Spam Campaign Targeting South Korean Users With GandCrab v4.3 Ransomware

A group of digital attackers are staging a spam email campaign to target South Korean users with GandCrab v4.3 ransomware. On 7 August, researchers at Trend Micro first came across instances of the spam campaign. The attack emails arrived under the gui… Continue reading Spam Campaign Targeting South Korean Users With GandCrab v4.3 Ransomware

Sextortion Scams Using Redacted Phone Numbers to Demand Payment

Sextortion scammers are now using potential targets’ redacted phone numbers in an attempt to trick them into submitting payment. Perhaps after having obtained a list that ties people’s phone numbers and email addresses together, scammers ar… Continue reading Sextortion Scams Using Redacted Phone Numbers to Demand Payment

Man Gets Jail Time for Helping to “Cash Out” Ransomware Payments

A man received a prison sentence for his part in helping to “cash out” ransom payments made by victims of a specific ransomware family. On 13 August, the U.S. Department of Justice (DOJ) announced the sentencing of Raymond Odigie Uadiale, 4… Continue reading Man Gets Jail Time for Helping to “Cash Out” Ransomware Payments

‘Hack the Marine Corps’ Bug Bounty Program Announced by DoD

The U.S. Department of Defense (DoD) and HackerOne together announced the creation of a new bug bounty program called “Hack the Marine Corps.” On 12 August, DoD kicked off its new vulnerability disclosure initiative at DEF CON 26 in Las Veg… Continue reading ‘Hack the Marine Corps’ Bug Bounty Program Announced by DoD

Researchers Showed It’s Possible to Take Over a Network With Malicious Faxes

Researchers demonstrated the feasibility of taking over a enterprise network and abusing that access to exfiltrate data using just a fax number. On 12 August, Yaniv Balmas and Eyal Itkin of Check Point’s malware research team presented their find… Continue reading Researchers Showed It’s Possible to Take Over a Network With Malicious Faxes

Ransomware Strikes Computer Servers of Golfers’ Association

Digital attackers targeted the computer servers of a golfers’ association with ransomware and encrypted files stored on those assets. Staff at the Professional Golfers’ Association of America (PGA) discovered the attack on 7 August. When th… Continue reading Ransomware Strikes Computer Servers of Golfers’ Association

Many Developers Have Yet to Take Responsibility for Code Security, Reveals DevOps Study

A DevOps survey revealed that many developers have yet to take responsibility for the security of the code they produce. According to Checkmarx’s report, “Managing Software Exposure: Time to Fully Embed Security into Your Application Lifecy… Continue reading Many Developers Have Yet to Take Responsibility for Code Security, Reveals DevOps Study

Semiconductor Foundry Notifies Customers of Computer Virus Incident

A semiconductor foundry notified its customers of a computer virus incident that at least partly disrupted its shipping schedule. On 5 August, Taiwan Semiconductor Manufacturing Company, Limited (TSMC) published an update about a computer virus infecti… Continue reading Semiconductor Foundry Notifies Customers of Computer Virus Incident

How the CIS Controls Can Help You Achieve PCI DSS 3.2 Compliance

Compliance with version 3.2 of the Payment Card Industry Data Security Standard (PCI DSS) is a must for organizations that handle, process, transmit and store payment card data. But compliance isn’t always easy to establish or maintain. Indeed, t… Continue reading How the CIS Controls Can Help You Achieve PCI DSS 3.2 Compliance

Three Suspected Members of Computer Crime Group in Custody for Malware Campaigns

Law enforcement personnel have arrested three suspected members of an international computer crime group for their roles in perpetrating malware campaigns against U.S. companies. On 1 August, the Department of Justice (DOJ) announced in a press release… Continue reading Three Suspected Members of Computer Crime Group in Custody for Malware Campaigns