"Chenlun's Evolving Phishing Tactics Target Trusted Brands"

"Chenlun's Evolving Phishing Tactics Target Trusted Brands"

The threat actor "Chenlun" has been linked to a sophisticated phishing campaign impersonating trusted brands such as Amazon through text messages. Researchers at DomainTools attributed this activity to Chenlun, who exploited USPS delivery alerts last year to steal sensitive information. A new wave of phishing messages warns users about suspicious account activity and encourages them to verify accounts via malicious links. This article continues to discuss the evolution of Chenlun's tactics and the importance of collaborating to combat phishing attacks.

Submitted by Gregory Rigby on

"CISA Releases Its First Ever International Strategic Plan"

"CISA Releases Its First Ever International Strategic Plan"

The US Cybersecurity and Infrastructure Security Agency (CISA) released its first International Strategic Plan for 2025-2026. It supports the CISA's first comprehensive strategic plan and aligns with the National Security Memorandum on Critical Infrastructure Security and Resilience. The International Strategic Plan outlines how CISA will actively work with international partners to bolster critical infrastructure security and resiliency. This article continues to discuss CISA's 2025-2026 International Strategic Plan.

Submitted by Gregory Rigby on

"Android Malware "FakeCall" Now Reroutes Bank Calls to Attackers"

"Android Malware "FakeCall" Now Reroutes Bank Calls to Attackers"

Security researchers at CheckPoint have discovered that a new version of the FakeCall malware for Android hijacks outgoing calls from a user to their bank, redirecting them to the attacker's phone number instead.  The goal of the latest version remains to steal people's sensitive information and money from their bank accounts.  The researchers noted that FakeCall (or FakeCalls) is a banking trojan with a focus on voice phishing, in which victims are deceived through fraudulent calls impersonating banks, asking them to convey sensitive information.

Submitted by Adam Ekwall on

SenSys 2025 - Call for Papers

SenSys 2025 - Call for Papers

We invite submissions on a broad range of topics that have been covered by SenSys, IPSN, and IoTDI, as well as new emerging topics of interest.

Submitted by Regan Williams on

"Google Patches Critical Chrome Vulnerability Reported by Apple"

"Google Patches Critical Chrome Vulnerability Reported by Apple"

Google and Mozilla recently announced security updates for their Chrome and Firefox web browsers, and some of the vulnerabilities they patch are potentially severe.  Google announced the release of Chrome 130, which patches two vulnerabilities.   The first vulnerability, tracked as CVE-2024-10487, has been described as a critical out-of-bounds write issue in Dawn, the cross-platform implementation of the WebGPU standard. The second vulnerability patched with the release of Chrome 130 is CVE-2024-10488, a high-severity use-after-free in WebRTC.

Submitted by Adam Ekwall on

"Over Half of US County Websites Could Be Spoofed"

"Over Half of US County Websites Could Be Spoofed"

Security researchers at Comparitech have sounded another US election warning after claiming that the majority of US county websites could be copied to spread disinformation and steal info.  The researchers analyzed the websites and official contact email addresses for 3144 US counties to compile its report. The researchers found that 57% of county websites are registered with non-.gov domains, meaning they could easily be spoofed with malign intent. Additionally, over half (55%) of counties in the seven swing states have non-.gov registered domains.

Submitted by Adam Ekwall on

"French ISP Confirms Cyberattack, Data Breach Affecting 19M"

"French ISP Confirms Cyberattack, Data Breach Affecting 19M"

Free, a French telecommunications company and the country's second-largest Internet service provider (ISP), has recently disclosed that it fell victim to a cyberattack over the weekend. It was noted that a threat actor stole information from the company's internal management tool, gathered data on its subscribers, and attempted to sell the data on the Dark Web in a cybercrime forum. The hacker behind the breach, known as "drussellx," posted a message on the forum, putting two databases stolen from the ISP company up for auction.

Submitted by Adam Ekwall on

NSA Updates Guidance on Russian SVR Cyber Operations

NSA Updates Guidance on Russian SVR Cyber Operations

The NSA has issued updated guidance on Russian SVR cyber operations, highlighting new tactics used to target U.S. networks and providing recommendations for mitigating these threats.

Submitted by Regan Williams on

"New LightSpy Spyware Targets iOS with Enhanced Capabilities"

"New LightSpy Spyware Targets iOS with Enhanced Capabilities"

Security researchers at ThreatFabric have discovered a newer version of the LightSpy spyware, known for targeting iOS devices.  The researchers noted that it has been expanded to include capabilities for compromising device security and stability.  This latest version, identified as 7.9.0, is more sophisticated and adaptable than the original version, featuring 28 plugins compared to the 12 observed in the earlier version.

Submitted by Adam Ekwall on
Subscribe to