Infosecurity News

  1. Telegram Bot Abuse For Phishing Increased By 800% in 2022

    The growth is associated with using HTML attachments as a delivery method in credential phishing

  2. Cyber-Threat Actors Tailoring Attacks to Key Sectors

    Darktrace’s latest report analyses findings from the energy, retail and healthcare sectors

  3. Google Chrome 'SymStealer' Vulnerability Could Affect 2.5 Billion Users

    The warning comes from Imperva's security researcher Ron Masas

  4. Quarter of UK SMBs Hit by Ransomware in 2022

    War in Ukraine is making firms more anxious

  5. Twitter: Leak of 200 Million Accounts Not Due to Historic Bug

    Social media firm claims its systems were not compromised

  6. Royal Mail Halts International Deliveries After Cyber-Incident

    It's still unclear whether customer data has been compromised

  7. New APT Dark Pink Hits Asia-Pacific, Europe With Spear Phishing Tactics

    The group began operations as early as mid-2021, but its activity increased in mid-to-late 2022

  8. Multiple Danish Banks Disrupted By DDoS Cyber-Attack

    The attack also affected IT financial industry solutions developer Bankdata

  9. Sensitive Files From San Francisco Transit Police Allegedly Leaked

    The leaked files include some 120,000 files, with specific allegations of child abuse

  10. Customer and Employee Data the Top Prize for Hackers – Imperva

    Customer and employee data accounts for almost half all stolen data while credit cards and password see a decline

  11. Applications Five Years or Older Likely to have Security Flaws

    Veracode’s 2023 State of Software Security Report is focused on flaw introduction

  12. Over 100 CVEs Addressed in First Patch Tuesday of 2023

    Microsoft's January Patch Tuesday resolved over 100 CVEs, including an actively exploited zero day

  13. US Supreme Court Allows WhatsApp to Sue NSO Group

    WhatsApp can now sue for damages ensued by the installation of the Pegasus spyware

  14. Researchers Find Security Flaw in JsonWebToken Library Used By 20,000+ Projects

    An attacker could perform RCE on a server verifying a maliciously crafted JWT request

  15. GitHub Adds Features to Automate Vulnerability Code Scanning

    Called “default setup,” the novel capability simplifies starting code scanning on repositories

  16. UK Charities Offered Free Cyber Essentials Support

    The NCSC’s new Funded Cyber Essentials Programme will support SMEs as well as charities

  17. Ukraine: Russian Cyber-Attacks Should Be Considered War Crimes

    A Ukrainian official revealed that evidence of Russian cyber-attacks are being gathered to support potential war crime prosecutions

  18. Freejacking Campaign By PurpleUrchin Bypasses Captchas

    The threat actors also deployed more aggressive techniques for mining CPU resources

  19. ChatGPT Used to Develop New Malicious Tools

    These include infostealers, multi-layer encryption tools and dark web marketplace scripts

  20. Dark Web Actors Fight For Drug Trafficking and Illegal Pharmacy Supremacy

    Following the takedown of the Hydra Marketplace in 2022, 10 darknet markets rose to fill the void

What’s Hot on Infosecurity Magazine?