PhishingMandiant X/Twitter hacker linked to $900K cryptocurrency phishing schemeLaura FrenchJanuary 11, 2024The cybersecurity company, a Google subsidiary, said a 2FA policy change on X helped enable the “brute force” attack.
Cloud SecurityCloud 2024: SaaS nightmares, API security boom and the impending cloud ‘identity crisis’Stephen WeigandJanuary 11, 2024"In 2024, SaaS applications will present the next biggest attack surface that organizations have not yet addressed," says Adam Gavish, CEO and co-founder, DoControl.
RansomwareFidelity National Financial confirms data of 1.3 million customers exposed in cyberattackSteve ZurierJanuary 11, 2024Large mortgage company did not use the word “ransomware” in its 8K filing, but security experts say the evidence points to a likely ransomware attack.
PrivacyProlific ShinyHunters hacker jailed, ordered to repay $5 millionSimon HenderyJanuary 11, 2024French citizen was part of a gang that stole and sold hundreds of millions of records in 2020 and 2021 from over 60 companies.
IdentitySEC X/Twitter account hack: How 2FA could have stopped SIM swap scamLaura FrenchJanuary 10, 2024Hijacked SEC account used to falsely announce Bitcoin ETF approval: everything you need to know.
Patch/Configuration ManagementMicrosoft fixes 48 bugs in January Patch Tuesday, none of them zero-daysSteve ZurierJanuary 10, 2024Security pros noted that the first Patch Tuesday of 2024 was the second consecutive release by Microsoft with no zero-days.
RansomwareCrooks pose as researchers to retarget ransomware victimsSimon HenderyJanuary 10, 2024Organizations hit by the Royal and Akira ransomware gangs have been approached by fake researchers claiming they can access and delete stolen files.
RansomwareProxyShell-targeting Babuk Tortilla ransomware decrypted after hacker’s arrestLaura FrenchJanuary 9, 2024A free decryptor is available to recover files affected by Babuk malware variant targeting Microsoft Exchange.
Patch/Configuration ManagementHigh-severity RCE among 6 bugs added to CISA’s exploited vulnerability catalogSteve ZurierJanuary 9, 2024Some of the most dangerous vulnerabilities of 2023 make it to CISA's KEV list, including bugs in Apple and Apache products.
AI/ML4 key takeaways from NIST’s new guide on AI cyber threatsLaura FrenchJanuary 8, 2024Adversarial machine learning terms, types and mitigations outlined in the National Institute of Standards and Technology's 98-page paper.