Security News > 2022 > December

The Decoupling Principle
2022-12-07 12:04

The idea is simple, yet previously not clearly articulated: to ensure privacy, information should be divided architecturally and institutionally such that each entity has only the information they need to perform their relevant function. Architectural decoupling entails splitting functionality for different fundamental actions in a system, such as decoupling authentication from connectivity.

Russian Hackers Spotted Targeting U.S. Military Weapons and Hardware Supplier
2022-12-07 11:58

A state-sponsored hacking group with links to Russia has been linked to attack infrastructure that spoofs the Microsoft login page of Global Ordnance, a legitimate U.S.-based military weapons and hardware supplier. The cybersecurity firm said it discovered 38 domains, nine of which contained references to companies like UMO Poland, Sangrail LTD, DTGruelle, Blue Sky Network, the Commission for International Justice and Accountability, and the Russian Ministry of Internal Affairs.

Taiwan bans state-owned devices from running Chinese platform TikTok
2022-12-07 10:48

Public sector bans of Chinese platform TikTok on the grounds of national security have arisen in both Taiwan and additional US states following last week's ban in South Dakota. Last month, Taiwan's Mainland Affairs Council reportedly said the government has prohibited Chinese-funded corporations from operating online platforms in Taiwan and ByteDance does not operate a branch in Taiwan.

Microsoft Alerts Cryptocurrency Industry of Targeted Cyberattacks
2022-12-07 09:22

Cryptocurrency investment companies are the target of a developing threat cluster that uses Telegram groups to seek out potential victims. "DEV-0139 joined Telegram groups used to facilitate communication between VIP clients and cryptocurrency exchange platforms and identified their target from among the members," the tech giant said.

New Vivaldi version integrates Mastodon into the browser sidebar
2022-12-07 08:00

Vivaldi 5.6 was released today with a Mastodon client integrated directly into the browser's sidebar, seamlessly incorporating the rising social media platform in the browser's interface. [...]

Microsoft: (Cyber) winter is coming as DDoS attack disrupts Russian bank
2022-12-07 07:25

Where's the Night's Watch when you need them? Microsoft has warned Europe to be on alert for cyber attacks from Russia this winter, just as a series of attacks hit Russian organizations –...

Open-source tool for security engineers helps automate access reviews
2022-12-07 05:30

ConductorOne open-sourced their identity connectors in a project called Baton, available on GitHub. Each connector gives developers the ability to extract, normalize, and interact with workforce...

Deal with sophisticated bot attacks: Learn, adapt, improve
2022-12-07 05:00

A computer program known as a "Bot" acts as an agent for a user or another program or mimics human action. Bots are typically used to automate particular tasks so they can be used without specific human instructions.

7 reasons why you must embed trust into the core of your business
2022-12-07 04:30

Achieving that at scale requires trust intelligence: technology, process, workflow, and metrics to measure trust across the business. Stakeholders from across the business must understand how trust is measured and how it should be managed.

Amnesty International Canada claims attack by China-backed forces
2022-12-07 04:29

Threat actors allegedly looking for contacts and monitoring org's future plans The Canadian branch of Amnesty International was the target of an attack it has pinned on a Chinese state-sponsored actor.…