> TODAY'S SUMMARY (126 articles)
Today's cyber news highlights several significant threats and trends in the cybersecurity landscape:
1. Zohar Pinhasi, CEO of MonsterCloud, has been indicted for allegedly defrauding ransomware victims by secretly paying attackers while significantly overcharging clients for recovery services.
2. A malware campaign named 'Midnight Mimosa' has been uncovered, involving low-cost Android phones pre-installed with residential proxy malware, enabling covert installations of malicious apps.
3. The FBI reported that China-linked hackers compromised email systems of various Southeast Asian government and healthcare organizations, creating a portal for third-party access to stolen data.
4. A critical vulnerability in multiple Atlassian products is currently being exploited, allowing unauthorized access to sensitive files.
5. Cybercriminals have hijacked country-code domains to obtain certificates for impersonating trusted services, while a new phishing campaign targets YouTube creators through fake sponsorship offers.
These incidents reflect ongoing challenges in ransomware, malware distribution, and sophisticated phishing tactics, underscoring the need for heightened cybersecurity measures.
|
// AI-powered summary generated at 20:01
Why trying to avoid trusting the KMS doesn't make sense (and other common misconceptions).
Avoiding common problems when moving to the cloud.
Lors de l’assemblée générale de Cybermalveillance.gouv.fr qui s’est tenue le 12 mars, Florence Puybareau, directrice du Clusif, a été désignée, pour le Clusif, membre titulaire du conseil d’administration. Elle y représente le collège des utilisateurs. Ce mandat, d’une durée de deux ans, est désorma...
The 'Motivating Jenny' project is helping to change the conversation about security in software development.
New guidance from the NCSC helps system and risk owners plan their migration to post-quantum cryptography (PQC).
Mandiant revealed that Chinese espionage actor UNC3886 has deployed modified versions of the TinyShell backdoor across multiple Juniper OS routers
A new collection of resources from the NCSC can help take your supply chain knowledge to the next level
A new paper from the ONCD explores how metrics can influence markets to improve the cyber security ecosystem.
Why now? Artificial intelligence is rapidly transforming industries, and security testing is no exception. At PortSwigger, we’ve always been driven by innovation, but we don’t chase trends for the sak
The NCSC's Chief Executive Ciaran Martin outlines why the UK needs a National Cyber Security Centre.
An update on the work to make Principles Based Assurance (PBA) usable in practice.
Microsoft has fixed seven zero-days this Patch Tuesday, including one not currently being actively exploited
Revised principles will help people make the right security decisions when developing systems with AI/ML components.
NCSC CEO Felicity Oswald shares reflections on keeping the 2024 General Election safe.
Traced Mobile Security co-founder Benedict Jones describes how 'NCSC for Startups' helped evolve his business.
New guidelines will help developers make informed decisions about the design, development, deployment and operation of their AI systems.
Trial project makes vulnerability scanning easier.
Launching a new Industry Assurance scheme aimed at helping the UK’s small organisations.
ACD 2.0 aims to build the next generation of services in partnership with industry and academia.
Tips to help you secure and reduce interactive access to your cloud infrastructure.