Security News > 2024 > February

Why We Must Democratize Cybersecurity
2024-02-16 10:50

With breaches making the headlines on an almost weekly basis, the cybersecurity challenges we face are becoming visible not only to large enterprises, who have built security capabilities over the...

Malicious 'SNS Sender' Script Abuses AWS for Bulk Smishing Attacks
2024-02-16 10:49

A malicious Python script known as SNS Sender is being advertised as a way for threat actors to send bulk smishing messages by abusing Amazon Web Services (AWS) Simple Notification Service (SNS)....

U.S. State Government Network Breached via Former Employee's Account
2024-02-16 07:40

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed state government organization's network environment was compromised via an administrator account...

U.S. Government Disrupts Russia-Linked Botnet Engaged in Cyber Espionage
2024-02-16 06:49

The U.S. government on Thursday said it disrupted a botnet comprising hundreds of small office and home office (SOHO) routers in the country that was put to use by the Russia-linked APT28 actor to...

Gmail & Yahoo DMARC rollout: When cyber compliance gives a competitive edge
2024-02-16 06:00

As Gmail and Yahoo take steps to enforce stricter email authentication, organizations that are proactive in their DMARC compliance will not only enhance their security posture but also gain a significant advantage: improved email deliverability translates into better engagement rates, bolstering sales and revenue. Thus, DMARC compliance is not merely about meeting a standard but seizing an opportunity to stand out in a crowded digital marketplace.

Cybersecurity sectors adjust as DDoS attacks reach new heights
2024-02-16 05:00

In this Help Net Security video, Andrey Slastenov, Head of Security Department at Gcore, discusses the findings of their latest report that provide insights into the current state of the DDoS protection market and cybersecurity trends. The maximum attack power rose from 800 Gbps to 1.6 Tbps. UDP floods constitute 62% of DDoS attacks.

Physical security is becoming a top priority in building design
2024-02-16 04:30

A decade ago, the top three priorities for building design were safety, materials used, and reliability, with security absent from the top three. Despite the industry's expressed commitment to making security a fundamental part of design, visible challenges persist in the integration of physical security in building design.

Cyber threats cast shadow over 2024 elections
2024-02-16 04:00

Considering that 2024 is a historic year for elections - with an estimated half of the world's population taking part in democratic votes - this high threat of cyber interference has significant implications for global free society, threatening to undermine confidence in voting processes or - at worst - even alter electoral outcomes, according to Tidal Cyber. A concerning 27% of countries with 2024 national elections face the highest threat levels, facing multiple priority adversary groups and many state-backed groups associated with priority adversary countries.

Quest Diagnostics pays $5M after mixing patient medical data with hazardous waste
2024-02-16 01:20

Quest Diagnostics has agreed to pay almost $5 million to settle allegations it illegally dumped protected health information - and hazardous waste - at its facilities across California. Quest takes patient privacy and the protection of the environment very seriously and has made significant investments to implement industry best practices to ensure hazardous waste, medical waste, and confidential patient information are disposed of properly.

Zeus, IcedID malware gangs leader pleads guilty, faces 40 years in prison
2024-02-15 23:05

Ukrainian national Vyacheslav Igorevich Penchukov, one of the heads of the notorious JabberZeus cybercrime gang, has pleaded guilty to charges related to his leadership roles in the Zeus and IcedID malware groups. The U.S. Department of Justice first charged him in 2012 for his involvement in the Zeus malware operation and the theft of millions of dollars using personal identification numbers, bank account numbers, credentials, and other sensitive info stolen from infected devices.