Security News > 2024 > May

US Treasury says NFTs 'highly susceptible' to fraud, but ignored by high-tier criminals
2024-05-30 21:47

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Proofpoint’s CISO 2024 Report: Top Challenges Include Human Error & Risk
2024-05-30 21:00

In Proofpoint's 2024 Voice of the CISO report, the cybersecurity company found that CISOs are dealing with people-centric threats more than ever. According to the survey, more CISOs than ever believe human error is the biggest vulnerability for their organizations; 74% of the CISOs feel this way, up from 60% in 2023.

Pirated Microsoft Office delivers malware cocktail on systems
2024-05-30 20:53

Cybercriminals are distributing a malware cocktail through cracked versions of Microsoft Office promoted on torrent sites. The malware delivered to users includes remote access trojans, cryptocurrency miners, malware downloaders, proxy tools, and anti-AV programs.

Data of 560 million Ticketmaster customers for sale after alleged breach
2024-05-30 20:34

A threat actor known as ShinyHunters is selling what they claim is the personal and financial information of 560 million Ticketmaster customers on the recently revived BreachForums hacking forum for $500,000. Ticketmaster has yet to reply to multiple requests from BleepingComputer to confirm the threat actor's claims and provide more information on this alleged breach.

Malware botnet bricked 600,000 routers in mysterious 2023 attack
2024-05-30 18:56

A malware botnet named 'Pumpkin Eclipse' performed a mysterious destructive event in 2023 that destroyed 600,000 office/home office internet routers offline, disrupting customers' internet access. The incident had a focused impact, affecting a single internet service provider and three models of routers used by the firm: the ActionTec T3200s, ActionTec T3260s, and Sagemcom F5380.

Malware botnet bricked 600,000 routers in mysterious 2023 event
2024-05-30 18:56

A malware botnet named 'Pumpkin Eclipse' performed a mysterious destructive event in 2023 that destroyed 600,000 office/home office internet routers offline, disrupting customers' internet access. The incident had a focused impact, affecting a single internet service provider and three models of routers used by the firm: the ActionTec T3200s, ActionTec T3260s, and Sagemcom F5380.

Euro cops disrupt malware droppers, seize thousands of domains
2024-05-30 18:00

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw
2024-05-30 17:45

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence...

FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine
2024-05-30 16:37

Cloudflare on Thursday said it took steps to disrupt a month-long phishing campaign orchestrated by a Russia-aligned threat actor called FlyingYeti targeting Ukraine. "The FlyingYeti campaign...

Everbridge warns of corporate systems breach exposing business data
2024-05-30 15:45

Everbridge, an American software company focused on crisis management and public warning solutions, notified customers that unknown attackers had accessed files containing business and user data in a recent corporate systems breach. They breached Everbridge's corporate systems using information collected in a previous phishing attack targeting some of its employees.