Infosecurity News

Most Federal Agencies Ignored GAO's Cybersecurity Recommendations
Out of the 335 public recommendations issued since 2010, 190 still needed to be implemented

Ad Fraud Scheme Tops 12 Billion Daily Bid Requests
Vastflux operation injected obfuscated JavaScript into ads

Riot Games Halts Work After Cyber-Attack
Compromise impacts developer's ability to release updates

New Government Cyber Advice for £100bn UK Charity Sector
NCSC report warns of surging threat to the third sector

WhatsApp Hit with €5.5m fine for GDPR Violations
The case raised disagreements between Ireland's DPC and the European Data Protection Board

"Workarounds" Helped Royal Mail Resume Shipping After Ransomware Attack
Thanks to technical “workarounds,” Royal Mail has been able to resume “limited” export services one week after being hit by cyber-attack

Phishers Use Blank Images to Disguise Malicious Attachments
Researchers see another sophisticated attempt to obfuscate links

API Attacker Steals Data on 37 Million T-Mobile Customers
Carrier says attack began in November 2022

Massive Credential Stuffing Campaign Hits 35,000 PayPal Users
Payments giant says attacks happened in early December

Roaming Mantis' Hacking Campaign Adds DNS Changer to Mobile App
The new feature can infiltrate WiFi routers and undertake DNS hijacking

ThreatModeler Makes DevSecOps More Accessible With New Marketplace
The store includes pre-built threat models that can be integrated into a development pipeline

Mailchimp Hit By Another Data Breach Following Employee Hack
According to the company, the incident was limited to 133 accounts

Ransomware Payments Fall by 40% in 2022
The Chainalysis report found that victim organizations are increasingly reluctant to pay ransom demands

Over a Third of Recent ICS Bugs Still Have No Vendor Patch
News comes as thousands of critical infrastructure attacks are detected

FTX: Over $400m Stolen from Bankrupt Exchange
FTX founder already charged with fraud and money laundering

Crypto-Exchange Used to Launder Ransomware Transactions Dismantled
The US Justice Department arrested Russian national named Anatoly Legkodymov, the alleged owner of the China-based underground platform Bitzlato

Hundreds of Malicious Packages Found in npm Registry
Data exfiltration was a common goal, says Sonatype

Chinese APT Group Vixen Panda Targets Iranian Government Entities
The claims come from cybersecurity researchers at Palo Alto Networks’ Unit 42

Over Four Billion People Affected By Internet Censorship in 2022
Individuals experienced 112 internet restrictions across 32 countries throughout the year

1000 Shipping Vessels Impacted by Ransomware Attack
The ships were impacted following an attack on a major software supplier



