PyPI Revival Hijack Puts Thousands of Applications at Risk(link is external) Information Security Magazine 8 months ago Revival Hijack Python Package Index supply chain attack threatens 22,000 packages through malicious downloads
Security Budgets Come Under Pressure as “Hypergrowth” Ends(link is external) Information Security Magazine 8 months ago Despite rising threats researchers find a third of firms see flat or falling security budgets and hiring slows
UK Signs Council of Europe AI Convention(link is external) Information Security Magazine 8 months ago The first legally binding international treaty on AI was adopted by all 46 Council of Europe member states in May 2024
Cisco Warns of Critical Vulnerabilities in Smart Licensing Utility(link is external) Information Security Magazine 8 months ago Cisco has urged customers to apply software updates to fix the critical vulnerabilities, which could allow attackers to collect sensitive data or administer services
Researcher Finds Unfixable Yet Tricky to Exploit Flaw in Yubikeys(link is external) Information Security Magazine 8 months ago A security flaw exploiting side channel attacks means some Yubikeys can be cloned
OnlyFans Hackers Targeted With Infostealer Malware(link is external) Information Security Magazine 8 months ago Hackers interested in targeting OnlyFans users have themselves been singled out by an infostealing campaign
Russian Blamed For Mass Disinformation Campaign Ahead of US Election(link is external) Information Security Magazine 8 months ago The DoJ says Russia paid a US company $10m to post disinformation that attracted millions of views online
US Government Set Out to Improve Internet Routing Security(link is external) Information Security Magazine 8 months ago The US White House Office of the National Cyber Director proposes improving internet security by protecting the Border Gateway Protocol
North Korea Targeting Crypto Industry, Says FBI(link is external) Information Security Magazine 8 months ago US law enforcement is tracking aggressive social engineering attacks against cryptocurrency operations
Red Teaming Tool Abused for Malware Deployment(link is external) Information Security Magazine 8 months ago Cisco Talos has assessed that red teaming tool MacroPack is being abused by various threat actors in different geographies to deploy malware
Clearview AI Fined €30.5m by Dutch Watchdog Over Illegal Data Collection(link is external) Information Security Magazine 8 months ago The US-based facial recognition data company may even have to pay up to €5.1m in penalties for non-compliance
Initial Access Brokers Target $2bn Revenue Companies(link is external) Information Security Magazine 8 months ago Cyberint claims that initial access brokers target companies with average revenue of nearly $2bn
APP Fraud Dominates as Scams Hit All-Time High(link is external) Information Security Magazine 8 months ago UK’s Financial Ombudsman warns fraud and scams hit a record high in Q2 2024
Civil Rights Groups Call For Spyware Controls(link is external) Information Security Magazine 8 months ago Civil society and journalists’ organizations in Europe ask the EU to take steps to regulate spyware technologies
Rapid Growth of Password Reset Attacks Boosts Fraud and Account Takeovers(link is external) Information Security Magazine 8 months ago Researchers say password reset attacks have grown fourfold in the last year and one in four password reset attempts are fraudulent
Active Ransomware Groups Surge by 56% in 2024(link is external) Information Security Magazine 8 months 1 week ago Searchlight Cyber observed a 56% rise in active ransomware groups in H1 2024, demonstrating the growing fragmentation of the ransomware landscape
Palo Alto's GlobalProtect VPN Spoofed to Deliver New Malware Variant(link is external) Information Security Magazine 8 months 1 week ago A variant of the WikiLoader malware was observed being delivered via SEO poisoning and spoofing Palo Alto Networks’ GlobalProtect VPN software
Three Plead Guilty to Running MFA Bypass Site(link is external) Information Security Magazine 8 months 1 week ago Three British men are facing jail after pleading guilty to running an MFA bypass site dubbed “OTP Agency”
TfL Claims Cyber-Incident is Not Impacting Services(link is external) Information Security Magazine 8 months 1 week ago London’s transport body, TfL, is playing down the impact of a cybersecurity incident on its services
Irish Wildlife Park Warns Customers to Cancel Credit Cards Following Breach(link is external) Information Security Magazine 8 months 1 week ago Fota Wildlife Park in Co Cork has told visitors to its website to cancel credit and debit cards, following a cyber-attack