Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys

A newly spotted campaign is leveraging BPL sideloading and other uncommon tricks to deliver the IDAT Loader (aka HijackLoader) malware and prevent its detection. The campaign Spotted by Kroll’s incident responders and analyzed by the company’s Cy… Continue reading Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys

Arrests in $400M SIM-Swap Tied to Heist at FTX?

Three Americans were charged this week with stealing more than $400 million in a November 2022 SIM-swapping attack. The U.S. government did not name the victim organization, but there is every indication that the money was stolen from the now-defunct cryptocurrency exchange FTX, which had just filed for bankruptcy on that same day. Continue reading Arrests in $400M SIM-Swap Tied to Heist at FTX?

Kroll SIM-swap attack: FTX, BlockFi and Genesis clients’ info exposed

Financial and risk advisory firm Kroll has suffered a SIM-swapping attack that allowed a threat actor to access files containing personal information of clients of bankrupt cryptocurrency platforms FTX, BlockFi and Genesis. The Kroll SIM-swapping attac… Continue reading Kroll SIM-swap attack: FTX, BlockFi and Genesis clients’ info exposed

3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack

Three bankrupt cryptocurrency companies — FTX, BlockFi and Genesis — suffered data breaches following a SIM swapping attack at Kroll. 
The post 3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack appeared first on SecurityWeek.
Continue reading 3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack

Open redirect flaws increasingly exploited by phishers

Phishing attacks using open redirect flaws are on the rise again, according to Kroll’s Cyber Threat Intelligence (CTI) team, which means organizations should consider refreshing employees’ awareness and knowledge on how to spot them. Malicious UR… Continue reading Open redirect flaws increasingly exploited by phishers

It’s time to patch your MOVEit Transfer solution again!

Progress Software customers who use the MOVEit Transfer managed file transfer solution might not want to hear it, but they should quickly patch their on-prem installations again: With the help of researchers from Huntress, the company has uncovered add… Continue reading It’s time to patch your MOVEit Transfer solution again!

CFOs’ overconfidence in cybersecurity can cost millions

Kroll announced its report Cyber Risk and CFOs: Over-Confidence is Costly which found chief financial officers (CFOs) to be woefully in the dark regarding cybersecurity, despite confidence in their company’s ability to respond to an incident. The repor… Continue reading CFOs’ overconfidence in cybersecurity can cost millions

Risk astute leadership: Converting intelligence into actionable controls

In this Help Net Security video, John deCraen, Associate Managing Director at Kroll, talks about risk astute leadership and the leveraging of threat intelligence to inform actionable controls.
The post Risk astute leadership: Converting intelligence in… Continue reading Risk astute leadership: Converting intelligence into actionable controls

Kroll expands in Central Europe to address raising cyber risks in the region

Kroll announced that its Cyber Risk practice has expanded across Central Europe in response to the heightened cyber risks organizations are facing in the region. A new office and operations have launched in Belgium, led by Vito Rallo, Associate Managin… Continue reading Kroll expands in Central Europe to address raising cyber risks in the region