News
-
"Malicious Npm Packages Designed to Steal Discord Tokens"Security researchers at Kaspersky have discovered yet another supply chain attack campaign using malicious npm packages, this time targeting Discord users. The researchers said they identified four suspicious packages in the popular npm repository…
-
"Secure Cryptography with Real-World Devices Is Now a Realistic Possibility"A new study published in Nature describes how an international team of researchers experimentally implemented a type of quantum cryptography thought to be the 'ultimate,' 'bug-proof' means of communication for the first time. In an experiment based on…
-
"RaaS Groups Forced to Change Tack as Payments Decline"Security researchers at Coveware found that Ransomware-as-a-service (RaaS) operators are evolving their tactics yet again in response to more aggressive law enforcement efforts. The researchers identified three characteristics of RaaS operations…
-
"Microsoft Links Raspberry Robin Malware to Evil Corp Attacks"Microsoft discovered that an access broker tracked as DEV-0206 uses the Raspberry Robin Windows worm to deploy a malware downloader on networks. Evidence of malicious activity matching Evil Corp tactics was also discovered. Microsoft researchers…
-
"Euro Police Bust 3m Euro Internet Fraud Gang"Spanish and Romanian police recently joined forces to take down a gang suspected of earning at least €3m ($3.1) from internet scams. Spanish National Police arrested three suspects in the southern city of Malaga, while their Romanian counterparts…
-
"Dahua IP Camera Vulnerability Could Let Attackers Take Full Control Over Devices"Information has been released on a security flaw in Dahua's implementation of the Open Network Video Interface Forum (ONVIF) standard that, if abused, might result in the takeover of IP cameras. According to a report released by Nozomi Networks, the CVE-…
-
"Akamai Thwarted The Biggest DDoS Attack in Europe"The largest Distributed Denial-of-Service (DDoS) attack to ever affect Europe was launched this month and was directed at a corporation in Eastern Europe. The target, an Akamai customer who receives cybersecurity and cloud services, has been subjected to…
-
"APT-Like Phishing Threat Mirrors Landing Pages"A phishing campaign is tricking users into providing login information by using mirror versions of landing pages from target companies. The malicious actors can then use these stolen credentials to access a wealth of private or business files, as well as…
-
"Virginia Tech, International Partners Debut First-Of-Its Kind Testbed for Resiliency, Security in Space-Based Internet Networks"Elon Musk's Starlink and other satellite Internet projects aim to provide high-speed, low-latency broadband Internet around the world. However, some major questions remain unanswered, such as how to build a resilient, secure network in space. Therefore,…
-
Pub Crawl #64Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.
-
"House Passes Cybersecurity Bills Focusing on Energy Sector, Information Sharing"The US House of Representatives recently passed two cybersecurity bills, the Energy Cybersecurity University Leadership Act and the RANSOMWARE Act. RANSOMWARE is an acronym for "Reporting Attacks from Nations Selected for Oversight and Monitoring Web…
-
"Ransomware Gang LockBit Claims to Have Gained Access to Italian Revenue Agency"The Italian Revenue Agency (Agenzia delle Entrate) has been added to the list of victims listed on the ransomware gang LockBit's dark web leak website. The gang claims to have stolen 78GB of data, which included contracts, financial reports, and…