Infosecurity News

#SOOCon23: UK Government Urges Industry Input on Software Security Policy
A UK government official asks the cyber industry, including the open software community, to help shape software security policies

BEC Attacks Surge 81% in 2022
Open rates for emails hit 28%

#SOOCon23: Global Cooperation Needed to Enhance Open Source Software Security
A panel of policy experts discuss how to improve global cooperation around open source software security

CISA Releases Recovery Tool for VMware Ransomware Victims
Legacy bug in ESXi servers is being targeted by threat actors

Regulator Halts AI Chatbot Over GDPR Concerns
Replika accused of posing risk to children

Cyber Insurance, A Must-Have for Small Businesses
With $10m in seed funding, Guardz looks to tackle cyber insurance for small businesses

UK Metal Engineering Firm Vesuvius Hit by Cyber-Attack
The engineering firm has started an investigation “to identify the extent of the issue”

Drugs Labs Busted After Encrypted Chat App Takedown
Dutch and German police team up to take down Exclu

Thirteen Teams Win at UK's CyberFirst Girls Competition
NCSC contest sees thousands of schoolgirls enter

UK Banks Still Failing on Digital Security - Report
Which? study finds many fail to provide basic online protection

Novel Banking Trojan 'PixPirate' Targets Brazil
Scripts could interact with the device's UI and enter text, simulate touch events, etc.

Iranian Threat Actor Neptunium Associated With Charlie Hebdo Cyber-Attacks
Microsoft's Digital Threat Analysis Center shared the findings last Friday in a blog post

Major Florida Hospital Shuts Down Networks, Ransomware Attack Suspected
The Tallahassee Memorial HealthCare hospital is following protocols for system downtime

Stalkerware Developer Hit with $400K Fine
New York attorney general says software facilitates domestic abuse

Legacy VMware Bug Exploited in Global Ransomware Campaign
Vendor's ESXi hypervisors are being targeted

Scam Alert for Dingo Token That Charges 99% Fee
Crypto has a market cap of close to $11m

MalVirt Loaders Exploit .NET Virtualization to Deliver Malvertising Attacks
The new loaders also leverage obfuscated virtualization techniques to avoid detection

Atlassian Patches Critical Authentication Flaw in Jira Software
The Jira versions affected by the vulnerability are 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1 and 5.5.0

New Credential-Stealing Campaign By APT34 Targets Middle East Firms
The malware had additional exfiltration techniques compared to previously studied variants

ICO Relaxes Breach Reporting for Comms Providers
New rules are designed to reduce regulatory burden



