Cybersecurity News
Russian Govt. Continues Carding Shop Crackdown
Russian authorities have arrested six men accused of operating some of the most active online bazaars for selling stolen payment card data. The crackdown -- the second closure of major card fraud shops by Russian authorities in as many weeks -- comes closely behind Russia's arrest of 14 alleged affiliates of the REvil ransomware gang, and has many in the cybercrime underground asking who might be next.Cybercriminals Swarm Windows Utility Regsvr32 to Spread Malware

3 Tips for Facing the Harsh Truths of Cybersecurity in 2022, Part I

Russian ransomware attacks increased during 2021, joint review finds

Britain, the US and Australia point to growth in ‘sophisticated, high-impact ransomware incidents’
There have been further increases in “sophisticated, high-impact ransomware incidents” coming from Russia and other former Soviet states during 2021, Britain, the US and Australia said in a joint review of cyber-extortion trends.
Universities and schools were one of the top sectors targeted in the UK last year, the National Cyber Security Centre (NCSC) said, as well as businesses, charities, law firms, councils and the NHS. Hackers are increasingly offering services or exploits “for hire”.
Continue reading...MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign

Ex-Gumshoe Nabs Cybercrooks with FBI Tactics

ESET Threat Report T3 2021
A view of the T3 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
The post ESET Threat Report T3 2021 appeared first on WeLiveSecurity
Brute-forcing passwords, ProxyLogon exploits were some of 2021's most popular attack methods
Log4j also became a top pick for exploitation after the discovery of a critical RCE flaw.Lazarus hackers target defense industry with fake Lockheed Martin job offers
The APT has previously masqueraded as Northrop Grumman and BAE Systems.Microsoft Patch Tuesday, February 2022 Edition
Microsoft today released software updates to plug security holes in its Windows operating systems and related software. This month's relatively light patch batch is refreshingly bereft of any zero-day threats, or even scary critical vulnerabilities. But it does fix four dozen flaws, including several that Microsoft says will likely soon be exploited by malware or malcontents.No Critical Bugs for Microsoft February 2022 Patch Tuesday, 1 Zero-Day

China Suspected of News Corp Cyberespionage Attack

US: Your AI has to explain its decisions
No more turning a blind eye to algorithmic bias and discrimination if US lawmakers get their way
The post US: Your AI has to explain its decisions appeared first on WeLiveSecurity
Pay to play PrivateLoader spreads Smokeloader, Redline, Vidar malware
The pay-per-install malware is one of the most popular loaders on the market today.Chinese telecom Hytera charged for allegedly recruiting Motorola employees to steal trade secrets
The firm allegedly conspired with employees to steal digital radio technology.CISA Orders Federal Agencies to Fix Actively Exploited Windows Bug

Medusa Malware Joins Flubot’s Android Distribution Network

LockBit, BlackCat, Swissport, Oh My! Ransomware Activity Stays Strong

IRS To Ditch Biometric Requirement for Online Access
The Internal Revenue Service (IRS) said today it will be transitioning away from requiring biometric data from taxpayers who wish to access their records at the agency's website. The reversal comes as privacy experts and lawmakers have been pushing the IRS and other federal agencies to find less intrusive methods for validating one's identity with the U.S. government online.QuaDream, 2nd Israeli Spyware Firm, Weaponizes iPhone Bug
