Threat actors could exploit a new unpatched security flaw in PayPal's money transfer service to facilitate clickjacking attacks, which involve deceiving targets into interacting with webpage elements that trigger malicious activity, reports The Hacker News.
Thirty-five or more of 75 widely-used online services including LinkedIn, WordPress, Zoom, Instagram, and Dropbox could be subjected to pre-hijacking attacks involving threat actors exploiting already addressed vulnerabilities to takeover online accounts prior to their creation, according to BleepingComputer.
BleepingComputer reports that General Motors had information from some of its customers compromised as a result of a credential stuffing incident last month.
SecurityWeek reports that Trickbot Group, also known as ITG23 or Wizard Spider, has moved to quickly expand its operations following the deployment of the TrickBot malware family six years ago, while moving to automated malware encryption.
New data-extortion cybercrime operation RansomHouse has claimed to leveraged vulnerabilities to infiltrate targets' networks and later blame attacks on improperly secured networks and "ridiculously small" security flaw disclosure rewards, reports BleepingComputer.
The annual Verizon Data Breach Investigations report shows external actors were the driving cause in security incidents in healthcare last year, driven by a spike in web application attacks.
TechRepublic reports that artificial intelligence has continued to be the key priority for CEOs for the third straight year, with 97% of senior executives intending to place significant AI investments.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.