Infosecurity News

Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Although the patches for these vulnerabilities have already been released, public attacks are still occurring

BYOD Security Gap: Survey Finds 49% of European Firms Unprotected
Jamf suggested firms enroll employees in a BYOD or Mobile Device Management (MDM) program

New Research Exposes Airbnb as Breeding Ground For Cybercrime
Slashnext unveiled a disturbing arsenal of stealers, cookies and exploits

Facebook Accounts Targeted by Vietnamese Threat Groups
These groups often sell ads to other cybercriminals, either for a fee or a share of the operations

GRU Blamed for Infamous Chisel Malware Targeting Ukraine's Military Phones
Infamous Chisel, which enables unauthorized access to compromised Android devices used by the Ukrainian military, has been linked to Sandworm

Russian APT Intensifies Cyber Espionage Activities Amid Ukrainian Counter-Offensive
The Gamaredon group has ramped up attacks against Ukrainian military entities, with the aim of hindering Ukraine’s counter-offensive operations

Classiscam Spreads: $64.5M Scheme Targets 79 Countries
Group-IB’s analysis showed that between H1 2021 and H1 2023, 251 brands were targeted by Classiscam

Flaw Exposes WP Migration Plugin to Hacks
The vulnerable code was identified by the security research team at PatchStack

Chinese APT Group GREF Use BadBazaar in Android Espionage
ESET said BadBazaar was available via the Google Play Store, Samsung Galaxy Store and various app sites

Chinese Hackers Target US, Other Govts With Barracuda Flaw
The campaign deployed many malware families, including Skipjack, DepthCharge, Foxglove and Foxtrot

FBI-Led Operation Duck Hunt Shuts Down QakBot Malware
With Operation Duck Hunt, the FBI took control of the botnet, allowed victims to uninstall the malware loader and seized $8.6m in cryptocurrency

OpenAI Promises Enterprise-Grade Security with ChatGPT for Business
OpenAI has launched ChatGPT Enterprise highlighting high-profile customers including Klarna, PwC and The Estee Lauder Companies

NCSC Issues Cyber Warning Over AI Chatbots
The UK cyber agency highlights the lack of understanding of LLMs among industry and academia

LockBit 3.0 Ransomware Variants Surge Post Builder Leak
Kaspersky explained that LockBit 3.0, also known as LockBit Black, first emerged in June 2022

New Ransomware Campaign Targets Citrix NetScaler Flaw
Sophos X-Ops suspects the involvement of a well-known ransomware threat actor known as STAC4663

Report Reveals Growing Disparity in Cyber Insurance Landscape
Delinea’s report shows gap grows as firms struggle for cyber insurance, longer policy wait times

Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms
Existing phishing-as-a-service platforms are increasingly incorporating adversary-in-the-middle capabilities

Four in Five Cyber-Attacks Powered by Just Three Malware Loaders
ReliaQuest found that 80% of cyber intrusion campaigns used either QakBot, SocGholish or Raspberry Robin

Privacy Regulator Warns of Surge in “Text Pest” Cases
Nearly one in three young adults has had their personal information misused

Researchers Discover Reply URL Takeover Issue in Azure
Vulnerability could be exploited to gain elevated privileges



