Infosecurity News

  1. Business Logic Abuse Dominates as API Attacks Surge

    Imperva finds attacks targeting API business logic increased to 27% in 2023

  2. White House Urges Tech Industry to Eliminate Memory Safety Vulnerabilities

    A new White House report has urged software and hardware developers to adopt memory safe programming languages, and eliminate one of the most pervasive classes of bugs

  3. CISA Issues Alert on APT29’s Cloud Infiltration Tactics

    Known as Midnight Blizzard, the Dukes or Cozy Bear, the group has been identified as a Russian entity likely operating under the SVR

  4. Expert Warns of Growing Android Malware Activity

    Kaspersky said that in 2023, the number of mobile attacks soared to nearly 33.8 million

  5. LockBit Takedown: What You Need to Know about Operation Cronos

    What businesses should know about Operation Cronos and LockBit, one of the largest ransomware takedowns in history

  6. Avast Faces $16.5m Fine for Unlawfully Selling User Browsing Data

    The FTC order found that Avast sold browsing data to advertisers that could reveal highly sensitive insights about users, misleading them about privacy protections in the process

  7. NCSC to Offer Cyber Governance Guidance to Boards

    The UK’s National Cyber Security Centre is preparing a new cyber governance training pack for boards

  8. U-Haul Informs Customers of Major Data Breach

    Moving giant U-Haul has revealed that 67,000 customers were caught in a data breach last year

  9. Operation Cronos: Who Are the LockBit Admins?

    Law enforcement agencies involved in Operation Cronos have announced they have been in contact with the LockBit kingpin aka LockbitSupp

  10. ICO Bans Serco Leisure's Use of Facial Recognition for Employee Attendance

    The UK’s ICO has ruled Serco Leisure’s use facial recognition technology and fingerprint scanning to monitor employee attendance is in breach of data protection law

  11. 78% of Organizations Suffer Repeat Ransomware Attacks After Paying

    Cybereason found that 78% of organizations who paid a ransom demand were hit by a second ransomware attack, often by the same threat actor

  12. SMBs at Risk From SendGrid-Focused Phishing Tactics

    Kaspersky explained the fraudulent emails prompted recipients to enable two-factor authentication

  13. Change Healthcare Cyber-Attack Leads to Prescription Delays

    The incident has impacted numerous Change Healthcare applications, including pharmacy, medical records

  14. Russian-Aligned Network Doppelgänger Targets German Elections

    SentinelLabs and ClearSky said the group leverage a substantial network of social media accounts

  15. OWASP Releases Security Checklist for Generative AI Deployment

    The OWASP Foundation provides new guidelines to deploy secure-by-design LLM use cases

  16. Cyber Pros Embrace AI, Over 80% Believe It Will Enhance Jobs

    ISC2 found that 82% of cybersecurity professionals believe AI will improve the efficiency of their jobs

  17. Chinese Duo Found Guilty of $3m Apple Fraud Plot

    Two Maryland residents have been convicted of a multimillion-dollar fraud scheme against Apple

  18. Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited

    Researchers warn of a “ransomware free-for-all” after ScreenConnect vulnerability is exploited

  19. Businesses Increase Cybersecurity as Budgets Surge in 2024

    Over two-thirds of IT decision-makers increase cybersecurity budgets in 2024, prioritizing cloud security and incident response as cyber threats escalate

  20. Over 40% of Firms Struggle With Cybersecurity Talent Shortage

    Kaspersky’s recent report said the shortage is particularly acute in Europe, Russia and Latin America

What’s Hot on Infosecurity Magazine?