Category: Uncategorized
-

Hook: New Android Banking Trojan That Expands on ERMAC’s Legacy [email protected] (The Hacker News)
A new analysis of the Android banking trojan known as Hook has revealed that it’s based on its predecessor called ERMAC. “The ERMAC source code was used as a base for Hook,” NCC Group security researchers Joshua Kamp and Alberto Segura said in a technical analysis published last week. “All commands (30 in total) that the malware…
-
Two Vegas Casinos Fell Victim to Cyberattacks, Shattering the Image of Impenetrable Casino Security Associated Press
MGM Resorts and Caesars Entertainment hit by cyberattacks, shattering the image of impenetrable casino security. The post Two Vegas Casinos Fell Victim to Cyberattacks, Shattering the Image of Impenetrable Casino Security appeared first on SecurityWeek. Read More
-
CISA Releases New Identity and Access Management Guidance Ionut Arghire
CISA has released new guidance on how federal agencies can integrate identity and access management into their ICAM architecture. The post CISA Releases New Identity and Access Management Guidance appeared first on SecurityWeek. Read More
-
TikTok Is Hit With $368 Million Fine Under Europe’s Strict Data Privacy Rules Associated Press
European regulators slapped TikTok with a $368 million fine for failing to protect children’s privacy, the first time that the popular short video-sharing app has been punished for breaching Europe’s strict data privacy rules. The post TikTok Is Hit With $368 Million Fine Under Europe’s Strict Data Privacy Rules appeared first on SecurityWeek. Read More
-
ICS Security Firm Dragos Raises $74 Million in Series D Extension Eduard Kovacs
ICS/OT security firm Dragos has raised $74 million in a Series D extension funding round that brings the total to $440 million. The post ICS Security Firm Dragos Raises $74 Million in Series D Extension appeared first on SecurityWeek. Read More
-

Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud Clients [email protected] (The Hacker News)
Software development company Retool has disclosed that the accounts of 27 of its cloud customers were compromised following a targeted and SMS-based social engineering attack. The San Francisco-based firm blamed a Google Account cloud synchronization feature recently introduced in April 2023 for making the breach worse, calling it a “dark pattern.” “The fact that Google Authenticator syncs…
-

Financially Motivated UNC3944 Threat Actor Shifts Focus to Ransomware Attacks [email protected] (The Hacker News)
The financially motivated threat actor known as UNC3944 is pivoting to ransomware deployment as part of an expansion to its monetization strategies, Mandiant has revealed. “UNC3944 has demonstrated a stronger focus on stealing large amounts of sensitive data for extortion purposes and they appear to understand Western business practices, possibly due to the geographical composition of the…
-

North Korea’s Lazarus Group Suspected in $31 Million CoinEx Heist [email protected] (The Hacker News)
The North Korea-affiliated Lazarus Group has stolen nearly $240 million in cryptocurrency since June 2023, marking a significant escalation of its hacks. According to multiple reports from Certik, Elliptic, and ZachXBT, the infamous hacking group is said to be suspected behind the theft of $31 million in digital assets from the CoinEx exchange on September 12, 2023. The crypto heist…
-
Imagine Making Shadowy Data Brokers Erase Your Personal Info. Californians May Soon Live the Dream Associated Press
California state Legislature has passed the Delete Act to allow individuals to order data brokers to delete their personal data — and to cease acquiring and selling it in the future. The post Imagine Making Shadowy Data Brokers Erase Your Personal Info. Californians May Soon Live the Dream appeared first on SecurityWeek. Read More
-

TikTok Faces Massive €345 Million Fine Over Child Data Violations in E.U. [email protected] (The Hacker News)
The Irish Data Protection Commission (DPC) slapped TikTok with a €345 million (about $368 million) fine for violating the European Union’s General Data Protection Regulation (GDPR) in relation to its handling of children’s data. The investigation, initiated in September 2021, examined how the popular short-form video platform processed personal data relating to child users (those between theRead…
