Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

MuddyWater Targets 100+ Gov Entities in MEA With Phoenix Backdoor

The Iranian threat group is using a compromised mailbox accessed through NordVPN to send phishing emails that prompt recipients to enable macros.

DARKReading
#mac#backdoor
Verizon: Mobile Blindspot Leads to Needless Data Breaches

People habitually ignore cybersecurity on their phones. Instead of compensating for that, organizations are falling into the very same trap, even though available security options could cut smishing success and breaches in half.

Asian Nations Ramp Up Pressure on Cybercrime 'Scam Factories'

After a particularly gruesome murder, South Korea issues "code black" travel ban for several regions in Cambodia, while other nations urge more raids.

Electronic Warfare Puts Commercial GPS Users on Notice

Interference with the global positioning system (GPS) isn't just a problem for airlines, but for shipping, trucking, car navigation, agriculture, and even the financial sector.

Streaming Fraud Campaigns Rely on AI Tools, Bots

Fraudsters are using generative AI to generate fake music and boost the popularity of the fake content.

‘PassiveNeuron’ Cyber Spies Target Orgs With Custom Malware

A persistent cyber-espionage campaign focused on SQL servers is targeting government, industrial, and financial sectors across Asia, Africa, and Latin America.

ColdRiver Drops Fresh Malware on Targets

The Russia-backed threat actor's latest cyber spying campaign is a classic example of how quickly sophisticated hacking groups can pivot when exposed.

International Sting Takes Down SIM Box Criminal Network

The operation took down a massive SIM card fraud network that provided fake phone numbers from more than 80 countries to criminals.

Is Your Car a BYOD Risk? Researchers Demonstrate How

If an employee's phone connects to their car and then their corporate network, an attack against the car can reach the company.

Flawed Vendor Guidance Exposes Enterprises to Avoidable Risk

Oracle E-Business Suite customers received conflicting deployment guidance, leaving enterprises exposed a recent zero-day flaw, Andrew argues.