-
"Google: Use SLSA Framework for Better Software Security"Google recommends that organizations use the Supply Chain Levels for Software Artifacts (SLSA) framework when developing software to improve software security and integrity, following an exploration of best practices for securing the software supply…
-
"New Ransomware Strain Discovered Lurking in Open-Source Packages"Checkmarx and Phylum detailed a typosquatting campaign aimed at the NPM and PyPI package managers. This campaign includes embedded ransomware and targets the popular "requests" package on PyPI and the "discord.js" package on NPM. When the…
-
"MuddyWater APT Group Is Back With Updated TTPs"Deep Instinct's Threat Research team discovered a new campaign carried out by the MuddyWater Advanced Persistent Threat (APT) group, also known as SeedWorm, TEMP.Zagros, and Static Kitten. The APT's campaign has targeted Armenia, Azerbaijan, Egypt, Iraq…
-
"Security Is No Longer an Internal Affair"Dimensional Research surveyed 1,175 security professionals and executives from five continents to get a global perspective of the capabilities of security solutions, deployment strategies, gaps, and the value of tool consolidation. According to the…
-
"Hack-for-Hire Group Targets Travel and Financial Entities with New Janicab Malware Variant"As part of a broader campaign aimed at legal and financial investment institutions in the Middle East and Europe, a hack-for-hire group called Evilnum has targeted travel agencies. The attacks, which occurred in 2020 and 2021 and most likely began in…
-
"UCalgary Research Raises Questions About Internet Security"Research by Dr. Joel Reardon, a University of Calgary Internet security and privacy expert, and his colleague, Dr. Serge Egelman, at the University of California Berkeley, has led to the web browser firm Mozilla removing an offshore company as a trusted…
-
"FAU Receives NSF Grant for Secure Communications Over 5G Networks"To deter and defeat agile adversaries, people and assets deployed by the US Department of Defense (DOD) in ground, sea, air, and space must maintain operational wireless network connectivity. Researchers from Florida Atlantic University's (FAU) College…
-
"Testing Environments Help S&T and CISA Secure Transportation Infrastructure"The Science and Technology Directorate (S&T) is working with the Cybersecurity and Infrastructure Security Agency (CISA) to develop and test new technologies and tools to combat both online and physical threats. According to the S&T program…
-
"Truebot Malware Activity Increases With Possible Evil Corp Connections"Security researchers at Cisco Talos have discovered that threat group Silence has been infecting an increasing number of devices using Truebot malware. The researchers suggest that there is a connection between Silence and the infamous hacking…
-
"Hive Ransomware Group Leaks Data From European Retailer"The Hive Ransomware-as-a-Service (RaaS) group claims to have published customer data obtained during an attack on French sports retailer Intersport in November. The notorious RaaS group leaked some Intersport data to its dark web leak site and threatened…
-
"CommonSpirit Health Says Patient Data Was Stolen During Ransomware Attack"CommonSpirit Health, based in Chicago, has confirmed that an October ransomware attack exposed the personal information of over 620,000 patients. On October 5, CommonSpirit Health, which operates over 700 care sites and 142 hospitals across 21 states,…
-
"DHS Secretary Says US Faces a New Kind of Warfare"Secretary of Homeland Security Alejandro Mayorkas recently stated that national security and homeland security are now more interconnected than ever before, largely driven by the fact that U.S. adversaries can execute attacks “with a keystroke.” …
News