Infosecurity News

  1. Sophisticated Phishing Campaign Targets Microsoft OneDrive Users

    The OneDrive campaign uses social engineering to trick users into executing a PowerShell script

  2. Stolen GenAI Accounts Flood Dark Web With 400 Daily Listings

    According to eSentire, around 400 GenAI account logins are sold daily on the dark web, including credentials for GPT, Quillbot, Notion and Replit

  3. ICO Slams Electoral Commission for Basic Security Failings

    The ICO found that the Electoral Commission did not have appropriate security measures in place, allowing hackers to access the personal details of 40 million UK voters

  4. Just One in 10 Attacks Flagged By Security Tools

    Picus Security claims just 12% of simulated attacks trigger an alert

  5. Millions of Spoofed Emails Bypass Proofpoint Security in Phishing Campaign

    Guardio Labs found that attackers exploited a configuration setting in Proofpoint’s email protection service, allowing outbound messages to bypass email protections

  6. HealthEquity Breach Hits 4.3 Million Customers

    Health savings specialist HealthEquity reveals over four million customers were impacted in a recent breach

  7. Mandrake Spyware Infects 32,000 Devices Via Google Play Apps

    Updated Mandrake samples, identified by Kaspersky, displayed enhanced obfuscation and evasion tactics

  8. Walmart Discovers New PowerShell Backdoor Linked to Zloader Malware

    Walmart detailed findings about an unknown PowerShell backdoor, which was potentially utilized alongside a new Zloader variant

  9. Hotjar, Business Insider Vulnerabilities Expose OAuth Data Risks

    Salt Labs also said XSS combined with OAuth can lead to severe breaches

  10. Less Than Half of European Firms Have AI Controls in Place

    Sapio Research claims that fewer than 50% of European companies place usage and other restrictions on AI

  11. US Crypto Exchange Gemini Reveals Breach

    Thousands of customers of cryptocurrency exchange Gemini have had personal data compromised

  12. Synnovis Restores Systems After Cyber-Attack, But Blood Shortages Remain

    Synnovis has rebuilt “substantial parts” of its systems following the Qilin ransomware attack on June 3, enabling the restoration of core blood supplies to NHS hospitals

  13. Hacktivists Claim Leak of CrowdStrike Threat Intelligence

    CrowdStrike has acknowledged the claims by the USDoD hacktivist group, which has provided a link to download the alleged threat actor list on a cybercrime forum

  14. Despite Bans, AI Code Tools Widespread in Organizations

    Despite bans on AI code generation tools, widespread use and lack of governance are creating significant security risks for organizations

  15. North Korean Hackers Target Critical Infrastructure for Military Gain

    A joint advisory by the UK, US and South Korea have warned of a global espionage campaign by a North Korea threat actor, Andariel, targeting CNI organizations

  16. Ransomware and BEC Make Up 60% of Cyber Incidents

    Cisco Talos found that ransomware and BEC accounted for 60% of all cyber incidents in Q2 2024, with ransomware rising by 22% compared to Q1

  17. Malware Attacks Surge 30% in First Half of 2024

    SonicWall observed a surge in malware attacks in H1 2024, with strains becoming more adept at defense evasion

  18. Most IT Leaders Say Severity of Cyber-Attacks has Increased

    Appsbroker CTS found that nine in 10 IT leaders believe the severity of cyber-attacks has increased over the past year

  19. CrowdStrike Shares How a Rapid Response Content Update Caused Global Outage

    CrowdStrike has published a preliminary Post Incident Review into the global IT outage on July 19, revealing the issue came from a Rapid Response Content update

  20. North Korean Hackers Targeted Cybersecurity Firm KnowBe4 with Fake IT Worker

    KnowBe4 revealed it was duped into hiring a fake IT worker from North Korea resulting in attempted insider threat activity

What’s hot on Infosecurity Magazine?