Infosecurity News

Bug Bounty Giant Slams Quality of Vendor Patching
Zero Day Initiative says incomplete or faulty patches now commonplace

Two Additional Malicious Python Libraries Found on PyPI Repository
The new packages were masquerading as one of the most popular open-source packages on PyPI

Healthcare Provider Issues Warning After Tracking Pixels Leak Patient Data
The leak was caused by incorrect configurations of an online tracking tool from Meta

New Attack Weaponizes PLCs to Hack Enterprise and OT Networks
The research resulted in proof-of-concept exploits against seven market-leading automation firms

#DEFCON: Electrovolt Exploits Against Electron Desktop Apps Exposed
Electron-based desktop application including Discord, Microsoft Teams and VScode were at risk from a series of vulnerabilities

#DEFCON: How US Teen RickRolled His High School District
American teenager explains how he was able to hack his local high school district

Hybrid Vishing Attacks Soar 625% in Q2
Agari warns of multi-stage phishing threat

Microsoft Disrupts Russian Cyber-Espionage Group Seaborgium
APT group focused on classic data theft via email accounts

Water Company Says Supply Safe After Ransom Group Claims
South Staffordshire Water admits it was compromised

Software Patches Flaw on macOS Could Let Hackers Bypass All Security Levels
After deploying the initial attack, the researcher was able to escape the macOS sandbox

Luckymouse Uses Compromised MiMi Chat App to Target Windows and Linux Systems
The news comes from two different security reports published by SEKOIA and Trend Micro

Dutch Authorities Arrest Tornado Cash Developer Following US Sanctions on Crypto Mixer Firm
The Financial Advanced Cyber Team of the FIOD started the criminal investigation in June

#DEFCON: How Sanctions Impact Internet Operators
Following government sanctions against Russia, Internet providers have had to learn how to implement actions

#DEFCON: CISA Director Praises Congress and International Cybersecurity Cooperation
Jen Easterly discusses the progress and challenges at CISA

Three Extradited from UK to US on $5m BEC Charges
Nigerian nationals accused of targeting US universities

New Study Reveals Serious Cyber Insurance Shortfalls
Most companies do not have enough coverage to recover from ransomware

Critical Infrastructure at Risk as Thousands of VNC Instances Exposed
Researchers find many deployments have authentication disabled

Meta Tests Encrypted Backups and End-to-End Encryption in Facebook Messenger
Meta is also introducing an encrypted backup feature called Secure Storage

Xiaomi Smartphone Vulnerabilities Could Lead to Forged Payments
The devices were powered by MediaTek chips and susceptible to two kinds of attacks

SolidBit Ransomware Group Recruiting New Affiliates on Dark Web
20% of the earned profit from the distribution of the ransomware will be paid to the affiliates



