Security News > 2024 > February

HPE investigates new breach after data for sale on hacking forum
2024-02-05 18:33

Hewlett Packard Enterprise is investigating a potential new breach after a threat actor put allegedly stolen data up for sale on a hacking forum, claiming it contains HPE credentials and other sensitive information.IntelBroker, the threat actor selling the alleged HPE data, shared screenshots of some of the supposedly stolen HPE credentials but has yet to disclose the source of the information or the method used to obtain it.

AnyDesk revokes signing certs, portal passwords after crooks sneak into systems
2024-02-05 18:30

AnyDesk has copped to an IT security "Incident" in which criminals broke into the remote-desktop software maker's production systems. "We have revoked all security-related certificates and systems have been remediated or replaced where necessary," AnyDesk said.

Belarusian National Linked to BTC-e Faces 25 Years for $4 Billion Crypto Money Laundering
2024-02-05 16:36

A 42-year-old Belarusian and Cypriot national with alleged connections to the now-defunct cryptocurrency exchange BTC-e is facing charges related to money laundering and operating an unlicensed...

Deepfake Fraud
2024-02-05 16:10

B.J. Herbison February 5, 2024 11:36 AM. Was the call recorded? On the call we have a bunch of scammers and one person who says "The deepfakes were great, I was fooled." and sends the money. The "Worried about a phishing email" might be just posturing.

Newest Ivanti SSRF zero-day now under mass exploitation
2024-02-05 15:55

An Ivanti Connect Secure and Ivanti Policy Secure server-side request forgery vulnerability tracked as CVE-2024-21893 is currently under mass exploitation by multiple attackers. The exploitation volume of this particular vulnerability is far greater than that of other recently fixed or mitigated Ivanti flaws, indicating a clear shift in the attackers' focus.

Deepfaked video conference call makes employee send $25 million to scammers
2024-02-05 14:46

A deepfake video conference call paired with social engineering tricks has led to the theft of over US$25 million from a multinational firm, the South China Morning Post has reported. They have been later quelled by a group video conference to which the employee was invited.

Lurie Children's Hospital back to pen and paper after cyberattack
2024-02-05 14:45

Lurie Children's Hospital said it pulled network systems offline as it continues to respond to "a cybersecurity matter" alongside outside experts and law enforcement agencies. "Lurie Children's Hospital said in a statement:"As Illinois' leading provider for pediatric care, our overarching priority is to continue providing safe, quality care to our patients and the communities we serve.

Combined Security Practices Changing the Game for Risk Management
2024-02-05 13:19

A significant challenge within cyber security at present is that there are a lot of risk management platforms available in the market, but only some deal with cyber risks in a very good way. The...

Patchwork Using Romance Scam Lures to Infect Android Devices with VajraSpy Malware
2024-02-05 13:18

The threat actor known as Patchwork likely used romance scam lures to trap victims in Pakistan and India, and infect their Android devices with a remote access trojan called VajraSpy. Slovak...

AnyDesk has been hacked, users urged to change passwords
2024-02-05 12:24

AnyDesk Software GmbH, the German company behind the widely used remote desktop application of the same name, has confirmed they've been hacked and their production systems have been compromised.The statement was published on Friday evening and lacks technical details about the breach.