Infosecurity News

#BHUSA: Security Risks to Boom in the Era of Widespread Generative AI Adoption
Enterprise usages of generative AI are what is going to turn the threat model of many organizations upside down, Maria Markstedter argued during her speech at Black Hat USA

UK Government Slammed For Encryption Mistruths
Technology secretary branded “delusion”

CISA: New Whirlpool Backdoor Used in Barracuda ESG Campaign
China-linked APT group has been blamed for the attacks

Researchers Suggest Ways to Tackle Thermal Attacks
Device manufacturers and users have a role to play in mitigating the threat

#BHUSA: White House, DARPA and CISA Ask for Help in Securing Open Source Software
Kemba Walden announced at Black Hat USA that five US government agencies were launching a request for information on open source software security

#BHUSA: US National Security Agency Announces Codebreaker Challenge Theme
Contestants of the 10-year-old NSA competition will have to decipher an unknown signal in overseas US territory

New York Introduces First-Ever Statewide Cybersecurity Strategy
Governor Kathy Hochul reinforced the strategy with a $600m commitment

APT31 Linked to Recent Industrial Attacks in Eastern Europe
Kaspersky published the third installment of their investigation on this campaign earlier today

#BHUSA: Only 22% of Firms Have Mature Threat Intelligence Programs
OPSWAT presented the findings is its latest Threat Intelligence Survey

Potent Trojans Targeting MacOS Users
A new Bitdefender report finds that attackers are building more sophisticated malware creations tailored to macOS

#BHUSA: DARPA Challenges AI Pros to Safeguard US Infrastructure
The new AI Cyber Challenge (AIxCC) is sponsored by DARPA, Google, Microsoft, OpenAI, Anthropic and the Open Source Security Foundation

#BHUSA: ESET Unmasks Cyber-Espionage Group Targeting Embassies in Belarus
The new APT is allegedly aligned with the Belarusian regime and has operated under the radar for at least nine years

Fresh Blow to PSNI Security as Second Data Breach Disclosed
This latest incident involved the theft of a spreadsheet containing the names of over 200 serving police officers and staff

Regulator: “Harmful” Web Design Could Break Data Protection Laws
ICO wants an end to dishonest practices

EvilProxy Campaign Fires Out 120,000 Phishing Emails
Threat actors are targeting execs and Microsoft 365 accounts

NIST Expands Cybersecurity Framework with New Pillar
Version 2.0 draft is first refresh in nearly a decade

#BHUSA: New Zero-Day Vulnerabilities Could Instantly Drain Crypto Wallets
A number of popular crypto wallet providers have been affected by the vulnerabilities, including Coinbase WaaS, Zengo and Binance

Rhysida Ransomware Analysis Reveals Vice Society Connection
Check Point highlighted the necessity of understanding the the entire attack process of ransomware groups

Breach Connected to MOVEit Flaw Affects Missouri Medicaid Recipients
Information involved in the incident includes names, dates of birth and medical claims information

High-Severity Access Control Vulnerability Found in Spring WebFlux
Tracked as CVE-2023-34034, the flaw has a CVSS score of 9.8



