Security News > 2024 > October

Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure
2024-10-03 17:58

Microsoft and the Justice Department have seized over 100 domains used by the Russian ColdRiver hacking group to target United States government employees and nonprofit organizations from Russia...

Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
2024-10-03 17:19

Approximately 5% of all Adobe Commerce and Magento online stores, or 4,275 in absolute numbers, have been hacked in "CosmicSting" attacks. [...]

Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks
2024-10-03 17:00

Google has revealed the various security guardrails that have been incorporated into its latest Pixel devices to counter the rising threat posed by baseband security attacks. The cellular baseband...

Fraudsters imprisoned for scamming Apple out of 6,000 iPhones
2024-10-03 16:27

Two Chinese nationals were sentenced to prison for scamming Apple out of more than $2.5 million after exchanging over 6,000 counterfeit iPhones for authentic ones. [...]

Cloudflare blocks largest recorded DDoS attack peaking at 3.8Tbps
2024-10-03 16:11

During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors, volumetric attacks peaked at 3.8 terabits per second,...

DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks
2024-10-03 16:00

Winter is coming The US Department of Justice and Microsoft have seized 107 websites used by Russian cyberspies in a phishing campaign to steal sensitive information from US government agencies,...

One-Third of UK Teachers Lack Cybersecurity Training, While 34% Experience Security Incidents
2024-10-03 15:40

A third of U.K. teachers have not received cyber security training this year, and only two-thirds of those that did deemed it useful, according to a government poll.

Critical Ivanti Endpoint Manager flaw exploited (CVE-2024-29824)
2024-10-03 15:20

CVE-2024-29824, an unauthenticated SQL Injection vulnerability in Ivanti Endpoint Manager (EPM) appliances, is being exploited by attackers, the Cybersecurity and Infrastructure Security Agency...

The Secret Weakness Execs Are Overlooking: Non-Human Identities
2024-10-03 15:06

For years, securing a company’s systems was synonymous with securing its “perimeter.” There was what was safe “inside” and the unsafe outside world. We built sturdy firewalls and deployed...

Linux malware “perfctl” behind years-long cryptomining campaign
2024-10-03 14:33

A Linux malware named "perfctl" has been targeting Linux servers and workstations for at least three years, remaining largely undetected through high levels of evasion and the use of rootkits. [...]