risk management

  3. TikTok Withdraws Lite Rewards Program from EU Over Child Safety Fears

    TikTok has committed to permanently withdraw the Lite Rewards program from the EU, after legal proceedings were launched relating to its risks to users, particularly children

  4. White House and EC-Council Launch $15m Cybersecurity Scholarship Program

    The White House and EC-Council scholarship program aims to train over 50,000 students in critical cybersecurity skills

  5. US Sues TikTok For Children’s Law Violations

    The US government is taking TikTok to court for alleged violations of the COPPA regulation

  6. APT Group StormBamboo Attacks ISP Customers Via DNS Poisoning

    Volexity claims the StormBamboo group compromised an ISP to push malicious software updates to customers

  7. Social Media Firms Fail to Protect Children’s Privacy, Says ICO

    The UK’s ICO has identified children’s privacy concerns in 11 social media and video sharing platforms, warning of regulatory action if these issues are not addressed

  8. EPA Told to Address Cyber Risks to Water Systems

    The US Government Accountability Office has told the Environmental Protection Agency to urgently develop a strategy to tackle rising cyber-threats to the water industry

  9. NCSC Unveils Advanced Cyber Defence 2.0 to Combat Evolving Threats

    The UK's NCSC is launching ACD 2.0, an advanced suite of cybersecurity tools and services designed to protect businesses from evolving cyber threats

  10. Gaming Industry Faces 94% Surge in DDoS Attacks

    The rise in DDOS attacks against the gaming industry is accompanied by increasing bot activity

  11. Scam Platform Shut Down by UK Authorities After 1.8 Million Fraudulent Calls

    UK authorities shut down a scam platform responsible for over 1.3 million calls to 500,000 victims, resulting in millions of pounds in losses

  12. RansomEXX Group Targets Indian Banking With New Tactics

    CloudSek said the RansomEXX breach occurred via a misconfigured Jenkins server at Brontoo Technology

  13. Cencora Confirms Patient Data Stolen in Cyber-Attack

    Pharma company Cencora confirmed in an updated SEC filing that sensitive personal and health data was exfiltrated by attackers in a February 2024 incident

  14. E-Commerce Fraud Campaign Uses 600+ Fake Sites

    The “Eriakos” info-stealing campaign is using hundreds of fake web shops to defraud victims

  15. BEC Attacks Surge 20% Annually Thanks to AI Tooling

    A Vipre study reveals a 20% increase in business email compromise attacks

  16. Urgent Blood Appeal Issued in US After Ransomware Attack

    US non-profit OneBlood has issued an urgent appeal for donations after a ransomware attack has significantly reduced its capacity to distribute blood to hospitals

  17. New SMS Stealer Malware Targets Over 600 Global Brands

    Discovered by Zimperium’s zLabs team, the SMS Stealer malware was found in over 105,000 samples

  18. Meta to Pay Texas $1.4bn for Unlawful Biometric Data Capture

    Meta has agreed a $1.4bn settlement with the State of Texas for failing to inform Facebook users about its biometric data capturing practices

  19. New PyPI Package Zlibxjson Steals Discord, Browser Data

    According to Fortinet, PyPI package Zlibxjson steals Discord tokens and browser data, including passwords and extensive user information

  20. DDoS Attack Triggers New Microsoft Global Outage

    A global outage of Microsoft services was triggered by a DDoS attack, with an error Microsoft’s DDoS protection measures amplifying the impact

What’s Hot on Infosecurity Magazine?