-
"Most Cyberattacks Hide in Encrypted Web Traffic"According to Zscaler's ThreatLabz 2023 State of Encrypted Attacks Report, most cyberattacks involve malware being hidden in encrypted web traffic. The spread of cyber threats through encrypted (HTTPS) web traffic is increasing year after year.
-
"Vulnerabilities Now Top Initial Access Route For Ransomware"Corvus Insurance recently did a study and found that threat actors are switching tactics to compromise their victims with ransomware, with more attacks now exploiting vulnerabilities rather than using phishing emails.
-
"Ransomware Groups Are Using Media Coverage to Coerce Victims Into Paying"According to new Sophos X-Ops research, ransomware gangs use media coverage of attacks to increase pressure on victims to meet their demands.
-
"PNNL Creates Center for Artificial Intelligence"The Department of Energy's (DOE) Pacific Northwest National Laboratory (PNNL) has established the Center for AI @ PNNL to coordinate the pioneering research of hundreds of scientists working on various projects focusing on science, security, and
-
"New Pierogi++ Malware by Gaza Cyber Gang Targeting Palestinian Entities"The Gaza Cyber Gang, a pro-Hamas threat actor, is targeting Palestinian entities with an updated version of the Pierogi backdoor.
-
"Dell Urges Customers to Patch Vulnerabilities in PowerProtect Products"Dell is urging customers of its PowerProtect products to review a newly released security advisory and patch a series of potentially serious vulnerabilities.
-
"NSA Releases Recommendations to Mitigate Software Supply Chain Risks"In response to a rise in supply chain cyberattacks over the past five years, the National Security Agency (NSA) has released a Cybersecurity Information Sheet (CSI) titled "Recommendations for Software Bill of Materials (SBOM) Management." This CSI off
-
"MITRE Debuts ICS Threat Modeling for Embedded Systems"In collaboration with researchers from three other organizations, MITRE has released a draft of a new threat-modeling framework for those who make embedded devices used in critical infrastructure environments.
-
"Hackers Keep Winning by Gambling on SQL Injection Exploits"Group-IB warns that a hacking group dubbed GambleForce has been targeting businesses and government agencies in attacks involving exploiting SQL injection flaws.
-
"Cybercrime Operation That Sold Millions of Fraudulent Microsoft Accounts Disrupted"Microsoft has disrupted Storm-1152, an alleged threat actor group that built Cybercrime-as-a-Service (CaaS) businesses.
-
"Stealthy KV-Botnet Hijacks SOHO Routers and VPN Devices"Volt Typhoon, also known as Bronze Silhouette, a Chinese state-sponsored Advanced Persistent Threat (APT) hacking group, has been linked to a botnet called KV-botnet, which it has been using since at least 2022 to attack Small Office Home Office
-
"Approval Phishing Scams Drain $1bn of Cryptocurrency From Victims"According to security researchers at Chainalysis, approval phishing scams have been used to steal at least $1bn in cryptocurrency since May 2021.
News