Latest Cybersecurity News and Articles
31 October 2023
Meta on Monday announced plans to offer an ad-free option to access Facebook and Instagram for users in the European Union (EU), European Economic Area (EEA), and Switzerland to comply with "evolving" data protection regulations in the region.
The ad-free subscription, which costs €9.99/month on the web or €12.99/month on iOS and Android, is expected to be officially available starting next
30 October 2023
The SEC filed charges against SolarWinds and its CISO over misleading investors about its cybersecurity practices and known risks.
The post SEC Charges SolarWinds and Its CISO With Fraud and Cybersecurity Failures appeared first on SecurityWeek.
30 October 2023
NASCO announced a data breach. NASCO utilized MOVEit software, which was accessed in late May and the breach was discovered in mid-July.
30 October 2023
The Federal Trade Commission (FTC) has amended the Safeguards Rule requiring non-banking financial institutions to report data breaches.
30 October 2023
Researchers uncovered a phishing campaign distributing the Remcos remote access trojan. Cybercriminals disguised the malware as a payslip in a deceptive email. Remcos RAT can perform a range of malicious activities, including keylogging, capturing screenshots, controlling webcams and microphones, and extracting browser histories and passwords.
30 October 2023
The Chief Information Officer of Canada determined that WeChat and Kaspersky applications present an unacceptable level of risk to privacy and security.
The post Canada Bans WeChat and Kaspersky on Government Phones appeared first on SecurityWeek.
30 October 2023
QR code phishing attacks, including quishing and QRLJacking, have seen a dramatic 587% increase from August to September 2023, with threat actors extracting login information from users. This social engineering tactic takes advantage of the trust in QR codes and the routine nature of security updates. The prevalence of quishing is a testament to the ever-evolving nature of cyber threats.
30 October 2023
Huawei, Honor, and Vivo devices are displaying false security alerts urging the deletion of the Google app due to a supposed TrojanSMS-PA malware, but Google denies that its app triggered the alerts.
30 October 2023
The Wiki-Slack attack relies on crafting a legitimate footnote in a Wikipedia article and exploiting Slack's rendering of the shared page's preview to generate a hidden malicious link.
30 October 2023
A pro-Hamas hacktivist group has been observed using a new Linux-based wiper malware dubbed BiBi-Linux Wiper, targeting Israeli entities amidst the ongoing Israeli-Hamas war.
"This malware is an x64 ELF executable, lacking obfuscation or protective measures," Security Joes said in a new report published today. "It allows attackers to specify target folders and can potentially destroy an entire
30 October 2023
The organization has confirmed that it is a cybersecurity incident, and while there is no evidence of compromised personal information, it may take several days to fully restore normal operations.
30 October 2023
According to a public Wi-Fi security survey by NordVPN, almost 70% of U.S. respondents prefer mobile internet for public online activities.
30 October 2023
The manufacturing sector is particularly vulnerable to IoT malware attacks, experiencing an average of 6,000 attacks per week according to Zscaler, which can disrupt critical OT processes and pose long-term challenges for security teams.
30 October 2023
The order directs the National Institute of Standards and Technology to establish new standards for red-team testing and the Department of Health and Human Services to create a safety program for AI in healthcare.
30 October 2023
A 20-year-old Floridian was sentenced to prison for his role in a hacking scheme that led to the theft of $1 million in cryptocurrency.
The post Florida SIM Swapper Sentenced to Prison for Cryptocurrency Theft appeared first on SecurityWeek.
30 October 2023
The compromised website injected malicious content, including overlays promoting software serial keys, which resulted in misleading ads being automatically generated by Google Ads.
30 October 2023
Proofpoint removes a formidable competitor from the crowded email security market and adds technology to address risk from misdirected emails.
The post Proofpoint to Acquire Tessian for AI-Powered Email Security Tech appeared first on SecurityWeek.
30 October 2023
The LockBit ransomware gang claims to have stolen large amounts of data from aerospace giant Boeing.
The post Boeing Investigating Ransomware Attack Claims appeared first on SecurityWeek.
30 October 2023
New capability detects attacks on iMessage servers and allows users to verify a conversation partner’s identity.
The post Apple Improves iMessage Security With Contact Key Verification appeared first on SecurityWeek.
30 October 2023
The threat actor behind the campaign quickly scans and clones GitHub repositories to capture exposed keys, highlighting the importance of promptly removing and revoking any compromised credentials.