International Centre for Migration Policy Development, which operates across 90 countries, had its servers breached in an attack claimed by the Karakurt ransomware group, reports The Record, a news site by cybersecurity firm Recorded Future.
The FBI is set to deploy a cyber team to Montenegro to assist in the investigation of a massive cyberattack against the Balkan country, which resulted in the disruption of government systems and services, according to The Associated Press.
The Hacker News reports that malicious implant ModernLoader, also known as Avatar bot, has been leveraged by a Russian-speaking threat actor to deploy various malware in three separate but related campaigns between March and June 2022.
People still prefer the phone to do customer support and private business calls, so security teams need to focus more on vishing and all the malware hitting voice traffic.
In the Security News: Lastpas breach, long live John McAfee, Macs getting fewer updates, CPE correlating to CVE, clicky clicky hacks, anti-cheat is not anti-hack, new LVFS release, $8 million zero day, don't sign crappy code, a very handy PI and a site that lets you send poop anonymously is hacked (it was a pretty crappy exploit)!
BleepingComputer reports that the FBI has warned about the increasing exploitation of decentralized finance platforms' security vulnerabilities to facilitate cryptocurrency theft.
SecurityWeek reports that nearly 25,000 WordPress websites have been installed with more than 47,000 malicious plugins between July 2012 and July 2020, over 94% of which are still being used.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.