Infosecurity News

  1. Bridgestone Confirms "Limited Cyber Incident" Impacting Facilities in North America

    Bridgestone Americas confirmed the incident but has not detailed the scope of the attack

  2. South Carolina School District Data Breach Affects 31,000 People

    An investigation has revealed that files were stolen in a data breach affecting a South Carolina school district

  3. macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Security

    Trend Micro observed the attackers using terminal-based installation methods for the AMOS malware, luring macOS users into installing cracked versions of apps

  4. US and 14 Allies Release Joint Guidance on Software Bill of Materials

    The joint guidance is a welcome first step towards a common, global adoption of SBOMs, experts argued

  5. 61% of US Companies Hit by Insider Data Breaches

    The OPSWAT report found that insider breaches cost impacted firms $2.7m on average due to factors such as regulatory fines and diminished productivity

  6. GhostRedirector Emerges as New China-Aligned Threat Actor

    A newly identified hacking group named GhostRedirector has compromised 65 Windows servers using previously unknown tools

  7. North Korean Hackers Exploit Threat Intel Platforms For Phishing

    North Korean hackers have been observed exploiting cyber threat intelligence platforms in a campaign targeting job seekers with malware-laced lures

  8. CMS Provider Sitecore Patches Exploited Critical Zero Day

    Google Cloud’s Mandiant successfully disrupted an active ViewState deserialization attack affecting Sitecore deployments

  9. Scattered Spider-Linked Group Claims JLR Cyber-Attack

    JLR said it is investigating following claims by the actor “Scattered Lapsus$ Hunters” that it had stolen data from the firm and had issued an extortion demand

  10. Threat Actors Abuse Hexstrike-AI Tool to Accelerate Exploitation

    Hackers are using legitimate red team tool Hexstrike-AI to simplify and speed up vulnerability exploitation

  11. Healthcare Sector Takes 58 Days to Resolve Serious Vulnerabilities

    A new Cobalt study finds healthcare organizations among the slowest at resolving serious vulnerabilities

  12. Malicious npm Packages Exploit Ethereum Smart Contracts

    A malicious campaign using Ethereum smart contracts has been observed targeting developers via npm and GitHub

  13. Russian APT28 Expands Arsenal with 'NotDoor' Outlook Backdoor

    The backdoor is a sophisticated VBA-based malware targeting Microsoft Outlook

  14. Major IPTV Piracy Network Uncovered Spanning 1100 Domains

    A massive IPTV privacy network has been uncovered distributing unlicensed content from major brands including Apple TV, Disney+, HBO, Netflix and more

  15. Cloudflare and Palo Alto Networks Victimized in Salesloft Drift Breach

    Cloudflare has notified customers that hackers may have accessed their data as part of the Salesloft Drift campaign

  16. Tycoon Phishing Kit Utilizes New Capabilities to Hide Malicious Links

    Barracuda observed new methods to disguise phishing links in Tycoon phishing attacks, which are designed to bypass automated email security systems

  17. Brazilian Fintech Giant Sinqia Reveals $130m Heist Attempt

    Evertec subsidiary Sinqia has posted details of an attempt to steal $130m from two B2B partners

  18. ICE Reinstates Contract with Spyware Vendor Paragon

    The US Immigration agency has resumed a $2m contract with the Graphite spyware developer, now owned by US investor AE Industrial Partners

  19. Malicious npm Package Masquerades as Popular Email Library

    A malicious npm package “nodejs-smtp” has been discovered impersonating nodemailer and injecting code to drain crypto wallets

  20. Azure AD Credentials Exposed in Public App Settings File

    Experts have revealed an Azure AD vulnerability exposing ClientId and ClientSecret in a publicly accessible appsettings.json file

What’s hot on Infosecurity Magazine?