Infosecurity News

Ransomware Affiliates Adopt Data Destruction
Concerning signs of escalation in tactics

US Duo Plead Guilty to $30m Forex Fraud Scheme
Each face a maximum term of five years behind bars

UK Teen Arrested on Computer Misuse Charges
Individual may be linked to Lapsus$ group

Air Force Upgrades Digital Modernization Strategy to "As a Service" Model
The transition will be carried out through three procurements to be awarded before the end of 2024

Hackers Deploy Malicious OAuth Apps to Compromise Email Servers, Spread Spam
The spam emails were sent to trick recipients into signing up for fake paid subscriptions

Cyber Mercenary Group Void Balaur Continues Hack-For-Hire Campaigns
Void Balaur campaigns in 2022 targeted various industries across the US, Russia and Ukraine

Details of Over 300,000 Russian Reservists Leaked, Anonymous Claims
The group claims the individuals are likely to be mobilized by the Russian government to fight in Ukraine

Seven-Year Mobile Surveillance Campaign Targets Uyghurs
Scarlet Mimic group uses over 20 Android malware variants

NSA Reveals "Hackers' Playbook" for OT Attacks
New report outlines key mitigations for OT owners

Europol "Hackathon" Identifies Scores of Human Trafficking Victims
Over 100 online platforms checked for illegal activity

Optus Hit By Cyber-Attack, Breach Affects Nearly 10 Million Customers
Home addresses, driver's licenses and passport numbers were potentially accessed by the attacker

Morgan Stanley Fined $35m By SEC For Data Security Lapse
The improper data disposal reportedly started in 2016 and exposed 15 million customers' data

Russia-Based Hackers FIN11 Impersonate Zoom to Conduct Phishing Campaigns
Cyfirma said the motive behind the attacks may be financial in nature

Twitter Password Reset Bug Exposed User Accounts
Social media firm fixes issue that left sessions open

Authorized Push Payments Surge to 75% of Banking Fraud
Social engineering tactics bear fruit for digital scammers

Iranian Hackers Hid in Albanian Networks for Over a Year
CISA report reveals extent of state-backed campaign

Microsoft Upgrades Windows 11 With New Security Features
The list includes application control enhancements and vulnerable drivers protection, among others

350K Open-Source Projects At Risk of Supply Chain Vulnerability
The flaw resides in the tarfile module, automatically installed in any Python project

NCSC: British Retailers Need to Move Beyond Passwords
The UK’s national cybersecurity agency also advised organizations on what steps they should take if their brand has been spoofed online

Multiple Vulnerabilities Discovered in Dataprobe's iBoot-PDUs
They pose a number of risks to Dataprobe, including giving control of the iBoot-PDU to attackers



