Dark Reading

'Dubai Police' Lures Anchor Wave of UAE Mobile Attacks

The Dubai Police are the latest victims of impersonation by fraudsters in the United Arab Emirates (UAE), who are sending thousands of text messages out to unwitting mobile users while purporting to represent the law enforcement agency.

Geico, Travelers Fined $11.3M for Lax Data Security

The two auto insurance companies will pay a hefty penalty for what the State of New York says was inadequate security that allowed hackers to compromise the personal data of more than 12,000 state residents.

RomCom Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

The Russian-linked APT RomCom exploited two zero-day vulnerabilities in Firefox, Tor, and Windows for zero-click attacks in October. Victims unknowingly downloaded a backdoor from spoofed websites, targeting North America and Europe.

BlackBasta Ransomware Brand Picks up Where Conti Left off

By last August 2024, the ransomware group was using its own custom-developed malware, Cogscan, used to map victim networks and sniff out the most valuable data, as well as a .NET-based utility called Knotrock, used to execute ransomware.

OpenSea NFT Phishers Aim to Drain Crypto Wallets

Researchers at Cofense discovered the campaign, in which adversaries impersonate the OpenSea website and claim a user has a new offer on a listing on the site to try to bait them into clicking on a malicious link.

Faux ChatGPT, Claude API Packages Deliver JarkaStealer

Two Python packages posing as tools to integrate with popular chatbots and provide API access are actually delivering "JarkaStealer," an infostealer designed to target potentially thousands of victims.

'GoIssue' Cybercrime Tool Targets GitHub Developers for Bulk Credential Theft

A cybercrime tool called GoIssue is being sold for $700 on a forum. It helps cyberattackers steal email addresses from GitHub profiles to use for further attacks like malware delivery and data breaches.

Citrix Issues Patches for Zero-Day Recording Manager Bugs

Citrix has released patches for two vulnerabilities in its Virtual Apps and Desktop technology that could allow remote attackers to escalate privileges or execute arbitrary code on affected systems.

Fake Copyright Infringement Emails Spread Rhadamanthys

The emails are automated, and they look like they come from legal representatives of real companies. Many of these companies are in the technology, media, and entertainment industries.

OWASP Beefs up GenAI Security Advice Amid Growing Deepfakes

OWASP's guidance focuses on building infrastructure for authenticating human identity in video calls, creating processes for financial transactions, and developing incident-response plans.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags