Infosecurity News

UK Government Backs Down on Anti-Encryption Stance
Statement to Lords heralds delay to on-device message scanning

MITRE and CISA Release OT Attack Emulation Tool
The open source tool will enable cyber teams to consistently test and boost the defenses of ICS environments

Russia-Backed APT28 Tried to Attack a Ukrainian Critical Power Facility
The attack has been carried out using legitimate services and standard software functions, CERT-UA observed

High-Severity Vulnerability Discovered in Popular CMS
The unpatched bug in PHPFusion could result in the theft of sensitive data, Synopsys researchers warn

UK Boards Are Growing Less Concerned About Cyber-Risk
Their global peers feel the opposite, according to Proofpoint study

Experts Uncover Underground Phishing “Empire” W3LL
Secretive group targets specifically Microsoft 365 accounts

Crypto Casino Stake.com Back Online After $40m Heist
Hot wallets were compromised at firm

Mend.io SAML Vulnerability Exposed
SAML flaw in enabled rogue customers to access others’ SaaS data

Airlines Battle Surge in Loyalty Program Fraud
Group-IB said 2022 saw 30% more loyalty fraud, impacting 75+ airlines and involving 2000 malicious sources

UK Electoral Commission Fails Cybersecurity Test Amid Data Breach
Auditors cited outdated software and unsupported iPhones as key reasons for the failed test

More Schools Hit By Cyber-Attacks Before Term Begins
Highgate Wood School forced to delay new term for six days

UK National Cyber Security Centre Gets a New CTO
Industry veteran Ollie Whitehouse is confirmed

Freecycle Breach May Have Hit Millions of Users
Non-profit urges all users to reset passwords

Python Package Index Targeted Again By VMConnect
ReversingLabs uncovered three additional malevolent packages believed to be part of the campaign

New Attack Technique “MalDoc in PDF” Alarms Experts
JPCERT/CC said it can elude detection by embedding a malicious Word file within a PDF document

Medical Data Breach: Ayush Jharkhand Hacked
According to CloudSEK, the leaked database contains over 320,000 patient records

Sensitive Data about UK Military Sites Potentially Leaked by LockBit
Zaun, the UK’s only manufacturer of fencing systems, saw its IT systems being compromised in early August

Sydney University Suffers Supply Chain Breach
Blast radius appears limited to international students

Four Convicted in $18m Investment Fraud Scheme
The Brittingham Group promised outsized returns to victims

Suffolk High School Forced Offline After Cyber-Attack
Separate research warns of widespread email security failings



