"CISA Awards CYBER.ORG $6.8M in Funding for K-12 Cyber Education"

"CISA Awards CYBER.ORG $6.8M in Funding for K-12 Cyber Education"

The US Cybersecurity and Infrastructure Security Agency (CISA) awarded $6.8 million through the Cybersecurity Education and Training Assistance Program (CETAP) to CYBER.ORG, a nonprofit cybersecurity workforce development organization. With this funding, CYBER.ORG will continue supporting the educational growth of elementary and secondary-level students. The organization encourages cybersecurity literacy, instruction, and career exploration opportunities to help address the nation's cybersecurity workforce shortage of more than 660,000 professionals.

Submitted by Gregory Rigby on

"Spanish Police Arrest 34 Alleged Cybercriminals for Scamming Operation"

"Spanish Police Arrest 34 Alleged Cybercriminals for Scamming Operation"

The Spanish police have arrested 34 alleged cybercriminals accused of various online scams. In the provinces of Madrid, Málaga, Huelva, Alicante, and Murcia, police conducted 16 investigations as part of the operation against the group. It is believed that the alleged cybercriminals performed scams via email, phone, and text. They allegedly perpetrated "son in distress" scams, the manipulation of delivery notes from technology companies, and vishing campaigns pretending to be electrical supply company employees. They are estimated to have gained around $3.2 million from their scams.

Submitted by Gregory Rigby on

"University of Michigan Says Personal Information Stolen in August Data Breach"

"University of Michigan Says Personal Information Stolen in August Data Breach"

The University of Michigan recently confirmed that personal information was accessed in a data breach discovered in August 2023.  The incident involved unauthorized access to the academic institution’s campus computer network and resulted in system disruption and internet outages.  The university’s investigation into the data breach has revealed that the attackers had access to certain systems between August 23 and 27.

Submitted by Adam Ekwall on

"Backdoor Implant on Hacked Cisco Devices Modified to Evade Detection"

"Backdoor Implant on Hacked Cisco Devices Modified to Evade Detection"

The backdoor implanted on Cisco devices by exploiting a couple of zero-day vulnerabilities in the IOS XE software has been modified to evade detection through previous fingerprinting techniques. According to NCC Group's Fox-IT team, network traffic to a compromised device has shown that the threat actor has changed the implant to perform an additional header check. Therefore, the implant remains active for many devices but now only responds if the proper Authorization HTTP header is set.

Submitted by Gregory Rigby on

2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)

"IEEE CloudCom is the premier conference on Cloud Computing worldwide, attracting researchers, engineers, and students from the fields of cloud computing, big data, systems architecture, service-oriented architecture, virtualization, security and privacy, high performance computing, always with an emphasis on how to build cloud computing platforms with impact."

2024 IEEE 14th Annual Computing and Communication Workshop and Conference (CCWC)

"IEEE CCWC 2024 which will provide an opportunity for researchers, educators and students to discuss and exchange ideas on issues, trends, and developments in Computing and Communication. The conference aims to bring together scholars from different disciplinary backgrounds to emphasize dissemination of ongoing research in the fields of Computing and Communication. Research papers are invited describing original work in the above-mentioned fields and related technologies. The conference will include a peer-reviewed program of technical sessions."

"The Primary Pain Points for SoC Teams"

"The Primary Pain Points for SoC Teams"

According to Tines, growing workloads, shrinking budgets, and a worsening skills shortage are the main factors holding security professionals back from pursuing high-impact work. Nine out of 10 security teams automate at least a portion of their work, and 93 percent of respondents believe that more automation would improve their work-life balance. Sixty-three percent of surveyed security decision-makers and practitioners are experiencing burnout due to constant cyberattacks, internal pressures, and a lack of resources.

Submitted by Gregory Rigby on

"September Was a Record Month for Ransomware Attacks in 2023"

"September Was a Record Month for Ransomware Attacks in 2023"

Ransomware activity reached unprecedented levels in September, following a relative pause in August that was still well above summer norms. In September, ransomware groups launched 514 attacks, according to data from NCC Group. This exceeds March 2023's total of 459 attacks, which was significantly skewed by Clop's MOVEit Transfer data theft attacks. During the month, Clop exhibited almost no activity, which may indicate that the sophisticated ransomware group is preparing for its next major attack.

Submitted by Gregory Rigby on

"DC Board of Elections Says Full Voter Roll Compromised in Data Breach"

"DC Board of Elections Says Full Voter Roll Compromised in Data Breach"

The District of Columbia Board of Elections (DCBOE) recently announced that its full voter roll might have been accessed in a recent data breach at a third-party services provider.  The incident was initially disclosed on October 6, when the agency said that a threat actor accessed 600,000 lines of US voter data after breaching DataNet, which provides website hosting services to DCBOE.  In a recent update, DCBOE revealed that the attackers might have accessed the information of all registered voters.

Submitted by Adam Ekwall on

"'Log in With...' Feature Allows Full Online Account Takeover for Millions"

"'Log in With...' Feature Allows Full Online Account Takeover for Millions"

Vulnerabilities in the implementation of the Open Authorization (OAuth) standard across three major online services may have exposed users to credential theft, financial fraud, and other cybercriminal activities. Researchers from Salt Labs discovered critical Application Programming Interface (API) misconfigurations on the websites of several online companies, including Grammarly, Vidio, and Bukalapak, which leads them to believe that dozens of other websites are likely compromised in the same way.

Submitted by Gregory Rigby on
Subscribe to