Security News

US and allies officially accuse China of Microsoft Exchange attacks
2021-07-19 11:49

US and allies, including the European Union, the United Kingdom, and NATO, are officially blaming China for this year's widespread Microsoft Exchange hacking campaign. The Biden administration attributes "With a high degree of confidence that malicious cyber actors affiliated with PRC's MSS conducted cyber espionage operations utilizing the zero-day vulnerabilities in Microsoft Exchange Server disclosed in early March 2021.".

Facebook Suspends Accounts Used by Iranian Hackers to Target US Military Personnel
2021-07-18 22:59

Facebook on Thursday disclosed it dismantled a "Sophisticated" online cyber espionage campaign conducted by Iranian hackers targeting about 200 military personnel and companies in the defense and aerospace sectors in the U.S., U.K., and Europe using fake online personas on its platform. The social media giant pinned the attacks to a threat actor known as Tortoiseshell based on the fact that the adversary used similar techniques in past campaigns attributed to the threat group, which was previously known to focus on the information technology industry in Saudi Arabia, suggesting an apparent expansion of malicious activity.

Kaseya ransomware attack should be a wake-up call to all of us, expert says
2021-07-16 20:40

Thousands of small- and medium-sized businesses were affected, just because they trusted their suppliers. How can companies protect against this sort of breach?

US govt offers $10 million reward for tips on nation-state hackers
2021-07-16 18:46

The other is offering a reward of up to $10 million for information on operations conducted by actors working for a foreign government. On Thursday, the U.S. Department of State announced that its Rewards for Justice program now incentivize reports of foreign malicious activity against U.S. critical infrastructure.

Wanted: State-backed bandits planning cyberattacks on US infrastructure. Reward: $10m
2021-07-16 16:30

The US is offering a $10m reward to anyone who dobs in digital outlaws responsible for foreign government-backed cyberattacks on critical national infrastructure such as pipelines, power grids, and communication networks. The cash incentive is part of the US State Department's Rewards for Justice programme and the ongoing war on cybercrime that has in recent months crippled fuel pipelines and meat production.

Facebook: Iranian Hackers Target Military, Aerospace Entities in the US
2021-07-15 17:27

Recent activity that Facebook associated with the group focused on military personnel, defense organizations, and aerospace entities primarily in the United States and, to a lesser extent, the U.K. and Europe, showing an escalation of the group's cyberespionage activities. Today, Facebook revealed that it took action against similar attacks from the Iranian hacking group, which leveraged its online platform to lure victims into downloading malware.

Regulating facial recognition technology? It's the 'Wild West out there,' says US law boffin
2021-07-15 14:16

The role of facial-recognition technology was put under the microscope earlier this week after the US House Committee on the Judiciary heard evidence about how it's used by law enforcement agencies. Dr Cedric Alexander, a former member of President Barack Obama's Task Force on 21st Century Policing, underlined the minefield facing lawmakers by laying out how, on the one hand, FRT can promote justice and "Even save lives" but not if it means sacrificing constitutional rights.

US to Seek Global Rules on AI misuse, Blinken Says
2021-07-14 08:30

The United States will seek global rules on how to prevent misuse of artificial intelligence, Secretary of State Antony Blinken said Tuesday, as he renewed warnings against Russia over hacking. Speaking at a conference on emerging technologies, the top US diplomat voiced alarm that a growing number of authoritarian states led by China are using the internet as well as new technologies to curb dissent and exert greater control.

Hackers use new SolarWinds zero-day to target US Defense orgs
2021-07-13 23:54

China-based hackers actively target US defense and software companies using a vulnerability in the SolarWinds Serv-U FTP server. Today, SolarWinds released a security update for a zero-day vulnerability in Serv-U FTP servers that allow remote code execution when SSH is enabled.

Hackers used SolarWinds zero-day bug to target US Defense orgs
2021-07-13 23:54

China-based hackers actively target US defense and software companies using a vulnerability in the SolarWinds Serv-U FTP server. Today, SolarWinds released a security update for a zero-day vulnerability in Serv-U FTP servers that allow remote code execution when SSH is enabled.