"SwRI Evaluates Cybersecurity Risks Associated With EV Fast-Charging Equipment"

"SwRI Evaluates Cybersecurity Risks Associated With EV Fast-Charging Equipment"

Southwest Research Institute (SwRI) engineers have identified cybersecurity vulnerabilities with Electric Vehicles (EVs) using direct current fast-charging systems. The technology uses Power Line Communication (PLC) to transmit smart-grid data between vehicles and charging equipment. SwRI exploited PLC layer vulnerabilities to gain access to network keys and digital addresses on the charger and the vehicle.

Submitted by grigby1 CPVI on

"Life Sciences Sector Turns to AI to Bridge Cybersecurity Skills Gap"

"Life Sciences Sector Turns to AI to Bridge Cybersecurity Skills Gap"

A new survey by Code42 found that 73 percent of life sciences companies are using Artificial Intelligence (AI) to fill the cybersecurity skills gap. According to Code42, the life sciences sector is at the forefront of AI use, with AI tools allowing cybersecurity teams to automate detection and response as well as free up resources for strategic tasks. However, AI use has drawbacks, as 86 percent of cybersecurity leaders say it puts their company at risk of data exfiltration.

Submitted by grigby1 CPVI on

"Safety Equipment Giant Cadre Holdings Hit by Cyberattack"

"Safety Equipment Giant Cadre Holdings Hit by Cyberattack"

Florida-based safety equipment giant Cadre Holdings recently disclosed a cyberattack that has impacted some of the company’s operations.  The company provides safety and survivability products for first responders, federal agencies, outdoor recreation, and personal protection in over 100 countries.  Its products include body armor, bomb squad equipment, duty gear, and nuclear safety solutions.

Submitted by Adam Ekwall on

"Prolific DDoS Marketplace Shut Down by UK Law Enforcement"

"Prolific DDoS Marketplace Shut Down by UK Law Enforcement"

UK law enforcement agencies recently infiltrated and took down DigitalStress, the world's most prolific underground marketplace offering distributed denial of service(DDoS) services.  The National Crime Agency (NCA) said that it had taken over and disabled DigitallStress on July 2 in collaboration with the Police Service of Northern Ireland (PSNI).  The NCA noted that DigitalStress was a marketplace offering DDoS-for-hire or "booter" services.  These services allow users to create accounts and order DDoS attacks within minutes.

Submitted by Adam Ekwall on

"UK Arrests Suspected Scattered Spider Hacker Linked to MGM Attack"

"UK Arrests Suspected Scattered Spider Hacker Linked to MGM Attack"

UK police have recently arrested a 17-year-old boy suspected of being involved in the 2023 MGM Resorts ransomware attack and a member of the Scattered Spider hacking collective. Officers from the Regional Organised Crime Unit for the West Midlands (ROCUWM) joined officers from the National Crime Agency, in coordination with the United States Federal Bureau of Investigation (FBI), to make the arrest.  The authorities have seized the suspect's digital devices, which will be investigated for further evidence.

Submitted by Adam Ekwall on

"Two Members of LockBit Ransomware Group Plead Guilty in US Court"

"Two Members of LockBit Ransomware Group Plead Guilty in US Court"

Two members of the infamous LockBit gang recently pleaded guilty in court in the United States over their roles in deploying ransomware against organizations in the US and worldwide.  In early May, the US announced charges against Dimitry Yuryevich Khoroshev, 31, of Voronezh, Russia, also known as LockBitSupp, LockBit, and putinkrab, allegedly the mastermind behind the RaaS.  The US government is offering a reward of $10 million for information on Khoroshev, who is estimated to have made over $100 million from the LockBit operation.

Submitted by Adam Ekwall on

"California Officials Say Largest Trial Court in US Victim of Ransomware Attack"

"California Officials Say Largest Trial Court in US Victim of Ransomware Attack"

Officials with the Superior Court of Los Angeles County have announced that a ransomware attack has shut down the computer system of the largest trial court in the country.  The officials noted that the cyberattack began early Friday and is not believed to be related to the faulty CrowdStrike software update.  The court disabled its computer network systems upon discovery of the attack.  According to the officials, a preliminary investigation shows no evidence that users’ data was compromised.

Submitted by Adam Ekwall on

"Ransomware Recovery in Energy, Water Sectors Hits $3M, Quadrupling in One Year"

"Ransomware Recovery in Energy, Water Sectors Hits $3M, Quadrupling in One Year"

According to Sophos, the energy and water infrastructure sectors' median ransomware recovery cost has quadrupled to $3 million in a year. Sophos surveyed 5,000 cybersecurity and Information Technology (IT) leaders in 15 industries and 14 countries. Ransomware attacks were second-highest in the energy and water sectors in 2024, with 67 percent of organizations reporting ransom demands, compared to 59 percent across all sectors. This article continues to discuss findings regarding ransomware recovery in the energy and water sectors.

Submitted by grigby1 CPVI on

"HotPage Adware Disguised as Ad Blocker Installs Malicious Kernel Driver"

"HotPage Adware Disguised as Ad Blocker Installs Malicious Kernel Driver"

ESET researchers discovered an adware module that appears to block ads and malicious websites but stealthily offloads a kernel driver component that lets attackers run arbitrary code with elevated permissions on Windows hosts. The malware's name, "HotPage," stems from the installer "HotPage.exe." According to ESET researcher Romain Dumont, the installer launches a driver that injects code into remote processes and two libraries that can intercept and tamper with browsers' network traffic. This article continues to discuss findings regarding the HotPage malware.

Submitted by grigby1 CPVI on
Subscribe to