"Dozens of High-Profile Israeli Firms Hacked by Iran-Sponsored Gang"

"Dozens of High-Profile Israeli Firms Hacked by Iran-Sponsored Gang"

According to the threat intelligence platform FalconFeedsio, a newly emerged Iranian cyber gang called "Cyber Toufan" has allegedly leaked data from 49 Israeli companies. Researchers believe many incidents were caused by a breach faced by one hosting company. Since its appearance on November 16, 2023, Cyber Toufan says it compromised high-profile organizations, including the Israel Innovation Authority, Toyota Israel, the Ministry of Welfare and Social Security, Ikea Israel, the cybersecurity and geo-intelligence company Max Security, and more.

Submitted by Gregory Rigby on

"Member of Lapsus$ Gang Sentenced to an Indefinite Hospital Order"

"Member of Lapsus$ Gang Sentenced to an Indefinite Hospital Order"

Arion Kurtaj, a prominent member of the international cyber extortion gang Lapsus$, has been sentenced to an indefinite hospital order by the UK Southwark Crown Court. The Lapsus$ gang has compromised many high-profile companies, including NVIDIA, Samsung, Ubisoft, Mercado Libre, Vodafone, Microsoft, Okta, and Globant. Kurtaj was found guilty of hacking multiple high-profile companies by a London jury in August 2023. He has been conducting a series of solo attacks since September 2022, gaining access to about 5,000 Revolut customers' records and causing $3 million in damage to Uber.

Submitted by Gregory Rigby on

"CISA Finalizes Microsoft 365 Secure Configuration Baselines"

"CISA Finalizes Microsoft 365 Secure Configuration Baselines"

The US Cybersecurity and Infrastructure Security Agency (CISA) has announced the release of Version 1.0 of its Secure Configuration Baselines for Microsoft 365 (M365), along with its ScubaGear tool that helps organizations quickly assess their M365 services against CISA's recommended policies. These baselines provide easily implementable policy configuration recommendations that complement each federal agency's unique requirements and risk tolerance levels.

Submitted by Gregory Rigby on

"Cybercrooks Book a Stay in Hotel Email Inboxes to Trick Staff Into Spilling Credentials"

"Cybercrooks Book a Stay in Hotel Email Inboxes to Trick Staff Into Spilling Credentials"

Sophos researchers have detailed a new malware campaign targeting hotels that involves sending emails that play on employees' emotions while putting them under time pressure to trick them into downloading and running password-stealing Windows malware. There are two types of emails sent, with the first being those that complain about serious issues with a recent stay, and the second being those that request information to help with a future booking. Both situations typically call for a quick response from hotel management.

Submitted by Gregory Rigby on

"Nissan Australia Cyberattack Claimed by Akira Ransomware Gang"

"Nissan Australia Cyberattack Claimed by Akira Ransomware Gang"

The Akira ransomware gang recently claimed it breached the network of Nissan Australia, the Australian division of Japanese car maker Nissan.  In a new entry added to the operation's date leak blog on December 22, Akira says it allegedly stole around 100GB of documents from the automaker's systems.  The attackers have threatened to leak sensitive business and client data online, as ransom negotiations with Nissan failed after the company either refused to engage or pay the ransom.

Submitted by Adam Ekwall on

"OpenAI Rolls Out Imperfect Fix for ChatGPT Data Leak Flaw"

"OpenAI Rolls Out Imperfect Fix for ChatGPT Data Leak Flaw"

OpenAI has addressed a ChatGPT data exfiltration bug that could leak conversation details to an external URL. However, the mitigation is not perfect, according to security researcher Johann Rehberger, who discovered the flaw. According to Rehberger, attackers can still exploit it under certain conditions. The safety checks for ChatGPT have also yet to be implemented in the iOS mobile app, so the threat on that platform remains unaddressed. This article continues to discuss the ChatGPT data leak vulnerability and OpenAI's fix for it.

Submitted by Gregory Rigby on

"UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware"

"UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware"

A threat actor called UAC-0099 has been linked to attacks against Ukraine, some of which exploit a high-severity flaw contained by WinRAR software to deliver the LONEPAGE malware strain. According to researchers at Deep Instinct, the threat actor targets Ukrainian employees in companies based outside of Ukraine. The Computer Emergency Response Team of Ukraine (CERT-UA) first documented UAC-0099 in June 2023, describing its attacks against state organizations and media entities for espionage purposes.

Submitted by Gregory Rigby on

"'BattleRoyal' Hackers Deliver DarkGate RAT Using Every Trick"

"'BattleRoyal' Hackers Deliver DarkGate RAT Using Every Trick"

An unidentified threat actor conducted various social engineering campaigns against American and Canadian organizations in different industries to infect them with the multifaceted DarkGate malware. Proofpoint researchers could not determine whether the perpetrator dubbed "BattleRoyal" is a completely new actor or related to existing ones, partly because of the number of tactics, techniques, and procedures (TTPs) used.

Submitted by Gregory Rigby on

"86% Of Cyberattacks Are Delivered Over Encrypted Channels"

"86% Of Cyberattacks Are Delivered Over Encrypted Channels"

According to Zscaler, threats over HTTPS have increased by 24 percent since 2022, highlighting the sophistication of cybercriminal tactics that target encrypted channels. Manufacturing was the most commonly targeted industry for the second year in a row, with education and government organizations experiencing the most significant year-over-year increase in attacks. In addition, malware, including malicious web content and malware payloads, continued to conquer other types of encrypted attacks.

Submitted by Gregory Rigby on

33rd International Conference on Computer Communications and Networks (ICCCN 2024)

"ICCCN is one of the leading international conferences for presenting novel ideas and fundamental advances in the fields of computer communications and networks. ICCCN serves to foster communication among researchers and practitioners with a common interest in improving communications and networking through scientific and technological innovation. The primary focus of the conference is on new and original research results in the areas of design, implementation, and applications of computer communications and networks."

Subscribe to