Menu

Monthly Archives: November 2023

FBI Director: FISA Section 702 warrant requirement a ‘de facto ban’
How cyber training can help you beat the bad guys
Ransomware more efficient than ever, and baddies are still after your logs
Another month, another bunch of fixes for Microsoft security bugs exploited in the wild
Russian national pleads guilty to building now-dismantled IPStorm proxy botnet

security update

security update

AMD SEV OMG: Trusted execution undone by cache meddling
Intel out-of-band patch addresses privilege escalation flaw
Ransomware royale: US confirms Royal, BlackSuit are linked
Novel backdoor persists even after critical Confluence vulnerability is patched
6 security best practices for cloud-native applications
Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain
NCSC says cyber-readiness of UK’s critical infrastructure isn’t up to scratch
Beijing reportedly asked Hikvision to identify fasting students in Muslim-majority province
Passive SSH server private key compromise is real … for some vulnerable gear
Google sues scammers peddling fake malware-riddled Bard chatbot download

security update

Inside Denmark’s hell week as critical infrastructure orgs faced cyberattacks
Introducing the tech that keeps the lights on
When traditional AV solutions are not enough
Security, privacy, and generative AI
Royal Mail cybersecurity still a bit of a mess, infosec bods claim
Australia declares ‘nationally significant cyber incident’ after port attack
Spyware disguised as a news app – Week in security with Tony Anscombe

The Urdu version of the Hunza News website offers readers the option to download an Android app – little do they know that the app is actually spyware

Cyber threat intelligence: Getting on the front foot against adversaries

By collecting, analyzing and contextualizing information about possible cyberthreats, including the most advanced ones, threat intelligence offers a critical method to identify, assess and mitigate cyber risk

Unlucky Kamran: Android malware spying on Urdu-speaking residents of Gilgit-Baltistan

ESET researchers discovered Kamran, previously unknown malware, which spies on Urdu-speaking readers of Hunza News

Impatient LockBit says it’s leaked 50GB of stolen Boeing files after ransom fails to land
Poloniex crypto-exchange offers 5% cut to thieves if they return that $120M they nicked
Strangely enough, no one wants to buy a ransomware group that has cops’ attention
World’s biggest bank hit by ransomware, forced to trade via USB stick
CherryBlos, the malware that steals cryptocurrency via your photos – what you need to know
China’s top bank ICBC hit by ransomware, derailing global trades
Downfall fallout: Intel knew AVX chips were insecure and did nothing, lawsuit claims

security update

Oracle open-sources Jipher for FIPS-compliant SSL
SolarWinds: SEC ‘lacks the competence’ to regulate cybersecurity
MOVEit cybercriminals unearth fresh zero-day to exploit on-prem SysAid hosts
Russia’s Sandworm – not just missile strikes – to blame for Ukrainian power blackouts
What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh
Smashing Security podcast #347: Trolls, military data, and the hitman and her

security update

Women sue plastic surgery after hack saw their naked photos posted online
Microsoft, Meta detail plans to fight election disinformation in 2024
Microsoft .NET 8 enhances ID management
Atlassian cranks up the threat meter to max for Confluence authorization flaw
Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach
Making iPhones and iPads crash with a Flipper Zero
Cancer treatments cancelled after Canadian hospitals hit by ransomware attack
Preventing data theft with ADX technology
Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button
UK may demand tech world tell it about upcoming security features
Fresh find shines new light on North Korea’s latest macOS malware
Google hopes to better fight malicious apps with real-time scanning on Android devices
Woman jailed after Rentahitman.com assassin turned out to be – surprise – FBI
ICE faces heat after agents install thousands of personal apps, VPNs on official phones

security update

security update

US slaps sanctions on accused fave go-to money launderer of Russia’s rich
Okta breach affected 134 orgs, ‘or less than 1%’ of customers, company admits
Securing frontline Operational Technology environments
KubeCon points to the future of enterprise IT
Is ChatGPT writing your code? Watch out for malware

security update

The mysterious demise of the Mozi botnet – Week in security with Tony Anscombe

Various questions linger following the botnet’s sudden and deliberate demise, including: who actually initiated it?

Who killed Mozi? Finally putting the IoT zombie botnet in its grave

How ESET Research found a kill switch that had been used to take down one of the most prolific botnets out there

‘Corrupt’ cop jailed for tipping off pal to EncroChat dragnet

security update

security update

81K people’s sensitive info feared stolen from Hilb after email inboxes ransacked
Ex-GCHQ software dev jailed for stabbing NSA staffer
Microsoft pins hopes on AI once again – this time to patch up Swiss cheese security
UK data watchdog fines three text spammers for flouting electronic marketing rules
FTX crypto-villain Sam Bankman-Fried convicted on all charges
Feds collar suspected sanctions-busting Russian smugglers of US tech
Infosec pros can secure IT, but have harder time securing job satisfaction
Critical Apache ActiveMQ flaw under attack by ‘clumsy’ ransomware crims
Okta tells 5,000 of its own staff that their data was accessed in third-party breach
The state of API security in 2023
Boeing acknowledges cyberattack on parts and distribution biz
FBI boss: Taking away our Section 702 spying powers could be ‘devastating’
Smashing Security podcast #346: How hackers are breaching Booking.com, and the untrustworthy reviews
Ransomware crooks SIM swap medical research biz exec, threaten to leak stolen data

security update

security update

Mozi botnet murder mystery: China or criminal operators behind the kill switch?
Splunk cuts 7% of workforce ahead of Cisco acquisition
Critical vulnerability in F5 BIG-IP under active exploitation
Cybercrooks amp up attacks via macro-enabled XLL files
Get your very own ransomware empire on the cheap, while stocks last
Meeting the challenge of OT security
Indian politicians say Apple warned them of state-sponsored attacks