Infosecurity News

Security Incident Impacts CardioComm’s Operations
Several of the company’s products are affected by the outage

High Severity Vulnerabilities Discovered in Ninja Forms Plugin
The popular forms builder plugin for WordPress has over 900,000 active installations

China’s Wuhan Earthquake Center Suffers Cyber-Attack
Responding to the news, a Chinese Foreign Ministry Spokesperson claimed the US is engaging in malicious cyber operations across the world

“Mysterious Elephant” Emerges, Kaspersky Reports
Kaspersky also sheds light on more information related to the “Operation Triangulation” campaign

OpenAI, Microsoft, Google and Anthropic Form Body to Regulate AI
Four generative AI pioneers launched the Frontier Model Forum, which will focus on ‘safe and responsible’ creation of new AI models

NCSC Publishes New Guidance on Shadow IT
Security agency suggests mitigations and technical solutions

Supply Chain Attack Hits NHS Ambulance Trusts
Electronic patient records unavailable for over a week

SEC Wants Cyber-Incident Disclosure Within Four Days
More consistent notification rules required of public firms

Repeatable VEC Attacks Target Critical Infrastructure
Likelihood of a firm falling victim to a VEC attack rose from 45% in June 2022 to 70% in May 2023

VMware Patches Vulnerability Exposing Admin Credentials
The issue arises from the logging of credentials in hex encoding in platform system audit logs

Group-IB Founder Sentenced in Russia to 14 Years for Treason
Reports said Ilya Sachkov was suspected of passing on state secrets

Dark Web Markets Offer New FraudGPT AI Tool
The tool can craft phishing emails, create undetectable malware and identify vulnerable sites

Ransomware Attacks Skyrocket in 2023
SonicWall’s report finds that ransomware rebounded in Q2 2023 following a major reduction in Q1

Education Sector Has Highest Share of Ransomware Victims
Extortionists know their targets have low tolerance for outages

Over 900,000 MikroTik Routers Exposed to Critical Bug
Attackers could covertly gain remote control of devices

Industry Coalition Calls For Enhanced Network Resilience
Alliance wants to improve visibility and patching

Decoy Dog Malware Upgraded to Include New Features
Decoy Dog used DNS for C2 and is suspected to be employed in ongoing nation-state cyber-attacks

North Korean Cyber Group Suspected in JumpCloud Breach
Mandiant said the compromise resulted from a sophisticated spear-phishing campaign

Critical Flaws Found in Microsoft Message Queuing Service
FortiGuard Labs described the vulnerabilities in an advisory published on Monday

UK Government Report Finds Cybersecurity Skills Gap Stagnant
A new report shows that 50% of all UK businesses have a basic cyber security skills gap, and 33% have an advanced skills gap



