Infosecurity News

  1. Fraudsters Exploit Telegram’s Popularity For Toncoin Scam

    The scheme was uncovered by Kaspersky and has been operational since November 2023

  2. Dependency Confusion Vulnerability Found in Apache Project

    This occurs when a private package fetches a similar public one, leading to exploit due to misconfigurations in package managers

  3. CrushFTP File Transfer Vulnerability Lets Attackers Download System Files

    CrushFTP is urging customers to download v11 of its file transfer platform, with attackers actively exploiting a vulnerability that allows them to download system files

  4. NSA Launches Guidance for Secure AI Deployment

    The new document is the first release from NSA’s Artificial Intelligence Security Center (AISC), in partnership with other government agencies in the US and other Five Eyes countries

  5. NCSC Announces PwC’s Richard Horne as New CEO

    The UK’s National Cyber Security Centre will see Richard Horne take over as its new boss in the autumn

  6. MITRE Reveals Ivanti Breach By Nation State Actor

    Non-profit MITRE says a sophisticated state group breached its network via two chained Ivanti zero-days

  7. Alarming Decline in Cybersecurity Job Postings in the US

    This drop represents a direct threat to US national cybersecurity infrastructure, said CyberSN representatives in their report

  8. Akira Ransomware Group Rakes in $42m, 250 Organizations Impacted

    A joint advisory from Europol and US and Dutch government agencies estimated that Akira made around $42m in ransomware proceeds from March 2023 to January 2024

  9. Quishing Attacks Jump Tenfold, Attachment Payloads Halve

    The figures come from Egress’s latest report, which also suggests secure email gateways lag behind tech advancements

  10. Russia's Sandworm Upgraded to APT44 by Google's Mandiant

    Mandiant has confirmed that Sandworm is responsible for many cyber-attacks against Ukraine has close ties with a Russian hacktivist group

  11. New Cyber-Threat MadMxShell Exploits Typosquatting and Google Ads

    Zscaler also confirmed MadMxShell uses DLL sideloading and DNS tunneling for C2 communication

  12. US Election Officials Told to Prepare for Nation-State Influence Campaigns

    A US government advisory sets out actions election officials need to take to mitigate the impact of nation-state influence campaigns ahead of the November elections

  13. Trust in Cyber Takes a Knock as CNI Budgets Flatline

    Bridewell report reveals critical infrastructure firms are losing faith in their defensive tooling

  14. UK Police Lead Disruption of £1m Phishing-as-a-Service Site LabHost

    The Metropolitan Police and partners have disrupted the prolific LabHost phishing-as-a-service platform

  15. Linux Cerber Ransomware Variant Exploits Atlassian Servers

    The attacks exploit CVE-2023-22518, a critical flaw in Atlassian Confluence Data Center and Server

  16. North Korean Group Kimsuky Exploits DMARC and Web Beacons

    Proofpoint confirmed Kimsuky has directly contacted foreign policy experts since 2023 through seemingly benign email conversations

  17. US Government and OpenSSF Partner on New SBOM Management Tool

    OpenSSF, in collaboration with the US Government, has developed Protobom, a open source tool designed to simplify SBOM management for organizations

  18. EU Election: Pro-Russian Propaganda Exploits Meta's Failure to Moderate Political Ads

    This year’s EU election will be a stress test to see whether the newly adopted Digital Services Act can efficiently mitigate misinformation threats

  19. Ivanti Patches Two Critical Avalanche Flaws in Major Update

    Ivanti has fixed two critical vulnerabilities in its Avalanche MDM product which could lead to remote code execution

  20. Insider Threats Surge 14% Annually as Cost-of-Living Crisis Bites

    Cifas reveals 14% rise in dishonest employees, driven mainly by financial necessity last year

What’s Hot on Infosecurity Magazine?