ZeroFox predicts that attackers will increase their use of initial access brokers, or IABs, to hack into systems. A new intelligence risk forecast from cybersecurity firm ZeroFox predicts that 2024 will be more of the same for ransomware and AI—and that threat actors are likely to focus on third party vendors as access points forContinue reading “Intelligence forecast sees ransomware, third-party vendors as major 2024 threats.”
Category Archives: Security
New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices.
A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS and iOS devices. Tracked as CVE-2023-45866, the issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. “Multiple Bluetooth stacks have authenticationContinue reading “New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices.”
Your mobile password manager might be exposing your credentials.
A number of popular mobile password managers are inadvertently spilling user credentials due to a vulnerability in the autofill functionality of Android apps. The vulnerability, dubbed “AutoSpill,” can expose users’ saved credentials from mobile password managers by circumventing Android’s secure autofill mechanism, according to university researchers at the IIIT Hyderabad, who discovered the vulnerability and presented theirContinue reading “Your mobile password manager might be exposing your credentials.”
23andMe updates user agreement to prevent data breach lawsuits.
As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company. In October, a threat actor attempted to sell 23andMe customer data and, after failing to do so, leakedContinue reading “23andMe updates user agreement to prevent data breach lawsuits.”
Hacktivists Hacked An Irish Water Utility And Interrupted The Water Supply.
Threat actors launched a cyberattack on an Irish water utility causing the interruption of the power supply for two days. Threat actors hacked a small water utility in Ireland and interrupted the water supply for two days. The victim of the attack is a private group water utility in the Erris area, the incident impactedContinue reading “Hacktivists Hacked An Irish Water Utility And Interrupted The Water Supply.”
Ransomware gang hits British Library, internal files leaked.
Authorities first noticed the attack on Oct. 28, when hackers took down the library website. Three weeks after a cyberattack took down the British Library—one of the world’s largest athenaeums—alleged attackers appear to be leaking HR data stolen in the breach. The library confirmed the leak on November 20 in a post on X, formerly Twitter,Continue reading “Ransomware gang hits British Library, internal files leaked.”
Apple fixes two new iOS zero-days in emergency updates.
Apple released emergency security updates to fix two zero-day vulnerabilities exploited in attacks and impacting iPhone, iPad, and Mac devices, reaching 20 zero-days patched since the start of the year. “Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1,” the company said in an advisory. TheContinue reading “Apple fixes two new iOS zero-days in emergency updates.”
Google Will Start Deleting Old Accounts This Week. Here’s How to Save Your Google Account.
Don’t wait: You’ll need to take several steps to keep your inactive Google account safe from deletion. Act now if you want to keep your old Google accounts. Starting this week, on Dec. 1, Google will start deleting inactive Google accounts, it said, and all their contents, including Gmail messages, Photos, Calendar appointments, Contacts records, YouTubeContinue reading “Google Will Start Deleting Old Accounts This Week. Here’s How to Save Your Google Account.”
The Spelling Police: Searching for Malicious HTTP Servers by Identifying Typos in HTTP Responses.
At Fox-IT (part of NCC Group) identifying servers that host nefarious activities is a critical aspect of our threat intelligence. One approach involves looking for anomalies in responses of HTTP servers. Sometimes cybercriminals that host malicious servers employ tactics that involve mimicking the responses of legitimate software to evade detection. However, a common pitfall ofContinue reading “The Spelling Police: Searching for Malicious HTTP Servers by Identifying Typos in HTTP Responses.”
Phishers add QR codes to the menu.
Please don’t make us say QRishing. Taking a page from restaurants of the early-Covid era, hackers are trying out QR codes, frustrating IT pros by sneaking poisoned pixel squares past filters and into inboxes. A report from the cybersecurity company Reliaquest discovered a 51% increase in QR-code attacks in September, compared to the cumulative number from JanuaryContinue reading “Phishers add QR codes to the menu.”

You must be logged in to post a comment.