FreshRSS

πŸ”’
☐ β˜† βœ‡ The first stop for security news | Threatpost

Student Loan Breach Exposes 2.5M Records

By Nate Nelson β€” August 31st 2022 at 12:57
2.5 million people were affected, in a breach that could spell more trouble down the line.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Watering Hole Attacks Push ScanBox Keylogger

By Nate Nelson β€” August 30th 2022 at 16:00
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Tentacles of β€˜0ktapus’ Threat Group Victimize 130 Firms

By Nate Nelson β€” August 29th 2022 at 14:56
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Ransomware Attacks are on the Rise

By Nate Nelson β€” August 26th 2022 at 16:44
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

By Nate Nelson β€” August 25th 2022 at 18:47
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Twitter Whistleblower Complaint: The TL;DR Version

By Threatpost β€” August 24th 2022 at 14:17
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Firewall Bug Under Active Attack Triggers CISA Warning

By Threatpost β€” August 23rd 2022 at 13:19
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Fake Reservation Links Prey on Weary Travelers

By Nate Nelson β€” August 22nd 2022 at 13:59
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
☐ β˜† βœ‡ The first stop for security news | Threatpost

iPhone Users Urged to Update to Patch 2 Zero-Days

By Elizabeth Montalbano β€” August 19th 2022 at 15:25
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Google Patches Chrome’s Fifth Zero-Day of the Year

By Elizabeth Montalbano β€” August 18th 2022 at 14:31
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
☐ β˜† βœ‡ The first stop for security news | Threatpost

APT Lazarus Targets Engineers with macOS Malware

By Elizabeth Montalbano β€” August 17th 2022 at 15:07
The North Korean APT is using a fake job posting for Coinbase in a cyberespionage campaign targeting users of both Apple and Intel-based systems.
☐ β˜† βœ‡ The first stop for security news | Threatpost

U.K. Water Supplier Hit with Clop Ransomware Attack

By Elizabeth Montalbano β€” August 16th 2022 at 14:30
The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Xiaomi Phone Bug Allowed Payment Forgery

By Nate Nelson β€” August 16th 2022 at 12:26
Mobile transactions could’ve been disabled, created and signed by attackers.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Black Hat and DEF CON Roundup

By Threatpost β€” August 15th 2022 at 13:56
β€˜Summer Camp’ for hackers features a compromised satellite, a homecoming for hackers and cyberwarfare warnings.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics

By Elizabeth Montalbano β€” August 12th 2022 at 18:20
The CISA has seen a resurgence of the malware targeting a range of verticals and critical infrastructure organizations by exploiting RDP, firewall vulnerabilities.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Facebook’s In-app Browser on iOS Tracks β€˜Anything You Do on Any Website’

By Threatpost β€” August 12th 2022 at 13:24
Researcher shows how Instagram and Facebook’s use of an in-app browser within both its iOS apps can track interactions with external websites.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Starlink Successfully Hacked Using $25 Modchip

By Elizabeth Montalbano β€” August 11th 2022 at 15:48
Belgian researcher Lennert Wouters revealed at Black Hat how he mounted a successful fault injection attack on a user terminal for SpaceX’s satellite-based internet system
☐ β˜† βœ‡ The first stop for security news | Threatpost

New Hacker Forum Takes Pro-Ukraine Stance

By Elizabeth Montalbano β€” August 11th 2022 at 15:14
A uniquely politically motivated site called DUMPS focuses solely on threat activity directed against Russia and Belarus
☐ β˜† βœ‡ The first stop for security news | Threatpost

Cisco Confirms Network Breach Via Hacked Employee Google Account

By Threatpost β€” August 11th 2022 at 12:51
Networking giant says attackers gained initial access to an employee’s VPN client via a compromised Google account.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Inside the Hackers’ Toolkit – Podcast

By Jeffrey Esposito β€” August 11th 2022 at 04:30
This edition of the Threatpost podcast is sponsored by Egress.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Microsoft Patches β€˜Dogwalk’ Zero-Day and 17 Critical Flaws

By Threatpost β€” August 10th 2022 at 12:48
August Patch Tuesday tackles 121 CVEs, 17 critical bugs and one zero-day bug exploited in the wild.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Virtual Currency Platform β€˜Tornado Cash’ Accused of Aiding APTs

By Elizabeth Montalbano β€” August 9th 2022 at 17:58
U.S. Treasury blocked the business of the virtual currency mixer for laundering more than $7 billion for hackers, including $455 million to help fund North Korea’s missile program.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Phishers Swim Around 2FA in Coinbase Account Heists

By Elizabeth Montalbano β€” August 8th 2022 at 15:26
Attackers are spoofing the widely used cryptocurrency exchange to trick users into logging in so they can steal their credentials and eventually their funds.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Open Redirect Flaw Snags Amex, Snapchat User Data

By Elizabeth Montalbano β€” August 5th 2022 at 13:17
Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims.
☐ β˜† βœ‡ The first stop for security news | Threatpost

VMWare Urges Users to Patch Critical Authentication Bypass Bug

By Elizabeth Montalbano β€” August 3rd 2022 at 15:23
Vulnerabilityβ€”for which a proof-of-concept is forthcomingβ€”is one of a string of flaws the company fixed that could lead to an attack chain.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Universities Put Email Users at Cyber Risk

By Elizabeth Montalbano β€” August 2nd 2022 at 23:02
DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Securing Your Move to the Hybrid Cloud

By Infosec Contributor β€” August 1st 2022 at 13:29
Infosec expert Rani Osnat lays out security challenges and offers hope for organizations migrating their IT stack to the private and public cloud environments.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Malicious Npm Packages Tapped Again to Target Discord Users

By Elizabeth Montalbano β€” July 29th 2022 at 15:07
Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Threat Actors Pivot Around Microsoft’s Macro-Blocking in Office

By Elizabeth Montalbano β€” July 28th 2022 at 17:24
Cybercriminals turn to container files and other tactics to get around the company’s attempt to thwart a popular way to deliver malicious phishing payloads.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Messaging Apps Tapped as Platform for Cybercriminal Activity

By Elizabeth Montalbano β€” July 27th 2022 at 16:57
Built-in Telegram and Discord services are fertile ground for storing stolen data, hosting malware and using bots for nefarious purposes.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Novel Malware Hijacks Facebook Business Accounts

By Elizabeth Montalbano β€” July 26th 2022 at 18:15
Newly discovered malware linked to Vietnamese threat actors targets users through a LinkedIn phishing campaign to steal data and admin privileges for financial gain.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands

By Nate Nelson β€” July 26th 2022 at 13:05
Instances of phishing attacks leveraging the Microsoft brand increased 266 percent in Q1 compared to the year prior.
☐ β˜† βœ‡ The first stop for security news | Threatpost

IoT Botnets Fuels DDoS Attacks – Are You Prepared?

By Sponsored Content β€” July 26th 2022 at 12:38
The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. This is a dangerous warning that the possibility of a sophisticated DDoS attack and a prolonged service outage will prevent businesses from growing.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Why Physical Security Maintenance Should Never Be an Afterthought

By Infosec Contributor β€” July 25th 2022 at 11:00
SecuriThings' CEO Roy Dagan tackles the sometimes overlooked security step of physical security maintenance and breaks down why it is important.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Hackers for Hire: Adversaries Employ β€˜Cyber Mercenaries’

By Elizabeth Montalbano β€” July 21st 2022 at 12:59
Also known as the Atlantis Cyber-Army, the emerging organization has an enigmatic leader and a core set of admins that offer a range of services, including exclusive data leaks, DDoS and RDP.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Conti’s Reign of Chaos: Costa Rica in the Crosshairs

By Aamir Lakhani β€” July 20th 2022 at 12:35
Aamir Lakhani, with FortiGuard Labs, answers the question; Why is the Conti ransomware gang targeting people and businesses in Costa Rica?
☐ β˜† βœ‡ The first stop for security news | Threatpost

Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems

By Elizabeth Montalbano β€” July 20th 2022 at 12:14
300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Authentication Risks Discovered in Okta Platform

By Nate Nelson β€” July 19th 2022 at 15:33
Four newly discovered attack paths could lead to PII exposure, account takeover, even organizational data destruction.
☐ β˜† βœ‡ The first stop for security news | Threatpost

FBI Warns Fake Crypto Apps are Bilking Investors of Millions

By Elizabeth Montalbano β€” July 19th 2022 at 15:20
Threat actors offer victims what appear to be investment services from legitimate companies to lure them into downloading malicious apps aimed at defrauding them.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Google Boots Multiple Malware-laced Android Apps from Marketplace

By Elizabeth Montalbano β€” July 18th 2022 at 12:32
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
☐ β˜† βœ‡ The first stop for security news | Threatpost

CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2

By Threatpost β€” July 18th 2022 at 12:19
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Emerging H0lyGh0st Ransomware Tied to North Korea

By Elizabeth Montalbano β€” July 15th 2022 at 16:26
Microsoft has linked a threat that emerged in June 2021 and targets small-to-mid-sized businesses to state-sponsored actors tracked as DEV-0530.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Journalists Emerge as Favored Attack Target for APTs

By Elizabeth Montalbano β€” July 14th 2022 at 15:08
Since 2021, various state-aligned threat groups have turned up their targeting of journalists to siphon data and credentials and also track them.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Large-Scale Phishing Campaign Bypasses MFA

By Elizabeth Montalbano β€” July 13th 2022 at 11:45
Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.
☐ β˜† βœ‡ The first stop for security news | Threatpost

How War Impacts Cyber Insurance

By Infosec Contributor β€” July 12th 2022 at 12:20
Chris Hallenbeck, CISO for the Americas at Tanium, discusses the impact of geopolitical conflict on the cybersecurity insurance market.
☐ β˜† βœ‡ The first stop for security news | Threatpost

β€˜Callback’ Phishing Campaign Impersonates Security Firms

By Elizabeth Montalbano β€” July 12th 2022 at 11:43
Victims instructed to make a phone call that will direct them to a link for downloading malware.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Rethinking Vulnerability Management in a Heightened Threat Landscape

By Infosec Contributor β€” July 11th 2022 at 20:26
Find out why a vital component of vulnerability management needs to be the capacity to prioritize from Mariano Nunez, CEO of Onapsis and Threatpost Infosec Insiders columnist.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Popular NFT Marketplace Phished for $540M

By Nate Nelson β€” July 11th 2022 at 20:06
In March, a North Korean APT siphoned blockchain gaming platform Axie Infinity of $540M.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Sneaky Orbit Malware Backdoors Linux Devices

By Elizabeth Montalbano β€” July 8th 2022 at 14:45
The novel threat steals data and can affect all processes running on the OS, stealing information from different commands and utilities and then storing it on the affected machine.
☐ β˜† βœ‡ The first stop for security news | Threatpost

U.S. Healthcare Orgs Targeted with Maui Ransomware

By Elizabeth Montalbano β€” July 8th 2022 at 10:46
State-sponsored actors are deploying the unique malware--which targets specific files and leaves no ransomware note--in ongoing attacks.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Hack Allows Drone Takeover Via β€˜ExpressLRS’ Protocol

By Nate Nelson β€” July 7th 2022 at 11:31
A radio control system for drones is vulnerable to remote takeover, thanks to a weakness in the mechanism that binds transmitter and receiver.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Human Error Blamed for Leak of 1 Billion Records of Chinese Citizens

By Elizabeth Montalbano β€” July 6th 2022 at 10:33
A developer appears to have divulged credentials to a police database on a popular developer forum, leading to a breach and subsequent bid to sell 23 terabytes of personal data on the dark web.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Latest Cyberattack Against Iran Part of Ongoing Campaign

By Nate Nelson β€” July 5th 2022 at 12:35
Iran's steel manufacturing industry is victim to ongoing cyberattacks that previously impacted the country's rail system.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Google Patches Actively Exploited Chrome Bug

By Elizabeth Montalbano β€” July 5th 2022 at 11:54
The heap buffer overflow issue in the browser’s WebRTC engine could allow attackers to execute arbitrary code.
☐ β˜† βœ‡ The first stop for security news | Threatpost

ZuoRAT Can Take Over Widely Used SOHO Routers

By Elizabeth Montalbano β€” June 30th 2022 at 17:20
Devices from Cisco, Netgear and others at risk from the multi-stage malware, which has been active since April 2020 and shows the work of a sophisticated threat actor.
☐ β˜† βœ‡ The first stop for security news | Threatpost

A Guide to Surviving a Ransomware Attack

By Oliver Tavakoli β€” June 30th 2022 at 11:59
Oliver Tavakoli, CTO at Vectra AI, gives us hope that surviving a ransomware attack is possible, so long as we apply preparation and intentionality to our defense posture.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Leaky Access Tokens Exposed Amazon Photos of Users

By Nate Nelson β€” June 29th 2022 at 20:18
Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Patchable and Preventable Security Issues Lead Causes of Q1 Attacks

By Sagar Tiwari β€” June 29th 2022 at 13:00
Attacks against U.S. companies spike in Q1 2022 with patchable and preventable external vulnerabilities responsible for bulk of attacks.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Top Six Security Bad Habits, and How to Break Them

By Infosec Contributor β€” June 28th 2022 at 13:05
Shrav Mehta, CEO, Secureframe, outlines the top six bad habits security teams need to break to prevent costly breaches, ransomware attacks and prevent phishing-based endpoint attacks.
☐ β˜† βœ‡ The first stop for security news | Threatpost

Mitel VoIP Bug Exploited in Ransomware Attacks

By Sagar Tiwari β€” June 28th 2022 at 12:42
Researchers warn threat actors are using a novel remote code execution exploit to gain initial access to victim’s environments.
❌