23 May

Here’s yet more ransomware using BitLocker against Microsoft’s own users

Yet more ransomware is using Microsoft BitLocker to encrypt corporate files, steal the decryption key, and then extort a payment from victim organizations, according to

Author rabih
23 May

Casino cyberattacks put a bullseye on Scattered Spider – and the FBI is closing in

Interview The cyberattacks against Las Vegas casinos over the summer put a big target on the backs of Scattered Spider, the suspected perps, according to

Author rabih
23 May

Google guru roasts useless phishing tests, calls for fire drill-style overhaul

A Google security bigwig has had enough of federally mandated phishing tests, saying they make colleagues hate IT teams for no added benefit. Matt Linton

Author rabih
23 May

Veeam says critical flaw can’t be abused to trash backups

Veeam says the recent critical vulnerability in its Backup Enterprise Manager (VBEM) can’t be used by cybercriminals to delete an organization’s backups. Rated 9.8 out

Author rabih
23 May

70% of CISOs worry their org is at risk of a material cyber attack

Chief information security officers around the globe “are nervously looking over the horizon,” according to a survey of 1,600 CISOs that found more than two

Author rabih
23 May

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

ESET Research Available as both an IDA plugin and a Python script, Nimfilt helps to reverse engineer binaries compiled with the Nim programming language compiler

Author rabih
23 May

UK data watchdog wants six figures from N Ireland cops after 2023 data leak

Following a data leak that brought “tangible fear of threat to life”, the UK’s data protection watchdog says it intends to fine the Police Service

Author rabih
23 May

How Apple Wi-Fi Positioning System can be abused to track people around the globe

In-depth Academics have suggested that Apple’s Wi-Fi Positioning System (WPS) can be abused to create a global privacy nightmare. In a paper titled, “Surveilling the

Author rabih
23 May

Would you buy Pegasus spyware from this scammer?

Indian infosec firm CloudSEK warned on Wednesday that scammers are selling counterfeit code advertised as the NSO Group’s notorious Pegasus spyware. “Threat actors created their

Author rabih
23 May

‘China-aligned’ spyware slingers operating since 2018 unmasked at last

Bitdefender says it has tracked down and exposed an online gang that has been operating since 2018 nearly without a trace – and likely working

Author rabih
23 May

Lawmakers advance bill to tighten White House grip on AI model exports

The House Foreign Affairs Committee voted Wednesday to advance a law bill expanding the White House’s authority to police exports of AI systems – including

Author rabih
22 May

Go after UnitedHealth, not us, 100+ medical groups urge Uncle Sam

More than 100 medical industry groups have asked the Feds to make UnitedHealth Group, not them, go through the rigmarole of notifying everyone about the

Author rabih
22 May

Canada’s London Drugs confirms ransomware attack after LockBit demands $25M

Canadian pharmacy chain London Drugs has confirmed that ransomware thugs stole some of its corporate files containing employee information and says it is “unwilling and

Author rabih
22 May

Confused by the SEC’s IT security breach reporting rules? Read this

The US Securities and Exchange Commission (SEC) wants to clarify guidelines for public companies regarding the disclosure of ransomware and other cybersecurity incidents. According to

Author rabih
22 May

NYSE parent gets $10M wrist tap for failing to report 2021 systems break-in

The New York Stock Exchange’s parent company has just been hit with a $10 million fine for failing to properly inform the Securities and Exchange

Author rabih
22 May

Laundering cash from healthcare, romance scams lands US man in prison for a decade

Georgia resident Malachi Mullings received a decade-long sentence for laundering money scored in scams against healthcare providers, private companies, and individuals to the tune of

Author rabih
22 May

Confused by the SEC’s breach reporting rules? Read this

The US Securities and Exchange Commission (SEC) wants to clarify guidelines for public companies regarding the disclosure of ransomware and other cybersecurity incidents. According to

Author rabih
22 May

Stopping ransomware in multicloud environments

Sponsored Survey and Live Event What are the biggest risks to your organization posed by ransomware and what security defenses does it have in place

Author rabih
Load moreLoadingAll items loaded