Security News > 2022 > August

1 in 3 organizations don’t know if their public cloud data was exfiltrated
2022-08-31 03:30

65.1% of respondents said they currently have data resident in the public cloud. With public cloud adoption having a compound annual growth rate of nearly 26%, it's surprising that respondents haven't yet hardened data security for these assets.

Ransomware gangs’ favorite targets
2022-08-31 03:00

Barracuda released its fourth-annual threat research report which looks at ransomware attack patterns that occurred between August 2021 and July 2022. The number of ransomware attacks increased year-over-year across each of these five industry verticals, and attacks against other industries more than doubled compared to last year's report.

Chinese Hackers Used ScanBox Framework in Recent Cyber Espionage Attacks
2022-08-31 01:53

A months-long cyber espionage campaign undertaken by a Chinese nation-state group targeted several entities with reconnaissance malware so as to glean information about its victims and meet its strategic goals. "The targets of this recent campaign spanned Australia, Malaysia, and Europe, as well as entities that operate in the South China Sea," enterprise security firm Proofpoint said in a published in partnership with PwC. Targets encompass local and federal Australian Governmental agencies, Australian news media companies, and global heavy industry manufacturers which conduct maintenance of fleets of wind turbines in the South China Sea.

Why MDR Has Become Integral to Modern Cybersecurity Strategies is a new ESG Showcase Report Available Now
2022-08-31 00:00

Threats are multiplying in number and morphing in complexity faster than most organizations can adapt. Managed detection and response as a third-party managed service is an approach that allows organizations to keep pace.

Find a security hole in Google's open source and you could bag a $31,337 reward
2022-08-30 22:58

Google has created a bug bounty program that will reward those who find and report vulnerabilities in its open-source projects, thereby hopefully strengthening software supply-chain security. The Open Source Software Vulnerability Rewards Program will pay bug hunters between $100 and $31,337, with the highest payments going to "Unusual or particularly interesting vulnerabilities," according to Googlers Francis Perron, open source security technical program manager, and infosec engineer Krzysztof Kotowicz.

Ukraine takes down cybercrime group hitting crypto fraud victims
2022-08-30 22:20

The National Police of Ukraine took down a network of call centers used by a cybercrime group focused on financial scams and targeting victims of cryptocurrency scams under the guise of helping them recover their stolen funds. The fraudsters behind these illegal call centers were also allegedly involved in scamming citizens of Ukraine and European Union countries interested in cryptocurrency, securities, gold, and oil investments.

Hackers hide malware in James Webb telescope images
2022-08-30 22:08

Threat analysts have spotted a new malware campaign dubbed 'GO#WEBBFUSCATOR' that relies on phishing emails, malicious documents, and space images from the James Webb telescope to spread malware. The malware is written in Golang, a programming language that is gaining popularity among cybercriminals because it is cross-platform and offers increased resistance to reverse engineering and analysis.

Russian streaming platform confirms data breach affecting 7.5M users
2022-08-30 20:15

Russian media streaming platform 'START' has confirmed rumors of a data breach impacting millions of users. Even though a global reset isn't enforced by START, it is recommended that all users change their passwords.

JavaScript bugs aplenty in Node.js ecosystem – found automatically
2022-08-30 18:59

That's where you aim to review source code for likely coding blunders and security holes without actually running it at all. If someone has copied-and-pasted that buggy code into other software components in your company repository, you might be able to find them with a text search, assuming that the overall structure of the code was retained, and that comments and variable names weren't changed too much.

Chinese hackers target Australian govt with ScanBox malware
2022-08-30 17:26

China-based threat actors have been targeting Australian government agencies and wind turbine fleets in the South China Sea by directing select individuals to a fake impersonating an Australian news media outlet. Victims landed on the fraudulent site after receiving phishing emails with enticing lures and received a malicious JavaScript payload from the ScanBox reconnaissance framework.