Infosecurity News

  1. Crypto Companies Freeze $47m in Romance Baiting Funds

    Chainalysis, OKX, Binance and Tether have managed to stop nearly $50m reaching romance baiting fraudsters

  2. Ransomware Actor Deletes Data and Backups Post-Exfiltration on Azure

    Microsoft observed Storm-0501 pivot to the victim’s cloud environment to exfiltrate data rapidly and prevent the victim’s recovery

  3. CISA Strengthens Software Procurement Security With New Tool

    CISA has launched a new Software Acquisition Guide Web Tool to enhance security in software procurement

  4. Researchers Discover First Reported AI-Powered Ransomware

    While still in development, PromptLock is described as the “first known AI-powered ransomware” by ESET researchers

  5. Nevada “Network Security Incident” Shuts Down State Offices and Services

    The Office of the Governor of Nevada revealed that the incident has shut down in-person State services, while government phone lines and websites are offline

  6. ShadowSilk Campaign Targets Central Asian Governments

    A series of cyber-attacks against government organizations in Central Asia and Asia- Pacific has been linked to the ShadowSilk threat cluster

  7. Citrix Patches Three NetScaler Zero Days as One Sees Active Exploitation

    Citrix customers are urged to patch their vulnerable NetScaler appliances, but “patching alone won’t cut it,” experts said

  8. ENISA to Coordinate €36m EU-Wide Incident Response Scheme

    EU security agency ENISA is being handed €36m to operate the EU Cybersecurity Reserve

  9. New Data Theft Campaign Targets Salesforce via Salesloft App

    Google is warning of a new credential theft campaign targeting Salesforce customers via Salesloft Drift

  10. New Phishing Campaign Abuses ConnectWise ScreenConnect to Take Over Devices

    Abnormal AI said the campaign, which lures victims into downloading legitimate RMM software, marks a major evolution in phishing tactics

  11. New Android Trojan Variant Expands with Ransomware Tactics

    A new version of the Hook Android banking Trojan features 107 remote commands, including ransomware overlays

  12. Phishing Campaign Uses UpCrypter to Deploy Remote Access Tools

    A global phishing campaign has been identified using personalized emails and fake websites to deliver malware via UpCrypter

  13. US: Maryland Confirms Cyber Incident Affecting State Transport Systems

    All previously scheduled mobility trips across Maryland for this week will be honored, said the state’s transportation administration

  14. CIISec: Most Security Professionals Want Stricter Regulations

    A new CIISec poll finds the majority of industry professionals would prefer more rigorous cybersecurity laws

  15. Tech Manufacturer Data I/O Hit by Ransomware

    Data I/O has revealed operational disruption following a ransomware breach that forced it to take some systems offline

  16. Fake macOS Help Sites Seek to Spread Infostealer in Targeted Campaign

    A variant of the Atomic macOS Stealer (AMOS) targets macOS users via fake support sites in malvertising campaign

  17. Chinese Developer Jailed for Deploying Malicious Code at US Company

    A Chinese developer has been sentenced to four years in prison after being found to deploy malicious code in his employer’s network, including a “kill switch”

  18. CISA Seeks Biden Era's SBOM Minimum Requirements Guideline Change

    The US Cybersecurity and Infrastructure Security Agency is planning to launch an update to a 2021 guideline for SBOM requirements

  19. Interpol-Led African Cybercrime Crackdown Leads to 1209 Arrests

    Operation Serengeti 2.0 operators helped recover $97.4m stolen by cybercriminals

  20. Attackers Abuse Virtual Private Servers to Compromise SaaS Accounts

    Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers

What’s Hot on Infosecurity Magazine?