Europol and Eurojust announced today the arrest of five individuals believed to be part of a massive online investment fraud ring with at least 33,000 victims who...
Month: April 2023
Russian hackers linked to widespread attacks targeting NATO and EU
Poland’s Military Counterintelligence Service and its Computer Emergency Response Team have linked APT29 state-sponsored hackers, part of the Russian government’s Foreign Intelligence Service (SVR), to widespread...
WhatsApp boosts defense against account takeover via malware
WhatsApp announced today the introduction of several new security features, one of them dubbed “Device Verification” and designed to provide better protection against account takeover (ATO)...
Legion: New hacktool steals credentials from misconfigured sites
A new Python-based credential harvester and SMTP hijacking tool named ‘Legion’ is being sold on Telegram that targets online email services for phishing and spam attacks....
Windows Admins Warned About a Critical MSMQ QueueJumper Vulnerability
Security researchers and experts warn Windows admins about a critical vulnerability discovered in the Windows Message Queuing (MSMQ) middleware service, that can expose hundreds of thousands...
Ransomware Attack Shuts Down KFC and Pizza Hut Brand Owner`s Restaurants (Update)
Yum! recently disclosed that employees` data were exfiltrated in the January 2023 cyberattack. On January 18th, Yum! Brands closed almost 300 of its restaurants in the...
Google Play threats on the dark web are big business
Android infections are also prevalent on the dark web, according to Kaspersky. Learn how to keep your workforce safe from these mobile and BYOD security threats....
Bypassing a Theft Threat Model
Thieves cut through the wall of a coffee shop to get to an Apple store, bypassing the alarms in the process. I wrote about this kind...
What are the cybersecurity concerns of SMBs by sector?
Some sectors have high confidence in their in-house cybersecurity expertise, while others prefer to enlist the support of an external provider to keep their systems and...
Former TSB chief information officer fined £81,000 over IT meltdown in 2018
UK regulators have imposed an £81,000 fine on a former TSB information officer over the bank’s IT meltdown in 2018 that left millions of customers locked...
GuLoader Targets US Financial Firms With Tax-Themed Phishing Lures
A malware loader known as GuLoader has been observed targeting the US financial sector using phishing emails with a tax-themed lure. Security researchers at eSentire shared...
Fortinet fixed a critical vulnerability in its Data Analytics product
Fortinet addressed a critical vulnerability that can lead to remote, unauthenticated access to Redis and MongoDB instances. Fortinet has addressed a critical vulnerability, tracked as CVE-2022-41331...
How to Combat Insider Threats
Knowing that insider threats are a risk is one thing. Knowing how to fight them off is entirely another. Dealing with issues of insider cyber risk...
Hyundai suffered a data breach that impacted customers in France and Italy
Hyundai disclosed a data breach that impacted Italian and French car owners and clients who booked a test drive. Hyundai has suffered a data breach that...
QuaDream surveillance firm’s spyware targeted iPhones with zero-click exploit
At least five members of civil society worldwide have been targeted with spyware and exploits developed by surveillance firm QuaDream. Citizen Lab researchers reported that at...
Smashing Security podcast #317: Another Uber SNAFU, an AI chatbot quiz, and is juice-jacking genuine?
Everyone’s talking juice-jacking – but has anyone ever been juice-jacked? Uber suffers yet another data breach, but it hasn’t been hacked. And Carole hosts the “AI-a-go-go...
Plenty of juice-jacking scare stories, but precious little juice-jacking
Travellers are being told to be wary when plugging their smartphones and laptops into USB chargers. On Thursday last week, the official Twitter account of the...
Google Tackles Open Source Security With New Dependency Service
In a bid to reduce software supply chain risks in the open source software ecosystem, Google launched a free API service providing dependency data and security-related...
Menlo Security Illustrates Importance of Browser Security as 4 in 5 Ransomware Attacks Include Threats Beyond Data Encryption
MOUNTAIN VIEW, Calif., April 11, 2023 – Menlo Security, a leader in browser security, today shared results from the CyberEdge Group’s 10th Annual Cyberthreat Defense Report (CDR). This year’s...
VulnCheck Named CVE Numbering Authority for Common Vulnerabilities and Exposures
LEXINGTON, Mass.–(BUSINESS WIRE)–VulnCheck, the vulnerability intelligence company, today announced it has been authorized by the CVE Program as a CVE Numbering Authority (CNA). The company also announced the launch of VulnCheck...
Report Reveals ChatGPT Already Involved in Data Leaks, Phishing Scams & Malware Infections
MIAMI, April 12, 2023 /PRNewswire/ — Network Assured has reported that data leaks, phishing scams and malware infections attributable to ChatGPT are on the rise. The report tracks the most...
(ISC)² Certified in Cybersecurity Earns ANAB Accreditation to ISO 17024 and Surpasses 15,000 Certification Holders
ALEXANDRIA, Va., April 12, 2023 /PRNewswire/ — (ISC)² – the world’s largest nonprofit association of certified cybersecurity professionals – today announced that the (ISC)² Certified in Cybersecurity℠ certification has received accreditation...
Lazarus Group’s ‘DeathNote’ Cluster Pivots to Defense Sector
An operation within North Korea’s notorious Lazarus Group that initially focused solely on coin-mining attacks has begun targeting defense sector organizations around the world. The DeathNote...
When Banking Laws Don’t Protect Consumers From Cybertheft
Banking laws designed to protect Federal Deposit Insurance Corp. (FDIC)-insured accounts contain loopholes that strip consumers of coverage against certain cyberattacks. Less than a month before...
Opera Adds Free VPN to Opera for iOS
OSLO, Norway , April 12, 2023 /PRNewswire/ — Opera (NASDAQ: OPRA) – the company behind the award-winning family of web browsers – is announcing the extension of its free browser...
FBI & FCC Warn on ‘Juice Jacking’ at Public Chargers, but What’s the Risk?
US government agencies are warning that malware planted in public charging stations for phones and other electronics can sneak onto your device when you least expect...
Survey Findings Show Link Between Data Silos and Security Vulnerabilities
What are the consequences of operating your business with risk and compliance data in silos? Turns out, it might be more impactful than you think. A...
HHS Wants HIPAA Changes to Protect Reproductive Health Info
Governance & Risk Management , Healthcare , HIPAA/HITECH Proposed Rule Would Prohibit Certain PHI Disclosures, Uses for Law Enforcement Marianne Kolbasuk McGee (HealthInfoSec) • April 12,...
Will Generative AI’s Use in Cyber Tools Exceed Expectations?
Artificial Intelligence & Machine Learning , Cloud Security , Next-Generation Technologies & Secure Development To What Extent Will Security Tools Benefit From Linking Arms With OpenAI’s...
MY TAKE: Putin’s weaponizing of ransomware shows why network security needs an overhaul
At 10 am PDT, next Wednesday, April 19th, I’ll have the privilege of appearing as a special guest panelist and spotlight speaker on Virtual Guardian’s monthly...




























