"How AI Can Be Hacked With Prompt Injection: NIST Report"

"How AI Can Be Hacked With Prompt Injection: NIST Report"

In "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations," the National Institute of Standards and Technology (NIST) defines different Adversarial Machine Learning (AML) tactics and cyberattacks, as well as provides guidance on how to mitigate and manage them. AML tactics gather information about how Machine Learning (ML) systems work in order to determine how they can be manipulated.

Submitted by Gregory Rigby on

"RaaS Groups Increasing Efforts to Recruit Affiliates"

"RaaS Groups Increasing Efforts to Recruit Affiliates"

According to GuidePoint Security, smaller Ransomware-as-a-Service (RaaS) groups are trying to recruit new and "displaced" LockBit and Alphv/BlackCat affiliates by offering better payout splits, full-time support, and more. RaaS operations typically include a core group that develops the ransomware and maintains the underlying infrastructure. Such operations also involve affiliates who use it after infiltrating target systems and networks. They pay the core group a part of the ransom for their services.

Submitted by Gregory Rigby on

"'Fluffy Wolf' Spreads Meta Stealer in Corporate Phishing Campaign"

"'Fluffy Wolf' Spreads Meta Stealer in Corporate Phishing Campaign"

A threat actor, tracked as "Fluffy Wolf," is spreading different types of malware using accounting report lures in a phishing campaign that relies on malicious and legitimate software. According to researchers from Bi.Zone, Fluffy Wolf's active phishing campaign shows how even unskilled threat actors can use Malware-as-a-Service (MaaS) models to execute successful cyberattacks. The campaign is currently aimed at Russian organizations but could expand to other regions.

Submitted by Gregory Rigby on

"Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands"

"Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands"

According to the 2024 Thales Data Threat Report, ransomware attacks increased by 27 percent in 2023, with 8 percent of impacted organizations deciding to pay the demanded ransom. These numbers suggest that less than half of organizations have formal ransomware response plans in place. The report also cites malware as the fastest-growing threat, with 41 percent of companies reporting malware incidents in the past year. Phishing and ransomware attacks on cloud assets such as Software-as-a-Service (SaaS) applications and cloud-based storage are also growing.

Submitted by Gregory Rigby on

"CISA Shares Critical Infrastructure Defense Tips Against Chinese Hackers"

"CISA Shares Critical Infrastructure Defense Tips Against Chinese Hackers"

The US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and several other agencies in the US and around the world urge critical infrastructure leaders to protect their systems from the "Volt Typhoon" hacking group. Last month, they also warned that the Chinese hackers had breached multiple critical infrastructure organizations in the US, gaining access to at least one of them for at least five years before being detected.

Submitted by Gregory Rigby on

"1 in 4 Organizations Shut Down OT Operations Due to Cyberattacks: Survey"

"1 in 4 Organizations Shut Down OT Operations Due to Cyberattacks: Survey"

According to a survey commissioned by Palo Alto Networks, many industrial organizations are hit with cyberattacks, which result in the shutdown of Operational Technology (OT) processes in a significant percentage of cases. The survey was conducted in December 2023, with nearly 2,000 respondents from 16 countries in the Americas, Europe, and the Asia-Pacific region. Three-quarters of respondents revealed they had detected malicious cyber activity in their OT environment.

Submitted by Gregory Rigby on

SecureWorld Kansas City

"For more than 22 years, SecureWorld has been tackling global cybersecurity issues and sharing critical knowledge and tools needed to protect against ever-evolving threats. Through our network of industry experts, thought leaders, practitioners, and solution providers, we collaborate to produce leading-edge, relevant content. We host in-person conferences across North America, executive roundtable dinners, and virtual conferences focused on industry verticals and regions, and publish original news and analysis of the InfoSec world.

FinCrime & Cybersecurity Summit

"Join us in April as we bring together the top thinkers and executives across the financial crime industry as we explore the newest regulations, the biggest challenges and the solutions that can help catch the financial criminals. Based in the financial epicenter of the world, Transform Finance FinCrime & Cyber Security will ensure attendees stay in the know on how they can stay vigilant against fraud and attacks through sparking the conversations and discussions with high profile panels, expert led workshops and plenty of time for networking in between."



 

"BunnyLoader 3.0 Surfaces in the Threat Landscape'"

"BunnyLoader 3.0 Surfaces in the Threat Landscape'"

Researchers have discovered a new variant of the "BunnyLoader" malware with a modular structure and improved evasion capabilities. In October 2023, Zscaler ThreatLabz researchers discovered BunnyLoader, a new Malware-as-a-Service (MaaS) advertised for sale in multiple cybercrime forums since September 4, 2023. The BunnyLoader malware loader is written in C/C++ and is available on several forums for $250 for a lifetime license. According to researchers, BunnyLoader is in rapid development, with the authors releasing multiple updates to implement new features and address bugs.

Submitted by Gregory Rigby on

"EPA Floats Task Force to Address Cyberattacks on Water Infrastructure"

"EPA Floats Task Force to Address Cyberattacks on Water Infrastructure"

Recent cyberattacks on water plants have driven the US Environmental Protection Agency (EPA) to form a task force aimed at addressing the security risks that water infrastructure providers face. Attacks on US water and wastewater facilities could put a "critical lifeline" at risk and inflict significant costs on impacted communities, according to a letter from White House National Security Advisor Jake Sullivan and EPA Administrator Michael Regan to state governors.

Submitted by Gregory Rigby on
Subscribe to