Infosecurity News

Air Force Upgrades Digital Modernization Strategy to "As a Service" Model
The transition will be carried out through three procurements to be awarded before the end of 2024

Hackers Deploy Malicious OAuth Apps to Compromise Email Servers, Spread Spam
The spam emails were sent to trick recipients into signing up for fake paid subscriptions

Cyber Mercenary Group Void Balaur Continues Hack-For-Hire Campaigns
Void Balaur campaigns in 2022 targeted various industries across the US, Russia and Ukraine

Details of Over 300,000 Russian Reservists Leaked, Anonymous Claims
The group claims the individuals are likely to be mobilized by the Russian government to fight in Ukraine

Seven-Year Mobile Surveillance Campaign Targets Uyghurs
Scarlet Mimic group uses over 20 Android malware variants

NSA Reveals "Hackers' Playbook" for OT Attacks
New report outlines key mitigations for OT owners

Europol "Hackathon" Identifies Scores of Human Trafficking Victims
Over 100 online platforms checked for illegal activity

Optus Hit By Cyber-Attack, Breach Affects Nearly 10 Million Customers
Home addresses, driver's licenses and passport numbers were potentially accessed by the attacker

Morgan Stanley Fined $35m By SEC For Data Security Lapse
The improper data disposal reportedly started in 2016 and exposed 15 million customers' data

Russia-Based Hackers FIN11 Impersonate Zoom to Conduct Phishing Campaigns
Cyfirma said the motive behind the attacks may be financial in nature

Twitter Password Reset Bug Exposed User Accounts
Social media firm fixes issue that left sessions open

Authorized Push Payments Surge to 75% of Banking Fraud
Social engineering tactics bear fruit for digital scammers

Iranian Hackers Hid in Albanian Networks for Over a Year
CISA report reveals extent of state-backed campaign

Microsoft Upgrades Windows 11 With New Security Features
The list includes application control enhancements and vulnerable drivers protection, among others

350K Open-Source Projects At Risk of Supply Chain Vulnerability
The flaw resides in the tarfile module, automatically installed in any Python project

NCSC: British Retailers Need to Move Beyond Passwords
The UK’s national cybersecurity agency also advised organizations on what steps they should take if their brand has been spoofed online

Multiple Vulnerabilities Discovered in Dataprobe's iBoot-PDUs
They pose a number of risks to Dataprobe, including giving control of the iBoot-PDU to attackers

Two-Fifths of US Consumers Suffer Personal Data Theft
Those suffering emotional and physical impact surges

Video Game Publisher Admits Helpdesk Was Hijacked
Players were sent malicious links disguised as support tickets

Open Source Repository Attacks Soar 700% in Three Years
Sonatype says it has detected 95,000 since 2019



