Cybersecurity News


UK Cops Collar 7 Suspected Lapsus$ Gang Members

UK Cops Collar 7 Suspected Lapsus$ Gang Members London Police can't say if they nabbed the 17-year-old suspected mastermind & multimillionaire – but researchers say they’ve been tracking an Oxford teen since mid-2021.
24 March 2022

Microsoft Azure Developers Awash in PII-Stealing npm Packages

Microsoft Azure Developers Awash in PII-Stealing npm Packages A large-scale, automated typosquatting attack saw 200+ malicious packages flood the npm code repository, targeting popular Azure scopes.
24 March 2022

Just-Released Dark Souls Game, Elden Ring, Includes Killer Bug

Just-Released Dark Souls Game, Elden Ring, Includes Killer Bug A patch fixes exploit hidden in Elden Ring that traps PC players in a ‘death loop.’
24 March 2022

PCI DSS v4.0: A Preview of the Standard and Transition Training

 

Alicia Malone: Welcome to our podcast series, Coffee with the Council. I'm Alicia Malone, senior manager of public relations for the PCI Security Standards Council. Today we'll be talking about the much-anticipated release of version 4.0 of our PCI Data Security Standard, or DSS. In addition to the timeline and some key highlights, we'll be discussing what you need to know to prepare for PCI DSS version 4.0 transition training. My guests for this episode are Kandyce Young, standards development manager at PCI SSC, and Tom White, training content manager at PCI SSC. Welcome to both of you!

24 March 2022

HubSpot Data Breach Ripples Through Crytocurrency Industry

HubSpot Data Breach Ripples Through Crytocurrency Industry ~30 crypto companies were affected, including BlockFi, Swan Bitcoin and NYDIG, providing an uncomfortable reminder about how much data CRM systems snarf up.
24 March 2022

Is a nation‑state digital deterrent scenario so far‑fetched?

Why has the conflict in Ukraine not caused the much anticipated global cyber-meltdown?

The post Is a nation‑state digital deterrent scenario so far‑fetched? appeared first on WeLiveSecurity

24 March 2022

Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection

Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection Mustang Panda's already sophisticated cyberespionage campaign has matured even further with the introduction of a brand-new PlugX RAT variant.
24 March 2022

Microsoft Help Files Disguise Vidar Malware

Microsoft Help Files Disguise Vidar Malware Attackers are hiding interesting malware in a boring place, hoping victims won’t bother to look.
24 March 2022

Top 3 Attack Trends in API Security – Podcast

Top 3 Attack Trends in API Security – Podcast Bots & automated attacks have exploded, with attackers and developers alike in love with APIs, according to a new Cequence Security report. Hacker-in-residence Jason Kent explains the latest.
24 March 2022

Tax-Season Scammers Spoof Fintechs, Including Stash, Public

Tax-Season Scammers Spoof Fintechs, Including Stash, Public Threat actors are impersonating such wildly popular personal-finance apps (which are used more than social media or streaming services) to try to fool people into giving up their credentials.
24 March 2022

Vidar spyware is now hidden in Microsoft help files

The malware is being spread through an interesting phishing tactic.
24 March 2022

Crypto malware in patched wallets targeting Android and iOS devices

ESET Research uncovers a sophisticated scheme that distributes trojanized Android and iOS apps posing as popular cryptocurrency wallets

The post Crypto malware in patched wallets targeting Android and iOS devices appeared first on WeLiveSecurity

24 March 2022

Mustang Panda hacking group takes advantage of Ukraine crisis in new attacks

Just as criminals seized on the pandemic, this group is trying to capitalize on Russia's invasion of Ukraine.
24 March 2022

Malicious npm packages target Azure developers to steal personal data

Typosquatting and automatic tools are the weapons of choice.
24 March 2022

A Closer Look at the LAPSUS$ Data Extortion Group

Microsoft and identity management platform Okta both disclosed this week breaches involving LAPSUS$, a relatively new cybercrime group that specializes in stealing data from big companies and threatening to publish the information unless a ransom demand is paid. Here's a closer look at LAPSUS$, and some of the low-tech but high-impact methods the group uses to gain access to targeted organizations.
23 March 2022

Okta names Sitel in Lapsus$ security incident impacting up to 366 customers

The analogy "walking away from your computer at a coffee shop" has been used to describe the incident.
23 March 2022

DeadBolt Ransomware Resurfaces to Hit QNAP Again

DeadBolt Ransomware Resurfaces to Hit QNAP Again A new steady stream of attacks against network-attached storage devices from the Taiwan-based vendor is similar to a wave that occurred in January.
23 March 2022

Microsoft: Lapsus$ Used Employee Account to Steal Source Code

Microsoft: Lapsus$ Used Employee Account to Steal Source Code The data-extortion gang got at Microsoft's Azure DevOps server. Meanwhile, fellow Lapsus$ victim and authentication firm Okta said 2.5 percent of customers were affected in its own Lapsus$ attack.
23 March 2022

This is how much the average Conti hacking group member earns a month

While ransom payments can reach millions of dollars, it isn't as much as you'd think.
23 March 2022

Mustang Panda’s Hodur: Old tricks, new Korplug variant

ESET researchers have discovered Hodur, a previously undocumented Korplug variant spread by Mustang Panda, that uses phishing lures referencing current events in Europe, including the invasion of Ukraine

The post Mustang Panda’s Hodur: Old tricks, new Korplug variant appeared first on WeLiveSecurity

23 March 2022