Infosecurity News

Former Twitter Employee Gets 42 Months for Saudi Scheme
Insider was bribed by the Middle East kingdom

OECD Signs "Landmark" Privacy Agreement
Club of rich countries wants to improve cross-border data flows

Senate Approves Bill Banning TikTok From US Government Devices
The bill still needs to receive approval from the US House of Representatives

NSA, CISA Warn Against Threats to 5G Network Slicing
Improper network slice management may enable attackers to access data from different network slices

Loan Scam Campaign 'MoneyMonger' Exploits Flutter to Hide Malware
Zimperium said the code was part of an existing campaign previously discovered by K7 Security Labs

Feds Hit DDoS-for-Hire Services with 48 Domain Seizures
Six also charged in connection with booter services

Over 85% of Attacks Hide in Encrypted Channels
Zscaler reveals 20% increase in malicious use of encryption

Platforms Flooded with 144,000 Phishing Packages
NuGet, PyPi and npm inundated with malicious packages

Signed Microsoft Drivers Used in Attacks Against Businesses
In some cases, the threat actor's intent was to ultimately provide SIM-swapping services

AgentTesla Remains Most Prolific Malware in November, Emotet and Qbot Grow
These are some of the key findings from the latest Check Point Research Most Wanted report

Apple Fixes Actively Exploited iPhone Zero-Day Vulnerability
The vulnerability could allow remote code execution (RCE) on a victim's device

New Google Tool Helps Devs Root Out Open Source Bugs
Free OSV-Scanner searches transitive dependencies

Loan Fee Fraud Surges by a Fifth as Christmas Approaches
FCA warns of pressure tactics as cost of living bites

Two Zero-Days Fixed in December Patch Tuesday
Close to 50 CVEs addressed this month

Twitter Addresses November Data Leak Claims
No passwords were reportedly exposed, but Twitter prompted users to enable 2FA to protect accounts

California Hit By Cyber-Attack, LockBit Claims Responsibility
At the time of writing, the California Budget website remains offline

Uber Hit By New Data Breach After Attack on Third-Party Vendor
Company information was stolen from third-party vendor Teqtivity and posted on a dark web forum

Experts Warn ChatGPT Could Democratize Cybercrime
Researchers claim AI bot can write malware and craft phishing emails

Aussie Data Breaches Surge 489% in Q4 2022
Country bucks the global trend thanks to high-profile incidents

Security Overlooked in Rush to Hybrid Working
Apogee study finds just 14% consider it a priority



