Security News > 2022 > October

How ransomware gangs operate like legitimate businesses
2022-10-03 19:30

How ransomware gangs operate like legitimate businesses. Ransomware gangs these days operate like businesses with all the personnel, services and subcontractors that make up a legitimate company.

From today, America and UK follow new rules on how they can demand your data from each other
2022-10-03 19:11

The Data Access Agreement, by which the US and UK have agreed how one country can respond to lawful data demands from police and investigators in the other, took effect on Monday. The DAA spells out US and UK obligations under the Clarifying Lawful Overseas Use of Data Act, which the US Congress approved in 2018.

Russian retail chain 'DNS' confirms hack after data leaked online
2022-10-03 18:35

Russian retail chain 'DNS' disclosed yesterday that they suffered a data breach that exposed the personal information of customers and employees. While the firm has not provided details on what information was compromised, it clarified that the hackers didn't steal user passwords and payment card data, as that data isn't stored on their systems.

It's 2058. A quantum computer is just another decade away. Still, you curse Cloudflare
2022-10-03 18:22

Cloudflare is the first major internet infrastructure provider to support post-quantum cryptography for all customers, which, in theory, should protect data if quantum computing ever manages to break today's encryption technologies. Starting today all websites and APIs served through Cloudflare support post-quantum TLS based on the Kyber hybrid key agreement.

Live support service hacked to spread malware in supply chain attack
2022-10-03 17:58

The official installer for the Comm100 Live Chat application, a widely deployed SaaS that businesses use for customer communication and website visitors, was trojanized as part of a new supply-chain attack. Because the trojanized installer used a valid digital signature, antivirus solutions would not trigger warnings during its launch, allowing for a stealthy supply-chain attack.

National Cybersecurity Awareness program 18 years on: Don't click that
2022-10-03 17:30

If you've ever found yourself in an interminable meeting listening to the CISO ramble on about the important role you play in protecting yourself and the company from cyberthreats, you could probably point an accusatory finger in large part at the National Cybersecurity Awareness Month program. To be fair, if you've ever found yourself sitting at your desk, staring at an email that didn't seem right - that seemed a little off - and you decided to just close the message and alert the cybersecurity team, you likely could give a nod of thanks to NCSAM. Every October since 2004, the US Cybersecurity and Infrastructure Security Agency and National Cybersecurity Alliance in public-private cooperation have directed NCSAM in an effort to make organizations and individuals around the world more aware of the myriad cyberthreats out there and how to guard against them.

FBI: We tracked who was printing secret documents to unmask ex-NSA suspect
2022-10-03 17:00

The FBI alleges it then followed the money as it moved from a cryptocurrency exchange to the NSA staffer's personal bank account. Jareh Sebastian Dalke, who was employed at the NSA as an information security systems designer from June 6 to July 1, allegedly began communicating with what he believed to be a foreign agent on July 29, according to a statement from the Department of Justice announcing his arrest in Denver on September 28.

Web browser app mode can be abused to make desktop phishing pages
2022-10-03 16:35

A new phishing technique using Chrome's Application Mode feature allows threat actors to display local login forms that appear as desktop applications, making it easier to steal credentials. Because desktop applications are generally harder to spoof, users are less likely to treat them with the same caution they reserve for browser windows that are more widely abused for phishing.

Comm100 Chat Provider Hijacked to Spread Malware in Supply Chain Attack
2022-10-03 14:35

A threat actor likely with associations to China has been attributed to a new supply chain attack that involves the use of a trojanized installer for the Comm100 Live Chat application to distribute a JavaScript backdoor. Cybersecurity firm CrowdStrike said the attack made use of a signed Comm100 desktop agent app for Windows that was downloadable from the company's website.

Microsoft Exchange server zero-day mitigation can be bypassed
2022-10-03 14:21

Microsoft has shared mitigations for two new Microsoft Exchange zero-day vulnerabilities tracked as CVE-2022-41040 and CVE-2022-41082, but researchers warn that the mitigation for on-premise servers is far from enough. Threat actors are already chaining both of these zero-day bugs in active attacks to breach Microsoft Exchange servers and achieve remote code execution.