Infosecurity News

New Study Reveals Serious Cyber Insurance Shortfalls
Most companies do not have enough coverage to recover from ransomware

Critical Infrastructure at Risk as Thousands of VNC Instances Exposed
Researchers find many deployments have authentication disabled

Meta Tests Encrypted Backups and End-to-End Encryption in Facebook Messenger
Meta is also introducing an encrypted backup feature called Secure Storage

Xiaomi Smartphone Vulnerabilities Could Lead to Forged Payments
The devices were powered by MediaTek chips and susceptible to two kinds of attacks

SolidBit Ransomware Group Recruiting New Affiliates on Dark Web
20% of the earned profit from the distribution of the ransomware will be paid to the affiliates

#BHUSA: Bug Bounty Botox – Why You Need a Security Process First
Katie Moussouris explains why simply having a bug bounty program isn't enough to fix security problems

#BHUSA: Failure to Challenge is a Social Engineering Risk
The UK Ministry of Defence is actively training staff to confront individuals that are engaged in risky behaviours

#BHUSA: What has Changed in the Post-Stuxnet Era?
Investigative journalist Kim Zetter explains that Stuxnet continues to serves as a precedent for attacks happening now

US Unmasks Suspected Conti Ransomware Actor
State Department offers $10m reward for info on notorious group

Zeppelin Ransomware Victims May Need Multiple Decryption Keys
CISA issues new alert about RaaS variant

Recovery From NHS Ransomware Attack May Take a Month
Managed service provider Advanced publishes update on recent cyber incident

CISA Unveils Cybersecurity Toolkit to Shield US Elections From Hackers
The toolkit protects election infrastructure targeted by phishing, ransomware and DDoS attacks

Zimbra RCE Vulnerability Exploited Without Admin Privileges
Over 1,000 ZCS instances around the world were reportedly backdoored and compromised

Android Banking Trojan SOVA Comes Back With New Features Including Ransomware
SOVA v4 features new capabilities and is reportedly targeting more than 200 mobile applications

#BHUSA: The Cyber Safety Review Board Outlines Log4j Lessons
The CSRB concluded that the initial disclosure on Log4j was done right, but there is still much to improve

#BHUSA: Russia's Wiper Attacks Against Ukraine Detailed
According to researchers, Russia is rolling out a growing list of wiper attacks against Ukraine

#BHUSA: Chris Krebs Explains How Cybersecurity Can Improve
Former US CISA Director Chris Krebs opens Black Hat USA detailing the state of cybersecurity today

#BHUSA: New Open Source Group Set to Streamline Threat Detection
New open source project set to reduce operational pain for SecOps analysts

Ransomware Data Theft Epidemic Fuelling BEC Attacks
Accenture warns that stolen data is flooding the cybercrime underground

Suspected $3m Romance Scammer Extradited to Japan
Interpol warns of growing role of money mules



