Security News

US Says Agencies Largely Fended Off Latest Russian Hack
2021-05-30 14:19

The White House says it believes U.S. government agencies largely fended off the latest cyberespionage onslaught blamed on Russian intelligence operatives, saying the spear-phishing campaign should not further damage relations with Moscow ahead of next month's planned presidential summit. The revelation of a new spy campaign so close to the June 16 summit between President Joe Biden and Russian counterpart Vladimir Putin adds to the urgency of White House efforts to confront the Kremlin over aggressive cyber activity that criminal indictments and diplomatic sanctions have done little to deter.

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents
2021-05-29 01:34

Cybersecurity researchers have disclosed two new attack techniques on certified PDF documents that could potentially enable an attacker to alter a document's visible content by displaying malicious content over the certified content without invalidating its signature. "The attack idea exploits the flexibility of PDF certification, which allows signing or adding annotations to certified documents under different permission levels," said researchers from Ruhr-University Bochum, who have systematically analyzed the security of the PDF specification over the years.

Russian gang behind SolarWinds hack returns with phishing attack disguised as mail from US aid agency
2021-05-28 07:57

Nobelium, the Russia-aligned gang identified as the perpetrators of the supply chain attack on SolarWinds' Orion software, has struck again, Microsoft vice president Tom Burt in a blogpost Thursday. Burt's post says the attacks saw Nobelium gain access to accounts on the email marketing service "Constant Contact" operated by The United States Agency for International Development.

US Pipelines Ordered to Increase Cyber Defenses After Hack
2021-05-27 14:24

U.S. pipeline operators will be required for the first time to conduct a cybersecurity assessment under a Biden administration directive in response to the ransomware hack that disrupted gas supplies in several states this month. The Transportation Security Administration directive being issued Thursday will also mandate that the owners and operators of the nation's pipelines report any cyber incidents to the federal government and have a cybersecurity coordinator available at all times to work with authorities in the event of an attack like the one that shut down Colonial Pipeline.

Fujitsu SaaS Hack Sends Govt. of Japan Scrambling
2021-05-27 13:56

Threat actors have stolen files from several official government agencies of Japan by hacking into Fujitsu's software-as-a-service platform and gaining access to its systems. ProjectWEB is a a cloud-based enterprise collaboration and file-sharing platform that Fujitsu has operated since the mid-2000s, and which a number of agencies within the Japan government currently use.

US announces new security directive after critical pipeline hack
2021-05-27 13:48

The US Department of Homeland Security has announced new pipeline cybersecurity requirements after the largest fuel pipeline in the United States was forced to shut down operations in early May following a ransomware attack. The new security directive requires critical pipeline owners and operators to report any confirmed and potential cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency.

The Story of the 2011 RSA Hack
2021-05-27 11:41

Banks use such devices with "Whales" and "Corporates" as well as Jo Average and her personal bank/cheque account. The banks actually do not care as others have noted for years, they have "Externalised the risk" and done so "At the lowest possible cost".

Japanese government agencies suffer data breaches after Fujitsu hack
2021-05-27 07:21

Offices of multiple Japanese agencies were breached via Fujitsu's "ProjectWEB" information sharing tool. Fujitsu also said that attackers had gained unauthorized access to projects that used ProjectWEB, and stolen proprietary data.

Hack Prompts New Security Regulations for US Pipelines
2021-05-25 19:32

The federal government will issue cybersecurity regulations in the coming days for U.S. pipeline operators following a ransomware attack that led to fuel shortages across much of the Eastern Seaboard. The Transportation Security Administration, which oversees the nation's network of pipelines, is expected to issue a security directive this week that will address some of the issues raised by the Colonial Pipeline shutdown, a U.S. official said Tuesday.

Hack, Disinform, Deny: Russia's Cybersecurity Strategy
2021-05-25 03:31

The term "Hacker" has almost become synonymous with Russia. Russia has for decades been a breeding ground for computer experts.