Infosecurity News

Singtel's Australian IT Firm Dialog Suffers Data Breach
The breach affected around 20 clients and 1000 current and/or former Dialog employees

Claroty Found Hardcoded Cryptographic Keys in Siemens PLCs Using RCE
The vulnerability has been assigned a CVE – Siemens has already updated affected systems and published recommendations for mitigating the risk

Polonium Uses Seven Backdoor Variants to Spy on Israeli Organizations
Researchers at ESET found evidence of previously undocumented custom tools used by the hackers

#ISC2Congress: US Government is Embracing 'Collective Defense'
We are all in it together, says the DoE's chief information officer

Google Unifies Recent Acquisitions Under New Cloud Security Offering
Google embeds in cloud security market with new software suite

Toyota Reveals Data Leak of 300,000 Customers
The leak was caused by an access key being made publicly available on GitHub for almost five years

A New Wave of PayPal Invoice Scams Using Crypto Disguise
Trend Micro found evidence of new PayPal scammers impersonating crypto-related businesses

#ISC2Congress: Cybersecurity Pros Must Prepare for Emerging Deepfake Threats
The security risks posed by deepfake technology are increasing

Calls for Better Microsoft Teams Backup as Confidential Info Sent on the Platform
Many admitted to sending messages on Teams they should not have

Pro-Russian Group KillNet Claims Responsibility for 14 US Airport DDoS Attacks
The websites of several major US airports were disrupted on October 10, 2022

Ukraine Enhances Cooperation With EU Cybersecurity Agencies
Ukraine looks to enhance European integration with ENISA special partner status

Intel Confirms Source Code Leak
Cyber-criminals could use the leaked source code to help launch attacks

ThermoSecure: Cracking Passwords Using Finger Heat on Keyboards is Now Possible
A group of researchers have guessed 100% of six-character passwords using this attack

German Cybersecurity Chief Faces Sacking Over Possible Russia Ties
Schoenbohm accused of having maintained contacts with people involved with Russian security services

Facebook Login Details at Risk as Meta Identifies Over 400 Malicious Apps
Some of the malicious apps are able to evade detection and continue to make it onto legitimate app stores

91% of Cyber Pros Experience Mental Health Challenges at Work
Factors contributing to mental health challenges included poor culture and the stressful nature of the work

LofyGang Group Linked to Recent Software Supply Chain Attacks
The group focuses on utilizing open-source software for malicious purposes

RCE on Log4j Among Top CVEs Exploited By Chinese-Backed Hackers
In a joint advisory, three US agencies, NSA, CISA and FBI, warned about Chinese threat actors

Russian Sanctions Instigator Lloyd's Possibly Hit by Cyber-Attack
The insurance market has detected “unusual activity” and turned off its systems

Businesses in Canada Warned Not to Overlook Cybersecurity As Recession Looms
CEOs put cybersecurity seventh behind near-term risks such as the economy and potential recession



