Infosecurity News

  1. Leeds Talent Pool Attracts BlueVoyant's First UK Security Operations Center

    The proximity of organizations’ headquarters, like Asda’s and NHS England’s, prompted BlueVoyant to choose Leeds as the location for its first UK SOC

  2. Security Leaders Braced for Daily AI-Driven Attacks by Year-End

    Netacea research found that 93% of security leaders expect to face daily AI-driven attacks by the end of 2024, with 65% predicting that offensive AI will be the norm for cybercriminals

  3. Fifth of CISOs Admit Staff Leaked Data Via GenAI

    One in five UK organizations have had corporate data exposed via generative AI, says RiverSafe

  4. North Korean Hackers Target Dozens of Defense Companies

    North Korean hackers ran a year-long cyber-espionage campaign against South Korean defense companies

  5. US Imposes Visa Restrictions on Alleged Spyware Figures

    The move is reportedly part of a broader effort to counter the misuse of surveillance technology

  6. End-to-End Encryption Sparks Concerns Among EU Law Enforcement

    The call comes amid the rollout of end-to-end encryption on Meta’s Messenger platform

  7. Millions of Americans' Data Potentially Exposed in Change Healthcare Hack

    Millions of Americans may be impacted by the Change Healthcare data breach as UnitedHealth confirms exposed data includes personal and health information

  8. Vulnerability Exploitation on the Rise as Attackers Ditch Phishing

    Mandiant’s latest M-Trends report found that vulnerability exploitation was the most common initial infection vector in 2023, making up 38% of intrusions

  9. Russian Sandworm Group Hit 20 Ukrainian Energy and Water Sites

    Notorious APT44 group Sandworm launched a major campaign against Ukrainian critical infrastructure in March

  10. Russian APT28 Group in New “GooseEgg” Hacking Campaign

    Microsoft has warned of a long-running credential stealing campaign from Russia’s APT28

  11. Fraudsters Exploit Telegram’s Popularity For Toncoin Scam

    The scheme was uncovered by Kaspersky and has been operational since November 2023

  12. Dependency Confusion Vulnerability Found in Apache Project

    This occurs when a private package fetches a similar public one, leading to exploit due to misconfigurations in package managers

  13. CrushFTP File Transfer Vulnerability Lets Attackers Download System Files

    CrushFTP is urging customers to download v11 of its file transfer platform, with attackers actively exploiting a vulnerability that allows them to download system files

  14. NSA Launches Guidance for Secure AI Deployment

    The new document is the first release from NSA’s Artificial Intelligence Security Center (AISC), in partnership with other government agencies in the US and other Five Eyes countries

  15. NCSC Announces PwC’s Richard Horne as New CEO

    The UK’s National Cyber Security Centre will see Richard Horne take over as its new boss in the autumn

  16. MITRE Reveals Ivanti Breach By Nation State Actor

    Non-profit MITRE says a sophisticated state group breached its network via two chained Ivanti zero-days

  17. Alarming Decline in Cybersecurity Job Postings in the US

    This drop represents a direct threat to US national cybersecurity infrastructure, said CyberSN representatives in their report

  18. Akira Ransomware Group Rakes in $42m, 250 Organizations Impacted

    A joint advisory from Europol and US and Dutch government agencies estimated that Akira made around $42m in ransomware proceeds from March 2023 to January 2024

  19. Quishing Attacks Jump Tenfold, Attachment Payloads Halve

    The figures come from Egress’s latest report, which also suggests secure email gateways lag behind tech advancements

  20. Russia's Sandworm Upgraded to APT44 by Google's Mandiant

    Mandiant has confirmed that Sandworm is responsible for many cyber-attacks against Ukraine has close ties with a Russian hacktivist group

What’s hot on Infosecurity Magazine?