> TODAY'S SUMMARY (126 articles)
Today's cyber news highlights several significant threats and trends in the cybersecurity landscape:
1. Zohar Pinhasi, CEO of MonsterCloud, has been indicted for allegedly defrauding ransomware victims by secretly paying attackers while significantly overcharging clients for recovery services.
2. A malware campaign named 'Midnight Mimosa' has been uncovered, involving low-cost Android phones pre-installed with residential proxy malware, enabling covert installations of malicious apps.
3. The FBI reported that China-linked hackers compromised email systems of various Southeast Asian government and healthcare organizations, creating a portal for third-party access to stolen data.
4. A critical vulnerability in multiple Atlassian products is currently being exploited, allowing unauthorized access to sensitive files.
5. Cybercriminals have hijacked country-code domains to obtain certificates for impersonating trusted services, while a new phishing campaign targets YouTube creators through fake sponsorship offers.
These incidents reflect ongoing challenges in ransomware, malware distribution, and sophisticated phishing tactics, underscoring the need for heightened cybersecurity measures.
|
// AI-powered summary generated at 20:01
The NCSC now uses 'allow list' and 'deny list' in place of 'whitelist' and 'blacklist'. Emma W explains why...
Why organisations should avoid âblame and fearâ, and instead use technical measures to manage the threat from phishing.
VC firms invested 35% more in cybersecurity startups in North America and Europe in Q4 2024 than a year previously
ThinkCyber's CEO Tim Ward reflects on the challenges that startups face when developing innovative products.
The UKâs information commissioner has warned that all digital firms using childrenâs data must follow the GDPR
Security is a team sport. Whether you're a pentester, bug bounty hunter, student, or just love breaking (and fixing) things, our field thrives on shared knowledge, collaboration, and support. We want
Questions to ask your suppliers that will help you gain confidence in their cyber security.
Worked examples for Operational Technology and Virtualised systems, using the NCSCâs secure design principles
Incident - Law Firm Ransomware Attack, 13 March 2025: Prominent Sydney law firm Brydens Lawyers reveals a serious cyber incident in the wake of a February intrusion into its network. More than 600 gigabytes of data â including case, client, and staff data â was stolen in the incident.
The post Inci...
New guidance to help organisations manage rogue devices and services within the enterprise.
Download the NCSCâs point-of-sale leaflet explaining how new PSTI regulation affects consumers and retailers.
You are likely aware of ASCII Smuggling via Unicode Tags. It is unique and fascinating because many LLMs inherently interpret these as instructions when delivered as hidden prompt injection, and LLMs can also emit them. Then, a few weeks ago, a post on Hacker News demonstrated how Variant Selectors...
If migrating SCADA solutions to the cloud, cyber security must be a key consideration for operational technology organisations.
Can a Software Bill of Materials (SBOM) provide organisations with better insight into their supply chains?
La mairie de Murça a été victime d'une cyberattaque dans la nuit de jeudi, ce qui a bloqué l'accÚs à plusieurs plateformes et services numériques. Les procédures de sécurité internes ont été activées et les autorités compétentes ont été notifiées. La mairie travaille à résoudre les problÚmes causés...
Discover the Research Institute in Trustworthy Inter-connected Cyber-physical Systems.
The âNCSC for Startupsâ alumnus giving identity verification the 'Trust Stamp'
Le district scolaire de Pelham a été victime d'une cyberattaque cette semaine, ce qui a entraßné la mise hors ligne des ordinateurs et des lignes téléphoniques du district pour les deux prochaines semaines. L'attaque a coupé l'accÚs à internet, aux lignes téléphoniques et aux courriels, affectant ai...
Introducing the next chapter of the NCSC research problem book, which aims to inspire research on the biggest impact topics in hardware cyber security.
Andrew A explains what's new in a significant update to the NCSC's flagship cloud guidance.