Menu

Monthly Archives: December 2023

https://security-tracker.debian.org/tracker/DSA-5592-1

CEO arranged his own cybersecurity, with predictable results

https://security-tracker.debian.org/tracker/DSA-5589-1

A tale of 2 casino ransomware attacks: One paid out, one did not
Kaspersky reveals previously unknown hardware ‘feature’ used in iPhone attacks

https://security-tracker.debian.org/tracker/DSA-5591-1

https://security-tracker.debian.org/tracker/DSA-5590-1

How software engineering will evolve in 2024
You should be worried about cloud squatting

https://security-tracker.debian.org/tracker/DSA-5588-1

Key findings from ESET Threat Report H2 2023 – Week in security with Tony Anscombe

How cybercriminals take advantage of the popularity of ChatGPT and other tools of its ilk to direct people to sketchy sites, plus other interesting findings from ESET’s latest Threat Report

Iranian cyberspies target US defense orgs with a brand new backdoor

https://security-tracker.debian.org/tracker/DSA-5587-1

https://security-tracker.debian.org/tracker/DSA-5585-1

https://security-tracker.debian.org/tracker/DSA-5584-1

https://security-tracker.debian.org/tracker/DSA-5583-1

https://security-tracker.debian.org/tracker/DSA-5582-1

Safeguard the joy: 10 tips for securing your shiny new device

Unwrapping a new gadget this holiday season will put a big smile on your face but things may quickly turn sour if the device and data on it aren’t secured properly

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

https://security-tracker.debian.org/tracker/DSA-5586-1

Lapsus$ teen sentenced to indefinite detention in hospital after Nvidia, GTA cyberattacks

https://security-tracker.debian.org/tracker/DSA-5581-1

Four in five Apache Struts 2 downloads are for versions featuring critical flaw
Mozilla decides Trusted Types is a worthy security feature
Data loss prevention isn’t rocket science, but NASA hasn’t made it work in Microsoft 365
Smashing Security podcast #353: Phone hacking, Piers Morgan, and Carole’s Christmas cockup
Something nasty injected login-stealing JavaScript into 50K online banking sessions
Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials
ALPHV/BlackCat ransomware operation disrupted, but criminals threaten more attacks
Manchester’s finest drowning in paperwork as Freedom of Information requests pile up
SSH shaken, not stirred by Terrapin vulnerability
Philippines, South Korea, Interpol cuff 3,500 suspected cyber scammers, seize $300M
Millions of Xfinity customers’ info, hashed passwords feared stolen in cyberattack

https://security-tracker.debian.org/tracker/DSA-5580-1

Before you go away for Xmas: You’ve patched that critical Perforce Server hole, right?
AlphV/BlackCat hits back as Feds offer decryptor to ransomware victims
Sharing stories on the CyberTuesday podcast
Qakbot’s backbot: FBI-led takedown keeps crims at bay for just 3 months
Hacktivists boast: We shut down Iran’s gas pumps today
Mr Cooper cyberattack laid bare: 14.7M people’s info stolen, costs hit $25M

https://security-tracker.debian.org/tracker/DSA-5579-1

Cyber-crooks slip into Vans, trample over operations
National Grid latest UK org to zap Chinese kit from critical infrastructure
3 ways to reduce stress on the DevSecOps team
MongoDB warns breach of internal systems exposed customer contact info
Pro-China campaign targeted YouTube with AI avatars
New iOS feature to thwart eavesdropping – Week in security with Tony Anscombe

Your iPhone has just received a new feature called iMessage Contact Key Verification that is designed to help protect your messages from prying eyes

https://security-tracker.debian.org/tracker/DSA-5576-2

https://security-tracker.debian.org/tracker/DSA-5578-1

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned
Kraft Heinz suggests we simmer down about Snatch ransomware attack claims
Gang charged with running $80 million “pig butchering” cryptocurrency investment scam
NKabuse backdoor harnesses blockchain brawn to hit several architectures
InfoWorld’s 2023 Technology of the Year Award winners
To BCC or not to BCC – that is the question data watchdog wants answered
Microsoft seizes websites used to sell phony email accounts to Scattered Spider and other crims

https://security-tracker.debian.org/tracker/DSA-5577-1

Prison for man who wiped bank’s data after being fired for accessing porn in the office
Smashing Security podcast #352: For research purposes only
Hackers exploit Google Forms to trick users into falling for call-back phishing attack
Russia joins North Korea in sending state-sponsored cyber troops to pick on TeamCity users
Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes
Fortifying confidential computing in Microsoft Azure
Surprise! Email from personal. information.reveal@gmail.com is not going to contain good news
The SANS Holiday Hack Challenge is back!
UK’s Ministry of Defence fined after Bcc email blinder that put the lives of Afghan citizens at risk
Black Hat Europe 2023: Should we regulate AI?

ChatGPT would probably say “Definitely not!”, but will we learn any lessons from the rush to regulate IoT in the past?

Learning the safety language of the cloud
Nearly a million non-profit donors’ details left exposed in unsecured database
Cyber security isn’t simple, but it could be
Think tank report labels NSO, Lazarus as ‘cyber mercenaries’
Final Patch Tuesday of 2023 goes out with a bang

https://security-tracker.debian.org/tracker/DSA-5576-1

https://security-tracker.debian.org/tracker/DSA-5575-1

https://security-tracker.debian.org/tracker/DSA-5574-1

Cloud engineer wreaks havoc on bank network after getting fired
Discord in the ranks: Lone Airman behind top-secret info leak on chat platform
Kelvin Security cybercrime gang suspect seized by Spanish police
Northern Ireland cops count human cost of August data breach
BlackBerry squashes plan to spin out its IoT biz
Interpol moves against human traffickers who enslave people to scam you online
Proposed US surveillance regime would enlist more businesses
2.5M patients infected with data loss in Norton Healthcare ransomware outbreak
Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware
Two years on, 1 in 4 apps still vulnerable to Log4Shell
Read the clouds, reduce the cyber risk
23andMe responds to breach with new suit-limiting user terms
VictoriaMetrics takes organic growth over investor pressure
Surge in deceptive loan apps – Week in security with Tony Anscombe

ESET Research reveals details about a growth in the number of deceptive loan apps on Android, their origins and modus operandi

Black Hat Europe 2023: The past could return to haunt you

Legacy protocols in the healthcare industry present dangers that can make hospitals extremely vulnerable to cyberattacks.

To tap or not to tap: Are NFC payments safer?

Contactless payments are quickly becoming ubiquitous – but are they more secure than traditional payment methods?

Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky

https://security-tracker.debian.org/tracker/DSA-5573-1

Competing Section 702 surveillance bills on collision path for US House floor
Meta releases open-source tools for AI safety
That call center tech scammer could be a human trafficking victim
UK and US expose Russian hacking plot intended to influence UK’s 2019 elections and spread disinformation
Zero trust security with a hardware root of trust
Polish train maker denies claims its software bricked rolling stock maintained by competitor
Five Eyes nations warn Moscow’s mates at the Star Blizzard gang have new phishing targets