News
-
"Over 700 Million Credentials Exposed and 22 Million Devices Infected in 2022"SpyCloud's latest Identity Exposure Report reveals that its researchers retrieved 721.5 million exposed credentials from the criminal underworld and discovered over 22 million unique devices infected with malware in the last year. Around 50 percent of…
-
"YoroTrooper Group Targets European, CIS Countries in Cyberespionage Campaigns"During the past nine months, a previously unknown Russian-speaking threat actor has launched cyber espionage campaigns against government, energy, and international organizations in Azerbaijan, Kyrgyzstan, Tajikistan, as well as European nations. The…
-
"FakeCalls Android Malware Targets Financial Firms in South Korea"Security researchers at Check Point Research have spotted a new Android vishing (voice phishing) malware tool targeting victims in South Korea by impersonating 20 leading financial institutions in the region. Dubbed "FakeCalls," the malware baits…
-
"Russian Cyberspies Abuse EU Information Exchange Systems in Government Attacks"Security researchers at BlackBerry have observed Russia-linked cyberespionage group APT29 abusing two legitimate information exchange systems used by European countries. APT29 is a Russian advanced persistent threat (APT) actor mainly focused on…
-
"DEV-1101 Updates Open Source Phishing Kit"The threat actor known as DEV-1101 has been spotted by security researchers at Microsoft, developing and advertising a new adversary-in-the-middle (AiTM) open source phishing kit. The researchers noted that the threat actor group began offering…
-
"This is What Happens When Your Phone is Spying on You"According to a team of computer scientists from New York and San Diego, smartphone spyware apps that allow people to spy on each other are difficult to notice and detect, and easily leak the sensitive personal information they collect. Spyware apps are…
-
"NSA Releases Recommendations for Maturing Identity, Credential, and Access Management in Zero Trust"The National Security Agency (NSA) has released a Cybersecurity Information Sheet (CSI) titled "Advancing Zero Trust Maturity throughout the User Pillar" to help system operators in maturing their Identity, Credential, and Access Management (ICAM)…
-
"Phishing Campaigns Use SVB Collapse to Harvest Crypto"Security researchers at Proofpoint have uncovered several new phishing campaigns using the collapse of Silicon Valley Bank (SVB) as a lure to steal cryptocurrency. The researchers stated that they spotted lures related to USD Coin (USDC), a digital…
-
"Key Aerospace Player Leaks Sensitive Data"According to research conducted by Cybernews, the top aviation company Safran Group left itself vulnerable to cyberattacks for over a year, thus highlighting the vulnerability of major aviation companies to being targeted by threat actors. The Cybernews…
-
"First Known Dero Cryptojacking Operation Seen Targeting Kubernetes"The first known cryptojacking operation mining the Dero cryptocurrency has been observed targeting vulnerable Kubernetes container orchestrator infrastructure with exposed Application Programming Interfaces (APIs). Dero is a privacy coin advertised as a…
-
"Data Loss Prevention Company Hacked by Tick Cyberespionage Group"ESET researchers have discovered that a Data Loss Prevention (DLP) company in East Asia has been compromised. During the intrusion, the attackers launched at least three malware families, compromising both the company's internal update servers and third-…
-
"Microsoft Zero-Day Bugs Allow Security Feature Bypass"Two zero-day vulnerabilities need to be patched immediately, one in Microsoft Outlook's authentication mechanism and another discovered to be a Mark-of-the-Web (MOTW) bypass. Automox researchers advised enterprises to patch these vulnerabilities within…