Infosecurity News

Google Unveils Open Source Project to Improve Software Supply Chain Security
GUAC aims to bring together many different sources of software security metadata

Thousands of Publicly Exposed API Tokens Could Threaten Software Integrity
JFrog scanned over eight million artifacts in the most common open-source software registries

NCSC CEO Calls for International Standards on IoT Security
Lindy Cameron argues that smart cities are becoming an attractive target for threat actors, including nation states

Lesson Learned: How SolarWinds Strengthened its Security Post-Incident
Tim Brown, CISO and VP of security at SolarWinds shared his experiences remediating a major cyber-attack during Mandiant’s mWISE event on October 18, 2022

Cyber-Enabled Crimes Are Biggest Police Concerns
Interpol study warns that many threats are expected to increase

OldGremlin Ransomware Ups Ante Against Russian Targets
Ransom demands soar to $17m, according to new report

Cops Arrest Suspected Multimillion-Dollar Fraud Mastermind
Spanish police apprehend suspect in Tenerife

Ransomware is Being Used As a Precursor to Physical War: Ivanti
The data also shows ransomware groups continuing to grow in volume and sophistication

Cybersecurity Workforce Gap Grows by 26% in 2022
What are the factors behind this stark rise, and how can the skills gap be closed?

FBI Warns Students Against Loan Forgiveness Scammers
Scammers are attempting to solicit PII, financial information or payment from potential victims

Singapore Creates Counter Ransomware Task Force to Tackle Threats
It will focus on protecting suppliers to critical information infrastructure operators

Brazilian Police Arrest Lapsus$ Suspect
Noose tightens around notorious cybercrime group

NCSC Updates Early Warning Threat Intelligence
UK security agency makes it easier to assess credibility of alerts

Microsoft Misconfiguration Exposes Customer Data
Researchers claim thousands of global customers were impacted

NSA Cybersecurity Director's Six Takeaways From the War in Ukraine
Rob Joyce was invited to speak during the Mandiant Worldwide Information Security Exchange (mWISE) event on October 18, 2022

Moola Market Reveals $9m Crypto Exploit
Most of the funds were later returned following negotiations with the hacker

Digital Natives Are Undermining Corporate Security - Report
EY finds younger workers are prone to engage in risky behavior

#CyberMonth: ENISA Celebrates 10 Years of European Cybersecurity Month with New, Proactive Slogan
For this year’s edition, ENISA introduced a new slogan for the event, #Choose2BeSafeOnline

Deadbolt Ransomware Extorts Vendors and Customers
New report provides in-depth look at novel NAS-based threat

Software Supply Chain Attacks Soar 742% in Three Years
Sonatype reveals scale of threats to open source ecosystem



