Infosecurity News

New Phishing Campaign Uses LinkedIn Smart Links in Blanket Attack
Email security provider Cofense has unveiled a large-scale phishing campaign leveraging LinkedIn Smart Links

CISOs Receive Smaller Raises and Bonuses in 2023
Most CISOs are considering a job change in the next 12 months

Vulnerability Exposed in WordPress Plugin User Submitted Posts
With over 20,000 active installations, the plugin is used for user-generated content submissions

California Enacts “Delete Act” For Data Privacy
Governor Newsom signed the first US bill requiring data brokers to delete personal data upon request

Chinese APT ToddyCat Targets Asian Telecoms, Governments
A cyber espionage campaign tied to the Chinese group ToddyCat is targeting high-profile organizations in Kazakhstan, Uzbekistan, Pakistan, and Vietnam

Half of Small Businesses Hit by Cyber-Attack Over the Past Year
A new survey from accounting software provider Sage showed that most SMEs have developed a cybersecurity posture but struggle to keep up with the threats

European Police Hackathon Hunts Down Traffickers
Many recruit victims on social media, says Europol

Fifth of UK Cybersecurity Pros Work Excessive Hours
Workload is biggest concern for industry professionals

US Smashes Annual Data Breach Record With Three Months Left
Volume of data compromises already exceeds previous high by 14%

Curl Releases Fixes For High-Severity Vulnerability
The flaw impacts curl and libcurl, causing SOCKS5 proxy handshake to suffer heap buffer overflow

US Government Issues Open-Source Security Guidance for Critical Infrastructure
The recommendations are designed to reduce the life-safety implications of cyber incidents in ICS environments

Exploitation Accounts For 29% of Education Sector Attacks
The figures from the latest Critical Start report also suggest 30% come from phishing campaigns

Cyber Professionals Alarmed by Growing Attacker Use of AI
IT security professionals are concerned about the increasing use of AI in cyber-attacks, particularly deepfakes

October Patch Tuesday Addresses Three Zero-Days
Microsoft issues updates for over 100 flaws

Air Europa Asks Customers to Cancel Cards After Breach
Spanish airline did not disclose scale of the attack

Tech Giants Reveal Record-Breaking “Rapid Reset” DDoS Bug
Zero-day has been exploited to launch largest attacks ever seen

IZ1H9 Botnet Targets IoT Devices With New Exploits
FortiGuard Labs said the new campaign incorporates 13 distinct payloads

Flagstar Bank MOVEit Breach Affects 800K Customer Records
The incident occurred between May 27 and 31 2023, before MOVEit Transfer vulnerability was publicly disclosed

#CyberMonth: Google Makes Passkeys Default Sign-In Option
The tech giant said the move is designed to help efforts to make passwords obsolete

Half of CISOs Now Report to CEO as Influence Grows
Trend is more pronounced in Europe than America



