Security News > 2023 > February

US teases more China tech sanctions, this time to deflate balloon-makers
2023-02-10 06:31

The Chinese surveillance balloon that drifted across the US last week looks set to spark a new round of sanctions against Middle Kingdom tech firms. Ned Price, the State Department spokesperson said on Thursday, "We're exploring taking action against PRC entities linked to the PLA that supported the balloon's incursion into US airspace."

The dangers of unsupported applications
2023-02-10 05:00

Of course, it's impossible to completely protect your business if you are running outdated systems or using unsupported applications. Unsupported applications and systems present an inescapable risk: critical security patches or updates can't - or won't - be provided and/or implemented.

An email attack can end up costing you over $1 million
2023-02-10 04:30

75% of the organizations had fallen victim to at least one successful email attack in the last 12 months, with those affected facing average potential costs of more than $1 million for their most expensive attack, according to a new Barracuda Networks report. 23% said that the cost of email attacks has risen dramatically over the last year.

Australia gives made-in-China CCTV cams the boot
2023-02-10 04:28

Australia's Defence Department removed all Chinese manufactured surveillance cameras after an audit detailed the number of Hikvision and Dahua devices installed in various government facilities. In an impromptu interview on Friday, deputy prime minister and minister of defence Richard Marles revealed that all the relevant Chinese-manufactured Defence department cameras had been removed.

Reddit Suffers Security Breach Exposing Internal Documents and Source Code
2023-02-10 04:28

Popular social news aggregation platform Reddit has disclosed that it was the victim of a security incident that enabled unidentified threat actors to gain unauthorized access to internal documents, code, and some unspecified business systems. The company blamed it on a "Sophisticated and highly-targeted phishing attack" that took place on February 5, 2023, targeting its employees.

Endpoint security getting easier, but most organizations lack tool consolidation
2023-02-10 04:00

IT and security teams are consolidating management and security functions to help better deliver new applications to end users, improve regulatory compliance, and reduce cyberattacks resulting from poor coordination between endpoint security and management teams, according to Syxsense. A key report finding indicates that unmanaged device usage continues to increase, with most organizations having endpoint security blind spots - only 43% of respondents claim to be actively monitoring 75% or more of endpoints.

Romance scammers' favorite lies cost victims $1.3B last year
2023-02-10 03:28

Do. It. Romance scams cost victims at least $1.3 billion in 2022, according to the US Federal Trade Commission's latest numbers. The most common lie that scammers told their marks is that they, or someone close to them, is sick, hurt or in jail, according to more than 8,000 romance scams reported to the FTC that cost consumers' money.

Reddit reveals security incident that looks more SNAFU than TIFU
2023-02-10 01:29

Colourful web forum Reddit has revealed it has suffered a security breach. Here's what we know Reddit's founding engineer and CTO "KeyserSosa" - aka Christopher Slowe - explained that late on February 5th "We became aware of a sophisticated phishing campaign that targeted Reddit employees."

Hackers breach Reddit to steal source code and internal data
2023-02-09 22:04

Reddit suffered a cyberattack Sunday evening, allowing hackers to access internal business systems and steal internal documents and source code. The company says the hackers used a phishing lure targeting Reddit employees with a landing page impersonating its intranet site.

Hackers use fake crypto job offers to push info-stealing malware
2023-02-09 21:34

A campaign operated by Russian threat actors uses fake job offers to target Eastern Europeans working in the cryptocurrency industry, aiming to infect them with a modified version of the Stealerium malware named 'Enigma. The attacks start with an email pretending to be a job offer with fake cryptocurrency interviews to lure their targets.