Infosecurity News

Fresh Blow to PSNI Security as Second Data Breach Disclosed
This latest incident involved the theft of a spreadsheet containing the names of over 200 serving police officers and staff

Regulator: “Harmful” Web Design Could Break Data Protection Laws
ICO wants an end to dishonest practices

EvilProxy Campaign Fires Out 120,000 Phishing Emails
Threat actors are targeting execs and Microsoft 365 accounts

NIST Expands Cybersecurity Framework with New Pillar
Version 2.0 draft is first refresh in nearly a decade

#BHUSA: New Zero-Day Vulnerabilities Could Instantly Drain Crypto Wallets
A number of popular crypto wallet providers have been affected by the vulnerabilities, including Coinbase WaaS, Zengo and Binance

Rhysida Ransomware Analysis Reveals Vice Society Connection
Check Point highlighted the necessity of understanding the the entire attack process of ransomware groups

Breach Connected to MOVEit Flaw Affects Missouri Medicaid Recipients
Information involved in the incident includes names, dates of birth and medical claims information

High-Severity Access Control Vulnerability Found in Spring WebFlux
Tracked as CVE-2023-34034, the flaw has a CVSS score of 9.8

Northern Ireland Police Officers Vulnerable After Data Leak
The accidental release of PSNI police officers’ names and department has raised huge safety fears

Notorious Phishing-as-a-Service Platform Shuttered
Suspected Indonesian admin arrested in multi-national operation

Summer Spending Pressure Fuels Loan Fee Fraud Fears
UK financial regulator in new consumer awareness campaign

Microsoft Patches 80+ Flaws Including Two Zero-Days
Another busy Patch Tuesday for sysadmins

Tampa General Hospital Sued Over Data Breach
Plaintiffs claim hospital didn't secure data and worsened the situation by delaying notification

#BHUSA: Ransomware Threat Activity Cluster Uncovered
The elusive ransomware group, Royal, might be collaborating with Hive and Black Basta

Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Cisco Talos said what sets this operation apart is the novel approach to delivering ransom notes

UK Voters’ Data Exposed in Electoral Commission Cyber-Attack
The attackers accessed personal data of anyone in the UK who was registered to vote between 2014 and 2022

#BHUSA: Identity Compromise the Cause of Most Breaches
Pushed to the edges by efficient EDRs, threat actors are forced to use living-off-the-land techniques

North Korean Hackers Compromise Russian Missile Maker
NPO Mashinostroyeniya is under sanctions for supporting Kremlin war machine

Two-Thirds of UK Sites Vulnerable to Bad Bots
Those selling goods and classified ads are particularly exposed

Over 200 Million Brits Have Data Compromised in Four Years
Nearly 100,000 breaches were reported to the ICO between 2019 and 2022



