Infosecurity News

Trojan Steals Facebook Details from Over 300K Victims
"Schoolyard Bully" has been active since 2018

Hackers Target Colombia's Healthcare System With Ransomware
The attack disrupted IT operations, websites and scheduling of medical appointments

Spyware Vendor Variston Exploited N-Days in Chrome, Firefox, Windows
The claims come from Google’s Threat Analysis Group, which published an advisory about the threat

WhatsApp Files on Dark Web Show Millions of Records For Sale
The list went on sale for four days and is now being distributed for free among dark web users

UK Extends NIS Regulations to IT Managed Service Providers
The UK strengthens its regulations on Network and Information Systems (NIS) to better prevent software supply chain attacks

Eight Charged with $30m Unemployment Benefits Fraud
Defendants allegedly used insider to obtain personal information

Researchers Accidentally Crash Cryptomining Botnet
Akamai reveals how a simple syntax error stopped it sending commands

LastPass Reveals Another Customer Data Breach
Incident is second this year, although company says passwords are safe

Majority of US Defense Contractors Not Meeting Basic Cybersecurity Requirements
87% of DoD contractors are failing to meet the basic level of compliance ahead of CMMC coming into force next year

Australian Parliament Passes Privacy Penalty Bill
The higher penalties and extended powers will become effective after the bill receives royal assent

China-Based Hackers Target Southeast Asia With USB-Based Malware
UNC4191 operations have affected several entities in Southeast Asia but also in the US, Europe and Asia Pacific Japan

Zero-Day Flaw Discovered in Quarkus Java Framework
The flaw has a CVSS v3 base score rating of 9.8 and can be found in the Dev UI Config Editor

Businesses Increasing Cyber Spend Without Clear Strategy, Fastly Finds
As businesses aim to spend more on cybersecurity, Fastly warns that many do so without a clear strategy

Let's Encrypt Issues Three Billionth Certificate
Free certificate authority serves over 300 million websites

Most Small Biz IaaS Users Seeing Surge in Attacks
A further 67% were hit by ransomware in past year

New "Icefall" Bugs Include Critical DoS Flaw
Millions of OT devices may be affected

Oracle Fusion Middleware Vulnerability Actively Exploited in the Wild: CISA
The bug allows unauthenticated attackers with network access to compromise Oracle Access Manager

PII May Have Been Stolen in Virginia County Ransomware Attack
A W-2 form was reportedly published on a dark web forum with stolen, sensitive data

US Census Bureau Head Fends Off Critics of 'Differential Privacy' Tool
Santos defended differential privacy against prominent researchers

Police Shutter 13,000 Sites in Piracy Crackdown
Fourteen detained as part of Europol operation



