Category: Uncategorized
-
Developers Warned of Malicious PyPI, NPM, Ruby Packages Targeting Macs Ionut Arghire
Malicious packages uploaded to PyPI, NPM, and Ruby repositories are targeting macOS users with information stealing malware. The post Developers Warned of Malicious PyPI, NPM, Ruby Packages Targeting Macs appeared first on SecurityWeek. Read More
-
Cybersecurity M&A Roundup: 40 Deals Announced in August 2023 Eduard Kovacs
Forty cybersecurity-related merger and acquisition (M&A) deals were announced in August 2023. The post Cybersecurity M&A Roundup: 40 Deals Announced in August 2023 appeared first on SecurityWeek. Read More
-
Ransomware Attack on Fencing Systems Maker Zaun Impacts UK Military Data Ionut Arghire
British mesh fencing systems maker Zaun discloses LockBit ransomware attack potentially impacting data related to UK military and intelligence sites. The post Ransomware Attack on Fencing Systems Maker Zaun Impacts UK Military Data appeared first on SecurityWeek. Read More
-

Meta Takes Down Thousands of Accounts Involved in Disinformation Ops from China and Russia [email protected] (The Hacker News)
Meta has disclosed that it disrupted two of the largest known covert influence operations in the world from China and Russia, blocking thousands of accounts and pages across its platform. “It targeted more than 50 apps, including Facebook, Instagram, X (formerly Twitter), YouTube, TikTok, Reddit, Pinterest, Medium, Blogspot, LiveJournal, VKontakte, Vimeo, and dozens of smaller…
-

Hackers Exploit MinIO Storage System Vulnerabilities to Compromise Servers [email protected] (The Hacker News)
An unknown threat actor has been observed weaponizing high-severity security flaws in the MinIO high-performance object storage system to achieve unauthorized code execution on affected servers. Cybersecurity and incident response firm Security Joes said the intrusion leveraged a publicly available exploit chain to backdoor the MinIO instance. The comprises CVE-2023-28432 (CVSS score: 7.5) and Read More
-

X (Twitter) to Collect Biometric Data from Premium Users to Combat Impersonation [email protected] (The Hacker News)
X, the social media site formerly known as Twitter, has updated its privacy policy to collect users’ biometric data to tackle fraud and impersonation on the platform. “Based on your consent, we may collect and use your biometric information for safety, security, and identification purposes,” the company said. The revised policy is expected to go into…
-

Everything You Wanted to Know About AI Security but Were Afraid to Ask [email protected] (The Hacker News)
There’s been a great deal of AI hype recently, but that doesn’t mean the robots are here to replace us. This article sets the record straight and explains how businesses should approach AI. From musing about self-driving cars to fearing AI bots that could destroy the world, there has been a great deal of AI…
-

Vietnamese Cybercriminals Targeting Facebook Business Accounts with Malvertising [email protected] (The Hacker News)
Malicious actors associated with the Vietnamese cybercrime ecosystem are leveraging advertising-as-a-vector on social media platforms such as Meta-owned Facebook to distribute malware. “Threat actors have long used fraudulent ads as a vector to target victims with scams, malvertising, and more,” WithSecure researcher Mohammad Kazem Hassan Nejad said. “And with businesses now leveraging the reachRead More
-

Beware of MalDoc in PDF: A New Polyglot Attack Allowing Attackers to Evade Antivirus [email protected] (The Hacker News)
Cybersecurity researchers have called attention to a new antivirus evasion technique that involves embedding a malicious Microsoft Word file into a PDF file. The sneaky method, dubbed MalDoc in PDF by JPCERT/CC, is said to have been employed in an in-the-wild attack in July 2023. “A file created with MalDoc in PDF can be opened in Word…
-

Chinese-Speaking Cybercriminals Launch Large-Scale iMessage Smishing Campaign in U.S. [email protected] (The Hacker News)
A new large-scale smishing campaign is targeting the U.S. by sending iMessages from compromised Apple iCloud accounts with an aim to conduct identity theft and financial fraud. “The Chinese-speaking threat actors behind this campaign are operating a package-tracking text scam sent via iMessage to collect personally identifying information (PII) and payment credentials from victims, in…
