> TODAY'S SUMMARY (126 articles)
Today's cyber news highlights several significant threats and trends in the cybersecurity landscape:
1. Zohar Pinhasi, CEO of MonsterCloud, has been indicted for allegedly defrauding ransomware victims by secretly paying attackers while significantly overcharging clients for recovery services.
2. A malware campaign named 'Midnight Mimosa' has been uncovered, involving low-cost Android phones pre-installed with residential proxy malware, enabling covert installations of malicious apps.
3. The FBI reported that China-linked hackers compromised email systems of various Southeast Asian government and healthcare organizations, creating a portal for third-party access to stolen data.
4. A critical vulnerability in multiple Atlassian products is currently being exploited, allowing unauthorized access to sensitive files.
5. Cybercriminals have hijacked country-code domains to obtain certificates for impersonating trusted services, while a new phishing campaign targets YouTube creators through fake sponsorship offers.
These incidents reflect ongoing challenges in ransomware, malware distribution, and sophisticated phishing tactics, underscoring the need for heightened cybersecurity measures.
|
// AI-powered summary generated at 20:01
New advice on implementing high-risk and ‘break-glass’ accesses in cloud services.
Why small organisations need to manage their private branch exchange (PBX) telephone networks.
Incident - Law Firm Ransomware Attack, 13 March 2025: Prominent Sydney law firm Brydens Lawyers reveals a serious cyber incident in the wake of a February intrusion into its network. More than 600 gigabytes of data – including case, client, and staff data – was stolen in the incident.
The post Inci...
Non-email sending (parked) domains can be used to generate spam email, but they're easy to protect.
How operators of critical national infrastructure (CNI) can use NCSC guidance and blogs to secure their internet-facing services.
You are likely aware of ASCII Smuggling via Unicode Tags. It is unique and fascinating because many LLMs inherently interpret these as instructions when delivered as hidden prompt injection, and LLMs can also emit them. Then, a few weeks ago, a post on Hacker News demonstrated how Variant Selectors...
Why it's important to protect the interfaces used to manage your infrastructure, and some recommendations on how you might do this.
Explaining the forthcoming NCSC Technology Assurance Principles.
La mairie de Murça a été victime d'une cyberattaque dans la nuit de jeudi, ce qui a bloqué l'accès à plusieurs plateformes et services numériques. Les procédures de sécurité internes ont été activées et les autorités compétentes ont été notifiées. La mairie travaille à résoudre les problèmes causés...
Although the UK has not experienced severe cyber attacks in relation to Russia’s invasion of Ukraine, now is not the time for complacency.
Jeremy B explains how the NCSC will help organisations plan their migration to PQC.
Le district scolaire de Pelham a été victime d'une cyberattaque cette semaine, ce qui a entraîné la mise hors ligne des ordinateurs et des lignes téléphoniques du district pour les deux prochaines semaines. L'attaque a coupé l'accès à internet, aux lignes téléphoniques et aux courriels, affectant ai...
For large, complex firms struggling with the prescriptiveness of Cyber Essentials, ‘Pathways’ will provide a new route to certification.
Introducing a new set of NCSC principles to strengthen the resilience of organisations' cloud backups from ransomware attackers.
Le comté de Union a détecté une attaque par ransomware sur son réseau informatique le 13 mars 2025, entraînant l'accès non autorisé et le vol de certaines données, principalement liées aux forces de l'ordre, aux affaires judiciaires et aux services du comté. Les informations compromises incluent pot...
How to protect your backups that are stored in the public cloud.
Horizon Behavioral Health a subi une faille de sécurité informatique, une attaque de ransomware, entre le 13 et le 16 mars 2025, qui a pu donner accès à des informations personnelles de ses patients, notamment des informations démographiques et des données relatives aux assurances.
Whittaker & Company experienced a security incident involving unauthorized access to its computer network, resulting in the theft of personal information. The breach occurred between February 28, 2025, and March 13, 2025. The attack was claimed by Spacebears on March 20th.
ISACA London Chapter members demand e-voting system investigation over security and privacy concerns
Union County, Pennsylvania suffered a ransomware attack on March 13, 2025, which resulted in unauthorized access to personal information.