Infosecurity News

Zimbra RCE Vulnerability Exploited Without Admin Privileges
Over 1,000 ZCS instances around the world were reportedly backdoored and compromised

Android Banking Trojan SOVA Comes Back With New Features Including Ransomware
SOVA v4 features new capabilities and is reportedly targeting more than 200 mobile applications

#BHUSA: The Cyber Safety Review Board Outlines Log4j Lessons
The CSRB concluded that the initial disclosure on Log4j was done right, but there is still much to improve

#BHUSA: Russia's Wiper Attacks Against Ukraine Detailed
According to researchers, Russia is rolling out a growing list of wiper attacks against Ukraine

#BHUSA: New Open Source Group Set to Streamline Threat Detection
New open source project set to reduce operational pain for SecOps analysts

#BHUSA: Chris Krebs Explains How Cybersecurity Can Improve
Former US CISA Director Chris Krebs opens Black Hat USA detailing the state of cybersecurity today

Ransomware Data Theft Epidemic Fuelling BEC Attacks
Accenture warns that stolen data is flooding the cybercrime underground

Suspected $3m Romance Scammer Extradited to Japan
Interpol warns of growing role of money mules

DeathStalker's VileRAT Continues to Target Foreign and Crypto Exchanges
The campaign is not only ongoing, the threat actors increased its efforts to compromise targets using VileRAT

Cyber-criminals Shift From Macros to Shortcut Files to Hack Business PCs, HP Reports
The report shows an 11% rise in archive files containing malware, including LNK files

Emotet Tops List of July's Most Widely Used Malware
The Emotet botnet continues to evolve and now includes a credit card stealer module

Predator Pleads Guilty After Targeting Thousands of Girls Online
West Sussex man blackmailed his victims

Exploit Activity Surges 150% in Q2 Thanks to Log4Shell
Malware and botnet detections also soar

Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs
August Patch Tuesday addresses over 120 vulnerabilities

New Malicious Python Libraries Found on PyPI Repository
Some of these packages were capable of stealing user credentials and environment variables

US Treasury Sanctions Virtual Currency Mixer For Connections With Lazarus Group
Tornado Cash would have been used to launder more than $7b in virtual currency since its foundation

Report Provides Updates on July's Maui Ransomware Incident
The report extends CISA's “first seen” date and the geolocation of the target to other countries

Health Adviser Fined After Illegally Accessing Medical Records
Former NHS employee ordered to pay victims compensation

Smishing Attack Led to Major Twilio Breach
Firm tight-lipped on how many customers are affected

Number of Firms Unable to Access Cyber-Insurance Set to Double
Even those with policies may see coverage greatly reduced



