News
  • "Fake 'Cthulhu World' P2E Project Used to Push Info-Stealing Malware"
    Hackers have set up a fake 'Cthulhu World' play-to-earn community, with websites, Discord groups, social accounts, and a Medium developer site, to infect unsuspecting victims with the Raccoon Stealer, AsyncRAT, and RedLine password-stealing malware.…
  • "Nitrokod Crypto Miner Infected Over 111,000 Users with Copies of Popular Software"
    Nitrokod, a Turkish-speaking entity, has been linked to an ongoing cryptocurrency mining campaign involving impersonating a desktop application for Google Translate to infect more than 111,000 victims in 11 countries since 2019. According to Check Point'…
  • "This New Chip Could Lead To Faster, More Secure AI"
    A team of researchers led by University of Pittsburgh Assistant Professor Rajkumar Kubendran in the Swanson School of Engineering has contributed to the development of a new type of computer chip that could run Artificial Intelligence (AI) programs…
  • "Maritime Cyber Incidents Increased at Least 68 Percent in 2021, Coast Guard Reports"
    According to a new US Coast Guard Cyber Command (CGCYBER) report on maritime cybersecurity trends, the importance of cyber hygiene, detection, and response grew exponentially last year because of a 68 percent increase in reported maritime cyber incidents…
  • "Cosmetics Giant Sephora to Pay $1m+ Privacy Settlement"
    One of the world’s biggest cosmetics retailers, Sephora, has agreed to pay $1.2 million in penalties and take corrective action after falling foul of the California Consumer Privacy Act (CCPA).  Sephora was accused of failing to disclose to…
  • "Eliminating Algorithmic Complexity Attacks"
    Malicious actors often use Denial-of-Service (DoS) attacks to slow down and disrupt network systems. Such attacks attempt to prevent network users from accessing online services by overloading the network with so much data to process that it cannot keep…
  • "DoorDash Data Compromised Following Twilio Hack"
    Food delivery company DoorDash recently revealed that customer and employee data has been exposed due to a recent breach at a third-party vendor.  DoorDash said hackers abused a third-party vendor's access to its systems.  The attacker abused…
  • "TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years"
    The threat actor known as TeamTNT has been targeting cloud instances and containerized environments on systems worldwide for at least two years.  The findings come from CloudSEK security researchers, who posted an advisory on Thursday detailing a…
  • Pub Crawl #65
    ​Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.
  • "New 'Agenda' Ransomware Customized for Each Victim"
    Cybersecurity researchers at Trend Micro are raising the alarm on a new ransomware family called Agenda, which has been used in attacks on organizations in Asia and Africa.  The researchers noted that Agenda is written in the Golang (Go) cross-…
  • "'Quantum-Safe' Crypto Hacked by 10-Year-Old PC"
    Cryptographers worldwide have spent the last two decades developing postquantum cryptography (PQC) algorithms to stay ahead of the quantum threat. These are based on new mathematical problems that are difficult to solve for both quantum and classical…
  • "How 'Kimsuky' Hackers Ensure Their Malware Only Reach Valid Targets"
    North Korean 'Kimsuky' threat actors are trying to ensure that their malicious payloads are only downloaded by legitimate targets and not by security researchers' systems. The threat group has been using new techniques to filter out invalid download…