Tag: Cybersecurity

The Pentagon’s next move in expanding zero trust (Defense News)

Andrew Eversden The Pentagon’s top IT office is considering establishing a portfolio management office dedicated to accelerating the adoption of zero-trust cybersecurity architectures, a senior IT official told...

Food Shortages at Dutch Supermarkets After Ransomware Outage (Info Security)

Phil Muncaster There were empty shelves at branches of the Netherlands’ largest supermarket chain recently after a ransomware attack on a key logistics supplier. https://www.infosecurity-magazine.com/news/food-shortages-dutch-supermarkets/

Expert publicly released Chromium-based browsers exploit demonstrated at Pwn2Own 2021 (Security Affairs)

Pierluigi Paganini An Indian security researcher has published a proof-of-concept (PoC) exploit code for a vulnerability impacting Google Chrome and other Chromium-based browsers. https://securityaffairs.co/wordpress/116727/hacking/chromium-based-browsers-exploit.html

Expired certificate caused a Pulse Secure VPN global scale outage (Security Affairs)

Pierluigi Paganini Pulse Secure VPN users were not able to login due to the expiration of a code signing certificate used to digitally sign and verify...

Microsoft is open sourcing CyberBattleSim Enterprise Environment Simulator (Security Affairs)

Pierluigi Paganini Microsoft released as open-source the ‘CyberBattleSim Python-based toolkit which is an Enterprise Environment Simulator. https://securityaffairs.co/wordpress/116702/security/cyberbattlesim-enterprise-environment-simulator.html

LinkedIn confirmed that it was not a victim of a data breach (Security Affairs)

Pierluigi Paganini LinkedIn has formally denied that the recently disclosed data leak was caused by a security breach, data were obtained via web scraping. https://securityaffairs.co/wordpress/116689/data-breach/linkedin-not-data-breach.html

Fitch Ratings: Cyberattacks could pose a material risk to water and sewer utilities (Security Affairs)

Pierluigi Paganini Fitch Ratings is warning that cyberattacks could pose a risk to water and sewer utilities potentially impacting their ability to repay debt. https://securityaffairs.co/wordpress/116680/security/fitch-ratings-risk-water-utilities.html

Is the recent accident at Iran Natanz nuclear plant a cyber attack? (Security Affairs)

Pierluigi Paganini On Sunday, an “accident” occurred in the electricity distribution network at Iran’s Natanz nuclear facility, experts speculate it was caused by a cyberattack. https://securityaffairs.co/wordpress/116668/cyber-warfare-2/iran-accident-natanz-cyberattack.html

(Cybersecurity) Personal data of 1.3 million Clubhouse users leaked online (Security Affairs)

Pierluigi Paganini An SQL database containing the personal data of 1.3 million Clubhouse users was leaked online for free, a few days after LinkedIn and Facebook...

Joker malware infected 538,000 Huawei Android devices (Security Affairs)

Pierluigi Paganini More than 500,000 Huawei users have been infected with the Joker malware after downloading apps from the company’s official Android store. https://securityaffairs.co/wordpress/116643/malware/huawei-store-joker-malware.html

Hackers compromised APKPure client to distribute infected Apps (Security Affairs)

Pierluigi Paganini APKPure, one of the largest alternative app stores, was the victim of a supply chain attack, threat actors compromised client version 3.17.18 to deliver...

UK Firms Suffer Record Number of Cyber-Attacks in Q1 (Info Security)

Phil Muncaster There was no let up for UK businesses in the first three months of 2021, with commercial organizations suffering an 11% year-on-year increase...

Crooks abuse website contact forms to deliver IcedID malware (Security Affairs)

Pierluigi Paganini Microsoft researchers spotted a malware campaign abusing contact forms on legitimate websites to deliver the IcedID malware. https://securityaffairs.co/wordpress/116620/cyber-crime/contact-forms-icedid-malware.html

Facebook tackles deepfake spread and troll farms in latest moderation push (ZD Net, OODA)

Charlie Osborne Facebook has removed a troll farm, spreaders of misinformation, and creators of deepfake images in its latest moderation efforts. https://www.zdnet.com/article/facebook-tackles-deepfake-spread-and-troll-farms-in-latest-moderator-report/

Washington State educational organizations targeted in cryptojacking spree (ZD Net, OODA)

Charlie Osborne The lucrative nature of cryptocurrency means no industry is safe. https://www.zdnet.com/article/washington-state-educational-organizations-targeted-in-cryptojacking-spree/

Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers (Threat Post, OODA)

Tom Spring Cisco says it will not patch three small business router models and one VPN firewall device with critical vulnerabilities. https://threatpost.com/zero-day-bug-soho-routers/165321/