"CISA, FBI Warn of Scattered Spider Expertise With Social Engineering, SIM Swapping"

"CISA, FBI Warn of Scattered Spider Expertise With Social Engineering, SIM Swapping"

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) are warning about a group of hackers known as Scattered Spider, who have disrupted some of the country's largest companies through social engineering and other methods. The hacking group, also known as Starfraud, UNC3944, Scatter Swine, and Muddled Libra, has recently made headlines for alleged attacks on MGM Resorts and Caesars Entertainment. The FBI and CISA supported research from cybersecurity experts on how the group works in a recent advisory and press roundtable.

Submitted by Gregory Rigby on

"CSA Launches First Zero Trust Certification"

"CSA Launches First Zero Trust Certification"

The Cloud Security Alliance (CSA) has recently introduced the Certificate of Competence in Zero Trust (CCZT), the industry’s inaugural authoritative zero trust certification.  CSA noted that the certification responds to the evolving landscape of pervasive technology and the inadequacy of legacy security models.  It aims to equip security professionals with the knowledge necessary to develop and implement a zero trust strategy.

Submitted by Adam Ekwall on

"British Library: Ransomware Recovery Could Take Months"

"British Library: Ransomware Recovery Could Take Months"

One of the world’s largest libraries has recently confirmed it was hit by a ransomware attack on October 28 and that it will take weeks or possibly months to fully recover.  The British Library noted that the breach impacted phone lines and on-site services at its main building in London and a separate facility in Yorkshire, as well as access to digital collections, its website, and its digital catalog.  The library stated that it was continuing to experience a major technology outage as a result of a cyberattack.

Submitted by Adam Ekwall on

"Royal Mail to Spend £10m on Ransomware Remediation"

"Royal Mail to Spend £10m on Ransomware Remediation"

Royal Mail has recently revealed a multimillion-pound cost attached to a serious ransomware breach it suffered earlier this year.  The British postal service company was hit by a LockBit affiliate in an incident which caused “severe service disruption” for items sent abroad.  The ransomware group was demanding nearly $80m from the firm to prevent it from leaking its stolen data.  Although Royal Mail refused to pay, in line with law enforcement advice, the operational costs associated with the incident are starting to emerge.

Submitted by Adam Ekwall on

"Unpatched Critical Vulnerabilities Open AI Models to Takeover"

"Unpatched Critical Vulnerabilities Open AI Models to Takeover"

Researchers discovered nearly a dozen critical vulnerabilities in the infrastructure used by Artificial Intelligence (AI) models, along with three high- and two medium-severity bugs, which could put companies at risk as they rush to capitalize on AI. The affected platforms host, deploy, and share Large Language Models (LLMs), as well as other Machine Learning (ML) platforms and AIs. They include Ray, MLflow, ModelDB, and H20 version 3. Protect AI, an ML security company, revealed the findings on November 16 as part of its AI-specific bug bounty program.

Submitted by Gregory Rigby on

"Virginia Tech Opens World’s First Fully Automated AI and Cyberbiosecurity Water Lab"

"Virginia Tech Opens World’s First Fully Automated AI and Cyberbiosecurity Water Lab"

The Artificial Intelligence (AI) and Cyber for Water and Agriculture (ACWA) lab at Virginia Tech is the world's first to combine cyberbiosecurity and AI automation to research water security. The multidisciplinary lab, led by a team of AI experts, seeks to protect the world's water resources from cyberattacks such as the one faced by a water treatment facility in Oldsmar, Florida, in 2021. During the attack, a sensor that measures the amount of sodium hydroxide in the water was compromised.

Submitted by Gregory Rigby on

"Children’s Tablet Has Malware and Exposes Kid’s Data, Researcher Finds"

"Children’s Tablet Has Malware and Exposes Kid’s Data, Researcher Finds"

Alexis Hancock, who works at the Electronic Frontier Foundation (EFF), discovered that the Dragon Touch KidzPad Y88X, a children's tablet, had security and privacy flaws that could have risked her daughter's and other children's data. According to Hancock, the tablet contains traces of well-known malware, runs a version of Android released five years ago, arrives pre-loaded with other software considered malware, and more. This article continues to discuss findings from the researcher's analysis of the Dragon Touch tablet and responses to her discovery. 

Submitted by Gregory Rigby on

"Google To Distribute 100,000 Titan Security Keys to High-Risk Users"

"Google To Distribute 100,000 Titan Security Keys to High-Risk Users"

Google is distributing 100,000 more free pieces of security hardware to people in high-risk industries. Google's Titan Security Keys are a "second factor" that can be used after entering passwords. During the Aspen Cyber Summit in New York City, Google rolled out the product and announced plans to distribute 100,000 keys for free to people working in governments worldwide, especially those involved in election administration.

Submitted by Gregory Rigby on

"Toyota Financial Services Attack Claimed by Medusa Ransomware"

"Toyota Financial Services Attack Claimed by Medusa Ransomware"

The Medusa ransomware gang claims to have been behind the disruptive cyberattack against Toyota Financial Services (TFS), the Japanese automakers' vehicle financing and leasing subsidiary. Although the company did not specify the nature of the attack, TFS was most likely hit with ransomware because it was listed on the Medusa ransomware gang's dark web website, where the group lists its latest victims.

Submitted by Gregory Rigby on

"9M Health Records Spilled by Transcription Firm"

"9M Health Records Spilled by Transcription Firm"

A cyberattack on the medical transcription service provider Perry Johnson & Associates (PJ&A) compromised the personal and health information of 9 million Americans. The attack, which has yet to be linked to a specific threat actor, was the second-largest breach of health-related data in the US this year. In July, HCA Healthcare reported a breach involving the theft of 11 million patient records.

Submitted by Gregory Rigby on
Subscribe to