Infosec News
banner
infosecnews.bsky.social
Infosec News
@infosecnews.bsky.social
Powered by the folks at Red Team Arts!
Gallery - coming soon
redteamarts.com
New research reveals ransomware gang negotiation tactics based on analysis of 200+ extortion transcripts. Learn how these criminals operate and what strategies actually work when facing down a demand. Essential insights for any security team:

substack.com/home/post/p-...

#ransomware #cybersecurity
Negotiating With Terrorists: Trends in Ransomware Negotiations from Both sides of the Table
A comprehensive analysis of ransomware negotiation dynamics and what really works when you’re staring down the barrel of an extortion demand.
https://substack.com/home/post/p-158460223​​​​​​​​​​​​​​​​
March 6, 2025 at 5:32 PM
The “tough on crime” party handed threat actors a big win. By dismantling the Cyber Safety Review Board mid-investigation into the Chinese telecom hack, the Trump admin is weakening US cybersecurity & aiding adversaries. A catastrophic decision for national security. arstechnica.com/tech-policy/...
Trump admin fires security board investigating Chinese hack of large ISPs
Dismantled Cyber Safety Review Board was investigating Salt Typhoon telecom hack.
arstechnica.com
January 23, 2025 at 1:51 PM
Govt now monitoring “negative sentiment” toward health insurance execs online after UHC’s CEO murder.

Fusion centers flagging posts critical of corporate greed as “threats”—fueling fears of free speech suppression in the name of “security.”

#CyberSecurity

www.kenklippenstein.com/p/government...
Government Monitoring Those With "Negative" Views of Health Insurance Companies
New documents reveal flurry of intelligence activity following Luigi Mangione's arrest
www.kenklippenstein.com
January 19, 2025 at 6:47 PM
Biden drops a sweeping cybersecurity EO 📜⚙️

Gov contractors must now prove secure dev practices & disclose updates. Will the next admin keep it?

#CyberSecurity #DataPrivacy #DigitalTrust #Biden

www.cnbc.com/2025/01/16/b...
Biden administration launches cybersecurity executive order
With this executive order, the Biden White House is looking to boost digital security in the U.S. for the government and the private sector.
www.cnbc.com
January 16, 2025 at 6:17 PM
TikTok ban incoming 🇺🇸➡️ Users flee… to a Chinese app?! 👀

“Red Note” (小红书) is now trending, as Americans say they’d rather hand data to Xi than trust Zuck, Elon, or the U.S. gov.

Irony’s dead, but the data privacy debate is alive 🔥 #CyberSecurity #TikTokBan #DataOwnership
January 13, 2025 at 11:32 PM
UN’s aviation agency hit by a “potential” breach—42,000 docs leaked, including PII, on hacking forums. Is global cybersecurity crumbling, or are threat actors just getting started? #CyberSecurity #DataBreach #UN

www.bleepingcomputer.com/news/securit...
UN aviation agency investigating 'potential' security breach
​On Monday, the United Nations' International Civil Aviation Organization (ICAO) announced it was investigating what it described as a "reported security incident."
www.bleepingcomputer.com
January 7, 2025 at 5:03 PM
USPS under fire: IG report reveals criminal groups recruiting postal workers to steal mail, checks, and credit cards. With $1M stolen in one case and faulty cameras at facilities, is the system failing us?

thehill.com/homenews/506...

#CyberCrime #USPS #MailTheft
thehill.com
January 6, 2025 at 4:05 AM
Struggling with inconsistent threat actor names? The IETF’s new draft proposes guidelines to standardize naming, reduce ambiguity, and enhance intelligence sharing. A must-read for #ThreatIntel pros.

#CyberSecurity #MISP #Hackers #ThreatGroups

www.misp-standard.org/rfc/threat-a...
Recommendations on Naming Threat Actors
This document provides advice on the naming of threat actors (also known as malicious actors). The objective is to provide practical advice for organizations such as security vendors or organizations ...
www.misp-standard.org
January 4, 2025 at 6:04 AM
Atos denies Space Bears ransomware attack claims, stating no breach of their systems occurred. The gang alleges otherwise, threatening a data leak next week. Who’s telling the truth? #CyberSecurity #Ransomware #SpaceBears #Infosec

www.bleepingcomputer.com/news/securit...
French govt contractor Atos denies Space Bears ransomware attack claims
French tech giant Atos, which secures communications for the country's military and secret services, has denied claims made by the Space Bears ransomware gang that they compromised one of its database...
www.bleepingcomputer.com
January 3, 2025 at 3:41 PM
🚨 Severe vulnerabilities in Microsoft Dynamics 365 and Power Apps Web API exposed sensitive data, including passwords and emails. These flaws, now patched, highlight the critical need for robust #CyberSecurity measures in APIs.

#DataSecurity #Microsoft

🔗 thehackernews.com/2025/01/seve...
Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
Three patched Dynamics 365 and Power Apps vulnerabilities exposed sensitive data, highlighting risks of API flaws.
thehackernews.com
January 2, 2025 at 3:52 PM
As we ring in the new year, it’s time to reflect on the most impactful cyber incidents of 2024. From massive data breaches to nation-state attacks, here’s a recap of the year’s biggest cybersecurity stories

What lessons will you take into 2025?

🔗 www.bleepingcomputer.com/news/securit...

#NYE
The biggest cybersecurity and cyberattack stories of 2024
2024 was a big year for cybersecurity, with significant cyberattacks, data breaches, new threat groups emerging, and, of course, zero-day vulnerabilities. Below are fourteen of what BleepingComputer b...
www.bleepingcomputer.com
January 2, 2025 at 3:50 PM
LockBit ransomware developer Rostislav Panev has been charged in the U.S. for creating tools behind BILLIONS in global damages 💻💰 Arrested in Israel, Panev allegedly developed malware to disable antivirus & exfiltrate data.

#CyberSecurity #Ransomware #LockBit

thehackernews.com/2024/12/lock...
LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages
LockBit's developer charged for enabling global ransomware attacks netting $500M; U.S. leads extradition effort.
thehackernews.com
December 21, 2024 at 6:32 PM
🚨 Researchers uncover 4.5M fake stars on GitHub 🌟, often boosting malware disguised as pirated software & crypto bots. Fake stars surge in 2024, posing major risks to open-source trust & security.

#CyberSecurity #GitHub #OpenSource #SupplyChainSecurity

arxiv.org/abs/2412.13459
4.5 Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Scams, and Malware
GitHub, the de-facto platform for open-source software development, provides a set of social-media-like features to signal high-quality repositories. Among them, the star count is the most widely used...
arxiv.org
December 20, 2024 at 8:58 PM
The Play ransomware gang claims responsibility for a cyberattack on Krispy Kreme 🍩💻, disrupting online orders & allegedly stealing sensitive data. The gang threatens to leak the data soon.

#CyberSecurity #Ransomware #DataBreach #KrispyKreme

www.bleepingcomputer.com/news/securit...
Krispy Kreme breach, data theft claimed by Play ransomware gang
The Play ransomware gang has claimed responsibility for a cyberattack that impacted the business operations of the U.S. doughnut chain Krispy Kreme in November.
www.bleepingcomputer.com
December 20, 2024 at 4:14 PM
Hackers breached BeyondTrust’s Remote Support SaaS instances, exploiting an API key to reset account passwords. Two critical vulnerabilities discovered; patches applied for cloud users. Investigations ongoing. 🔒💻

#CyberSecurity #DataBreach #BeyondTrust #PAM

www.bleepingcomputer.com/news/securit...
BeyondTrust says hackers breached Remote Support SaaS instances
Privileged access management company BeyondTrust suffered a cyberattack in early December after threat actors breached some of its Remote Support SaaS instances.
www.bleepingcomputer.com
December 19, 2024 at 5:29 PM
Iran-linked IOCONTROL malware is targeting SCADA & Linux-based IoT devices in the US and Israel, including fuel systems and IP cameras. Using MQTT for stealthy C2 comms, it can shut down critical services or steal data.

🔗 thehackernews.com/2024/12/iran...

#CyberSecurity #Iran #Israel #Malware #IoT
Iran-Linked IOCONTROL Malware Targets SCADA and Linux-Based IoT Platforms
Iranian-linked IOCONTROL malware targets IoT, OT, and SCADA systems with advanced evasion tactics.
thehackernews.com
December 13, 2024 at 3:43 PM
Photobucket, once a nostalgic photo vault, now embroiled in controversy: a lawsuit alleges it auto-opted dormant users into terms allowing their biometric data—like face and iris scans—to be sold for AI training. Privacy breach or AI gold rush?

🔗 arstechnica.com/tech-policy/...

#Privacy #AIEthics
Photobucket opted inactive users into privacy nightmare, lawsuit says
Class action could foil Photobucket’s plan to turn old photos into AI goldmine.
arstechnica.com
December 12, 2024 at 2:35 AM
Microsoft’s “AuthQuake” MFA flaw allowed unlimited brute-force attempts without alerting users. Attackers could bypass MFA in just an hour. A fix is in place now, but a reminder: MFA is best when configured with rate limits and alerts.

🔗 thehackernews.com/2024/12/micr...

#CyberSecurity #MFA #Hack
Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts
Microsoft’s MFA flaw, AuthQuake, let attackers bypass protections in 3 minutes. Fixed October 2024.
thehackernews.com
December 11, 2024 at 6:45 PM
Krispy Kreme’s sweet digital sales hit a sour note after a cyberattack disrupted online ordering and operations. While doughnuts still flow in-store, this shows even yummy treats aren’t immune to breaches. 🍩💻

🔗 www.bleepingcomputer.com/news/securit...

#CyberSecurity #DataBreach #KrispyKreme #Donut
Krispy Kreme cyberattack impacts online orders and operations
US doughnut chain Krispy Kreme suffered a cyberattack in November that impacted portions of its business operations, including placing online orders.
www.bleepingcomputer.com
December 11, 2024 at 6:43 PM
Law enforcement’s Operation PowerOFF dismantles 27 DDoS-for-hire platforms and leads to the arrest of admins. With 300 users identified, criminals are learning: renting chaos isn’t worth it.

Let’s hope the lesson sticks.

🔗 www.bleepingcomputer.com/news/securit...

#CyberSecurity #DDoS
Operation PowerOFF shuts down 27 DDoS-for-hire platforms
Law enforcement agencies from 15 countries have taken 27 DDoS-for-hire services offline, also known as "booters" or "stressers," arrested three administrators, and identified 300 customers of the plat...
www.bleepingcomputer.com
December 11, 2024 at 6:41 PM
A ransomware attack hit Artivion, a leading heart surgery device maker, encrypting systems and stealing sensitive data. With healthcare ransomware rising, critical patient safety and data security are on the line.

🔗 www.bleepingcomputer.com/news/securit...

#CyberSecurity
Ransomware attack hits leading heart surgery device maker
​Artivion, a leading manufacturer of heart surgery medical devices, has disclosed a November 21 ransomware attack that disrupted its operations and forced it to take some systems offline.
www.bleepingcomputer.com
December 10, 2024 at 2:43 PM
CERT-UA warns of Russian-linked phishing targeting Ukraine’s defense forces. Fake NATO conference invites hide malware, steal Signal, Telegram, and even military system credentials.
Stay vigilant, verify links, and secure your endpoints.

🔗 thehackernews.com/2024/12/cert...

#CyberSecurity #Ukraine
CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force
CERT-UA warns of Russian-linked phishing attacks exploiting a NATO alignment conference to target Ukraine's defense sector.
thehackernews.com
December 10, 2024 at 2:41 PM
Chinese hackers are abusing VSCode tunnels to maintain stealthy remote access during attacks. Signed EXEs, Azure traffic, and legit tools make detection tough.

Monitor rogue VSCode launches & unexpected *.devtunnels.ms connections.

🔗 www.bleepingcomputer.com/news/securit...

#CyberSecurity #APT
Chinese hackers use Visual Studio Code tunnels for remote access
Chinese hackers targeting large IT service providers in Southern Europe were seen abusing Visual Studio Code (VSCode) tunnels to maintain persistent access to compromised systems.
www.bleepingcomputer.com
December 10, 2024 at 2:36 PM
Microsoft 365 is having another rough day:

Office web apps, Outlook, OneDrive, and more are down for some users. Microsoft blames token generation issues but promises a fix in ~2 hours.

🔗 www.bleepingcomputer.com/news/microso...

#Microsoft365 #Outage
Microsoft 365 outage takes down Office web apps, admin center
Microsoft is investigating a widespread and ongoing Microsoft 365 outage impacting Office web apps and the Microsoft 365 admin center.
www.bleepingcomputer.com
December 10, 2024 at 2:33 PM
Black Basta ransomware steps up its game:
• Email bombing victims to overwhelm inboxes
• QR code phishing for credentials
• Social engineering via fake IT support on Teams

Hybrid attacks blend tech & tricks—stay alert and verify!

🔗 thehackernews.com/2024/12/blac...

#CyberSecurity #Ransomware
Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering
Black Basta evolves ransomware attacks with email bombing, QR codes, and social engineering, targeting credentials and VPNs.
thehackernews.com
December 9, 2024 at 8:02 PM