The phone call is the new phishing email

Voice-based phishing was at the root of multiple attack sprees Mandiant responded to last year, reflecting a concerning shift in tactics.

The post The phone call is the new phishing email appeared first on CyberScoop.

Continue reading The phone call is the new phishing email

3.7 Million Telehealth Patients Allegedly Affected By Two Recent Breaches

He hasn’t attracted much attention or media coverage yet, and he doesn’t have any leak site or Telegram account. However, those reporting breaches involving patient data should note a threat actor known as “Stuckin2019” (or simp… Continue reading 3.7 Million Telehealth Patients Allegedly Affected By Two Recent Breaches

Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack

Hackers published a malicious scanner release and replaced tags to point to information-stealer malware.
The post Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack appeared first on SecurityWeek.
Continue reading Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack

Apiiro introduces AI Threat Modeling to identify risks before code exists

Apiiro has announced AI Threat Modeling, a new capability within Apiiro Guardian Agent that automatically generates architecture-aware threat models to identify security and compliance risks before code exists. AI Threat Modeling allows enterprises to … Continue reading Apiiro introduces AI Threat Modeling to identify risks before code exists

Hackers target schools, towns in alarming attacks. Why aren’t more using New Jersey’s MS-ISAC ybersecurity service?

If you’re asking, “What MS-ISAC service?”, you’re not alone. Brianna Kudisch reports: A nationwide data breach exposing millions of K-12 students’ information, including kids in Cranford and Millburn. […] In November… Continue reading Hackers target schools, towns in alarming attacks. Why aren’t more using New Jersey’s MS-ISAC ybersecurity service?

AU: Fairfield Council obtains injunction against unknown threat actors in ransomware incident

Anthony Segaert reports: A western Sydney council is communicating with anonymous hackers by sending Dropbox links into a chatroom, after it suffered a major data breach. In October last year, Fairfield Council’s servers – which contained personal, fin… Continue reading AU: Fairfield Council obtains injunction against unknown threat actors in ransomware incident

Anvilogic’s Blueprints replaces SOAR complexity with natural language security automation

Anvilogic has launched Blueprints, a workflow automation capability that captures expert analyst practices and turns them into scalable, repeatable workflows across security teams. Instead of requiring specialized engineers to build and maintain code, … Continue reading Anvilogic’s Blueprints replaces SOAR complexity with natural language security automation