FreshRSS

πŸ”’
☐ β˜† βœ‡ Threatpost | The first stop for security news

Hackers for Hire: Adversaries Employ β€˜Cyber Mercenaries’

By Elizabeth Montalbano β€” July 21st 2022 at 12:59
Also known as the Atlantis Cyber-Army, the emerging organization has an enigmatic leader and a core set of admins that offer a range of services, including exclusive data leaks, DDoS and RDP.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Conti’s Reign of Chaos: Costa Rica in the Crosshairs

By Aamir Lakhani β€” July 20th 2022 at 12:35
Aamir Lakhani, with FortiGuard Labs, answers the question; Why is the Conti ransomware gang targeting people and businesses in Costa Rica?
☐ β˜† βœ‡ Threatpost | The first stop for security news

Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems

By Elizabeth Montalbano β€” July 20th 2022 at 12:14
300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Authentication Risks Discovered in Okta Platform

By Nate Nelson β€” July 19th 2022 at 15:33
Four newly discovered attack paths could lead to PII exposure, account takeover, even organizational data destruction.
☐ β˜† βœ‡ Threatpost | The first stop for security news

FBI Warns Fake Crypto Apps are Bilking Investors of Millions

By Elizabeth Montalbano β€” July 19th 2022 at 15:20
Threat actors offer victims what appear to be investment services from legitimate companies to lure them into downloading malicious apps aimed at defrauding them.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Google Boots Multiple Malware-laced Android Apps from Marketplace

By Elizabeth Montalbano β€” July 18th 2022 at 12:32
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
☐ β˜† βœ‡ Threatpost | The first stop for security news

CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2

By Threatpost β€” July 18th 2022 at 12:19
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Emerging H0lyGh0st Ransomware Tied to North Korea

By Elizabeth Montalbano β€” July 15th 2022 at 16:26
Microsoft has linked a threat that emerged in June 2021 and targets small-to-mid-sized businesses to state-sponsored actors tracked as DEV-0530.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Journalists Emerge as Favored Attack Target for APTs

By Elizabeth Montalbano β€” July 14th 2022 at 15:08
Since 2021, various state-aligned threat groups have turned up their targeting of journalists to siphon data and credentials and also track them.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Large-Scale Phishing Campaign Bypasses MFA

By Elizabeth Montalbano β€” July 13th 2022 at 11:45
Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.
☐ β˜† βœ‡ Threatpost | The first stop for security news

How War Impacts Cyber Insurance

By Infosec Contributor β€” July 12th 2022 at 12:20
Chris Hallenbeck, CISO for the Americas at Tanium, discusses the impact of geopolitical conflict on the cybersecurity insurance market.
☐ β˜† βœ‡ Threatpost | The first stop for security news

β€˜Callback’ Phishing Campaign Impersonates Security Firms

By Elizabeth Montalbano β€” July 12th 2022 at 11:43
Victims instructed to make a phone call that will direct them to a link for downloading malware.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Rethinking Vulnerability Management in a Heightened Threat Landscape

By Infosec Contributor β€” July 11th 2022 at 20:26
Find out why a vital component of vulnerability management needs to be the capacity to prioritize from Mariano Nunez, CEO of Onapsis and Threatpost Infosec Insiders columnist.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Popular NFT Marketplace Phished for $540M

By Nate Nelson β€” July 11th 2022 at 20:06
In March, a North Korean APT siphoned blockchain gaming platform Axie Infinity of $540M.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Sneaky Orbit Malware Backdoors Linux Devices

By Elizabeth Montalbano β€” July 8th 2022 at 14:45
The novel threat steals data and can affect all processes running on the OS, stealing information from different commands and utilities and then storing it on the affected machine.
☐ β˜† βœ‡ Threatpost | The first stop for security news

U.S. Healthcare Orgs Targeted with Maui Ransomware

By Elizabeth Montalbano β€” July 8th 2022 at 10:46
State-sponsored actors are deploying the unique malware--which targets specific files and leaves no ransomware note--in ongoing attacks.
❌