Infosecurity News

  1. Five Eyes Warn of Ivanti Vulnerabilities Exploitation, Detection Tools Insufficient

    Government agencies from the Five Eyes coalition said that Ivanti’s own tools are not sufficient to detect compromise

  2. UK Home Office Breached Data Protection Law with Migrant Tracking Program, ICO Finds

    The Home Office failed to assess the privacy intrusion of the continuous collection of migrants’ location information in breach of UK data protection law, according to the ICO

  3. Pharma Giant Cencora Reports Cybersecurity Breach

    The breach was discovered on February 21 2024, according to an SEC filing published on the same day

  4. Savvy Seahorse Targets Investment Platforms With DNS Scams

    Infoblox said Savvy Seahorse uses fake ChatGPT and WhatsApp bots to lure victims

  5. Dark Web Market Revenues Rebound but Sector Fragments

    Chainalysis study of crypto flows reveals darknet markets made $1.7bn in 2023

  6. US Government Warns Healthcare is Biggest Target for BlackCat Affiliates

    The US government advisory warns healthcare organizations are being targeted by BlackCat amid an ongoing cyber-incident affecting Change Healthcare

  7. TimbreStealer Malware Targets Mexican Victims with Tax-Related Lures

    The maker of the Mispadu Trojan started distributing a new infostealer with financial lures to Mexican users, Cisco Talos found

  8. Biden Bans Mass Sale of Data to Hostile Nations

    A new presidential executive order attempts to prevent the mass sales of personal data to countries like China and Russia

  9. FBI Issues Alert on Russian Threats Targeting Ubiquiti Routers

    The routers were hijacked to steal credentials, proxy traffic, and host phishing pages and custom tools

  10. 34 Million Roblox Credentials Exposed on Dark Web in Three Years

    Kaspersky reported a 231% surge in compromised accounts from 4.7 million in 2021 to 15.5 million in 2023

  11. How Security Leaders Can Break Down Barriers to Enable Digital Trust

    ISACA's Rob Clyde and Pam Nigro discuss how to advance digital trust in a security context

  12. UK ICO Vows to Safeguard Privacy in AI Era, Rules Out Bespoke Regulation

    UK Information Commissioner John Edwards explains how the ICO is working to provide clarity around the lawful use of AI

  13. Over Half of UK Firms Concerned About Insider Threats

    Cifas claims that most business decision makers are worried about fraudsters targeting employees

  14. Ads for Zero-Day Exploit Sales Surge 70% Annually

    Group-IB research warns of rising use of zero-day threats in targeted attacks

  15. Industrial Cyber Espionage France's Top Threat Ahead of 2024 Paris Olympics

    Ransomware and destabilization attacks rose in 2023, yet France’s National Cybersecurity Agency is most concerned about a diversification of cyber espionage campaigns

  16. Four Million WordPress Sites Vulnerable to LiteSpeed Plugin Flaw

    The flaw, discovered by Patchstack, stems from a lack of input sanitization and output escaping in the plugin’s code

  17. NIST Releases Final Version of Cybersecurity Framework 2.0

    NIST has made further tweaks to Version 2.0 of its Cybersecurity Framework following feedback from the cybersecurity community

  18. Half of IT Leaders Identify IoT as Security Weak Point

    The Viakoo study also said 50% firms faced IoT cyber incidents in past year, 44% of which were severe

  19. Most Commercial Code Contains High-Risk Open Source Bugs

    Synopsys report reveals 74% of codebases now contain risky open source components

  20. 69% of Organizations Infected by Ransomware in 2023

    Proofpoint found that 69% of organizations experienced a successful ransomware incident in the past year, with 60% hit on four or more occasions

What’s Hot on Infosecurity Magazine?