Infosecurity News

NCSC Launches Cyber Risk Management Toolbox
Security agency’s latest guidance refresh makes best practices more accessible

Payments Lobby: Anti-APP Fraud Policies Could Increase Scams
Payments Association wants social media firms to play role in crackdown

Are GPT-Based Models the Right Fit for AI-Powered Cybersecurity?
Many cybersecurity vendors are integrating general-purpose large language models into their solutions. However, some experts argue that these are not the best AI algorithms for security

Umbral Stealer Discovered in Trojanized Super Mario Installer
The discovery comes from security researchers at Cyble Research and Intelligence Labs

Millions Face RepoJacking Risk on GitHub Repositories
Aqua identified numerous high-profile targets, including organizations such as Google and Lyft

NSA Releases Guide to Mitigate BlackLotus Bootkit Infections
Microsoft patched exploited boot loader flaw but did not revoke trust in unpatched loaders

Companies Call for Changes to UK’s Cyber Essentials Scheme
Concerns over cost and one-size-fits-all approach

US Authorities Seize BreachForums Domain
Questions still to be answered over why it took so long

Twitter Celeb Hacker Jailed For Five Years
Joseph O'Connor hijacked over 100 accounts in bitcoin scam

US Military Personnel Warned of Malicious Smartwatches
The smartwatches have Wi-Fi auto-connect features and possibly contain malware

OpenSSH Trojan Campaign Targets IoT and Linux Systems
Microsoft said attackers used a patched version of OpenSSH to gain control of compromised devices

USB Drives Used as Trojan Horses By Camaro Dragon
The malicious software tools were discovered by Check Point Research

BlackBerry Cybersecurity President Warns Against Heavy-Handed AI Regulation
BlackBerry president John Giamatteo acknowledged that governments should intervene to mitigate AI risks – and his company is willing to help them

NCSC Updates Cybersecurity Guidance for the Legal Sector
Law firms remain a popular target for attack

Manchester University Breach Victims Hit with Triple Extortion
Threat actors seek to put pressure on university to pay

FBI Analyst Gets Three Years For National Security Breach
Kendra Kingsbury smuggled classified documents out on storage media

#InfosecurityEurope Case Study: Attack Surface Operations at Nationwide
Nationwide Building Society is setting up a new team tasked with monitoring and managing its attack surface

#InfosecurityEurope: Experts Highlight Evolving Attack Techniques
Experts discussed growing utilization of ChatGPT by threat actors and evolving identity-based attacks

Apple Addresses Exploited Security Flaws in iOS, macOS and Safari
Latest updates patch two zero-day vulnerabilities reportedly weaponized in Operation Triangulation

US Justice Department Launches New National Security Cyber Section
The primary objective of NatSec Cyber is to enhance the Justice Department’s capacity to counter malicious cyber activities effectively



