Infosecurity News

UK Security Agency Wants Fresh Approach to Combat Phishing
NCSC says "blame and fear" won’t work

Adult Google Ad Fraud Campaign Garnered Millions of Impressions
Fraudster used "popunders" and obfuscation to generate cash

Godfather Trojan Targets 400 Financial Services Firms
Mobile banking malware designed to steal bank and crypto credentials

Organizations Warned of New Attack Vector in Amazon Web Services
Researchers warned that threat actors could potentially exploit Elastic IP transfer and compromise an IP address

UK Privacy Regulator Names and Shames Breached Firms
ICO publishes detailed list of complaints and investigations

Fortnite Dev to Pay $520m in Record-Breaking Settlement
FTC reveals gaming firm's privacy violations and design tricks

Ukraine's Delta Military Intel System Hit by Attacks
Phishing campaign spotted by CERT-UA

Ransomware Groups to Increase Zero-Day Exploit-Based Access Methods in the Future
Trend Micro’s latest research paper analyzed ways in which ransomware groups could evolve to stay on top of strengthened cyber-protection measures

Meta Takes Down Over 200 Covert Influence Operations Since 2017
The most common location for influence operations was Russia, according to Meta

Mobile App Users at Risk as API Keys of Email Marketing Services Exposed
Leaked API keys allow threat actors to perform a variety of unauthorized actions

NIST to Scrap SHA-1 Algorithm by 2030
The agency said it will stop using SHA-1 in its last remaining specified protocols by December 31 2030

API Vulnerabilities Discovered in LEGO Marketplace
The vulnerabilities, which are now fixed, could have put sensitive customer data at risk

Agenda Ransomware Switches to Rust to Attack Critical Infrastructure
Victim companies have a combined revenue of around $550m

Meta's Bug Bounty Program Shows $2m Awarded in 2022
The total amount since the program's establishment in 2011 is reportedly $16m

Social Blade Confirms Data Breach Exposing PII on the Dark Web
The company confirmed the data does not include any credit card information

Two-Thirds of Security Pros Have Burnt Out in Past Year
Excessive workload is the most common contributing factor

Former Twitter Employee Gets 42 Months for Saudi Scheme
Insider was bribed by the Middle East kingdom

OECD Signs "Landmark" Privacy Agreement
Club of rich countries wants to improve cross-border data flows

Senate Approves Bill Banning TikTok From US Government Devices
The bill still needs to receive approval from the US House of Representatives

NSA, CISA Warn Against Threats to 5G Network Slicing
Improper network slice management may enable attackers to access data from different network slices



