Red Balloon Security CEO Ang Cui has spent over a decade looking into the most critical devices supporting our infrastructure. He explains why the insight that launched his company still holds true, and what it will take for security experts, manufacturers and end users to resolve our insecure stasis. Segment Resources: https://redballoonsecurity.c...
Threat actors could exploit the Application Mode feature in Chromium-based browsers Google Chorme, Microsoft Edge, and Brave Browser in a new phishing technique involving the creation of local login forms that impersonate desktop applications, reports BleepingComputer.
North Korean state-sponsored hacking group Lazarus has been engaging in a Bring Your Own Vulnerable Driver spear-phishing attack exploiting a Dell hardware driver since last autumn, BleepingComputer reports.
Cobalt Strike beacons are being deployed in a new malware campaign involving fraudulent job-themed lures, which was initially identified in August, reports The Hacker News.
The Federal Trade Commission and the Department of Justice have been called on by Senate Majority Leader Chuck Schumer, D-N.Y., to bolster efforts in ensuring proper consumer data protection against cyberattacks and investigating threat actors behind hacking incidents, CNN reports.
More corporations are being targeted by the Royal ransomware operation, which was launched in January but has significantly ramped up malicious activity this month, imposing demands of $250,000 to more than $2 million for its targets, BleepingComputer reports.
More than one-third of cyberattacks during the first six months of 2022 were business email compromise attacks, with incidents rising by nearly twofold between the first and second quarter, reports SiliconAngle.
Open-source software, including KiTTY, PuTTY, Sumatra PDF Reader, TightVNC, and muPDF/Subliminal Recording installer, are being leveraged by Lazarus affiliate ZINC in new malware attacks, according to SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.