Infosecurity News

  1. Australian ISP iiNet Suffers Breach of 280,000+ Records

    Over 280,000 customers of Australian ISP iiNet have been impacted by a data breach

  2. Popular npm Package Compromised in Phishing Attack

    An incident involving the npm package eslint-config-prettier has been uncovered spreading Scavenger RAT

  3. USB Malware Campaign Spreads Cryptominer Worldwide

    A multi-stage attack delivered via USB devices has been observed installing cryptomining malware using DLL hijacking and PowerShell

  4. Chinese APT Group Targets Web Hosting Services in Taiwan

    Cisco Talos observed the newly identified group compromise a Taiwanese web hosting provider to conduct a range of malicious activities

  5. Colt Customers Face Prolonged Outages After Major Cyber Incident

    The Warlock ransomware gang has taken credit for the cyber-attack after the UK telco giant publicly confirmed an incident on August 14

  6. Man Jailed for 20 Months After Compromising Millions of Accounts

    Al-Tahery Al-Mashriky has been sentenced to 20 months behind bars for hacktism-related offenses

  7. Workday Reveals CRM Breach

    Workday has revealed a breach of its third-party CRM systems in what could be the latest ShinyHunters attack

  8. US and Five Global Partners Release First Unified OT Security Taxonomy

    Germany, the Netherlands and four of the Five Eyes countries share a common asset inventory for industrial cybersecurity

  9. Cisco Discloses Critical RCE Flaw in Firewall Management Software

    Cisco has issued a software update to address the vulnerability, which can allow an unauthenticated, remote attacker to inject arbitrary shell commands

  10. Majority of Organizations Ship Vulnerable Code, Study Finds

    A new Checkmarx study reveals that AI-generated code now accounts for over 60% of codebases in some companies, much of which contains known vulnerabilities

  11. Authorized Push Payment Fraud a National Security Risk to UK, Report Finds

    A RUSI report warned that money mules are exploiting inadequate security controls in smaller payment service providers to move fraudulent transactions about

  12. KernelSU v0.5.7 Flaw Lets Android Apps Gain Root Access

    A flaw in KernelSU 0.5.7 allows attackers to impersonate its manager app and gain root access to Android devices

  13. Malvertising Campaign Deploys Modular PowerShell Malware PS1Bot

    An ongoing malware campaign has been observed using malvertising to deliver PS1Bot, a PowerShell-based framework

  14. FBI Shares Tips to Spot Fake Lawyer Schemes Targeting Crypto Scam Victims

    The Bureau’s Internet Crime Complaint Center has provided a list of indicators for potential cryptocurrency scam victims to avoid a double whammy

  15. Hacked Law Enforcement and Government Email Accounts Sold on Dark Web for $40

    Abnormal AI said gaining access to such accounts provides opportunities for sophisticated fraud schemes that impersonate officials

  16. Fortinet Warns Exploit Code Available for Critical Vulnerability

    Fortinet reveals details of a new critical-rated vulnerability in FortiSIEM circulating in the wild

  17. Campaigners Slam Expansion of Police Facial Recognition Schemes in UK

    The UK government has announced 10 new live facial recognition police vans to be deployed around the country

  18. Erlang/OTP SSH Vulnerability Sees Spike in Exploitation Attempts

    A critical RCE vulnerability in Erlang’s OTP SSH daemon has been identified that allows unauthenticated command execution

  19. Deepfake AI Trading Scams Target Global Investors

    AI-powered trading platforms have been observed exploiting deepfake technology to trick investors with fake endorsements

  20. Staffing Company Manpower Discloses Data Breach

    The personal data of almost 145,000 people who were registered in Manpower’s systems was compromised

What’s Hot on Infosecurity Magazine?