Taiwan Hit by Sophisticated Phishing Campaign Information Security Magazine 3 months 2 weeks ago Phishing campaign targeting Taiwan has been identified, using tax-themed emails and malware like Winos and HoldingHands
Chained Flaws in Enterprise CMS Provider Sitecore Could Allow Remote Code Execution Information Security Magazine 3 months 2 weeks ago WatchTowr has found three vulnerabilities in the Sitecore Experience Platform, used by HSBC and L’Oréal
Microsoft Promises to Keep European Cloud Data in Europe Information Security Magazine 3 months 2 weeks ago Microsoft’s Sovereign Cloud solutions are designed to ensure European cloud data is stored and processed in Europe
Brits Lose £106m to Romance Fraud in a Year Information Security Magazine 3 months 2 weeks ago New City of London Police data reveals British men and women lost over £100m to romance fraudsters in 2024
Threat Actors Target Victims with HijackLoader and DeerStealer Information Security Magazine 3 months 2 weeks ago Cyber-attacks using HijackLoader and DeerStealer have been identified exploiting phishing tactics via ClickFix
Archetyp Market Shut Down in Europe-wide Law Enforcement Operation Information Security Magazine 3 months 2 weeks ago Operation DEEP Sentinel has shut down Archetyp Market, the longest-running dark web drug marketplace
Tenable Fixes Three High-Severity Flaws in Vulnerability Scanner Nessus Information Security Magazine 3 months 2 weeks ago Nessus users should update patches as soon as possible
Anubis Ransomware Adds File-Wiping Capability Information Security Magazine 3 months 2 weeks ago Trend Micro identified a novel “wipe mode” included in Anubis ransomware to prevent file recovery, increasing pressure on victims to give in to demands
Over a Third of Grafana Instances Exposed to XSS Flaw Information Security Magazine 3 months 2 weeks ago Some 36% of Grafana instances are vulnerable to account takeover bug, putting DevOps teams at risk
WestJet Investigates Cyber-Attack Impacting Customers Information Security Magazine 3 months 2 weeks ago Canadian airline WestJet is investigating a cyber-attack that struck on June 13
Former CISA and NCSC Heads Warn Against Glamorizing Threat Actor Names Information Security Magazine 3 months 2 weeks ago Jen Easterly and Ciaran Martin called for a universal, vendor-neutral cyber threat actor naming system
European Journalists Targeted by Paragon Spyware, Citizen Lab Confirms Information Security Magazine 3 months 2 weeks ago This is the first forensic evidence that journalists’ devices have been infected with Paragon’s Graphite spyware
Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility Billing Firm Information Security Magazine 3 months 2 weeks ago A CISA advisory urged all software vendors and downstream customers to check if they are impacted by unpatched versions of the SimpleHelp RMM tool
Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft Information Security Magazine 3 months 2 weeks ago Researchers have found a flaw in Microsoft 365 Copilot that allows the exfiltration of sensitive corporate data with a simple email
Palo Alto Networks Patches Series of Vulnerabilities Information Security Magazine 3 months 3 weeks ago The cybersecurity provider also implemented recent fixes in Chromium that affected its Prisma Access Browser
NIST Publishes New Zero Trust Implementation Guidance Information Security Magazine 3 months 3 weeks ago The new NIST guidance sets out 19 example implementations of zero trust using commercial, off-the-shelf technologies
Europol Says Criminal Demand for Data is “Skyrocketing” Information Security Magazine 3 months 3 weeks ago Europol warns of “vicious circle” of data breaches and cybercrime
Phishing Alert as Erie Insurance Reveals Cyber “Event” Information Security Magazine 3 months 3 weeks ago Erie Insurance reveals suspected network breach and ongoing outage
Congress Introduces Bill to Strengthen Healthcare Cybersecurity Information Security Magazine 3 months 3 weeks ago The legislation aims to expand the federal government’s role in helping healthcare providers protect and respond to cyber-attacks
20,000 Asian IPs and Domains Dismantled in Infostealer Crackdown Information Security Magazine 3 months 3 weeks ago Interpol-coordinated Operation Secure led to 32 arrests, including the suspected ringleader of a cybercriminal organization