"Lloyd's of London Finds Hypothetical Cyberattack Could Cost World Economy $3.5 Trillion"

"Lloyd's of London Finds Hypothetical Cyberattack Could Cost World Economy $3.5 Trillion"

The insurance giant Lloyd's of London has warned that a major cyberattack against payment systems could cost the global economy $3.5 trillion. Modeled by the insurance marketplace and the Cambridge Centre for Risk Studies, the hypothetical scenario is deemed unlikely. Researchers estimated a 3.3 percent chance of happening. In addition, the British government has researched the probability of a cyberattack on the financial system and determined that a catastrophic incident is unlikely.

Submitted by grigby1 CPVI on

"FBI Warns of Extortion Groups Targeting Plastic Surgery Offices"

"FBI Warns of Extortion Groups Targeting Plastic Surgery Offices"

According to the FBI, cybercriminals are using spoofed emails and phone numbers to target plastic surgery offices across the US. After gaining access to their networks, the attackers steal data from compromised systems to extort surgeons and patients. Stolen documents may contain highly sensitive information, such as medical records and, in some instances, photos taken for medical purposes. The cybercriminals supplement the stolen data with open-source information, such as social media details, to strengthen their extortion attempts.

Submitted by grigby1 CPVI on

"Jupyter Notebooks Targeted by Cryptojackers"

"Jupyter Notebooks Targeted by Cryptojackers"

Researchers have discovered that cryptojackers are targeting exposed Jupyter Notebooks to install cryptocurrency miners and steal credential files for popular cloud services. Jupyter is a service that enables users to host individual code snippets and lets others execute this code in an isolated environment. According to Matt Muir, Threat Research Lead at Cado Security, a Jupyter Notebook refers to an instance of the Jupyter web application where a user would define the code to be run and how it is presented.

Submitted by grigby1 CPVI on

"Former Navy IT Manager Sentenced to Prison for Hacking, Selling PII"

"Former Navy IT Manager Sentenced to Prison for Hacking, Selling PII"

A former US Navy IT manager was recently sentenced to five years and five months in prison for hacking into a database, stealing personally identifiable information (PII), and selling it on the dark web.  The man, Marquis Hooper, 32, of Selma, California, who was a chief petty officer, opened under false pretenses an account at a private company operating a database containing the PII of millions of individuals.

Submitted by Adam Ekwall on

"Cybercriminals Register .AI Domains of Trusted Brands for Malicious Activity"

"Cybercriminals Register .AI Domains of Trusted Brands for Malicious Activity"

According to CSC's 2023 Domain Security Report, nearly half of Forbes Global 2000 companies do not have control over their branded Artificial Intelligence (.AI) domain names, which third parties register. Cybercriminals are exploiting the popularity of AI by registering the domains of trusted brands for malicious activity. There has been a 350 percent increase in domain dispute cases involving .AI extensions in 2023 from companies who discovered that third parties were misappropriating .AI domains using their brands.

Submitted by grigby1 CPVI on

"Russia's Sandworm Hacking Unit Targets Ukrainian Telecom Providers"

"Russia's Sandworm Hacking Unit Targets Ukrainian Telecom Providers"

According to a recent report from Ukrainian cybersecurity authorities, the Russian state hacking group Sandworm has targeted at least 11 Ukrainian Internet and telecommunication providers since May. Ukraine's Computer Emergency Response Team (CERT-UA) said the attacks resulted in service interruptions and potential data breaches. During the ongoing war, hackers target telecommunication providers in Russia and Ukraine to disrupt communications and Internet access.

Submitted by grigby1 CPVI on

"ServiceNow Leak: Thousands of Companies at Risk"

"ServiceNow Leak: Thousands of Companies at Risk"

According to cybersecurity expert Daniel Miessler, a potential data exposure issue within a built-in capability of the digital business platform ServiceNow has been identified, which could enable unauthenticated users to extract data from records. The types of data exposed include names, email addresses, and internal documents. The exposure likely impacts thousands of companies. Miessler suspects the vulnerability stems from a misconfiguration of a widget or component in ServiceNow's system called Simple List, which organizes records into easily readable tables.

Submitted by grigby1 CPVI on

"'EtherHiding' Blockchain Technique Hides Malicious Code in WordPress Sites"

"'EtherHiding' Blockchain Technique Hides Malicious Code in WordPress Sites"

A threat actor has been using blockchain technology to hide malicious code in a campaign involving fake browser updates that distribute malware, including RedLine, Amadey, and Lumma. Although the abuse of blockchain technology is typically seen in attacks targeting cryptocurrency, the EtherHiding technique shows how attackers can use it for other types of malicious activity. Over the past two months, Guardio researchers have been observing the campaign dubbed ClearFake, in which users are tricked into downloading malicious fake browser updates from at least 30 compromised WordPress sites.

Submitted by grigby1 CPVI on

"Cyberattacks on Healthcare Organizations Affect Patient Care"

"Cyberattacks on Healthcare Organizations Affect Patient Care"

A Proofpoint and Ponemon Institute survey found that 66 percent of healthcare organizations affected by the most common types of cyberattacks reported disruptions to patient care. Fifty-seven percent reported poor patient outcomes as a result of delays in procedures and tests, 50 percent reported an increase in medical procedure complications, and 23 percent revealed an increase in patient mortality rates. These numbers suggest that healthcare organizations have made little progress in mitigating the threat of cyberattacks to patient safety and well-being.

Submitted by grigby1 CPVI on

"Phishing Attacks Hit Record High in Third Quarter, With Malware Not Far Behind"

"Phishing Attacks Hit Record High in Third Quarter, With Malware Not Far Behind"

According to a new report from the threat detection and response company Vade Secure SASU, phishing and malware attacks increased significantly in the third quarter, to the point where the number of attacks is among the highest ever recorded for a quarter. The Vade Q3 Phishing and Malware Report found that phishing attacks increased by 173 percent over the previous quarter, from 180.4 million to 493.2 million. The report also reveals a 110 percent increase in malware attacks, with 125.7 million emails infected as opposed to 60 million in the second quarter.

Submitted by grigby1 CPVI on
Subscribe to