Commentaries and Analyses, Finance, Legal News, New Threats
March 30, 2024
917 views 3 mins 0

AI Poses a Threat to Financial Sector, and Cyberattackers are ‘Outpacing’ Defenses – Treasury

Law.com reports that the U.S. Treasury Department warned the financial services sector this week that artificial intelligence (AI) will become a powerful weapon for fraudsters and cyberattackers, who will outgun the sector’s defensive efforts in the foreseeable future.  The report was based on interviews with representatives from 42 financial services and technology companies about the […]

Consumer Alerts, Malware Ransomware, New Threats, News
February 15, 2024
482 views 51 secs 0

Cybercriminals are stealing Face ID scans to break into mobile banking accounts

The Register reports: Cybercriminals are targeting iOS users with malware that steals Face ID scans to break into and pilfer money from bank accounts – thought to be a world first. A Chinese-speaking cybercrime group, dubbed GoldFactory by Group-IB’s researchers, started distributing trojanized smartphone apps in June 2023, however, the latest GoldPickaxe version has been […]

Data Breach News, New Threats, Vulnerabilities
December 21, 2023
967 views 42 secs 0

Google fixes 8th Chrome zero-day exploited in attacks this year

Bleeping Computer reports: Google has released emergency updates to fix another Chrome zero-day vulnerability exploited in the wild, the eighth patched since the start of the year. “Google is aware that an exploit for CVE-2023-7024 exists in the wild,” a security advisory published Wednesday said. The company fixed the zero-day bug for users in the Stable Desktop […]

Data Breach News, New Threats, News, Vulnerabilities
December 05, 2023
851 views 16 secs 0

Russian state-sponsored hackers exploiting Outlook vulnerability, Microsoft warns

Cybernews reports: Microsoft is urging Outlook users to patch and update their systems to mitigate a new threat from Russia. Hackers associated with the Kremlin’s military intelligence agency GRU are exploiting the vulnerability to access victim’s emails. Microsoft warned that a nation-state actor tracked as Forest Blizzard is actively exploiting a vulnerability to provide secret, […]

Malware Ransomware, New Threats
September 29, 2023
793 views 42 secs 0

Two or More Ransomware Variants Impacting the Same Victims and Data Destruction Trends

SummaryThe Federal Bureau of Investigation (FBI) is releasing this Private Industry Notification tohighlight emerging ransomware trends and encourage organizations to implement therecommendations in the “Mitigations” section to reduce the likelihood and impact ofransomware incidents. ThreatAs of July 2023, the FBI noted two trends emerging across the ransomware environment and isreleasing this notification for industry awareness. […]

New Threats
September 26, 2023
805 views 10 secs 0

Is that blood drive message really from the American Red Cross? Be careful.

NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this finding through extensive research, they confirmed two new Trojan horse programs and many rare attack techniques and tactics. … AtlasCross designed a decoy document titled “Blood Drive September 2023.docm” with the United States […]

New Threats, Vulnerabilities
September 20, 2023
982 views 37 secs 0

Lazarus Group Exploits ManageEngine Vulnerability

HC3: Sector AlertTLP:CLEARReport: 202309181700 Executive Summary Cisco Talos has published an open-source report regarding the North Korean state-sponsored actor, the Lazarus Group, reported to be targeting internet backbone infrastructure and healthcare entities in Europe and the United States. The attackers have been exploiting a vulnerability in ManageEngine products, which is tracked as CVE-2022-47966. This vulnerability […]

New Threats
September 01, 2023
831 views 49 secs 0

Hackers use brute force and credential stuffing attacks on Cisco VPNs to breach networks

Hackers are targeting Cisco Adaptive Security Appliance (ASA) SSL VPNs in credential stuffing and brute-force attacks that take advantage of lapses in security defenses, such as not enforcing multi-factor authentication (MFA). Last week, BleepingComputer reported that the Akira ransomware gang was breaching Cisco VPNs for initial network access. Rapid7 security researchers have provided additional insights regarding these […]

News, New Threats
August 27, 2023
7192 views 7 mins 0

Etiology of a Breach

Most data breaches involve some level of victim human error, which theoretically employee training can address.  Human error can take the form of clicking on a link, where the email address of the sender is unknown to the person clicking on the link.  Malware then enters the scene.  Another common human error scenario involves phishing […]