Infosecurity News

Black Friday: Significant Security Gaps in E-Commerce Web Apps
Researchers warn that millions of consumers’ PII could be at risk due to exploitable vulnerabilities and a lack of basic security protocols in e-commerce web apps

Cybersecurity Executive Pleads Guilty to Hacking Hospitals
Securolytics COO wanted to drum up custom

Ukraine Sacks Two Senior Cyber Officials
Duo linked to corruption investigation

US Cybersecurity Lab Suffers Major Data Breach
Idaho National Laboratory is also a center for nuclear research

CISA Unveils Healthcare Cybersecurity Guide
The guide outlines mitigation strategies and best practices to counteract prevalent cyber-threats

Infostealer Lumma Evolves With New Anti-Sandbox Method
Outpost24 explained the technique relies on trigonometry to discern genuine human behavior

Secretary Fined For Accessing Scores of Patient Records
NHS worker broke strict rules governing the special category data

Russia’s APT29 Targets Embassies With Ngrok and WinRAR Exploit
Threat group may be looking for intel on Azerbaijan

NCSC Announces New Standard For Indicators of Compromise
Security agency authors first RFC document for IETF

Black Friday: Scammers Exploit Luxury Brands to Lure Victims
Check Point Research say these latest luxury brand scams are a wake-up call for shoppers to stay vigilant online

FBI Lifts the Lid on Notorious Scattered Spider Group
Security advisory details TTPs of prolific threat actors

Royal Mail to Spend £10m on Ransomware Remediation
Postal service was breached in January 2023

British Library: Ransomware Recovery Could Take Months
Famed institution warns of ongoing disruption

CSA Launches First Zero Trust Certification
The CCZT program incorporates foundational principles from leading sources such as CISA and NIST

Cyber-Criminals Exploit Gaza Crisis With Fake Charity
Attackers sought crypto donations of $100-$5000 using Bitcoin, Litecoin and Ethereum addresses

Russian Hacking Group Sandworm Linked to Unprecedented Attack on Danish Critical Infrastructure
A report described the coordinated attack, in which 22 critical infrastructure firms were targeted

Black Friday: Malwarebytes Warns of Credit Card Skimming Surge
Skimming threat actors ramp up their activity just in time for the holiday season

Half of Ransomware Groups Operating in 2023 Are New
WithSecure report highlights widespread code reuse

BlackCat Ransomware Group Reports Victim to SEC
ALPHV/BlackCat tries unusual extortion technique

European Police Take Down $9m Vishing Gang
Fraudsters operated from Ukrainian call centers



