Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2024-11-27 09:30:00 |
Operation Serengeti Disrupts $193m African Cybercrime Networks (lien direct) |
The Interpol-led Operation Serengeti has resulted in the arrest of 1000 suspects across Africa
The Interpol-led Operation Serengeti has resulted in the arrest of 1000 suspects across Africa |
|
|
★★
|
 |
2024-11-26 16:30:00 |
New DDoS Campaign Exploits IoT Devices and Server Misconfigurations (lien direct) |
DDoS campaign by Matrix targets IoT devices and servers, exploiting weak credentials and public scripts
DDoS campaign by Matrix targets IoT devices and servers, exploiting weak credentials and public scripts |
|
|
★★
|
 |
2024-11-26 15:00:00 |
NHS Trust Declares Major Incident for “Cybersecurity Reasons” (lien direct) |
Wirral University Teaching Hospital has cancelled outpatient appointments as it responds to a cybersecurity incident
Wirral University Teaching Hospital has cancelled outpatient appointments as it responds to a cybersecurity incident |
|
|
★★★
|
 |
2024-11-26 14:00:00 |
Darknet Services Fuel Holiday Scams and E-Commerce Exploits (lien direct) |
Cybercriminals are ramping up scams via darknet marketplaces, selling phishing kits for $100-$1000
Cybercriminals are ramping up scams via darknet marketplaces, selling phishing kits for $100-$1000 |
|
|
★★
|
 |
2024-11-26 13:00:00 |
Aggressive Chinese APT Group Targets Governments with New Backdoors (lien direct) |
A Trend Micro analysis of Earth Estries found that the Chinese threat actor is using new backdoors to avoid detection during espionage operations
A Trend Micro analysis of Earth Estries found that the Chinese threat actor is using new backdoors to avoid detection during espionage operations |
Threat
Prediction
|
|
★★★
|
 |
2024-11-26 12:15:00 |
Starbucks and Grocery Stores Face Disruption after Ransomware Attack on Blue Yonder (lien direct) |
Supply chain management provider Blue Yonder confirmed it was hit by ransomware attack
Supply chain management provider Blue Yonder confirmed it was hit by ransomware attack |
Ransomware
|
|
★★
|
 |
2024-11-26 10:15:00 |
Over a Third of Firms Struggling With Shadow AI (lien direct) |
Some 35% of global organizations report challenges monitoring use of non-approved AI tools
Some 35% of global organizations report challenges monitoring use of non-approved AI tools |
Tool
|
|
★★★
|
 |
2024-11-26 09:30:00 |
UK Scam Losses Surge 50% Annually to £11.4bn (lien direct) |
Cifas figures reveal scammers stole over £11bn from UK consumers in the past 12 months
Cifas figures reveal scammers stole over £11bn from UK consumers in the past 12 months |
|
|
★★
|
 |
2024-11-25 17:45:00 |
New York Secures $11.3m from Insurance Firms in Data Breach Settlement (lien direct) |
New York State has agreed a $11.3m settlement from two insurance firms following the breach of the personal data of over 120,000 drivers in the state
New York State has agreed a $11.3m settlement from two insurance firms following the breach of the personal data of over 120,000 drivers in the state |
Data Breach
|
|
★★
|
 |
2024-11-25 17:15:00 |
IoT Device Traffic Up 18% as Malware Attacks Surge 400% (lien direct) |
Zscaler\'s latest report finds 54.5% of IoT attacks target manufacturing, with the industry suffering more than three times the weekly attacks of other sectors
Zscaler\'s latest report finds 54.5% of IoT attacks target manufacturing, with the industry suffering more than three times the weekly attacks of other sectors |
Malware
|
|
★★★
|
 |
2024-11-25 16:30:00 |
npm Package Lottie-Player Compromised in Supply Chain Attack (lien direct) |
npm package @lottiefiles/lottie-player hacked with malicious code, draining crypto wallets via web3 pop-ups
npm package @lottiefiles/lottie-player hacked with malicious code, draining crypto wallets via web3 pop-ups |
|
|
★★
|
 |
2024-11-25 12:30:00 |
Google Deindexes Chinese Propaganda Network (lien direct) |
Google\'s threat intelligence team uncovered four Chinese PR firms operating networks of inauthentic news sites
Google\'s threat intelligence team uncovered four Chinese PR firms operating networks of inauthentic news sites |
Threat
|
|
★★
|
 |
2024-11-25 11:00:00 |
UK Launches AI Security Lab to Combat Russian Cyber Threats (lien direct) |
UK Minister Pat McFadden will say in a speech at a NATO conference that adversaries are looking at using AI on the physical and cyber battlefield
UK Minister Pat McFadden will say in a speech at a NATO conference that adversaries are looking at using AI on the physical and cyber battlefield |
Conference
|
|
★★★
|
 |
2024-11-25 10:15:00 |
Meta Shutters Two Million Scam Accounts in Two-Year Crackdown (lien direct) |
Meta has closed down two million accounts it says were used in scams such as pig butchering
Meta has closed down two million accounts it says were used in scams such as pig butchering |
|
|
★★★
|
 |
2024-11-25 09:30:00 |
ICO Urges More Data Sharing to Tackle Fraud Epidemic (lien direct) |
The UK\'s Information Commissioner\'s Office argues that regulatory concerns shouldn\'t prevent firms sharing data to stop scams
The UK\'s Information Commissioner\'s Office argues that regulatory concerns shouldn\'t prevent firms sharing data to stop scams |
|
|
★★
|
 |
2024-11-22 14:30:00 |
Microsoft Seizes 240 Websites to Disrupt Global Distribution of Phish Kits (lien direct) |
Microsoft has seized 240 websites associated with the “ONXX” phishing-as-a-service operation, and has sued the developer of this service
Microsoft has seized 240 websites associated with the “ONXX” phishing-as-a-service operation, and has sued the developer of this service |
|
|
★★
|
 |
2024-11-22 13:00:00 |
Russian Cyber Spies Target Organizations with HatVibe and CherrySpy Malware (lien direct) |
Russian-aligned TAG-110 uses custom tools to spy on governments, human rights groups and educational institutions in Europe and Asia
Russian-aligned TAG-110 uses custom tools to spy on governments, human rights groups and educational institutions in Europe and Asia |
Malware
Tool
|
|
★★
|
 |
2024-11-22 11:30:00 |
Three-Quarters of Black Friday Spam Emails Identified as Scams (lien direct) |
Bitdefender found that 77% of Black Friday-themed spam emails in 2024 have been identified as scams, with attackers becoming more creative in their campaigns
Bitdefender found that 77% of Black Friday-themed spam emails in 2024 have been identified as scams, with attackers becoming more creative in their campaigns |
Spam
|
|
★★
|
 |
2024-11-22 10:45:00 |
Five Ransomware Groups Responsible for 40% of Cyber-Attacks in 2024 (lien direct) |
Corvus Insurance highlighted the growing complexity and competition within the ransomware ecosystem, with the threat level remaining elevated
Corvus Insurance highlighted the growing complexity and competition within the ransomware ecosystem, with the threat level remaining elevated |
Ransomware
Threat
|
|
★★
|
 |
2024-11-22 10:15:00 |
MITRE Unveils Top 25 Most Critical Software Flaws (lien direct) |
The 25 most dangerous software weaknesses between June 2023 and June 2024 are responsible for almost 32,000 vulnerabilities
The 25 most dangerous software weaknesses between June 2023 and June 2024 are responsible for almost 32,000 vulnerabilities |
Vulnerability
|
|
★★★
|
 |
2024-11-22 09:15:00 |
Manufacturing Sector in the Crosshairs of Advanced Email Attacks (lien direct) |
Phishing attacks, business email compromise and vendor email compromise attacks on manufacturing have surged in the past 12 months
Phishing attacks, business email compromise and vendor email compromise attacks on manufacturing have surged in the past 12 months |
|
|
★★
|
 |
2024-11-21 17:15:00 |
Linux Malware WolfsBane and FireWood Linked to Gelsemium APT (lien direct) |
New Linux malware WolfsBane and FireWood have been linked to Gelsemium APT, a cyber-espionage group targeting critical systems
New Linux malware WolfsBane and FireWood have been linked to Gelsemium APT, a cyber-espionage group targeting critical systems |
Malware
|
|
★★★
|
 |
2024-11-21 16:30:00 |
Vietnam\\'s Infostealer Crackdown Reveals VietCredCare and DuckTail (lien direct) |
Group-IB revealed key differences in VietCredCare and DuckTail infostealer malware targeting Facebook Business accounts
Group-IB revealed key differences in VietCredCare and DuckTail infostealer malware targeting Facebook Business accounts |
Malware
|
|
★★
|
 |
2024-11-21 14:45:00 |
Google OSS-Fuzz Harnesses AI to Expose 26 Hidden Security Vulnerabilities (lien direct) |
One of these flaws detected using LLMs was in the widely used OpenSSL library
One of these flaws detected using LLMs was in the widely used OpenSSL library |
Vulnerability
|
|
★★
|
 |
2024-11-21 14:00:00 |
BianLian Ransomware Group Adopts New Tactics, Posing Significant Risk (lien direct) |
The BianLian ransomware group has shifted exclusively to exfiltration-based extortion and is deploying multiple new TTPs for initial access and persistence
The BianLian ransomware group has shifted exclusively to exfiltration-based extortion and is deploying multiple new TTPs for initial access and persistence |
Ransomware
|
|
★★
|
 |
2024-11-21 11:30:00 |
Lumma Stealer Proliferation Fueled by Telegram Activity (lien direct) |
Spreading malware via Telegram channels allows threat actors to bypass traditional detection mechanisms and reach a broad, unsuspecting audience
Spreading malware via Telegram channels allows threat actors to bypass traditional detection mechanisms and reach a broad, unsuspecting audience |
Malware
Threat
|
|
★★★
|
 |
2024-11-21 10:15:00 |
A Fifth of UK Enterprises “Not Sure” If NIS2 Applies (lien direct) |
Over a fifth of large UK businesses aren\'t sure of their compliance responsibilities under the new NIS2 directive
Over a fifth of large UK businesses aren\'t sure of their compliance responsibilities under the new NIS2 directive |
|
|
★★
|
 |
2024-11-21 09:30:00 |
Five Charged in Scattered Spider Case (lien direct) |
Five men have been indicted in connection with crimes committed by the Scattered Spider group
Five men have been indicted in connection with crimes committed by the Scattered Spider group |
|
|
★★
|
 |
2024-11-20 17:15:00 |
Five Privilege Escalation Flaws Found in Ubuntu needrestart (lien direct) |
Five LPE flaws in Ubuntu\'s needrestart utility enable attackers to gain root access in versions prior to 3.8
Five LPE flaws in Ubuntu\'s needrestart utility enable attackers to gain root access in versions prior to 3.8 |
|
|
★★
|
 |
2024-11-20 16:30:00 |
60% of Emails with QR Codes Classified as Spam or Malicious (lien direct) |
60% of QR code emails are spam according findings from Cisco Talos, who also identified attackers using QR code art to bypass security filters
60% of QR code emails are spam according findings from Cisco Talos, who also identified attackers using QR code art to bypass security filters |
Spam
|
|
★★★
|
 |
2024-11-20 12:45:00 |
Chinese APT Group Targets Telecom Firms Linked to Belt and Road Initiative (lien direct) |
CrowdStrike unveiled a new Chinese-aligned hacking group allegedly spying on telecom providers
CrowdStrike unveiled a new Chinese-aligned hacking group allegedly spying on telecom providers |
|
|
★★
|
 |
2024-11-20 12:00:00 |
Apple Issues Emergency Security Update for Actively Exploited Vulnerabilities (lien direct) |
Apple has urged customers to download the security updates, which address vulnerabilities relating to the JavaScriptCore and WebKit frameworks
Apple has urged customers to download the security updates, which address vulnerabilities relating to the JavaScriptCore and WebKit frameworks |
Vulnerability
|
|
★★
|
 |
2024-11-20 11:00:00 |
OWASP Warns of Growing Data Exposure Risk from AI in New Top 10 List for LLMs (lien direct) |
OWASP has updated its Top 10 list of risks for LLMs and GenAI, upgrading several areas and introducing new categories
OWASP has updated its Top 10 list of risks for LLMs and GenAI, upgrading several areas and introducing new categories |
|
|
★★★
|
 |
2024-11-20 10:15:00 |
Hackers Hijack Jupyter Servers for Sport Stream Ripping (lien direct) |
Aqua Security has observed threat actors using compromised Jupyter servers in a bid to illegally stream sporting events
Aqua Security has observed threat actors using compromised Jupyter servers in a bid to illegally stream sporting events |
Threat
|
|
★★
|
 |
2024-11-20 09:50:00 |
One Deepfake Digital Identity Attack Strikes Every Five Minutes (lien direct) |
Entrust claims deepfakes are driving a surge in digital identity fraud
Entrust claims deepfakes are driving a surge in digital identity fraud |
|
|
★★
|
 |
2024-11-20 08:45:00 |
Cybercriminals Exploit Weekend Lull to Launch Ransomware Attacks (lien direct) |
Ransomware groups are targeting weekends and holidays to exploit understaffed security teams in order to get the best chance of a pay day
Ransomware groups are targeting weekends and holidays to exploit understaffed security teams in order to get the best chance of a pay day |
Ransomware
Threat
|
|
★★★
|
 |
2024-11-19 17:30:00 |
CISA Chief Jen Easterly Set to Step Down on January 20 (lien direct) |
Easterly and her Deputy Director Nitin Natarajan are expected to leave office before President-elect Trump names a new leadership
Easterly and her Deputy Director Nitin Natarajan are expected to leave office before President-elect Trump names a new leadership |
|
|
★★
|
 |
2024-11-19 17:15:00 |
T-Mobile Breached in Major Chinese Cyber-Attack on Telecoms (lien direct) |
T-Mobile was hit by Salt Typhoon, a Chinese cyber-espionage group targeting US and global telecom firms
T-Mobile was hit by Salt Typhoon, a Chinese cyber-espionage group targeting US and global telecom firms |
|
|
★★
|
 |
2024-11-19 16:30:00 |
Helldown Ransomware Expands to Target VMware and Linux Systems (lien direct) |
Helldown ransomware has expanded its reach to target Linux and VMware systems, exploiting Zyxel firewall vulnerabilities and exfiltrating data
Helldown ransomware has expanded its reach to target Linux and VMware systems, exploiting Zyxel firewall vulnerabilities and exfiltrating data |
Ransomware
Vulnerability
|
|
★★
|
 |
2024-11-19 15:00:00 |
Palo Alto Networks Patches Critical Firewall Vulnerability (lien direct) |
Palo Alto advised users to patch urgently as the vulnerability is critical and actively exploited in the wild
Palo Alto advised users to patch urgently as the vulnerability is critical and actively exploited in the wild |
Vulnerability
|
|
★★★
|
 |
2024-11-19 13:35:00 |
Ransomware Gangs on Recruitment Drive for Pen Testers (lien direct) |
Ransomware groups are recruiting pen testers from the dark web to expand their operations, as revealed by Cato Network\'s Q3 2024 SASE Threat Report
Ransomware groups are recruiting pen testers from the dark web to expand their operations, as revealed by Cato Network\'s Q3 2024 SASE Threat Report |
Ransomware
Threat
|
|
★★
|
 |
2024-11-19 10:30:00 |
Suspected Phobos Ransomware Admin Extradited to US (lien direct) |
A Russian national suspected of involvement in Phobos ransomware has appeared in court in the US
A Russian national suspected of involvement in Phobos ransomware has appeared in court in the US |
Ransomware
|
|
★★★
|
 |
2024-11-19 09:45:00 |
Companies Take Over Seven Months to Recover From Cyber Incidents (lien direct) |
Fastly claims global organizations are taking 25% longer than expected to recover from security incidents
Fastly claims global organizations are taking 25% longer than expected to recover from security incidents |
|
|
★★
|
 |
2024-11-18 16:30:00 |
Swiss Cyber Agency Warns of QR Code Malware in Mail Scam (lien direct) |
Switzerland\'s National Cyber Security Centre has warned of a new QR code scam in fake MeteoSwiss letters spreading Android malware
Switzerland\'s National Cyber Security Centre has warned of a new QR code scam in fake MeteoSwiss letters spreading Android malware |
Malware
Mobile
|
|
★★
|
 |
2024-11-18 15:30:00 |
\\'ClickFix\\' Cyber-Attacks for Malware Deployment on the Rise (lien direct) |
Proofpoint researchers have observed the growing use of the ClickFix social engineering tactic, which lures people into running malicious content on their computer
Proofpoint researchers have observed the growing use of the ClickFix social engineering tactic, which lures people into running malicious content on their computer |
Malware
|
|
★★
|
 |
2024-11-18 14:45:00 |
Fake Donald Trump Assassination Story Used in Phishing Scam (lien direct) |
A phishing email claims to be from the New York Times with a story about an assassination attempt against President-elect Donald Trump
A phishing email claims to be from the New York Times with a story about an assassination attempt against President-elect Donald Trump |
|
|
★★
|
 |
2024-11-18 14:00:00 |
Surge in DocuSign Phishing Attacks Target US State Contractors (lien direct) |
Phishing attacks using DocuSign impersonations targeting state agencies have surged 98% since Nov 8
Phishing attacks using DocuSign impersonations targeting state agencies have surged 98% since Nov 8 |
|
|
★★
|
 |
2024-11-18 11:30:00 |
North Korean IT Worker Network Tied to BeaverTail Phishing Campaign (lien direct) |
BeaverTail malware has been used to target tech job seekers through fake recruiters, Palo Alto Networks\' Unit 42 has found
BeaverTail malware has been used to target tech job seekers through fake recruiters, Palo Alto Networks\' Unit 42 has found |
Malware
|
|
★★
|
 |
2024-11-18 10:15:00 |
FTC Records 50% Drop in Nuisance Calls Since 2021 (lien direct) |
The US Federal Trade Commission is celebrating a halving of unwanted telemarketing and scam calls since 2021
The US Federal Trade Commission is celebrating a halving of unwanted telemarketing and scam calls since 2021 |
|
|
★★
|
 |
2024-11-18 09:30:00 |
UK Shoppers Lost £11.5m Last Christmas, NCSC Warns (lien direct) |
The UK\'s National Cyber Security Centre is urging shoppers to stay safe this Christmas after revealing they lost £11.5m to fraudsters in 2023
The UK\'s National Cyber Security Centre is urging shoppers to stay safe this Christmas after revealing they lost £11.5m to fraudsters in 2023 |
|
|
★★
|