WordPress ASE Plugin Vulnerability Threatens Site Security Information Security Magazine 2 months 2 weeks ago Patchstack urges admins to patch new WordPress ASE plugin vulnerability that lets users restore previous admin privileges
New UK Cyber Monitoring Centre Introduces 'Richter Scale' for Cyber-Attacks Information Security Magazine 2 months 2 weeks ago This new independent non-profit was set up by the UK insurance industry to bring more transparency around cyber events
Lazarus Group Targets Bitdefender Researcher with LinkedIn Recruiting Scam Information Security Magazine 2 months 2 weeks ago A Bitdefender researcher was targeted by North Korea’s Lazarus with the lure of a fake job offer
NCSC Issues Guidance to Protect UK Research and Innovation Information Security Magazine 2 months 2 weeks ago The UK’s National Cyber Security Centre has published a new set of resources for startups and researchers
Spanish Police Arrest Suspected NATO and US Army Hacker Information Security Magazine 2 months 2 weeks ago Spain’s National Police force has arrested a suspected data thief who targeted government and military victims
Sophisticated Phishing Campaign Targets Ukraine’s Largest Bank Information Security Magazine 2 months 2 weeks ago A new phishing attack by UAC-0006 has been discovered targeting PrivatBank with malicious files in password-protected archives to evade detection
Ransomware Payments Decline 35% as Victims Resist Demands Information Security Magazine 2 months 2 weeks ago Chainalysis found that ransomware payments fell significantly year-over-year despite a recorded increase in the number of ransomware events in 2024
Mobile Malware Targeting Indian Banks Exposes 50,000 Users Information Security Magazine 2 months 2 weeks ago Indian banking malware attack exposes 50,000 users, stealing financial data via SMS interception and phishing
Five Eyes Launch Guidance to Improve Edge Device Security Information Security Magazine 2 months 2 weeks ago The UK and its Five Eyes partners have launched new security guidance for edge device manufacturers and network defenders
Cybercriminals Eye DeepSeek, Alibaba LLMs for Malware Development Information Security Magazine 2 months 2 weeks ago Check Point has observed cybercriminals toy with Alibaba’s Qwen LLM to develop infostealers
Destructive Attacks on Financial Institutions Surge Information Security Magazine 2 months 2 weeks ago Contrast Security reveals a 12.5% annual increase in destructive cyber-attacks on banks
DaggerFly-Linked Linux Malware Targets Network Appliances Information Security Magazine 2 months 2 weeks ago DaggerFly’s Lunar Peek campaign is using a new malware strain, identified by FortiGuard Labs, to compromise Linux networks
Threefold Increase in Malware Targeting Credential Stores Information Security Magazine 2 months 2 weeks ago Picus Security reports infostealer surge after revealing credentials appear in 29% of malware
Sophisticated Phishing Attack Bypasses Microsoft ADFS MFA Information Security Magazine 2 months 2 weeks ago A sophisticated phishing campaign targeting Microsoft ADFS has been observed, affecting more than 150 organizations
Surge in Infostealer Attacks Threatens EMEA Organizations' Data Security Information Security Magazine 2 months 2 weeks ago Check Point Research has found over 10 million stolen credentials associated with EMEA organizations exposed on cybercrime markets
Texas to Establish Cyber Command Amid “Dramatic” Rise in Attacks Information Security Magazine 2 months 2 weeks ago Texas Governor Greg Abbott announced a Cyber Command, designed to combat surging attacks on the state by nation-states and cybercriminals
Casio and Others Hit by Magento Web Skimmer Campaign Information Security Magazine 2 months 2 weeks ago Jscambler claims at least 17 sites have been infected with web skimmers, including Casio’s
CISA Warns of Backdoor Vulnerability in Contec Patient Monitors Information Security Magazine 2 months 2 weeks ago CISA has identified a backdoor in Contec CMS8000 devices that could allow unauthorized access to patient data and disrupt monitoring functions
High-profile X Accounts Targeted in Phishing Campaign Information Security Magazine 2 months 2 weeks ago Hackers hijack high-profile X accounts with phishing scams to steal credentials and promote fraudulent cryptocurrency schemes
768 CVEs Exploited in the Wild in 2024 Information Security Magazine 2 months 2 weeks ago VulnCheck observed 768 public reports of CVEs exploited in the wild for the first time in 2024, a 20% rise compared to 2023