Infosecurity News

UK Voters’ Data Exposed in Electoral Commission Cyber-Attack
The attackers accessed personal data of anyone in the UK who was registered to vote between 2014 and 2022

#BHUSA: Identity Compromise the Cause of Most Breaches
Pushed to the edges by efficient EDRs, threat actors are forced to use living-off-the-land techniques

North Korean Hackers Compromise Russian Missile Maker
NPO Mashinostroyeniya is under sanctions for supporting Kremlin war machine

Two-Thirds of UK Sites Vulnerable to Bad Bots
Those selling goods and classified ads are particularly exposed

Over 200 Million Brits Have Data Compromised in Four Years
Nearly 100,000 breaches were reported to the ICO between 2019 and 2022

US Primary Care Services Shuttered After Cyber-Attack
Prospect Medical Holdings took its systems offline on Friday and initiated an investigation

Invisible Ad Fraud Targets Korean Android Users
McAfee said the library registers device information and drains battery life and mobile data

FBI Warns Against Criminals Posing as NFT Developers
Users are tricked into connecting their cryptocurrency wallets to malicious smart contracts

Russian Hacktivists Overwhelm Spanish Sites With DDoS
Attacks come after Prime Minister’s trip to Kyiv

Colorado Education Department Suffers Ransomware Breach
Past and current staff and students are impacted

Clop Gang Offers Data Downloads Via Torrents
Latest innovation designed to speed up download process

Stealthy npm Malware Exposes Developer Data
Phylum said the attack demonstrated a carefully crafted development cycle

VMConnect: Python PyPI Threat Imitates Popular Modules
ReversingLabs said the attackers displayed a sophisticated approach and techniques

CISA Announces 2024-2026 Strategic Plan
The US’ leading cybersecurity agency calls for us to “embody the hacker spirit” in its latest strategic plan

Sophisticated Phishing Exploits Zero-Day Salesforce Vulnerability
Guardio Labs detected the campaign and detailed its findings in a technical blog post

Microsoft Warns of Growing Cyber-Threats to Sporting Events
Microsoft observed attackers continually attempting to compromise connected systems at the 2022 World Cup

Credentials Account For Over Half of Cloud Compromises
Google Cloud figures also point to misconfiguration

Legacy Flaws Dominate Top 12 Vulnerabilities List
Security agencies urge timely patching

UK Government: Cyber-Attacks Could Kill or Maim Thousands
Risk assessment predicts critical infrastructure attacks could cost billions

Hacktivist Collective “Mysterious Team Bangladesh” Revealed
Group-IB said the group carried out 750 DDoS attacks and more than 70 website defacements in a year



