Security News > 2023 > March

Russia bans private messaging apps owned by foreign entities
2023-03-01 16:27

Russia's internet watchdog agency Roskomnadzor is warning that today is the first day that laws banning the use of many foreign private messaging applications in the country come into force. The law is "On information, information technology, and information protection," specifically Part 8-10 of Article 10, which prohibits Russian organizations from using information exchange systems owned by foreign entities.

Microsoft fixes bug behind apps not installing during provisioning
2023-03-01 15:41

Microsoft has addressed a Windows 11 22H2 known issue causing some apps not to be installed during Windows provisioning. "Using provisioning packages on Windows 11, version 22H2 might not install all expected apps," the company explained in a new update to the Windows Release Health dashboard.

How to Prevent Callback Phishing Attacks on Your Organization
2023-03-01 15:05

According to the cyber intelligence report from Agari, hybrid phishing attacks have increased by 625%. One of the most damaging is callback phishing - also often known as a TOAD. First appearing in the wild in March 2021 as BazarCall, the attacks were mounted to install ransomware on corporate networks. Low levels of cybersecurity awareness can be the root cause of successful cyberattacks, especially attacks such as Callback phishing.

Google Cloud Platform allows data exfiltration without a (forensic) trace
2023-03-01 14:43

Attackers can exfiltrate company data stored in Google Cloud Platform storage buckets without leaving obvious forensic traces of the malicious activity in GCP's storage access logs, Mitiga researchers have discovered. "In normal usage, files inside storage objects are read multiple times a day as part of day-to-day activity of the organization," Mitiga cloud incident responder Veronica Marinov noted.

Cybercriminals Targeting Law Firms with GootLoader and FakeUpdates Malware
2023-03-01 14:02

Six different law firms were targeted in January and February 2023 as part of two disparate threat campaigns distributing GootLoader and FakeUpdates malware strains. GootLoader, active since late 2020, is a first-stage downloader that's capable of delivering a wide range of secondary payloads such as Cobalt Strike and ransomware.

Fooling a Voice Authentication System with an AI-Generated Voice
2023-03-01 12:06

A reporter used an AI synthesis of his own voice to fool the voice authentication system for Lloyd’s Bank.

DNS abuse: Advice for incident responders
2023-03-01 11:47

What DNS abuse techniques are employed by cyber adversaries and which organizations can help incident responders and security teams detect, mitigate and prevent them? The DNS Abuse Techniques Matrix published by FIRST provides answers. Among its many special interest groups is the DNS Abuse SIG, which compiled the DNS Abuse Techniques Matrix.

BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11
2023-03-01 11:32

A stealthy Unified Extensible Firmware Interface bootkit called BlackLotus has become the first publicly known malware capable of bypassing Secure Boot defenses, making it a potent threat in the cyber landscape. "This bootkit can run even on fully up-to-date Windows 11 systems with UEFI Secure Boot enabled," Slovak cybersecurity company ESET said in a report shared with The Hacker News.

CISOs Are Stressed Out and It's Putting Companies at Risk
2023-03-01 11:30

CISOs at small to midsize businesses with teams of five employees or fewer were surveyed to better understand how work-related stress is impacting CISOs - from their ability to do their job and lead their team to how it's affecting their own professional outlook and personal life. According to the report, 94% of CISOs reported being stressed at work, with 65% confiding that work-stress levels compromised their ability to protect their organizations.

Twitter is down with users seeing "Welcome to Twitter" screen
2023-03-01 10:45

We and our store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised ads and content, ad and content measurement, and audience insights, as well as to develop and improve products. With your permission we and our partners may use precise geolocation data and identification through device scanning.