Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-5566-1

https://security-tracker.debian.org/tracker/DSA-5564-1

https://security-tracker.debian.org/tracker/DSA-5563-1

https://security-tracker.debian.org/tracker/DSA-5565-1

Telekopye: Chamber of Neanderthals’ secrets

Insight into groups operating Telekopye bots that scam people in online marketplaces

OpenCart owner turns air blue after researcher discloses serious vuln
Cloud security and devops have work to do
$9 million seized from “pig butchering” scammers who preyed on lonely hearts
BlackCat claims it is behind Fidelity National Financial ransomware shakedown
Your voice is my password

AI-driven voice cloning can make things far too easy for scammers – I know because I’ve tested it so that you don’t have to learn about the risks the hard way.

Industry piles in on North Korea for sustained rampage on software supply chains
Smashing Security podcast #349: Ransomware gang reports its own crime, and what happened at OpenAI?
Attack on direct debit provider London & Zurich leaves customers with 6-figure backlogs
Hackers pose as officials to steal secrets and cryptocurrency for North Korea
Stop social engineering at the IT help desk
Mirai we go again: Zero-day flaws see routers and cameras co-opted into botnet
New Relic warns customers it’s experienced a cyber … something
North Korea makes finding a gig even harder by attacking candidates and employers
How to give Windows Hello the finger and login as someone on their stolen laptop
US nuke reactor lab hit by ‘gay furry hackers’ demanding cat-human mutants
Fuel for thought: Can a driverless car get arrested?

What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?

US cybercops take on ‘pig butchering’ org, return $9M in scammed crypto
Microsoft’s bug bounty turns 10. Are these kinds of rewards making code more secure?
UK’s cookie crumble: Data watchdog serves up tougher recipe for consent banners
Binance and CEO admit financial crimes, billions coughed up to US govt

https://security-tracker.debian.org/tracker/DSA-5561-1

https://security-tracker.debian.org/tracker/DSA-5562-1

https://security-tracker.debian.org/tracker/DSA-5560-1

Sumo Logic wrestles with security breach, pins down customer data
The XBOM vs SBOM debate
Third-party data breach affecting Canadian government could involve data from 1999
Maintaining a state of readiness to deal with cyber attacks
MOVEit victim count latest: 2.6K+ orgs hit, 77M+ people’s data stolen

https://security-tracker.debian.org/tracker/DSA-5559-1

Former infosec COO pleads guilty to attacking hospitals to drum up business
Rhysida ransomware gang: We attacked the British Library
Your password hygiene remains atrocious, says NordPass
Safeguarding ports from the rising tide of cyberthreats – Week in security with Tony Anscombe

An attack against a port operator that ultimately hobbled some 40 percent of Australia’s import and export capacity highlights the kinds of supply chain shocks that a successful cyberattack can cause

https://security-tracker.debian.org/tracker/DSA-5558-1

https://security-tracker.debian.org/tracker/DSA-5556-1

https://security-tracker.debian.org/tracker/DSA-5555-1

https://security-tracker.debian.org/tracker/DSA-5554-1

https://security-tracker.debian.org/tracker/DSA-5553-1

https://security-tracker.debian.org/tracker/DSA-5552-1

https://security-tracker.debian.org/tracker/DSA-5551-1

https://security-tracker.debian.org/tracker/DSA-5550-1

https://security-tracker.debian.org/tracker/DSA-5549-1

https://security-tracker.debian.org/tracker/DSA-5548-1

LockBit redraws negotiation tactics after affiliates fail to squeeze victims
SonicWall swallows Solutions Granted amid cybersecurity demand surge
Samsung UK discloses year-long breach, leaked customer data
Look out, Scattered Spider. FBI pumps ‘significant’ resources into snaring data-theft crew

https://security-tracker.debian.org/tracker/DSA-5557-1

How much to clean up a ransomware infection? For Rackspace, about $11M

security update

Windows Server 2022 update gave ESXi host VMs the blue screen blues
BlackCat plays with malvertising traps to lure corporate victims
Royal Mail’s recovery from ransomware attack will cost business at least $12M
Hundreds of websites cloned to run ads for Chinese football gambling outfits
Clorox CISO flushes self after multimillion-dollar cyberattack
Smashing Security podcast #348: Hacking for chimp change, and AI chatbot birthday
Google Workspace weaknesses allow plaintext password theft
FBI Director: FISA Section 702 warrant requirement a ‘de facto ban’
How cyber training can help you beat the bad guys
Ransomware more efficient than ever, and baddies are still after your logs
Another month, another bunch of fixes for Microsoft security bugs exploited in the wild
Russian national pleads guilty to building now-dismantled IPStorm proxy botnet

security update

security update

AMD SEV OMG: Trusted execution undone by cache meddling
Intel out-of-band patch addresses privilege escalation flaw
Ransomware royale: US confirms Royal, BlackSuit are linked
Novel backdoor persists even after critical Confluence vulnerability is patched
6 security best practices for cloud-native applications
Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain
NCSC says cyber-readiness of UK’s critical infrastructure isn’t up to scratch
Beijing reportedly asked Hikvision to identify fasting students in Muslim-majority province
Passive SSH server private key compromise is real … for some vulnerable gear
Google sues scammers peddling fake malware-riddled Bard chatbot download

security update

Inside Denmark’s hell week as critical infrastructure orgs faced cyberattacks
Introducing the tech that keeps the lights on
When traditional AV solutions are not enough
Security, privacy, and generative AI
Royal Mail cybersecurity still a bit of a mess, infosec bods claim
Australia declares ‘nationally significant cyber incident’ after port attack
Spyware disguised as a news app – Week in security with Tony Anscombe

The Urdu version of the Hunza News website offers readers the option to download an Android app – little do they know that the app is actually spyware

Cyber threat intelligence: Getting on the front foot against adversaries

By collecting, analyzing and contextualizing information about possible cyberthreats, including the most advanced ones, threat intelligence offers a critical method to identify, assess and mitigate cyber risk

Unlucky Kamran: Android malware spying on Urdu-speaking residents of Gilgit-Baltistan

ESET researchers discovered Kamran, previously unknown malware, which spies on Urdu-speaking readers of Hunza News

Impatient LockBit says it’s leaked 50GB of stolen Boeing files after ransom fails to land
Poloniex crypto-exchange offers 5% cut to thieves if they return that $120M they nicked
Strangely enough, no one wants to buy a ransomware group that has cops’ attention
World’s biggest bank hit by ransomware, forced to trade via USB stick
CherryBlos, the malware that steals cryptocurrency via your photos – what you need to know
China’s top bank ICBC hit by ransomware, derailing global trades
Downfall fallout: Intel knew AVX chips were insecure and did nothing, lawsuit claims

security update

Oracle open-sources Jipher for FIPS-compliant SSL
SolarWinds: SEC ‘lacks the competence’ to regulate cybersecurity
MOVEit cybercriminals unearth fresh zero-day to exploit on-prem SysAid hosts