Infosecurity News

Ransomware Threat Shifts from US to EMEA and APAC
SonicWall figures show overall attacks trending down

See Tickets Discloses Major Card Data Breach
Unspecified number of customers impacted over 2.5 years

ICO Warns of "Immature" Biometric Tech
UK privacy regulator says vulnerable people may be at risk

Data Breaches Rise By 70% Globally in Q3 2022
Russia had the most breaches overall and France had the highest breach density

Apple Fixes Actively Exploited iOS and iPadOS Zero-Day Vulnerability
The out-of-bounds write issue in the kernel could be exploited to execute arbitrary code

POS Malware Used to Steal Details of Over 167,000 Credit Cards
The operators could make over $3m if they decide to sell the card dumps on underground forums

Ukraine Warns of Cuba Ransomware Campaign
Financially motivated affiliate appears to be to blame

Iranian Atomic Energy Agency Admits Email Hack
Suspected hacktivists inside country share sensitive info

US Charges Two Chinese Agents in Huawei Obstruction Case
Indictments form one of three cases involving Chinese spies

CISA Warns Against Ransomware Group Daixin Team Targeting Health Organizations
Daixin Team is actively targeting US businesses, mainly in the healthcare sector

Multiple RCE Vulnerabilities Discovered in Veeam Backup & Replication App
The Veeamp malware was used by the Monti and Yanluowang ransomware groups in these attacks

DHL Replaces LinkedIn As Most Imitated Brand in Phishing Attempts
It is due partly to a major phishing attack DHL warned about before the quarter started

UK Cyber Security Council Creates Chartered Qualification for Industry Pros
The UK Cyber Security Council has announced a pilot program designed to create the country’s first chartered cyber professionals

Clicker Malware Garners Estimated 20 Million Downloads
Google forced to remove over a dozen malicious apps

UK Construction Company Fined £4.4m for Serious Security Failings
Interserve slammed by regulator after employee data breach

European Police Warn of Metaverse Cyber-Threats
Cops also identify opportunities to enhance law enforcement

New Phishing Campaign Targets Saudi Government Service Portal
The campaigns are set up to provide fake services to the citizens and steal their credentials

Google Unveils Open Source Project to Improve Software Supply Chain Security
GUAC aims to bring together many different sources of software security metadata

Thousands of Publicly Exposed API Tokens Could Threaten Software Integrity
JFrog scanned over eight million artifacts in the most common open-source software registries

NCSC CEO Calls for International Standards on IoT Security
Lindy Cameron argues that smart cities are becoming an attractive target for threat actors, including nation states



