Security News > 2023 > October

France says Russian state hackers breached numerous critical networks
2023-10-26 16:40

The Russian APT28 hacking group has been targeting government entities, businesses, universities, research institutes, and think tanks in France since the second half of 2021. The Russian hackers have been compromising peripheral devices on critical networks of French organizations and moving away from utilizing backdoors to evade detection.

Everything You Need to Know About Microsoft’s New $5 Billion Investment in Australia
2023-10-26 16:02

Microsoft plans to more than double its cloud computing capacity in Australia over the next two years and expand its support for critical national cyber security and technology skills priorities. Fast-growing demand for cloud computing services across Australia has seen Microsoft announce the injection of AU $5 billion into the market, in a move it says will support Australia's ability to seize the economic and productivity advantages of artificial intelligence.

StripedFly malware framework infects 1 million Windows, Linux hosts
2023-10-26 14:47

A sophisticated cross-platform malware platform named StripedFly flew under the radar of cybersecurity researchers for five years, infecting over a million Windows and Linux systems during that time. Kaspersky discovered the true nature of the malicious framework last year, finding evidence of its activity starting in 2017, with the malware wrongly classified as just a Monero cryptocurrency miner.

Microsoft Warns as Scattered Spider Expands from SIM Swaps to Ransomware
2023-10-26 13:56

The prolific threat actor known as Scattered Spider has been observed impersonating newly hired employees in targeted firms as a ploy to blend into normal on-hire processes and takeover accounts...

Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw
2023-10-26 13:00

Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed flaw called HTTP/2 Rapid Reset, 89 of...

Cloudflare sees surge in hyper-volumetric HTTP DDoS attacks
2023-10-26 13:00

Cloudflare says the number of hyper-volumetric HTTP DDoS attacks recorded in the third quarter of 2023 surpasses every previous year, indicating that the threat landscape has entered a new chapter. A Cloudflare report shared with BleepingComputer reveals that, during Q3 2023, the internet company mitigated thousands of hyper volumetric HTTP DDoS attacks.

Humans are still better than AI at crafting phishing emails, but for how long?
2023-10-26 12:14

Humans are still better at crafting phishing emails compared to AI, but not by far and likely not for long, according to research conducted by IBM X-Force Red. Creating phishing emails: Humans vs. AI. The researchers wanted to see whether ChatGPT is as capable of writing a "Good" phishing email as attackers are.

The Danger of Forgotten Pixels on Websites: A New Case Study
2023-10-26 11:59

While cyberattacks on websites receive much attention, there are often unaddressed risks that can lead to businesses facing lawsuits and privacy violations even in the absence of hacking...

New iLeakage attack steals emails, passwords from Apple Safari
2023-10-26 11:26

Academic researchers created a new speculative side-channel attack they named iLeakage that works on all recent Apple devices and can extract sensitive information from the Safari web browser. [...]

New NSA Information from (and About) Snowden
2023-10-26 11:00

Interesting article about the Snowden documents, including comments from former Guardian editor Ewen MacAskill. As far as he knows, a copy of the documents is still locked in the New York Times office.