Category: Uncategorized
-
UK’s New Online Safety Law Adds to Crackdown on Big Tech Companies Associated Press
British lawmakers approved an ambitious but controversial new internet safety law with wide-ranging powers to crack down on digital and social media companies. The post UK’s New Online Safety Law Adds to Crackdown on Big Tech Companies appeared first on SecurityWeek. Read More
-
Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks Ionut Arghire
The FBI and CISA are warning critical infrastructure organizations of ongoing Snatch ransomware attacks, which also involve data exfiltration. The post Critical Infrastructure Organizations Warned of Snatch Ransomware Attacks appeared first on SecurityWeek. Read More
-

The Rise of the Malicious App [email protected] (The Hacker News)
Security teams are familiar with threats emanating from third-party applications that employees add to improve their productivity. These apps are inherently designed to deliver functionality to users by connecting to a “hub” app, such as Salesforce, Google Workspace, or Microsoft 365. Security concerns center on the permission scopes that are granted to the third party…
-

China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers [email protected] (The Hacker News)
China’s Ministry of State Security (MSS) has accused the U.S. of breaking into Huawei’s servers, stealing critical data, and implanting backdoors since 2009, amid mounting geopolitical tensions between the two countries. In a message posted on WeChat, the government authority said U.S. intelligence agencies have “done everything possible” to conduct surveillance, secret theft, and intrusions onRead More
-
Omron Patches PLC, Engineering Software Flaws Discovered During ICS Malware Analysis Eduard Kovacs
Omron has patched PLC and engineering software vulnerabilities discovered by Dragos during the analysis of ICS malware. The post Omron Patches PLC, Engineering Software Flaws Discovered During ICS Malware Analysis appeared first on SecurityWeek. Read More
-

Cyber Group ‘Gold Melody’ Selling Compromised Access to Ransomware Attackers [email protected] (The Hacker News)
A financially motivated threat actor has been outed as an initial access broker (IAB) that sells access to compromised organizations for other adversaries to conduct follow-on attacks such as ransomware. SecureWorks Counter Threat Unit (CTU) has dubbed the e-crime group Gold Melody, which is also known by the names Prophet Spider (CrowdStrike) and UNC961 (Mandiant). “This…
-

Ukrainian Hacker Suspected to be Behind “Free Download Manager” Malware Attack [email protected] (The Hacker News)
The maintainers of Free Download Manager (FDM) have acknowledged a security incident dating back to 2020 that led to its website being used to distribute malicious Linux software. “It appears that a specific web page on our site was compromised by a Ukrainian hacker group, exploiting it to distribute malicious software,” it said in an alert last…
-

Beware: Fake Exploit for WinRAR Vulnerability on GitHub Infects Users with VenomRAT [email protected] (The Hacker News)
A malicious actor released a fake proof-of-concept (PoC) exploit for a recently disclosed WinRAR vulnerability on GitHub with an aim to infect users who downloaded the code with VenomRAT malware. “The fake PoC meant to exploit this WinRAR vulnerability was based on a publicly available PoC script that exploited a SQL injection vulnerability in an…
-
MGM Resorts Computers Back Up After 10 Days as Analysts Eye Effects of Casino Cyberattacks Associated Press
MGM Resorts brought its computer systems back online on September 20th after ransomware disrupted operations for 10 days. The post MGM Resorts Computers Back Up After 10 Days as Analysts Eye Effects of Casino Cyberattacks appeared first on SecurityWeek. Read More
-
Intel Launches New Attestation Service as Part of Trust Authority Portfolio Eduard Kovacs
Intel announces general availability of attestation service that is part of Trust Authority, a new portfolio of security software and services. The post Intel Launches New Attestation Service as Part of Trust Authority Portfolio appeared first on SecurityWeek. Read More
