Article Summary : π A new phishing kit called Tycoon 2FA has been discovered by the cybersecurity community, utilizing the Adversary-in-The-Middle (AiTM) technique. π The kit has been active since at least August 2023 and has become one of the most prevalent AiTM phishing kits. π Tycoon 2FA operates…
Category: Cyber Security News
Article Summary : πΉ A U.S. senator is raising questions about a report that $7.5 million was stolen by cyber thieves from the Department of Health and Human Services (HHS) last year. πΉ The hackers took over email accounts of grantees and tricked HHS into sending funds to their bank accounts. πΉ Sen….
Article Summary: π Organizations in the United Kingdom that work transparently with regulators and cybersecurity officials after a data breach will receive leniency in penalties and fines. π The Information Commissioner’s Office released new guidance detailing the legal framework for assessing penal…
Article Summary: πΉ The American Hospital Association is advocating for Change Healthcare to be solely responsible for notifying patients in the event of a breach. πΉ HHS OCR is investigating the cyberattack on Change Healthcare and UnitedHealth Group to determine if PHI was compromised. πΉ AHA is seek…
Article Summary: π Academic researchers developed ZenHammer, the first variant of the Rowhammer DRAM attack that works on CPUs based on recent AMD Zen microarchitecture. π‘οΈ AMD Zen chips and DDR5 RAM modules were previously considered less vulnerable to Rowhammer, but the latest findings challenge t…
Article Summary: π CISA and the FBI urge technology manufacturing companies to review software for SQL injection vulnerabilities before shipping. π‘οΈ SQL injection attacks exploit security vulnerabilities to access, manipulate, or delete sensitive data. π Parameterized queries with prepared statement…
Article Summary : π Despite the critical role of APIs, the vast majority of commercial decision-makers are ignoring the burgeoning security risk for businesses, according to Fastly. π APIs have become a favorite gateway for cybercriminals, with 84% of respondents admitting to not having advanced API…
Article Summary : π Another city in Florida, St. Cloud, has been hit by a ransomware attack affecting city services. π¨ City departments are operating as best as possible until the issue is resolved. π³ In-person payments for Parks and Recreation events are temporarily cash-only. π Police and Fire Res…
Article Summary: π Scams targeting consumers are increasing in complexity and volume, with scammers using generative AI and other technologies to create convincing fraud opportunities. π Despite a decrease in individual scam reports, the total money lost has increased, indicating scammers are using…
Article Summary: πΉ Russian state-backed hackers likely behind recent attacks on four small Ukrainian internet providers, disrupting operations for over a week. πΉ Group known as Solntsepek claimed responsibility for incidents, believed to be behind 2023 cyberattack on Ukraineβs largest telecommunicat…
Article Summary: π Customers of bankrupt crypto platform BlockFi have been targeted with a convincing phishing email impersonating the platform, resulting in millions being stolen in just five days. π¨ The latest BlockFi phishing campaign is well-made, impersonating the BlockFi team with no typos and…
Article Summary: π΅οΈββοΈ Police in Romania and Spain busted a cyber-fraud gang involved in fake ads and BEC scams. π° They seized cash, gold, electronic devices, and SIM cards from the gang’s locations in Romania. π The gang operated internationally, with most victims in Spain. π» The gang made millions…
Article Summary: π A United Nations panel is investigating 58 cyberattacks by North Korean hackers, resulting in $3 billion in revenue over six years. π΅οΈ The cyberthreat actors targeted defense companies, software supply chains, and cryptocurrency hacks. π° Stolen funds were used for technological ad…
Article Summary: π Another major airline company, Air Europa, has suffered a cyberattack resulting in sensitive customer data leaking to hackers. π The incident was discovered in October 2023 and confirmed by International Consolidated Airlines Group (IAG). π§ Affected individuals were notified that…
Article Summary : πΉ APT29, a Russian hacking group linked to SVR, is targeting political parties in Germany with phishing attacks. πΉ The group is using a backdoor malware named WineLoader to gain remote access to compromised devices. πΉ WineLoader has been used in previous attacks by APT29 and featur…