"Crypto Scams Reach New Heights, FBI Reports $5.6bn in Losses"

"Crypto Scams Reach New Heights, FBI Reports $5.6bn in Losses"

With over 69,000 financial fraud and cryptocurrency complaints received by the Federal Bureau of Investigation's (FBI) Internet Crime Complaint Center (IC3) in 2023, cryptocurrency losses totaled over $5.6 billion. Overall, cryptocurrency scam losses rose 45 percent since 2022. Losses from cryptocurrency-related investment fraud schemes increased from $2.57 billion in 2022 to $3.96 billion in 2023, a growth of 53 percent. Phishing scams made up more than $9 million in losses, and Business Email Compromise (BEC) connected to cryptocurrency saw losses of over $4 million.

Submitted by Gregory Rigby on

"New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks"

"New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks"

Mordechai Guri of the Ben-Gurion University of the Negev in Israel introduces a new side-channel attack called "RAMBO," which is short for "Radiation of Air-gapped Memory Bus for Offense." It uses radio signals emanated by a device's Random Access Memory (RAM) to exfiltrate data. According to Dr. Guri, with Software-Generated Radio (SDR) signals, malware can encode biometric information, encryption keys, and other sensitive information. An attacker can intercept transmitted raw radio signals from a distance using SDR hardware and a commercially available antenna.

Submitted by Gregory Rigby on

"PIXHELL Attack Allows Air-Gap Jumping via Noise From Screens"

"PIXHELL Attack Allows Air-Gap Jumping via Noise From Screens"

A new data exfiltration method named "PIXHELL," discovered by Mordechai Guri of the Ben-Gurion University of the Negev in Israel, uses noise generated by the pixels on the screen. The PIXHELL attack involves planting malware on an air-gapped computer to steal data. This can be done with social engineering, supply chain attacks, or malicious insiders. This article continues to discuss the PIXHELL attack that uses noise generated by pixels on a screen to exfiltrate data from air-gapped computers.

Submitted by Gregory Rigby on

"Applications Are Open for IoT Device Cyber Certifiers"

"Applications Are Open for IoT Device Cyber Certifiers"

The Federal Communications Commission (FCC) is accepting applications for administrator roles on a voluntary cybersecurity labeling program to help consumers purchase products less vulnerable to cyberattacks. Those serving as administrators would be authorized to certify the label's use. Accredited research labs will handle device compliance testing. The logo would be on Internet of Things (IoT) products that meet baseline cyber standards. It would be placed together with a QR code that users can scan for more information on the product's security features.

Submitted by Gregory Rigby on

"Chrome 128 Update Resolves High-Severity Vulnerabilities"

"Chrome 128 Update Resolves High-Severity Vulnerabilities"

Google recently announced a new Chrome 128 update that addresses five vulnerabilities, including four reported by external researchers.  Google noted that all four externally reported flaws are high-severity memory safety issues that were reported in late August.  The first vulnerability, tracked as CVE-2024-8636, is a heap buffer overflow bug in Skia, the open-source 2D graphics library that serves as the graphics engine in the browser.  Next is CVE-2024-8637, a use-after-free security defect in Media Router.

Submitted by Adam Ekwall on

"Data Breach at Golf Course Management Firm KemperSports Impacts 62,000"

"Data Breach at Golf Course Management Firm KemperSports Impacts 62,000"

Golf course management and hospitality company KemperSports Management recently disclosed a data breach impacting the personal information of tens of thousands of individuals.  The company said it became aware of suspicious activity on its network on April 1, 2024.  An investigation revealed that a threat actor had gained access to systems storing personal information, including names and Social Security numbers.  KemperSports told the AG that the data breach impacted more than 62,000 individuals.

Submitted by Adam Ekwall on

"Adobe Patches Critical, Code Execution Flaws in Multiple Products"

"Adobe Patches Critical, Code Execution Flaws in Multiple Products"

Software maker Adobe recently released patches for at least 28 documented security vulnerabilities in a wide range of products and warned that both Windows and macOS users are exposed to code execution attacks.  The most urgent issue, affecting the widely deployed Acrobat and PDF Reader software, covers two memory corruption vulnerabilities that could be exploited to launch arbitrary code.

Submitted by Adam Ekwall on

"Highline Public Schools Forced to Close By Cyberattack"

"Highline Public Schools Forced to Close By Cyberattack"

A group of schools in Washington State has been forced to close for at least two days following a cyberattack.  Highline Public Schools has more than 17,500 students in grades K-12.  The district has 34 schools and 2,000 staff.  Highline Public Schools are working closely with third-party, state, and federal partners to safely restore and test its systems.  Staff at Highline have been told not to use district issued computers and laptops as a precaution, and Highline said it has disconnected its network from the internet.

Submitted by Adam Ekwall on

"Wisconsin Insurer Discloses Data Breach Impacting 950,000 Individuals"

"Wisconsin Insurer Discloses Data Breach Impacting 950,000 Individuals"

Wisconsin Physicians Service Insurance Corporation (WPS) recently started notifying roughly 950,000 individuals that their personal information was stolen in the MOVEit campaign last year. The MOVEit hack was disclosed in May 2023 after Progress Software discovered that the Russian-speaking Cl0p ransomware group had exploited a zero-day in the MOVEit Transfer managed file transfer (MFT) software to access customer data.

Submitted by Adam Ekwall on

"DoJ Distributes $18.5m to Western Union Fraud Victims"

"DoJ Distributes $18.5m to Western Union Fraud Victims"

It has recently been announced that around 3000 victims of historic fraud facilitated by Western Union will receive millions of dollars in the latest round of reimbursements announced yesterday.  The Department of Justice (DoJ) said that the second distribution of the second phase of the Western Union Remission would compensate the victims another $18.5m forfeited to the government by the Colorado-headquartered money transfer business.

Submitted by Adam Ekwall on
Subscribe to