Infosecurity News

Arnold Clark Confirms Customer Data Compromised in Breach
Affected data includes names, contact details, vehicle details and ID documents, among others

Lazarus Group Attack Identified After Operational Security Fail
The new campaign highlighted several "noteworthy developments" in TTPs

Women in CyberSecurity Calls for Participants for New Measuring Inclusion Workshops
WiCyS is calling for workshop participants to inform its State of Inclusion of Women in Cybersecurity report

Record $3.8bn Stolen Via Crypto in 2022
North Korean hackers were a major cause

Researchers Warn of Crypto Scam Apps on Apple App Store
Sophos found two fraudulent crypto trading apps

City of London on High Alert After Ransomware Attack
Critical trading software firm Ion is compromised

Ransomware Attack Forces Closure of Nantucket Schools
The district’s superintendent Elizabeth Hallett announced the decision in an email to parents

Google Fi Confirms Data Breach, Hints At Link to T-Mobile Hack
The company uses a combination of T-Mobile and US Cellular for network connectivity

Researchers Claim High-Risk Vulnerabilities Found in 87% of All Container Images
But only 15% of these vulnerabilities with available fixes are in packages loaded at runtime

Almost all Organizations are Working with Recently Breached Vendors
The latest supply chain security report from SecurityScorecard and the Cyentia Institute shows worrying findings

BEC Group Uses Open Source Tactics in Hundreds of Attacks
Firebrick Ostrich has impersonated over 150 organizations

Thriving Dark Web Trade in Fake Security Certifications
Exam cheats, course leaks and fake certs offer career shortcuts

Nearly 30,000 QNAP Devices Exposed Via New Bug
Vulnerability could be exploited by ransomware groups

GitHub Confirms Signing Certificates Stolen in Cyber-Attack, Revokes Them
Revoking these certificates will invalidate some versions of GitHub Desktop for Mac and Atom

DocuSign Brand Impersonation Attack Bypasses Security Measures, Targets Over 10,000
Victims were redirected to a fake landing page to exfiltrate their Proofpoint credentials

Financial Services Targeted in 28% of UK Cyber-Attacks Last Year
API attacks, bad bots and DDoS attacks were the industry's main security challenges

Killnet Attackers DDoS US and Dutch Hospitals
Retaliatory Russian attacks latest response to geopolitical moves

Two US Doctors Convicted of $30m Medicare Fraud
Claims submitted for medical equipment not needed by patients

QNAP: Patch Critical Remote Code Injection Bug
Vulnerability affects QTS and QuTS Hero firmware

JD Sports Confirms Breach Affected 10 Million Customers
The cyber-attack hit the company between November 2018 and October 2020



