"Microsoft Warns of Election Threats in 2024"

"Microsoft Warns of Election Threats in 2024"

A recent threat intelligence assessment released by Microsoft’s Threat Analysis Center (MTAC) has warned of potential unprecedented challenges to the security of elections over the next year.  Microsoft suggested that authoritarian nation states may attempt to interfere with electoral processes using a combination of traditional methods and emerging technologies, including AI.  Microsoft stated that there is a need for governments, technology companies, businesses, and civil society to collaborate and take proactive steps to safeguard elections.

Submitted by Adam Ekwall on

"New Tool Automates the Formal Verification of Systems Software"

"New Tool Automates the Formal Verification of Systems Software"

Formal systems verification is a relatively new technology that mathematically proves code is secure. Traditional software testing techniques are becoming less effective as software becomes more complex. Making software correct, safe, and secure is becoming increasingly important as the use of generative Artificial Intelligence (AI) techniques to automatically write programs rises.

Submitted by Gregory Rigby on

"Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation"

"Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation"

Cybersecurity researchers have developed the first fully undetectable cloud-based cryptocurrency miner that uses the Microsoft Azure Automation service. The cybersecurity company SafeBreach discovered three different ways to run the miner, including one that can be executed on a victim's environment without drawing attention. Although this research is significant due to its potential impact on cryptocurrency mining, researchers believe it has far-reaching consequences in other areas, as the techniques could be applied to any task that requires code execution on Azure.

Submitted by Gregory Rigby on

"Russian-Speaking Threat Actor 'Farnetwork' Linked to 5 Ransomware Gangs"

"Russian-Speaking Threat Actor 'Farnetwork' Linked to 5 Ransomware Gangs"

Farnetwork, the threat actor behind the Nokoyawa Ransomware-as-a-Service (RaaS), gained experience over the years by helping the JSWORM, Nefilim, Karma, and Nemty affiliate programs with malware development and operation management. A report from the cybersecurity company Group-IB delves into Farnetwork's activity and how they became a highly active player in the ransomware business. Farnetwork shared details with threat intelligence analysts that link them to ransomware operations dating back to 2019 and a botnet with access to multiple corporate networks.

Submitted by Gregory Rigby on

"Three-Quarters of Retail Ransomware Attacks End in Encryption"

"Three-Quarters of Retail Ransomware Attacks End in Encryption"

According to security researchers at Sophos, the share of global retailers hit by a serious ransomware breach over the past 12 months fell nearly 10 percentage points year-on-year (YoY), but just 26% were able to disrupt an attack before data was encrypted.  The researchers polled 355 IT and cybersecurity leaders in retail organizations with between 100 and 5000 employees.

Submitted by Adam Ekwall on

"Silent Ransom Group Ramps up Callback Phishing Attacks, FBI Warns"

"Silent Ransom Group Ramps up Callback Phishing Attacks, FBI Warns"

The FBI warns of a callback phishing scam by the Silent Ransom Group to gain initial access to organizations targeted in a recent ransomware campaign. In callback phishing attacks, threat actors email employees at a target company, demanding payment for a fake account and instructing them to call the gang's call center to resolve the problem. Once the victim calls, the threat actors use social engineering techniques to trick them into installing malware on their computer, granting the group initial access to the target organization.

Submitted by Gregory Rigby on

"Virtual Kidnapping: AI Tools Are Enabling IRL Extortion Scams"

"Virtual Kidnapping: AI Tools Are Enabling IRL Extortion Scams"

Cybercriminals have the resources to fake a real-life kidnapping and make it believable, thanks to Artificial Intelligence (AI) and publicly available data. At this year's Black Hat Europe conference, two Trend Micro researchers will discuss the real and emerging new trend of "virtual kidnapping," which may be the most frightening malicious application of AI yet.

Submitted by Gregory Rigby on

"23andMe Data Theft Prompts DNA Testing Companies to Switch on 2FA by Default"

"23andMe Data Theft Prompts DNA Testing Companies to Switch on 2FA by Default"

Following the theft of millions of user records from the DNA genetic testing company 23andMe, DNA testing and genealogy companies are increasing their efforts to strengthen user account security by enabling two-factor authentication (2FA) by default. Ancestry, MyHeritage, and 23andMe have started notifying customers that 2FA will be enabled by default on their accounts. 2FA requires a user to enter an additional verification code sent to a device they own to confirm that they are the actual account holder logging in.

Submitted by Gregory Rigby on

"Companies Have Good Reasons To Be Concerned About Generative AI"

"Companies Have Good Reasons To Be Concerned About Generative AI"

According to Portal26, companies need help gaining visibility into their Artificial Intelligence (AI) programs' operations. A lack of visibility may reduce productivity and introduce significant risks in governance, data security, and other areas. In the past year, two-thirds of respondents reported a generative AI security or misuse incident. Seventy-three percent have already faced generative AI-related security incidents, with 67 percent occurring in the last year alone.

Submitted by Gregory Rigby on

"Marina Bay Sands Discloses Data Breach Impacting 665k Customers"

"Marina Bay Sands Discloses Data Breach Impacting 665k Customers"

Singapore's Marina Bay Sands luxury resort has recently revealed that 665,000 of its customers are impacted by a recent data breach.  The incident affects Marina Bay Sands' shopping loyalty program members.  There is no indication to date that the Sands Rewards Club casino rewards program was impacted as well.  The resort is owned by US casino and resort giant Las Vegas Sands.  The company discovered on October 20 that an unauthorized third party had gained access to shopping membership program data on October 19 and 20.

Submitted by Adam Ekwall on
Subscribe to