Infosecurity News

Google Exposes 18 Zero-Day Flaws in Samsung Exynos Chips
Four of these vulnerabilities enabled potential attackers to perform remote code execution

Pro-Russian Winter Vivern APT Targets Governments and Telecom Firm
SentinelOne shared details about the new campaign in an advisory published on Thursday

ICO Reprimands Metropolitan Police for Data Snafu
Negligence could have caused "significant damage"

Russian Military Preparing New Destructive Attacks: Microsoft
Organizations outside Ukraine could be targeted

Vishing Campaign Targets Social Security Administration
Tens of thousands of mailboxes targeted

US Government IIS Server Breached via Telerik Software Flaw
The critical vulnerability allows remote code execution and was assigned a CVSS v3.1 score of 9.8

ChipMixer Crypto Laundromat Shut Down By German, US Authorities
The operation seized four servers, 7TB of data and 1909.4 Bitcoins (roughly $47.3m)

UK Joins US, Canada, Others in Banning TikTok From Government Devices
The Chancellor of the Duchy of Lancaster, Oliver Dowden, confirmed the plans earlier today

NCSC Calms Fears Over ChatGPT Threat
Tool won't democratize cybercrime, agency argues

BEC Volumes Double on Phishing Surge
Business email compromise overtakes ransomware

Chinese SilkLoader Malware Sold to Russian Cyber-Criminals
Cobalt Strike beacon loader migrates across criminal ecosystems

Tick APT Group Hacked East Asian DLP Software Firm
The hacker breached the DLP company's internal update servers to deliver malware within its network

"FakeCalls" Android Malware Targets Financial Firms in South Korea
CPR discovered 2500 samples of the malware, impersonating 20 financial institutions in the region

Humans Still More Effective Than ChatGPT at Phishing
The research paper by HoxHunt analyzed 53,127 emails sent to users in over 100 countries

UK Bank Limits Crypto Payments to Smother Fraud
NatWest warns of "life-changing" customer losses

Phishing Campaigns Use SVB Collapse to Harvest Crypto
Experts warn users to be on their guard

Microsoft Patches Two Zero Days This Month
They include one likely exploited by Russian-linked threat actors

YoroTrooper Espionage Campaigns Target CIS, EU Countries
The threat actors mainly targeted organizations across Azerbaijan, Tajikistan and Kyrgyzstan

DEV-1101 Updates Open Source Phishing Kit
The kit is written in NodeJS and has automated setup and detection evasion capabilities

CISA Creates New Ransomware Vulnerability Warning Program
The Agency will warn critical infrastructure entities to enable mitigation before an incident



