Infosecurity News

  1. Chinese Developer Jailed for Deploying Malicious Code at US Company

    A Chinese developer has been sentenced to four years in prison after being found to deploy malicious code in his employer’s network, including a “kill switch”

  2. CISA Seeks Biden Era's SBOM Minimum Requirements Guideline Change

    The US Cybersecurity and Infrastructure Security Agency is planning to launch an update to a 2021 guideline for SBOM requirements

  3. Interpol-Led African Cybercrime Crackdown Leads to 1209 Arrests

    Operation Serengeti 2.0 operators helped recover $97.4m stolen by cybercriminals

  4. Attackers Abuse Virtual Private Servers to Compromise SaaS Accounts

    Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers

  5. Apple Releases Patch for Likely Exploited Zero-Day Vulnerability

    All Apple users are encouraged to update their iPhones, iPads and macOS devices

  6. Microsoft to Make All Products Quantum Safe by 2033

    Microsoft has set out a roadmap to complete transition to PQC in all its products and services by 2033, with roll out beginning by 2029

  7. Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw

    Russian state-backed hackers are exploiting a seven-year-old Cisco Smart Install vulnerability (CVE-2018-0171) in end-of-life devices, prompting warnings from the FBI and Cisco Talos

  8. Colt Admits Customer Data Likely Stolen in Cyber-Attack

    Colt customers can request a list of filenames posted on the dark web via a dedicated call center

  9. Oregon Man Charged in Rapper Bot DDoS-for-Hire Case

    A 22-year-old Oregon man has been charged with administering the Rapper Bot DDoS-for-hire Botnet

  10. Cybercriminal Linked to Notorious Scattered Spider Gang Gets 10-Year Sentence

    Noah Urban, linked with the Scattered Spider cybercriminal gang, will also pay $13m in restitution to victims

  11. Orange Data Breach Raises SIM-Swapping Attack Fears

    Orange Belgium revealed that a threat actor has compromised 850,000 customer accounts, with SIM card numbers among the data accessed

  12. “PromptFix” Attacks Could Supercharge Agentic AI Threats

    Guardio reveals a new AI take on ClickFix dubbed “PromptFix”

  13. NIST Unveils Guidelines to Help Spot Face Morphing Attempts

    NIST has released new guidelines examining the pros and cons of detection methods for face morphing software

  14. Pharmaceutical Company Inotiv Confirms Ransomware Attack

    Indiana-based pharmaceutical research company Inotiv has confirmed it suffered a ransomware attack, disrupting operations and compromising data

  15. TRM Launches Industry-Wide Platform to Fight Crypto Crimes

    With Beacon Network, TRM Labs has brought together law enforcement and some of the largest crypto exchanges to fight against crypto crimes

  16. Mule Operators in META Adopt Advanced Fraud Schemes

    A new report has mapped the tactical evolution of mule operators in the META region from VPNs to advanced fraud networks

  17. Hackers Weaponize QR Codes in New 'Quishing' Attacks

    Researchers discovered two new phishing techniques where attackers split malicious QR codes or embed them into legitimate ones

  18. Warlock Ransomware Hitting Victims Globally Through SharePoint ToolShell Exploit

    Trend Micro highlighted a sophisticated post-compromise attack chain to deploy the Warlock ransomware in unpatched SharePoint on-prem environments

  19. Executives Warned About Celebrity Podcast Scams

    The Better Business Bureau is urging business owners and influencers not to fall for a new type of podcast scam

  20. UK Retreats on Apple Encryption Backdoor Demand Following US Pressure

    US director of national intelligence, Tulsi Gabbard, stated that her government persuaded the UK to withdraw its controversial demand

What’s Hot on Infosecurity Magazine?