Infosecurity News

Zurich and Mondelez Reach NotPetya Settlement, but Cyber-Risk May Increase
The parties have mutually resolved the matter, but details of the settlement were not provided

Bot Warning for Retailers Ahead of Busy Shopping Season
Automated threats accounted for 62% of attacks last year

UK Security Agency to Scan the Country for Bugs
NCSC wants to determine "the vulnerability of the UK"

Threat Actor "OPERA1ER" Steals Millions from Banks and Telcos
More than 30 organizations compromised by off-the-shelf tools

US Hacker Group Indicted For Million-Dollar RICO Conspiracy
The group banded together to engage in a sophisticated cybercrime and tax fraud scheme

Android Apps With a Million Downloads Led Users to Phishing Sites
Chrome tabs remained open in the background, even while the smartphone was locked

Dropbox Suffers Breach, 130 GitHub Repositories Compromised
Dropbox believes the actors behind the attack are the same that targeted GitHub users in September

Mobile Phishing Attacks on Government Staff Soar
Lookout report finds over-reliance on unmanaged devices

Twitter Verified Status Users Flooded with Scams
Elon Musk’s arrival has opened the door for fraudsters

OpenSSL Security Advisory Downgraded to High Severity
Experts still recommend patching affected systems

A Third of Security Leaders Considering Quitting Their Current Role
Of those thinking of leaving their current organization, a third would do so within the next six months, according to the research

Osaka Hospital Halts Services After Ransomware Attack
Emergency operations are continuing, but the hospital system failed and cannot be accessed

CISA Publishes Multi-Factor Authentication Guidelines to Tackle Phishing
The guidelines describe methods threat actors use to steal MFA credentials and how to defend against them

LockBit Dominates Ransomware Campaigns in 2022: Deep Instinct
The figures come from the 2022 Interim Cyber Threat Report by Deep Instinct

NCSC Issued 34 Million Cyber Alerts in Past Year
UK security agency helps organizations with early warning service

FTC Takes Enforcement Action Against EdTech Giant Chegg
Regulator’s order requires firm to improve data security practices

Fraudulent Instruction Losses Spike in 2022
Insurer says claimants have risen in nearly every sector

CISA, FBI, MS-ISAC Publish Guidelines For Federal Agencies on DDoS Attacks
The guidance is for network defenders and leaders to understand and respond to DDoS attacks

Data Breach of Missile Maker MBDA May Have Been Real: CloudSEK
The researchers were able to obtain the ZIP file containing the samples for the data breach

Hackers Target Australian Defense Communications Platform With Ransomware
The firm is one of the defense department's external providers employed to run one of its websites



