Infosecurity News

DoppelPaymer Ransomware Gang Members Busted in Germany, Ukraine
Police also seized electronic equipment and are currently performing forensic examinations

City of Oakland Faces Major Data Leak
Information was stolen during recent ransomware attack

UK Government Plans Skills Boost for Public Sector Fraud Fight
Focus will be on enhancing prevention and identification skills

FTC Proposes $7.8m Fine for BetterHelp
Online counseling service shared health data

TPM 2.0 Library Vulnerabilities May Affect Billions of IoT Devices
The disclosed flaws occurred when handling malicious TPM 2.0 commands with encrypted parameters

New Backdoor MQsTTang Attributed to Mustang Panda Group
Unlike the group’s usual tactics, MQsTTang only has a single stage and does not use obfuscation

CISA Warns Against Royal Ransomware in New Advisory
Malicious activity using a particular malware variant has been spotted since September 2022

NCSC: Twitter Users Should Find MFA Alternatives
UK's security agency warns against letting protection lapse

At Least 30% of "Cyber-Criminals" Are Women: Report
New study uses AI to analyze text of dark web forum users

Experts Warn of "SMS Pumping" Fraud Epidemic
Small businesses are particularly vulnerable

API Security Flaw Found in Booking.com Allowed Full Account Takeover
The vulnerabilities could affect users logging into the site via their Facebook accounts

White House Launches National Cybersecurity Strategy
The Strategy provides guidelines on how companies allocate roles and responsibilities in cyber space

WH Smith Discloses Cyber-Attack, Company Data Theft
Employee data was accessed by the threat actors, including names, addresses, and more

Russian Government Bans Foreign Messaging Apps
Kremlin hunkers down as war enters its second year

ICO Calls for Review into Private Message Use by Ministers
Regulator says Hancock saga highlights dangers of using WhatsApp

Major Phishing Campaign Targets Trezor Crypto Wallets
Users bombarded with fake emails, texts and calls

Google Workspace Adds Client-Side Encryption to Gmail and Calendar
The move will facilitate compliance procedures for private and public sector organizations

CISA Shares Advice to Improve Networks' Monitoring and Hardening
The recommendations stem from a red team assessment conducted in 2022

Public SaaS Assets Are a Major Risk For Medium, Large Firms
The findings come from DoControl’s latest SaaS Security Threat Landscape report

Record Number of Mobile Phishing Attacks in 2022
Endpoint security provider Lookout released its Global State of Mobile Phishing Report, which shows an unprecedented rate of mobile phishing attacks



