Security News > 2024 > October

North Korean govt hackers linked to Play ransomware attack
2024-10-30 15:55

The North Korean state-sponsored hacking group tracked as 'Andariel' has been linked to the Play ransomware operation, using the RaaS to work behind the scenes and evade sanctions. [...]

North Korean Group Collaborates with Play Ransomware in Significant Cyber Attack
2024-10-30 15:44

Threat actors in North Korea have been implicated in a recent incident that deployed a known ransomware family called Play, underscoring their financial motivations. The activity, observed between...

Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info
2024-10-30 15:12

If you're gonna come at the mouse, you need to be better at hiding your tracks A disgruntled ex-Disney employee has been arrested and charged with hacking his former employer's systems to alter...

Android malware "FakeCall" now reroutes bank calls to attackers
2024-10-30 14:50

A new version of the FakeCall malware for Android hijacks outgoing calls from a user to their bank, redirecting them to the attacker's phone number instead. [...]

Simson Garfinkel on Spooky Cryptographic Action at a Distance
2024-10-30 14:48

Excellent read. One example: Consider the case of basic public key cryptography, in which a person’s public and private key are created together in a single operation. These two keys are...

Simpson Garfinkel on Spooky Cryptographic Action at a Distance
2024-10-30 14:48

Excellent read. One example: Consider the case of basic public key cryptography, in which a person’s public and private key are created together in a single operation. These two keys are...

Ransomware hits web hosting servers via vulnerable CyberPanel instances
2024-10-30 14:19

A threat actor – or possibly several – has hit approximately 22,000 vulnerable instances of CyberPanel and encrypted files on the servers running it with the PSAUX and other ransomware. The PSAUX...

Hackers steal 15,000 cloud credentials from exposed Git config files
2024-10-30 14:00

A global large-scale dubbed "EmeraldWhale" exploited misconfigured Git configuration files to steal over 15,000 cloud account credentials from thousands of private repositories. [...]

FBI: Upcoming U.S. general election fuel multiple fraud schemes
2024-10-30 13:44

The Federal Bureau of Investigation (FBI) is warning of multiple schemes taking advantage of the upcoming U.S. general election to scam people out of their money or personal data. [...]

Opera Browser Fixes Big Security Hole That Could Have Exposed Your Information
2024-10-30 13:05

A now-patched security flaw in the Opera web browser could have enabled a malicious extension to gain unauthorized, full access to private APIs. The attack, codenamed CrossBarking, could have made...