New cybersecurity data reveals persistent social engineering vulnerabilities

Ransomware was down last year, though LockBit led threat actors and employees opened a third of the toxic emails in the last six months of 2022.
The post New cybersecurity data reveals persistent social engineering vulnerabilities appeared first on Te… Continue reading New cybersecurity data reveals persistent social engineering vulnerabilities

Iranian state-aligned threat actor targets new victims in cyberespionage and kinetic campaigns

New research from Proofpoint exposes a large shift in the TA453 threat actor’s modus operandi, which started conducting more hostile attacks.
The post Iranian state-aligned threat actor targets new victims in cyberespionage and kinetic campaigns appear… Continue reading Iranian state-aligned threat actor targets new victims in cyberespionage and kinetic campaigns

Vivin Nets Thousands of Dollars Using Cryptomining Malware

A newly discovered threat actor named Vivin is raking in Monero from cryptomining malware, showing that this type of attack isn’t going away anytime soon. Continue reading Vivin Nets Thousands of Dollars Using Cryptomining Malware

Flash zero-day shows up in Qatar amid geopolitical struggles

A zero-day vulnerability in Adobe Flash was recently used to infect a likely diplomatic target in Qatar with malware, new research from Seattle-based cybersecurity company ICEBRG and Chinese tech firms Qihoo and Tencent shows. Adobe patched the vulnerability Thursday as part of a broader software update in a release that credited Seattle-based cybersecurity firm ICEBRG for alerting them to the flaw. The findings come as Qatar faces significant geopolitical struggles, including a trade blockade established by the United Arab Emirates (UAE), Saudi Arabia, Bahrain and Egypt. Over the last six months, politically-motivated Middle Eastern hacking has popped up numerous times. In late May, Qatar was outed as being connected to a hacking operation against top Republican donor Elliot Brody, an influential critic of the gulf state. Months earlier, Qater blamed UAE for hacking and editing content hosted by the Qatari News Agency (QNA), a government-backed news program. Subsequent reporting tied the QNA hack […]

The post Flash zero-day shows up in Qatar amid geopolitical struggles appeared first on Cyberscoop.

Continue reading Flash zero-day shows up in Qatar amid geopolitical struggles

Chinese hackers starting to return focus to U.S. corporations

Security researchers recently found a hacking group with suspected ties to the Chinese government engaged in what appears to be corporate espionage against multiple U.S. companies. The findings underscore an emerging, albeit opaque trend in which hackers linked to Beijing are conducting economic, cyber-enabled espionage, despite the Chinese Communist Party agreeing to stop such activity against the U.S. as part of a 2015 agreement between Chinese President Xi Jinping and U.S President Barack Obama. Experts say the 2015 truce resulted in a noticeable downturn in economic espionage. But there are signs the agreement may be deteriorating under the Trump administration.  According to recent research by multinational services giant PwC, a hacking group known as “KeyBoy” has returned to the fold with a data theft campaign aimed primarily at Western organizations. The operation, PwC Threat Intelligence Analyst Bart Parys told CyberScoop, shows the continued technical development of a previously reported group that has apparently […]

The post Chinese hackers starting to return focus to U.S. corporations appeared first on Cyberscoop.

Continue reading Chinese hackers starting to return focus to U.S. corporations

Insider threats in your work inbox

A new phishing campaign that targets businesses goes beyond business email compromise or CEO fraud.
Categories:
Business
Security world
Tags: becBusiness Email Compromisecloudinsider threatsphishingthreat actor

(Read more…)

The post Insider thre… Continue reading Insider threats in your work inbox

Insider threats in your work inbox

A new phishing campaign that targets businesses goes beyond business email compromise or CEO fraud.
Categories:
Business
Security world
Tags: becBusiness Email Compromisecloudinsider threatsphishingthreat actor

(Read more…)

The post Insider thre… Continue reading Insider threats in your work inbox