National Cyber Warfare Foundation (NCWF) Forums


Report reveals Pegasus spyware used to hack journalists and activists in Jordan - MyIndMakers


0 user ratings
2024-02-02 19:05:47
milo
Attacks

 - archive -- 


Comments
new comment
Nobody has commented yet. Will you be the first?
CVE mentions by industry news 
Undisclosed report reveals SEC cybersecurity flaws before fake Bitcoin ETF approval hack - Crypto Briefing 
Forget AI: Physical threats are biggest risk facing the 2024 election 
Cloud GPU provider CoreWeave opens its European HQ in London and plans two UK data centers this year as part of a £1B investment, after rais 
House panel leaders call on Microsoft president to testify over security shortcomings 
OpenAI announces a live stream at 10AM PT on May 13 to demo "some ChatGPT and GPT-4 updates", which Sam Altman says are "not gpt-5, not 
OpenAI announces a live stream at 10AM PT on May 13 to demo "some ChatGPT and GPT-4 updates"; Sam Altman says the new stuff is "not gpt 
Cybersecurity Insights with Contrast CISO David Lindner | 5 10 24 
MoD contractor hacked by China failed to report breach for months 
MoD contractor hacked by China failed to report breach for months - The Guardian 
Malicious Android Apps Pose as Google, Instagram, WhatsApp to Steal Credentials 
Malicious Android Apps Pose as Google, Instagram, WhatsApp, to Steal Credentials 
25% of CISOs in tech are not satisfied with their compensation 
Russia-linked APT28 targets government Polish institutions 
Google fixes fifth actively exploited Chrome zero-day this year 
Malicious Android Apps Pose as Google, Instagram, WhatsApp, Spread via Smishing 
Chrome Zero-Day Alert Update Your Browser to Patch New Vulnerability 
Citrix warns customers to update PuTTY version installed on their XenCenter system manually 
NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds 
Unity reports Q1 revenue down 8% YoY to $460M, vs. $433M est., a $291M net loss, including $212M of restructuring costs, compared with a $254M loss in 
A new alert system from CISA seems to be effective now we just need companies to sign up 
Major health care system hobbled by cyber incident  
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization 
CrowdStrike Cloud Security Defines the Future of an Evolving Market 
Russia-Linked CopyCop Uses LLMs to Weaponize Influence Content at Scale 
Mirai botnet also spreads through the exploitation of Ivanti Connect Secure bugs 
SMIC reports Q1 revenue up 4.3% YoY to $1.75B, vs. $1.69B est., and a $71.8M net income, vs. $76.8M est., as consumer sentiment remains weak in China  
Roblox reports Q1 revenue up 22% YoY to $801M, bookings up 19% YoY to $923M, DAUs up 17% YoY to 77.7M, and cuts its full-year bookings forecast; RBLX  
97% of organizations report difficulties with identity verification 
Zscaler is investigating data breach claims 
Instacart reports Q1 revenue up 8% YoY to $820M, vs. $794.5M est., gross transaction value up 11% to $8.32B; CFO Nick Giovanni retires, replaced by Em 
Robinhood reports Q1 revenue up 40% YoY to $618M, vs. $549M est., crypto transaction revenue up 232% to $126M, and a $157M net income, vs. a $511M net 
Airbnb reports Q1 revenue up 18% YoY to $2.14B, vs. $2.06B est., Nights and Experiences Booked up 9.5% YoY, and Q2 guidance below est.; ABNB drops 8%+ 
Bumble reports Q1 revenue up 10.2% YoY to $267.8M, vs. $265.5M est., total paying users of 4M, up from 3.5M a year ago, and expects Q2 revenue below  
Arm reports Q4 revenue up 47% YoY to $928M, vs. $875.6M est., royalty revenue up 37%, and forecasts FY 2025 revenue below est.; ARM drops 9%+ after ho 
Airbnb reports Q1 revenue up 18% YoY to $2.14B, vs. $2.06B est., Nights and Experiences Booked up 9.5%, and Q2 guidance below est.; ABNB drops 8%+ aft 
US hospital operator Ascension reports disruptions to its clinical operations due to a suspected cybersecurity incident and engages Mandiant to help i 
Instacart Q1: revenue up 8% YoY to $820M, vs. $794.5M est., gross transaction value up 11% to $8.32B; CFO Nick Giovanni is retiring, replaced by Emily 
Robinhood reports Q1 revenue up 40% YoY to $618M, vs. $549M est., crypto transaction revenue up 232% to $126M, net income of $157M, vs. a net loss of  
Airbnb reports Q1 revenue up 18% YoY to $2.14B, vs. $2.06B est., Nights and Experiences Booked up 9.5% to 132.6M, and forecasts Q2 revenue below expec 
Arm reports Q4 revenue up 47% YoY to $928M, vs. $875.6M est., royalty revenue up 37%, and forecasts FY 2025 revenue below expectations (Reuters) 
LockBit gang claimed responsibility for the attack on City of Wichita 
New TunnelVision technique can bypass the VPN encapsulation 
Phishing Reports in Switzerland More Than Doubled Last Year 
Talos discloses multiple zero-day vulnerabilities, two of which could lead to code execution 
Poland Says It Was Targeted by Russian Hacking Attack - U.S. News & World Report 
How an Iranian-linked influence campaign pivoted after Oct. 7 attack on Israel 
Iran-Aligned Emerald Divide Influence Campaign Evolves to Exploit Israel-Hamas Conflict 
LiteSpeed Cache WordPress plugin actively exploited in the wild 
Shopify reports Q1 revenue up 23% YoY to $1.9B, GMV up 23% YoY to $60.9B, and expects gross margins to drop by 50 basis points YoY in Q2; SHOP plumme 
Russia Says Germany Using Baseless 'Hacker Myths' to Destroy Ties - U.S. News & World Report 
Uber reports Q1 revenue up 15% YoY to $10.1B, Gross Bookings up 20% YoY to $37.7B, below $38B est., and adjusted EBITDA up 82% YoY to $1.4B; UBER fall 
Hijack Loader Malware Employs Process Hollowing, UAC Bypass in Latest Version 
Most Tinyproxy Instances are potentially vulnerable to flaw CVE-2023-49606 
Sources: SoftBank is in advanced talks to acquire Graphcore, a struggling UK-based chip startup once valued at $2.8B that reported just $2.7M in 2022  
President Biden signs the REPORT Act into law, to levy hefty fines against companies that neglect to report CSAM on their sites to the NCMEC's Cy 
UK Ministry of Defense disclosed a third-party data breach exposing military personnel data 
Global Cybercrime Report 2024: Which Countries Face the Highest Risk? 
Coupang reports Q1 revenue up 23% YoY to $7.1B, adjusted EBITDA up 17% YoY to $281M, vs. $283.3M est., and net income down 95% YoY including Farfetch  
President Biden signs the REPORT Act into law, which levies hefty fines against companies that neglect to report CSAM on their sites to the NCMEC&apos 
Twilio reports Q1 revenue up 4% YoY to $1.05B vs. $1.03B est., 313K+ active customer accounts, and forecasts Q2 revenue below est.; TWLO drops 5%+ aft 
GlobalFoundries reports Q1 revenue down 16% YoY to $1.55B, vs. $1.52B est., net income of $134M, and forecasts Q2 revenue above estimates; GFS closes  
EA reports Q4 revenue down 5% YoY to $1.78B, net income of $182M, net bookings down 14% YoY to $1.67B, and announces a three-year $5B stock buyback (B 
Match Group reports Q1 revenue up 9% YoY to $859.6M, vs. $855.5M est., paying users down 6% YoY to 14.9M, and forecasts Q2 revenue below expectations  
Lyft reports Q1 revenue up 28% YoY to $1.3B, a $31.5M net loss, gross bookings up 21%, active riders growing at the fastest pace since 2022, up 12% Yo 
Disney reported Disney+ and Hulu had a $47M operating income in Q2, vs. a $587M loss YoY, the first time the streaming services had a combined quarter 
Law enforcement agencies identified LockBit ransomware admin and sanctioned him 
RSAC: Log4J Still Among Top Exploited Vulnerabilities, Cato Finds 
Disney reported Disney+ and Hulu had an operating income of $47M in Q2, vs. a loss of $587M YoY, the first time the streamers had a combined profit in 
#RSAC: Log4J Still Among Top Exploited Vulnerabilities, Cato Finds 
'Malign actor' hacked UK defence ministry payroll, Sunak says after China reports - Reuters 
UK has taken military database offline after hack reports, says minister - Reuters UK 
ONCD report: Fundamental transformation in cyber, tech drove 2023 risks 
US, UK authorities unmask Russian national as LockBit administrator 
MITRE attributes the recent attack to China-linked UNC5221 
UK has taken military database offline after hack reports, says minister - Reuters.com 
MOD issues alert to personnel affected by reported Chinese hack of payroll database - Forces Network 
APT42 Hackers Pose as Journalists to Harvest Credentials and Access Cloud Data 
UK military personnel data accessed in alleged China hack: Reports - Deccan Herald 
'Malign actor' hacked UK defence ministry payroll, Sunak says after China reports - Reuters.com 
Securing the Vault: ASPM’s Role in Financial Software Protection 
Report Shows AI Fraud, Deepfakes Are Top Challenges For Banks 
80% of data experts believe AI increases data security challenges 
China suspected of hacking British military payment system, reports say - The Record from Recorded Future News 
Personnel affected by reported China hack on MOD payroll to be alerted - Forces Network 
China suspected of hacking UK's defence ministry payroll: Reports - Deccan Herald 
UK military personnel data accessed in alleged China hack, Sky reports - Reuters 
UK military personnel data accessed in alleged China hack, Sky reports - Reuters.com 
UK military personnel data accessed in alleged China hack, Sky reports - SWI swissinfo.ch in English 
China Suspected After Major MoD Payroll Breach 
Palantir reports Q1 revenue up 21% YoY to $634M, vs. $625M est., and a $106M net income, up from $16.8M in Q1 2023; PLTR drops 9% on weak guidance (Ro 
Nintendo reports net profit up 13% YoY to $3.2B in the past fiscal year and expects profit to drop 39% YoY and revenue to drop 19% YoY in this fiscal 
UK military personnel's data accessed in hack, Sky reports - Reuters.com 
Alexander Vinnik, the operator of BTC-e exchange, pleaded guilty to money laundering 
UK has taken military database offline after hack reports, says minister - SaltWire Halifax powered by The Chronicle Herald 
UK Military Personnel's Data Accessed In Hack: Report - NDTV 
What is Nahimic Companion? Should You Remove It From Windows 11? 
HYAS Threat Intel Report May 6 2024 
UK military personnel's data accessed in hack, BBC reports - Reuters 
UK military personnel's data accessed in hack, BBC reports - Reuters.com 
RSAC: Law Enforcement Takedowns Force Ransomware Affiliates to Diversify 
Krebs, Luber added to Cyber Safety Review Board 
Report claims China hacked British defense ministry Daily Sabah - Daily Sabah 
Ministry of Defence 'hacked by China' - reports - Yahoo News UK 
Palantir reports Q1 revenue of $634M, up 21% YoY, vs. $625M est., net income of $106M, up from $16.8M YoY; Palantir stock drops 9% after hours on weak 
#RSAC: Law Enforcement Takedowns Force Ransomware Affiliates to Diversify 
RSAC: 70% of Businesses Prioritize Innovation Over Security in Generative AI Projects 
Unearthed Government Report Found SEC Lacking "Effective" Cybersecurity Programs Two Weeks Before X Hack: Fox - Cryptonews 
Fortinet Report Sees Faster Exploitations of New Vulnerabilities 
City of Wichita hit by a ransomware attack 
Why Your VPN May Not Be As Secure As It Claims 
Identity, Credential Misconfigurations Open Worrying Security Gaps 
#RSAC: 70% of Businesses Prioritize Innovation Over Security in Generative AI Projects 
El Salvador suffered a massive leak of biometric data 
Stealing cookies: Researchers describe how to bypass modern authentication 
Ethical Hacking Service Market with Geographic Segmentation, Statistical Forecast and Competitive Landscape Report ... - openPR 
How to recover a hacked Facebook account - CyberGuy Report 
Finland authorities warn of Android malware campaign targeting bank users 
NATO and the EU formally condemned Russia-linked APT28 cyber espionage 
Security Affairs newsletter Round 470 by Pierluigi Paganini INTERNATIONAL EDITION 
Blackbasta gang claimed responsibility for Synlab Italia attack 
Biden is expected to sign the REPORT Act next week; the bipartisan bill targets child sextortion online through new CSAM reporting requirements and mo 
Crypto Hack Weekly Report: DeFi Double Trouble & A $70M Phishing Attack - Coinpedia Fintech News 
New Report Exposes Iranian Hacking Group's Media Masquerade - BankInfoSecurity.com 
New Report Exposes Iranian Hacking Group's Media Masquerade - GovInfoSecurity.com 
Our New Days of Rage Protest Activity and Considerations for Corporate Security 
Russia-linked APT28 and crooks are still using the Moobot botnet 
Verizon: The Percentage of Users Clicking Phishing Emails is Still Rising 
Top 5 Global Cyber Security Trends of 2023, According to Google Report 
Verizon 2024 Data Breach Report shows the risk of the human element 
Microsoft outlines security principles and goals tied to executive compensation packages, following a scathing US Cyber Safety Review Board report in  
CrowdStrike Named a Leader in IDC MarketScape for Worldwide MDR 
CrowdStrike Named Overall Leader in Industry s First ITDR Comparative Report 
CrowdStrike Named the Only Customers Choice in 2024 Gartner Voice of the Customer for External Attack Surface Management 
Microsoft outlines security principles and goals tied to executive compensation packages, following a scathing report from the US Cyber Safety Review  
Top 7 VAPT Testing Tools 
Cybersecurity Insights with Contrast CISO David Lindner | 5 3 24 
Microsoft organizational changes seek to address security failures 
Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications 
Dirty stream attack poses billions of Android installs at risk 
Report: The cost and complexity of data compliance impedes innovation 
FIN7 Cybercrime Group Strikes US Auto Sector Using Carbanak 
ZLoader Malware adds Zeus’s anti-analysis feature 
Israeli Private Eye Arrested in London Over Alleged Hacking for US Firm - U.S. News & World Report 
Cloudflare reports Q1 revenue up 30% YoY to $378.6M, vs. $373.7M est., and forecasts Q2 revenue below estimates; NET drops 13%+ after hours (Bloomberg 
Apple reports Q2 revenue down 8.1% YoY to $16.4B in Greater China, down 12.7% YoY to $6.3B in Japan, and down 17.2% YoY to $6.7B in the rest of Asia-P 
Apple reports Q2 revenue down 4% YoY to $90.75B, net income down 2% to $23.64B, and announces a $110B share buyback, its largest yet; AAPL jumps 5% af 
Coinbase reports Q1 net revenue up 116% YoY to $1.59B, vs. $1.32B est., net income of $1.18B, consumer transaction revenue of $935M, up 99% QoQ (Olga  
Apple reports Q2 revenue down 4% YoY to $90.75B, vs. $90.01B est., net income down 2% to $23.64B, and announces its largest-ever share buyback at $110 
Apple reports Q2 revenue down 4% YoY to $90.75B, vs. $90.01B est., net income down 2% to $23.64B, and announces largest-ever $110B share buyback (Appl 
Block Q1: revenue up 19% YoY to $5.96B, vs. $5.82B est., gross profit up 22% to $2.09B, Square profit up 19%, Cash App profit up 25%; SQ jumps 7%+ aft 
Apple reports second quarter results (Apple) 
What can we learn from the passwords used in brute-force attacks? 
Israeli Private Eye Arrested in UK Over Alleged Hacking for US PR Firm - U.S. News & World Report 
Verizon 2024 DBIR: Software supply chain risks fuel a data breach epidemic 
Threat actors hacked the Dropbox Sign production environment 
95% of organizations adjusted cybersecurity strategies this past year 
CISA adds GitLab flaw to its Known Exploited Vulnerabilities catalog 
Panda Restaurant Group disclosed a data breach 
Post DBIR 2024: 7 Ways to Reduce Your Cyber Risk 
Iranian hackers impersonate journalists in social engineering campaign 
Reading the Mandiant M-Trends 2024 
CISA’s incident reporting requirements go too far, trade groups and lawmakers say 
ADCS Attack Paths in BloodHound Part 2 
Qualcomm reports Q2 revenue up 1% YoY to $9.39B, vs. $9.34B est., handset sales up 1% YoY to $6.18B, and forecasts Q3 revenue above estimates (Kif Les 
eBay reports Q1 revenue up 2% YoY to $2.56B, vs. $2.53B est., GMV up 1% to $18.6B, net income down 23% to $439M, and forecasts Q2 revenue below estima 
DoorDash reports Q1 revenue up 23% YoY to $2.51B, vs. $2.45B est., total orders up 21% YoY, and forecasts Q2 core profit below est.; DASH drops 9%+ af 
Qualcomm reports Q2 revenue up 1% YoY to $9.39B, vs. $9.34B est., handset sales up 1% YoY to $6.18B, and Q3 revenue forecast above expectations (Kif L 
Lawsuits After Ransomware on the Rise, Comparitech Says 
Cuttlefish malware targets enterprise-grade SOHO routers 
Data stolen in Change Healthcare attack likely included U.S. service members, executive says 
Pro-Russia hacktivists attacking vital tech in water and other sectors, agencies say 
A flaw in the R programming language could allow code execution 
Lawsuits and Company Devaluations Await For Breached Firms 
Muddling Meerkat, a mysterious DNS Operation involving China’s Great Firewall 
Exploitation of vulnerabilities almost tripled as a source of data breaches last year 
Notorious Finnish Hacker sentenced to more than six years in prison 
Amazon reports Q1 ad revenue up 24% YoY to $11.8B, vs. $11.7B est., driven by the growth of its Stores and Prime Video businesses (Todd Spangler Varie 
Amazon reports Q1 net sales up 13% YoY to $143.3B, advertising services net sales up 24% YoY to $11.8B, and net income up from $3.2B to $10.4B (Amazon 
Pinterest reports Q1 revenue up 23% YoY to $740M, vs. $700.3M est., MAUs up 12% YoY to 518M, and Q2 revenue forecast above est.; PINS jumps 15%+ after 
Amazon reports Q1 AWS revenue up 17% YoY to $25.04B, vs. $24.49B est., and AWS operating income of $9.42B, vs. $7.52B est., up from $5.12B YoY (Jordan 
AMD reports Q1 revenue up 2% YoY to $5.47B, vs. $5.46B est., Data Center revenue up 80% YoY to $2.3B, and a $123M net income, up from a $139M net loss 
AMD reports Q1 revenue up 2% YoY to $5.47B, vs. $5.46B est., Data Center revenue up 80% YoY to $2.3B, and net income of $123M, up from a $139M loss Yo 
Pinterest reports Q1 revenue up 23% YoY to $740M, vs. $700.3M est., MAUs up 12% to 518M, and Q2 revenue forecast above estimates; PINS jumps 15%+ afte 
Amazon reports Q1 net sales up 13% YoY to $143.3B, AWS revenue up 17% to $25B, net income up from $3.2B to $10.4B, operating income up from $4.8B to $ 
Ransomware Rising Despite Takedowns, Says Corvus Report 
US spy agencies to share intelligence on critical infrastructure in policy revamp 
Man Who Mass-Extorted Psychotherapy Patients Gets Six Years 
In its first TikTok Shop Safety Report, TikTok reports 500K+ sellers in the US and 15M+ sellers worldwide in December 2023, adding 6M+ in H2 2023 (Ale 
PayPal reports Q1 revenue up 9% YoY to $7.7B, payment volume up 14% YoY to $404B, and transaction margin dollars up 4% YoY to $3.5B; PYPL rises 5%+ (P 
LockBit, RAGroup Drive Ransomware Attacks in March 
PayPal reports Q1 revenue up 9% YoY to $7.7B, payment volume up 14% YoY to $404B, transaction margin dollars up 4% YoY to $3.5B, and expects 2024 prof 
The Evolving Legislative and Compliance Landscape: A Roadmap for Business Leaders 
Huawei reports Q1 revenue up 37% YoY to $24.7B and net profit up 564% YoY to $2.7B, rising for the fourth consecutive quarter, buoyed by smartphone  
Lithuanian second hand marketplace Vinted reports 2023 revenue up 61% YoY to €596.3M and a €17.8M net profit, up from a €20 
Samsung reports Q1 revenue up 12.81% YoY to $52.3B, vs. $51.6B est., operating profit up 932.8% YoY to $4.8B, vs. $4.3B est., as memory chip price 
The FCC imposes $200 million in fines on four US carriers for unlawfully sharing user location data 
The Art of Huh? 
Chinese hackers are now using this tactic for spying: Report - India Today 
72% of CISOs believe AI solutions may lead to security breaches 
OfflRouter Malware Ukraine: Govt Network Breach Since 2015 
Report: Impacts of AI on Cyber Security Landscape - TechRepublic 
Crypto Hacking Group Lazarus Impersonates Fenbushi Capital Exec: Report - Milk Road 
Privacy Challenges in Relationships, Phishing Down but Vulnerabilities Up? 
The Los Angeles County Department of Health Services disclosed a data breach 
Multiple Brocade SANnav SAN Management SW flaws allow device compromise 
Exploring the Key Sections of a SOC 2 Report (In Under 4 Minutes) 
ICICI Bank exposed credit card data of 17000 customers 
Okta warns of unprecedented scale in credential stuffing attacks on online services 
Security Affairs newsletter Round 469 by Pierluigi Paganini INTERNATIONAL EDITION 
Targeted operation against Ukraine exploited 7-year-old MS Office bug 
Polish opposition lawmaker's phone was hacked while party was in power, paper reports - Reuters.com 
Hackers may have accessed thousands of accounts on the California state welfare platform 
Brokewell Android malware supports an extensive set of Device Takeover capabilities 
Alphabet closes above a $2T market cap for the first time, reaching a valuation of $2.15T after rising 10% on April 26, its biggest one-day jump since 
Polish opposition lawmaker's phone was hacked while party was in power, paper reports - Reuters 
Alphabet closes above a $2T market cap for the first time; the stock rose 10%, its biggest one-day jump since July 2015, resulting in a valuation of $ 
Hackers target critical vulnerability in WordPress plugin to compromise websites: Report - The Hindu 
As Intel reports disappointing earnings and guidance, and becomes S&P 500's worst performing stock in 2024, a look at the long history of com 
As Intel reports disappointing earnings and guidance, and becomes S&P's worst performing stock in 2024, a look at the long history of company 
BeyondTrust Report: Microsoft Security Vulnerabilities Decreased by 5% in 2023 
Discord bans Spy Pet-affiliated accounts, which were scraping 12K+ Discord servers to archive and sell user data, and says it is considering legal act 
The NHTSA finds that Tesla's driver-assist features insufficiently keep drivers engaged in the task of driving, and links them to 100+ crashes an 
Severe Flaws Disclosed in Brocade SANnav SAN Management Software 
ByteDance says it has no plans to sell TikTok, responding to a report suggesting that the Chinese company is considering selling a majority stake in T 
NHTSA finds that Tesla's driver-assist features are insufficient at keeping drivers engaged in the task of driving and links them to 100+ crashes 
Falcon Fund in Focus: Nagomi Helps Customers Maximize Their Cybersecurity Investments 
Experts warn of an ongoing malware campaign targeting WP-Automatic plugin 
Kaiser Permanente data breach may have impacted 13.4 million patients 
Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug 
Sweden s liquor supply severely impacted by ransomware attack on logistics company 
ByteDance says it has no plans to sell TikTok, responding to a report suggesting that it is considering scenarios for selling a majority stake in US T 
Intel reports Q1 revenue up 9% YoY to $12.72B, vs. $12.78B est., Data Center and AI up 5% to $3B, and Q2 revenue guidance below est.; INTC drops 7%+ a 
Snap reports Q1 revenue up 21% YoY to $1.19B, vs. $1.12B est., DAUs up 10% YoY to 422M, a net loss of $305M, compared to $329M YoY; SNAP jumps 24%+ af 
Microsoft reports Q3 Intelligent Cloud revenue up 21% YoY to $26.71B, vs. $26.26B est., with Azure and other cloud services revenue up 31% YoY (Jordan 
Nemesis 1.0.0 
Roku reports Q1 revenue up 19% YoY to $882M, vs. $848.62M est., a net loss of $50.9M, compared to $193.6M YoY, and 81.6M active accounts, up 1.6M from 
Snap reports Q1 revenue up 21% YoY to $1.19B, vs. $1.12B est., DAUs up 10% YoY to 422M, a net loss of $305M, compared to $329M YoY; SNAP is up 20%+ af 
Intel reports Q1 revenue up 9% YoY to $12.72B, vs. $12.78B est., Data Center and AI up 5% to $3B, and Q2 revenue guidance below est.; INTC falls 9%+ a 
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog 
Microsoft reports Q4 Intelligent Cloud revenue up 21% YoY to $26.71B, vs. $26.26B est., with Azure and other cloud services revenue up 31% YoY (Jordan 
Intel reports Q1 revenue up 9% YoY to $12.72B, vs. $17.78B est., Data Center and AI up 5% to $3B, and Q2 revenue guidance below est.; INTC down 7%+ af 
How to Protect Against Evolving Cyberattacks 
N.A. Developers Optimistic About Generative AI and Code Security 
Sources: Microsoft is prioritizing security over new features to win back consumer trust, as it scrambles to respond to new attacks from Russia-linked 
The private sector probably isn t coming to save the NVD 
CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog 
Hacker posts fake news story about Ukrainians trying to kill Slovak President 
Sources: Microsoft has scrambled to respond to new attacks from the Russia-linked SolarWinds hackers, as its engineers prioritize security over new fe 
AI-Assisted Phishing Attacks Are on the Rise 
Campaigns and political parties are in the crosshairs of election meddlers 
Franco-Italian chip company STMicro reports Q1 revenue down 18% YoY to $3.47B, below $3.63B est., and expects Q2 sales down 26% YoY to $3.2B, below $3 
Google fixed critical Chrome vulnerability CVE-2024-4058 
Best Practices to Strengthen VPN Security 
Hackers stole $35K from anti-Trump super PAC Lincoln Project: report - Business Insider 
SK Hynix reports Q1 revenue of $9B, more than doubling YoY, and $2B in operating income, above estimates of $1.3B and the biggest quarterly profit  
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks 
IBM reports Q1 revenue up 1% YoY to $14.46B, vs. $14.55B est., software revenue up 5.5% YoY to $5.9B, and net income of $1.6B, up from $927M YoY; IBM  
Meta reports Q1 revenue up 27% YoY to $36.46B, net income up 117% YoY to $12.37B, and family daily active people up 7% YoY to 3.24B for March 2024 (Me 
Prompt Hacking, Private GPTs, Zero-Day Exploits and Deepfakes: Report Reveals the Impact of AI on Cyber Security Landscape 
DirectDefense Report Sees Shifts in Cyberattack Patterns 
Hackers test their ransomwares in less protected regions like Africa before striking richer nations: Report - Business Insider Africa 
Hackers hijacked the eScan Antivirus update mechanism in malware campaign 
Popular Keyboard Apps Leak User Data: Billion Potentially Exposed 
North Korean Lazarus hacker group using LinkedIn to target and steal assets: Report - TradingView 
North Korean Lazarus hacker group using LinkedIn to target and steal assets: Report - Cointelegraph 
Back to Security Basics 
The street lights in Leicester City cannot be turned off due to a cyber attack 
US offers a $10 million reward for information on four Iranian nationals 
Win32 Packunwan:What Is It and How to Remove the Threat 
Taser company Axon launches an AI tool that turns body cam audio into police reports to save time; critics worry it will introduce errors into crucial 
North Korea-linked APT groups target South Korean defense contractors 
Democratic operative behind Biden AI robocall says lawsuit won t get anywhere  
Stolen Change Healthcare data could contain information on a substantial portion of Americans 
Details on the hacking charges against Congresswoman Carla Zambelli - The Brazilian Report 
AI: Friend or Foe? Unveiling the Current Landscape with MixMode s State of AI in Cybersecurity Report 
Hacking charges filed against far-right lawmaker - The Brazilian Report 
Reports: Russian hackers targeted west Texas water facilities - The Center Square 
Vulnerability Exploitation on the Rise as Attackers Ditch Phishing 
The Rise of the Bad Bots 
Suspected CoralRaider continues to expand victimology using three information stealers 
88% of respondents will focus security investments on cloud security 
Vulnerability Exploitation on the Rise as Attacker Ditch Phishing 
Spotify reports Q1 revenue up 20% YoY to €3.6B, MAUs up 19% YoY to 615M, below 617.9M est., subscribers up 14% YoY to 239M, and a €1 
Seceon, CompTIA and MSSP Leaders Panel Discussion: Unlocking New MRR with Advanced Cybersecurity Services 
How Rising Cyberattacks Risk Global Economic Stability 
U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity 
Cloud data management company Informatica says it is not currently in acquisition talks, after Salesforce's reported interest in a $10B deal; IN 
A cyber attack paralyzed operations at Synlab Italia 
North Korea Hacking Teams Hack South Korea Defence Contractors - Police - U.S. News & World Report 
Multiple third-party kernel drivers for Windows vulnerable to improper access control on IOCTL 
Is Your Password Strong Enough? Brute Force Attack on the Rise! 
Windows vulnerability reported by the NSA exploited to install Russian malware - Ars Technica 
Report: Russian Hackers Targeting Ukrainian Soldiers on Apps - BankInfoSecurity.com 
2024 Pen Testing Report 
Russia-linked APT28 used post-compromise tool GooseEgg to exploit CVE-2022-38028 Windows flaw 
Kremlin-backed hackers exploit critical Windows vulnerability reported by the NSA - Ars Technica 
Russian FSB Counterintelligence Chief Gets 9 Years in Cybercrime Bribery Scheme 
April 2024 Patch Tuesday: Three Critical RCE Vulnerabilities in Microsoft Defender for IoT 
CrowdStrike and Google Cloud Expand Strategic Partnership to Deliver Unified Cloud Security 
CrowdStrike Falcon Wins Best EDR Annual Security Award in SE Labs Evaluations 
CrowdStrike Extends Identity Security Capabilities to Stop Attacks in the Cloud 
CVE-2024-3400: What You Need to Know About the Critical PAN-OS Zero-Day 
Deploying the Droids: Optimizing Charlotte AI s Performance with a Multi-AI Architecture 
Secure Your Staff: How to Protect High-Profile Employees’ Sensitive Data on the Web 
5 Best Practices to Secure AWS Resources 
Microsoft: APT28 hackers exploit Windows flaw reported by NSA - BleepingComputer 
Three Ways Organizations Can Overcome the Cybersecurity Skills Gap 
Cloud data management company Informatica says it is not currently in talks to be acquired, after Salesforce's reported interest in a $10B deal; 
Informatica says it is not currently in talks to be acquired, following Salesforce's reported interest in a $10B deal; INFA falls 8%+ (Rohan Gos 
Stanford Internet Observatory: AI images could overwhelm federally authorized CSAM clearinghouse CyberTipline, which gets tens of millions of tips per 
Stanford Internet Observatory: federally authorized CSAM clearinghouse CyberTipline, which gets tens of millions of tips per year, could be overrun by 
Pentera's 2024 Report Reveals Hundreds of Security Events per Week, Highlighting the Criticality of Continuous Validation 
Windows DOS-to-NT flaws exploited to achieve unprivileged rootkit-like capabilities 
A flaw in the Forminator plugin impacts hundreds of thousands of WordPress sites 
Microsoft Warns: North Korean Hackers Turn to AI-Fueled Cyber Espionage 
Source: Salesforce has backed away from its talks to acquire cloud data management company Informatica, after the two companies could not agree on ter 
Akira ransomware received $42M in ransom payments from over 250 victims 
DuneQuixote campaign targets the Middle East with a complex backdoor 
Security Affairs newsletter Round 468 by Pierluigi Paganini INTERNATIONAL EDITION 
Cybersecurity Insights with Contrast CISO David Lindner | 4 19 24 
Pornhub, Stripchat, and XVideos will have to comply with additional obligations, such as submitting risk assessment reports, under the EU DSA starting 
UK ICO internal draft: Google's Privacy Sandbox must do more and leaves gaps that can be exploited to undermine the privacy of users who should r 
FBI director warns of China s preparations for disruptive infrastructure attacks 
66% of IT leaders doubt the government can defend against cyberwarfare 
Treasury official: Small financial institutions have growth to do in using AI against threats 
Netflix plans to stop reporting subscriber numbers and Average Revenue per Membership from Q1 2025, as time spent is its "best proxy for customer 
Companies Didn t Prioritize Third-Party Sources of CVEs, Here s What Happened 
Alarming Decline in Cybersecurity Job Postings in the US 
What s the deal with the massive backlog of vulnerabilities at the NVD? 
Report finds a near 20% increase in ransomware victims year-over-year 
FBI chief says China is preparing to attack US critical infrastructure 
Internal draft: UK's ICO says Google's Privacy Sandbox falls short and leaves gaps that can be exploited to undermine privacy of users who s 
Texas cyber attack report: Mulshoe was target of Russian hackers - KHOU.com 
FIN7 targeted a large U.S. carmaker with phishing attacks 
Consumer Reports: Some doorbell cameras vulnerable to hackers - WMUR Manchester 
FIN7 targeted a large U.S. carmaker phishing attacks 
Netflix won't report subscriber numbers or Average Revenue per Membership starting in Q1 2025, saying time spent is its "best proxy for cust 
Netflix reports Q1 revenue up 15% YoY to $9.37B, vs. $9.28B est., paid users up 16% YoY to 269.6M, vs. 264.2M est., and net income $2.3B, up from $1.3 
Fixing a $12bn Challenge for Banks Through Data-Centric Security 
MIVD security service takes action against Russian hackers: report - TVP World 
Could the Brazilian Supreme Court finally hold people accountable for sharing disinformation? 
Quishing Attacks Jump Tenfold, Attachment Payloads Halve 
Large volume of data stolen from UN agency after ransomware attack 
Report: Government-linked hackers in China target exiled Tibetan leaders - Voice of America - VOA News 
Hackers post Tarrant taxpayer data online after ransomware attack on appraisal district - Fort Worth Report 
Roku experiences another data breach; Apple notifies users about mercenary spyware attacks 
A Pandora’s Box: Unpacking 5 Risks in Generative AI 
US Water Supply Targeted by Russian Hackers: Report - Newsweek 
Trust in Cyber Takes a Knock as CNI Budgets Flatline 
TSMC reports Q1 revenue up 16.5% YoY to $18.87B, vs. $18B est., net income up 8.9% YoY to $6.97B, vs. $6.6B est., and expects strong AI chip deman 
Cisco warns of a command injection escalation flaw in its IMC. PoC publicly available 
TSMC reports Q1 revenue up 16.5% YoY to NT$592.64B ($18.87B) vs. NT$582.94B est., profit up 8.9% YoY to NT$225.49B vs. NT$213.59B est., on strong AI c 
Reports: Russian hackers caused Muleshoe water tank to overflow - KTSM 9 News 
Reports: Russian hackers caused Muleshoe water tank to overflow - KXAN.com 
MTAC report: foreign malign influence from Russia, China, and Iran in the US presidential election got off to a slower start this year compared to 201 
A hacker group with Kremlin ties takes responsibility for sabotaging U.S. water utilities, WIRED reports - The Insider 
Hackers behind water cyberattacks in U.S., France, Poland have ties to Russian military: report - Axios 
Linux variant of Cerber ransomware targets Atlassian servers 
Reports: Russian hackers caused Muleshoe water tank to overflow - KLBK KAMC EverythingLubbock.com 
Mandiant: Notorious Russian hacking unit linked to breach of Texas water facility 
After a sleepy primary season, Russia enters 2024 U.S. election fray 
Hacienda La Puente Unified reports potential cyber hack - The San Gabriel Valley Tribune 
With a mysterious surveillance target identified, calls for Congress to change course 
ASML reports China represented 49% of its system sales in Q1, while sales from Taiwan more than halved QoQ and the US dropped five percentage points Q 
Pentesting accounts for an average of 13% of total IT security budgets 
ASML reports China represented 49% of its system sales in Q1, while sales from Taiwan more than halved and the US dropped five percentage points to 6% 
KnowBe4 Named a Leader in the Spring 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) Software 
Decade-old malware haunts Ukrainian police 
HTTP 2 Vulnerability: Protect Web Servers from DoS Attacks 
ASML reports Q1 net sales down 21.6% YoY to €5.29B, vs. €5.39B est., net income down 37.4% YoY to €1.22B, vs. €1.0 
ASML reports Q1 net sales down 21.6% YoY to €5.29B v. €5.39B est., net income down 37.4% YoY to of €1.22B v. €1.07 
Researchers released exploit code for actively exploited Palo Alto PAN-OS bug 
The Linux Foundation announces the Open Platform for Enterprise AI, to foster the development of open, multi-provider, and composable generative AI sy 
IAB and PwC report on US digital ad sales in 2023: total revenue grew 7.3% YoY to $225B, digital video grew 10.6% to $52.1B, and digital audio grew 18 
Cloudflare says its network saw DNS-based DDoS attacks increase by 80% YoY in Q1 2024, with attacks on Sweden surging by 466% after its acceptance int 
Ex-White House cyber official says ransomware payment ban is a ways off 
Congress rails against UnitedHealth Group after ransomware attack 
Cisco Calls Out Organizations As Being Overconfident and Unprepared for Cyber Attacks 
Phishing Frenzy: Microsoft and Google Most Mimicked Brands in Cyber Scams 
Decision-Makers and Staffing Trends: Insights from the 2024 Benchmark Survey Report 
FTC Reports Email is a Popular Medium for Impersonation Scams 
Mobile NotPetya : Spyware Zero-Click Exploit Development Increases Threat of Wormable Mobile Malware 
A renewed espionage campaign targets South Asia with iOS spyware LightSpy 
Nevada loses the most money to cybercrime 
Report Suggests 93% of Breaches Lead to Downtime and Data Loss 
Misinformation and hacktivist campaigns targeting the Philippines skyrocket 
KnowBe4 Named a Leader in the Spring 2024 G2 Grid Report for Security Awareness Training 
Who Stole 3.6M Tax Records from South Carolina? 
Identity in the Shadows: Shedding Light on Cybersecurity's Unseen Threats 
Russia is trying to sabotage European railways, Czech minister said 
Mozilla and CheckFirst: Apple, Google, Meta, and others' ad transparency efforts are a work in progress, months after the EU's DSA mandated  
Five Key Takeaways from the 2024 Imperva Bad Bot Report 
Ransomware group Dark Angels claims the theft of 1TB of data from chipmaker Nexperia 
Critical RCE Vulnerability in 92,000 D-Link NAS Devices 
Mozilla and CheckFirst report: Apple, Google, Meta, and others' efforts are a work in progress at best, months after EU's DSA mandated a sea 
Cisco Duo warns telephony supplier data breach exposed MFA SMS logs 
Ukrainian Blackjack group used ICS malware Fuxnet against Russian targets 
[WARNING] FBI Issues Alert on Major Phishing Campaign That Impersonates US Toll Services 
MY TAKE: GenAI revolution the transformative power of ordinary people conversing with AI 
HYAS Threat Intel Report April 15 2024 
Roku: Credential Stuffing Attacks Affect 591,000 Accounts 
Sources detail how China-based ByteDance and US TikTok operations remain intertwined: some US staff effectively report to ByteDance, share user data,  
Stanford's AI Index report: training top AI models gets more expensive, AI still trails humans on complex tasks, people have become more worried  
LayerSlider Plugin Flaw Exposes 1M Sites To SQL Injections 
DinodasRAT Malware: A Multi-Platform Backdoor Targeting Linux 
10 Best Linux Server Security Practices for Sysadmin in 2024 
Crickets from Chirp Systems in Smart Lock Key Leak 
CISA adds Palo Alto Networks PAN-OS Command Injection flaw to its Known Exploited Vulnerabilities catalog 
Muddled Libra Shifts Focus to SaaS and Cloud for Extortion and Data Theft Attacks 
Threat actors exploited Palo Alto Pan-OS issue to deploy a Python Backdoor 
Singapore-based used car marketplace Carro raised $100M in pre-IPO funding at a $1.5B+ valuation and reports its first annual operating profit (Olivi 
Another CVE (PAN-OS Zero-Day), Another Reason to Consider Zero Trust 
Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users 
U.S. and Australian police arrested Firebird RAT author and operator 
Crooks manipulate GitHub’s search results to distribute malware 
Balbix Guide to XZ Utils Backdoor 
State-Sponsored Disinformation Campaigns Targeting Africa Driving Instability And Violence 
Chinese-owned Dutch chipmaker Nexperia is investigating a breach in March; report: customer data of companies including Apple, Huawei, and SpaceX was  
In Other News: Moscow Sewage Hack, Women in Cybersecurity Report, Dam Security Concerns - SecurityWeek 
LastPass employee targeted via an audio deepfake call 
Report finds that only 5% of businesses have a cyber expert 
TA547 targets German organizations with Rhadamanthys malware 
Six-year old bug will likely live forever in Lenovo, Intel products 
Why CISA is Warning CISOs About a Breach at Sisense 
US CISA published an alert on the Sisense data breach 
Met police failed to act on Commons honeytrap sexting reports last year 
CISA emergency directive tells agencies to fix credentials after Microsoft breach 
XZ Trojan highlights software supply chain risk posed by ‘sock puppets’ 
Safeguard Data with Access Governance and Monitoring 
Facebook ads used by hackers to promote fake versions of AI tools Sora, Dall-E, Midjourney: Report - The Indian Express 
Cybercriminal Campaign Spreads Infostealers, Highlighting Risks to Web3 Gaming 
Palo Alto Networks fixed multiple DoS bugs in its firewalls 
Sisense breach exposes customers to potential supply chain attack 
PCI DSS 4.0: The Compliance Countdown A Roadmap Through Phases 1 & 2 
Python's PyPI Reveals Its Secrets 
Apple warns of mercenary spyware attacks on iPhone users in 92 countries 
Microsoft fixed two zero-day bugs exploited in malware attacks 
US Data Breach Reports Surge 90% Annually in Q1 
Match Systems report on consequences of CBDC implementation, led by CEO Andrei Kutin 
Congress sounds alarm on lax dam cybersecurity 
AT&T states that the data breach impacted 51 million former and current customers 
Personal information of millions of AT&T customers leaked online 
Fortinet fixed a critical remote code execution bug in FortiClientLinux 
Vulnerability in some TP-Link routers could lead to factory reset 
Raspberry Robin Malware Now Using Windows Script Files to Spread 
Match Systems publishes report on the consequences of CBDC implementation, led by CEO Andrei Kutin 
Improving Dark Web Investigations with Threat Intelligence 
Microsoft Patches Tuesday security updates for April 2024 fixed hundreds of issues 
The state of secrets security: 7 action items for better managing risk 
Raspberry Robin Returns: New Malware Campaign Spreading Through WSF Files 
Women Experience Exclusion Twice as Often as Men in Cybersecurity 
D3 Security Releases In the Wild 2024 Report with Analysis and Incident Response Playbooks for the 10 Most Prevalent Cyber Attack Techniques 
Dracula Phishing Platform Targets Organizations Worldwide 
TSMC reports Q1 revenue up 16.5% YoY to $18.5B and expects revenue to grow at least 20% in 2024, reversing 2023's slight decline, and budgets cap 
Credential phishing accounted for 91% of active threat reports 
Extortion group threatens to sell Change Healthcare data 
Over 91,000 LG smart TVs running webOS are vulnerable to hacking 
ScrubCrypt used to drop VenomRAT along with many malicious plugins 
Civil society groups press platforms to step up election integrity work 
US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack 
Zero-Day Attacks on the Rise: Google Reports 50% Increase in 2023 
2023 Threat Analysis and 2024 Predictions 
10-Year-Old 'RUBYCARP' Romanian Hacker Group Surfaces with Botnet 
Federal Support for Open-Source Security 
Researchers Discover LG Smart TV Vulnerabilities Allowing Root Access 
From Marco Polo to Modern Mayhem: Why Identity Management Matters 
China is using generative AI to carry out influence operations 
William Wragg resigns from two Commons roles after divulging MPs phone numbers 
Barracuda Report Provides Insight into Cybersecurity Threat Severity Levels 
Tokyo Police Department Warns of Phishing Scam That Uses Phony Arrest Warrants 
Security leaders discuss the U.S. Treasury's concerns regarding AI 
U.S. Department of Health warns of attacks against IT help desks 
Lime plans to spend $55M in 2024 to expand its e-bike fleet, adding 30K+ bikes in North America and elsewhere, and reports 2023 gross bookings up 32%  
Massive AT&T Data Leak, The Danger of Thread Hijacking 
Report: Google changed its privacy policy on July 1, 2023, to more broadly cover its use of publicly available content, like in Google Docs, to train  
NHMFC reports hack attack, eyes possible data breach - Inquirer.net 
9 Best Practices for Using AWS Access Analyzer 
Over 92,000 Internet-facing D-Link NAS devices can be easily hacked 
35+ Alarming Hacking Statistics [Recently Updated Data] - The Tech Report 
More than 16,000 Ivanti VPN gateways still vulnerable to RCE CVE-2024-21894 
Report: Google changed its privacy policy in June 2022 to more broadly cover its use of publicly available content, including Google Docs, to train AI 
Chinese hackers likely to target 18th Lok Sabha polls using AI, says Microsoft report - The Economic Times 
Snapchat turns off Solar System, which lets users see their position in their friends' orbits, by default, after a report said it was adding to t 
Crypto Hack Report Q1 2024: Trends, Losses, and Recovery Efforts - Coinpedia Fintech News 
Cybersecurity Insights with Contrast CISO David Lindner | 4 5 24 
Supply chain attack sends shockwaves through open-source community 
Ghostwriter v4.1: The Custom Fields Update 
Magento flaw exploited to deploy persistent backdoor hidden in XML 
ALPHV steps up laundering of Change Healthcare ransom payments 
Ivanti CEO Promises Stronger Security After a Year of Flaws 
CISA Unveils Critical Infrastructure Reporting Rule 
Supply Chain Resilience & the Power of Continuous Monitoring 
Talent shortage is leading to automation and outsourcing 
Cyberattack disrupted services at Omni Hotels & Resorts 
China Using AI-Generated Content to Sow Division in US, Microsoft Finds 
New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA 
Testing in Detection Engineering (Part 8) 
Chinese hackers turn to AI to meddle in elections 
HTTP 2 CONTINUATION Flood technique can be exploited in DoS attacks 
Filings: Apple laid off 600+ employees in California; some layoffs correspond to addresses where Apple's display and car research teams were repo 
Federal government affected by Russian breach of Microsoft 
Catfishing Campaign Targets Members of the UK Government 
LockBit Scrambles After Takedown, Repopulates Leak Site with Old Breaches 
Biden review board blames Microsoft for China hack that targeted US officials: 'Cascade of avoidable errors' - Fox Business 
FBI seeks to balance risks, rewards of artificial intelligence 
A K-12 Guide To Post-Incident Analysis 
Fake Lawsuit Threat Exposes Privnote Phishing Sites 
New HTTP 2 Vulnerability Exposes Web Servers to DoS Attacks 
US Gov report slams Microsoft over email hack 'The Board finds that this intrusion was preventable and should never ... - PC Gamer 
AT&T plans to invest an additional $3B by 2030 to help close the US digital divide, after initially committing $2B by 2024, which helped nearly 5M 
CompTIA 2024 State of Cybersecurity Report and MSPs MSSPs 
Ivanti fixed for 4 new issues in Connect Secure and Policy Secure 
Building Trust in Finance: Challenges & Solutions 
'Cascade of errors' by Microsoft led to Chinese email hack of top US officials, scathing report says - New York Post 
Oceana: Amazon created 208M lbs of US plastic packaging waste in 2022, up 9.6% YoY: Amazon says it reduced plastic packaging use by 11.6% YoY globally 
'Cascade of errors' by Microsoft led to Chinese email hack, scathing report says - New York Post 
Streamlining Third-Party Risk Management: The Top Findings from the 2024 Benchmark Survey Report 
New Report Offers Insight On MGM Casino Hackers - Poker News - CardPlayer.com 
US reprimands Microsoft for security failures that allowed Chinese hack - The Guardian 
Google addressed another Chrome zero-day exploited at Pwn2Own in March 
Data-driven decision-making: The power of enhanced event logging 
PlayStation Portal PSP Emulation Exploit Gets Patched Out After Hackers Reported the Issue - ComicBook.com 
The New Version of JsOutProx is Attacking Financial Institutions in APAC and MENA via Gitlab Abuse 
Google Cloud Cloud Security Alliance Report: IT and Security Pros Are ‘Cautiously Optimistic’ About AI 
Cyber Safety Review Board Report Slams Microsoft Security Failures in Government Email Breach 
Satoshi Nakamoto's GMX Email Hacked in 2014, Here's Crucial Thing Here: Report - TradingView 
Sony Fixed Exploit That Let PlayStation Portal Run Emulated PSP Games After Hackers 'Responsibly Reported Issues ... - IGN 
Federal report blasts Microsoft for its lax security measures that led to Chinese hack of government emails - Fast Company 
Newzoo: PC and console game revenue grew 2.6% YoY to $93.5B in 2023, but average quarterly playtime hours fell 26% from Q1 2021 to Q4 2023 (Dean Takah 
Review board to issue report detailing Microsoft's lapses in China hack: report - The Economic Times 
Satoshi Nakamoto's GMX Email Hacked in 2014, Here's Crucial Thing Here: Report - U.Today 
‘The Manipulaters’ Improve Phishing, Still Fail at Opsec 
DHS blames Microsoft's 'culture' for 'preventable' hack in scathing report - Quartz 
Microsoft could have prevented Chinese cloud email hack, US cyber report says - The Verge 
Cybersecurity review board's report to flag Microsoft flaws in China hack: WaPo - Investing.com 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - MarketWatch 
Microsoft Is Faulted for 'Inadequate' Cyber Practices in US Report - Bloomberg 
PitchBook and NVCA: US VC investments in Q1 2024 hit $36.6B, the lowest since 2017, across 2,882 deals, down from $51.6B across 4,026 deals in Q1 2023 
Microsoft s security culture was inadequate and needs overhaul, says the US government report on Chinese - The Times of India 
Highly sensitive files mysteriously disappeared from EUROPOL headquarters 
Microsoft s security culture was inadequate and needs overhaul, says US government report on Chinese hack - The Times of India 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - The Associated Press 
PitchBook and NVCA report: US VC investments in Q1 2024 hit $36.6B, lowest since 2017, across 2,882 deals, down YoY from $51.6B across 4,026 deals (De 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - The Independent 
Report Slams Microsoft for Security Blunders in Chinese Hack - BankInfoSecurity.com 
Newzoo: PC and console game revenues grew 2.6% YoY to $93.5B in 2023, but average quarterly playtime hours fell 26% from Q1 2021 through Q4 2023 (Dean 
US report blames Microsoft s sloppy cybersecurity for Chinese hack - South China Morning Post 
Cybersecurity review board's report to flag Microsoft flaws in China hack: WaPo By Investing.com - Investing.com 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - ABC News 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - Yahoo! Voices 
Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack - Yahoo Finance 
DHS report rips Microsoft for 'cascade' of errors in China hack - The Washington Post - The Washington Post 
Cyber review board blames cascading Microsoft failures for Chinese hack 
The US Cyber Safety Review Board faults Microsoft for a "cascade of avoidable errors" that led to the 2023 Chinese hack of top US government 
DHS report rips Microsoft for cascade of errors in China hack - The Washington Post 
Review board to issue report detailing Microsoft's lapses in China hack, Washington Post reports - Yahoo Finance 
Intel Foundry reports 2023 revenue down 31% YoY to $18.9B, operating loss of $7B, up from $5.2B in 2022, and expects 2024 to be the peak of its losses 
Source: the independent Cyber Safety Review Board's forthcoming report on China's hack of Microsoft will fault the company for a "casca 
XSS flaw in WordPress WP-Members Plugin can lead to script injection 
CISA faces resource challenge in implementing cyber reporting rules 
Binarly released the free online scanner to detect the CVE-2024-3094 Backdoor 
Getting Intune with Bugs and Tokens: A Journey Through EPM 
Navigating the Maze: A Measured Approach to AI Adoption in Cybersecurity 
Researchers Report Sevenfold Increase in Data Theft Cases 
China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations 
Alert: Connectwise F5 Software Flaws Used To Breach Networks 
Google Reports Major Spike in Zero-Day Vulnerabilities 
Volt Typhoon Threat Report 
Hackers Turn Smart Fridges into Cryptocurrency Mining Rigs - The Tech Report 
Hackers Target Russian Prison Database To Avenge Navalny's Death: Report - NewsX 
HYAS Threat Intel Report April 1 2024 
Millions Impacted in Mass Passcode Reset of AT&T Accounts 
US Executive Gets UK Judgments Thrown Out After Showing Hackers Swayed His Case - U.S. News & World Report 
New Vultur malware version includes enhanced remote control and evasion capabilities 
Filing: Sam Altman no longer controls the OpenAI Startup Fund, which has a $325M+ gross asset value; Ian Hathaway, who has helped manage the fund, is  
Anti-Kremlin Hackers Infiltrate Russian Prison System Seeking Information On Navalny s Death, CNN Reports - Mediaite 
Space is essential for infrastructure. Why isn’t it considered critical? 
Pentagon established the Office of the Assistant Secretary of Defense for Cyber Policy 
Anti-Kremlin activists stole Russian database, hacked online marketplace to avenge Alexey Navalny's death: Report - Firstpost 
Report Unveils Crypto Hack Chaos: $336 Million Stolen in First Quarter of 2024 - Coinpedia Fintech News 
Pro-Navalny Hackers Swipe Monster Database of Russian Prisoners: Report - The Daily Beast 
Info stealer attacks target macOS users 
Navalny's Revenge? Hackers steal massive Russian prisoner database: Report - Hindustan Times 
Security Affairs newsletter Round 465 by Pierluigi Paganini INTERNATIONAL EDITION 
DinodasRAT Linux variant targets users worldwide 
AT&T confirmed that a data breach impacted 73 million customers 
Understanding and Mitigating the Fedora Rawhide Vulnerability (CVE-2024-3094) 
Expert found a backdoor in XZ tools used many Linux distributions 
Hackers Target macOS Users with Malicious Ads Spreading Stealer Malware 
Huawei reports its fastest growth in four years in 2023, with revenue up 9.63% YoY to 704.2B CNY ( $97.48B) and net profit up 144.5% YoY to 87B CNY (D 
An inside look at the Windows and Surface leadership changes that could help Microsoft capitalize on AI PCs and transition Surface consumer devices to 
Dormakaba Locks Used in Millions of Hotel Rooms Could Be Cracked in Seconds 
Prioritizing Vulnerabilities: A Growing Imperative 
Cisco warns of password-spraying attacks targeting Secure Firewall devices 
LockBit Hacker Sentenced To 4 Years Jail Plus Fined $860K 
Huawei reports fastest growth in four years for 2023, as revenue up 9.63% to $97.48B, net profit up 144.5% to $12.04B, consumer revenue up 17.3% to  
An inside look at Windows and Surface leadership changes that could help Microsoft capitalize on AI PCs and transition Surface devices to Arm chips (T 
Google: Zero-Day Attacks Rise, Spyware and China are Dangers 
GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats 
Checkmarx Aligns With Wiz to Improve Application Security 
US Treasury Urges Financial Sector to Address AI Cybersecurity Threats 
The US OMB releases new AI guidance, requiring that all federal agencies submit an annual AI report and have a senior leader overseeing all AI systems 
GoPlus Report: Blockchain Networks Using API Security Data to Mitigate Web3 Threats 
Using Generative AI to Understand How an Obfuscated Script Works 
Google: China dominates government exploitation of zero-day vulnerabilities in 2023 
17 Billion Personal Records Exposed in Data Breaches in 2023 
The US OMB releases new guidance on AI, requiring all federal agencies to have a senior leader overseeing all AI systems they use and submit an annual 
Google blocked or removed 5.5B ads and 12.7M advertiser accounts for violating its policies in 2023, up from 5.2B ads and 6.7M advertiser accounts in  
Leaked images show a white disc-less Xbox Series X console, which Microsoft plans to release in 2024, with the same design as the existing black Xbox  
GLAAD: Meta is failing to curb posts calling for violence against trans people, posts calling trans and gender nonconforming people "satanic" 
GLAAD: Meta is failing to curb posts that call for violence against trans people and describe trans and gender nonconforming people as "satanic&q 
Google TAG Reports Zero-Day Surge and Rise of State Hacker Threats - HackRead 
Google addressed 2 Chrome zero-days demonstrated at Pwn2Own 2024 
CISA releases draft rule for cyber incident reporting 
Treasury report calls out cyber risks to financial sector fueled by AI 
Google TAG Reports Zero-Day Surge and Rise of State Hacker Threats 
Google says it blocked or removed 5.5B ads and 12.7M advertiser accounts for violating its policies in 2023, up from 5.2B and 6.7M respectively in 202 
92% of IT leaders report cyberattacks are more frequent than last year 
Violent Extremists Dox Executives, Enabling Physical Threats 
At Intel's AI Summit in Taipei, executives say Copilot will soon run locally on PCs and that there will be a 40 TOPS requirement for NPUs on next 
Spyware and zero-day exploits increasingly go hand-in-hand, researchers find 
Attackers Keep Evolving: Lessons from Expel s Q2 2023 Quarterly Threat Report 
The DDR Advantage: Real-Time Data Defense 
SASE Solutions Fall Short Without Enterprise Browser Extensions, New Report Reveals 
Chinese hackers target family members to surveil hard targets 
TheMoon bot infected 40,000 devices in January and February 
Some Apple users report being targeted in an "MFA bombing" attack in which their devices are inundated with alerts to approve a password cha 
Women working in tech are less likely to be employed full time 
2024 IT Risk and Compliance Benchmark Report Findings: Why Unifying Risk and Compliance Work Is No Longer Optional 
Understanding Phishing: Banner Effectiveness 
Only 5% of Boards Have Cybersecurity Expertise, Despite Financial Benefits 
It s Official: Cyber Insurance is No Longer Seen as a 'Safety Net' 
Recent ‘MFA Bombing’ Attacks Targeting Apple Users 
The Identity Underground Report: Deep insight into the most critical identity security gaps 
[New Research] KnowBe4's Report is a Call to Action for Global Organizations to Improve Their Security Culture 
US Treasury Dep announced sanctions against members of China-linked APT31 
Memo: Microsoft's Bing chief Mikhail Parakhin plans to exit his roles and look for a new position, after Microsoft hired Mustafa Suleyman to run  
Evidence Britain Provided on Hacking Allegations Was Insufficient, Says Chinese Foreign Ministry - U.S. News & World Report 
Cybersecurity in Financial Disclosures: 11 Topics Your Section 1C of 10-K Filings Should Address 
CISA adds FortiClient EMS, Ivanti EPM CSA, Nice Linear eMerge E3-Series bugs to its Known Exploited Vulnerabilities catalog 
US and UK accuse China of cyber operations targeting domestic politics 
Britain Says China Hacked Electoral Watchdog, Targeted Lawmaker Emails - U.S. News & World Report 
Is it time to enforce an Authority-to-Operate (ATO) for Healthcare Organizations? 
US must establish independent military cyber service to fix alarming problems report 
Iran-Linked APT TA450 embeds malicious links in PDF attachments 
Match Group adds Instacart CMO Laura Jones and Zillow co-founder Spencer Rascoff to its board and signs a deal with Elliott, reported to have a $1B M 
Match Group adds Instacart CMO Laura Jones and Zillow co-founder Spencer Rascoff to its board and signs a deal with Elliott, reported to have a $1B Ma 
FBI: Losses Due to Cybercrime Jump to $12.5 Billion as Phishing Continues to Dominate 
StrelaStealer targeted over 100 organizations across the EU and US 
Nigeria files tax evasion charges against Binance and executives Tigran Gambaryan and Nadeem Anjarwalla, detained since February; reports say Anjarwal 
GoFetch side-channel attack against Apple systems allows secret keys extraction 
Sources: Chinese social media startup Xiaohongshu reported $500M in net profit on $3.7B revenue in 2023, its first profit, and reached 312M MAUs, up 2 
Data Security Trends: 2024 Report Analysis 
"EasyRange" may insecurely load executable files 
Sources: Chinese social media startup Xiaohongshu reported its first profit with $500M in net profit on $3.7B revenue in 2023, and reached 312M MAUs,  
Russian hackers targeting German politicians report - DW 
Cybercriminals Accelerate Online Scams During Ramadan and Eid Fitr 
Long Term Security Attitudes and Practices Study 
Didi Q4: revenue up 55.4% YoY to $6.83B, a $113.15M net income, up from a loss in Q4 2022, as the company continues its recovery after regulatory ch 
Russia-linked APT29 targeted German political parties with WINELOADER backdoor 
Didi Q4: revenue up 55.4% YoY to $6.83B, a $113.15M net income, up from a $131.8M loss YoY, as the company continues its recovery after regulatory  
BeReal's challenges show the difficulty for new consumer apps to break out absent a big platform shift, as users lack the time to try additional  
Large-scale Sign1 malware campaign already infected 39,000+ WordPress sites 
Mac Users At High Hacking Risk Due To This 'Flaw' In Apple's M-Series Chips: Report - Times Now 
GM says it has stopped sharing driving data with two data brokers, after a report showed GM and others collecting and sharing data without clear conse 
Fueling Efficiency and Safety with FireMon 
Mozilla ends a partnership with Onerep, which lets users remove data from people-search sites, after a report showed Onerep's CEO founded dozens  
Russian hackers targeting German politicians report - DW (English) 
Unsaflok flaws allow to open millions of doors using Dormakaba Saflok electronic locks 
Sources: CoreWeave, which offers Nvidia GPUs in the cloud, is in talks to raise funding at a $16B valuation, after being valued at a reported $7B in D 
Mozilla Drops Onerep After CEO Admits to Running People-Search Networks 
Donald Trump's Truth Social is going public via a SPAC merger after DWAC shareholders approved the move; TMTG will be listed on the Nasdaq as ear 
Meituan reports Q4 revenue up 23% YoY to $10.2B and a net income of $308.4M, both above estimates, as the food delivery giant plans an international 
New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S. 
Trump's Truth Social is going public via SPAC after DWAC shareholders approve the merger; TMTG will be listed on Nasdaq as early as next week (Da 
China under cyberattack, 100s of govt units and firms compromised: Report - Business Standard 
CrowdStrike Enhances Cloud Detection and Response (CDR) Capabilities to Protect CI CD Pipeline 
Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects 
Meituan reports Q4 revenue up 23% YoY to $10.2B and a net income of $308.4M, both above estimates, as the food delivery giant plans international ex 
Consumer Reports warns about home security cameras that are easy to hack into - WCPO 9 Cincinnati 
Guess What Hackers Are Targeting Now Water Systems - The Tech Report 
Critical Fortinet’s FortiClient EMS flaw actively exploited in the wild 
U.K. Office Investigating Report That Kate Middleton s Health Records Were Breached - Forbes 
Memory-safe languages and security by design: Key insights, lessons learned 
2023 Annual Report 
Evolving Cyber Threats: Insights and Strategies from the 2023 FBI IC3 Report 
ICO Probes Kate Middleton Medical Record Breach 
CISA Recommends Continuous Cybersecurity Training 
North Korean Crypto Hackers Have Stolen $3B Since 2017, Says UN Security Council: Report - CoinDesk 
Ivanti urges customers to fix critical RCE flaw in Standalone Sentry solution 
Making Sense of Operational Technology Attacks: The Past, Present, and Future 
Aligning With NSA s Cloud Security Guidance: Four Takeaways 
Python Snake Info Stealer Spreading Via Facebook Messages 
Paris-based Greenly, whose carbon accounting software helps SMBs track their carbon emissions, raised a $52M Series B, and reports $10M+ in ARR in 202 
Fix Windows Cannot Access Shared Folder In Windows 11 
The Not-so-True People-Search Network from China 
Five Key Findings from the 2023 FBI Internet Crime Report 
Micron reports Q2 revenue up 58% YoY to $5.82B, vs. $5.53B est., and forecasts Q3 revenue above estimates, buoyed by demand for AI hardware; MU jumps  
Pwned by the Mail Carrier 
Netgear wireless router open to code execution after buffer overflow vulnerability 
Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands 
Threat actors actively exploit JetBrains TeamCity flaws to deliver malware 
CARFAX Puts an End to Scrapers and API Abuse With DataDome 
[Heads Up] Reinforce Your Defenses Against Rising Supply-Chain Cyber Threats 
15% of adults have been targeted by inheritance scams 
Attributing I-SOON: Private Contractor Linked to Multiple Chinese State-sponsored Groups 
UK Government: 75% of UK Businesses Experienced a Cyber Incident in 2023 
US-listed PDD, which runs Temu and Pinduoduo, reports Q4 revenue up 123% YoY to $12.5B and operating profit up 146% YoY to $3.2B, boosted by merchan 
BunnyLoader 3.0 surfaces in the threat landscape 
Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word 
A new report predicts the threats that will be most prevalent in 2024 
Tencent reports Q4 revenue up 7% YoY to $21.6B, vs. $21.8B est., a $3.8B net income, vs. $4.6B est., and plans a $12.8B+ stock buyback, as gaming  
Pokemon Company resets some users’ passwords 
GoTo reports a $5.76B net loss in 2023, up over 2x YoY, due to a write-down after TikTok bought a 75% stake in GoTo's Tokopedia, on $933.6M in  
Navigating the EU compliance landscape: How Detectify helps support customers in their NIS2 Directive, CER, and DORA compliance challenges 
Enterprise data security startup BigID raised $60M led by Riverwood Capital at a $1B+ valuation, bringing its total funding to $320M, and reports $10 
GoTo reports $5.76B net loss for 2023, up 2x+ YoY, due to a write-down on TikTok's acquisition of a 75% stake in GoTo's Tokopedia, on a net 
How AI can be hacked with prompt injection: NIST report - Security Intelligence 
Ukraine cyber police arrested crooks selling 100 million compromised accounts 
Michigan lawyer in voting machine tampering case arraigned in D.C. 
APIs Drive the Majority of Internet Traffic and Cybercriminals are Taking Advantage 
Xiaomi reports Q4 revenue up 11% YoY to $10.2B, vs. $10.1B est., net income up 50% YoY to $653M, and aims for its SU7 to become one of China's 
Research Shows IT and Construction Sectors Hardest Hit By Ransomware 
Adversarial Intelligence: Red Teaming Malicious Use Cases for AI 
From Deepfakes to Malware: AI's Expanding Role in Cyber Attacks 
Players hacked during the matches of Apex Legends Global Series. Tournament suspended 
Xiaomi reports Q4 revenue up 11% YoY to $10.2B, above $10.1B est., net income up 50% YoY to $653M, and plans to diversify its business by launching 
Earth Krahang APT breached tens of government organizations worldwide 
Unity's 2024 Gaming Report: the number of multiplatform games rose 40% since 2021, in-app ad revenue rose 26.7% YoY, 62% of studios are using AI, 
Protecting Against Attacks on NTLM Authentication 
Unity's 2024 Gaming Report: the number of multiplatform games up 40% since 2021, in-app advertising revenue up 26.7% YoY, 62% of studios are usin 
PoC exploit for critical RCE flaw in Fortra FileCatalyst transfer tool released 
5 Best Practices to Secure Azure Resources 
Carlsmed, which is developing an AI-powered personalized surgery tool, raised a $52.5M Series C co-led by B Capital and US Venture Partners (Abhinaya  
CISA guidance on AI security coming as part of DHS roadmap 
Fujitsu suffered a malware attack and probably a data breach 
Report reveals an increase in cloud account compromise incidents 
Pentagon Received Over 50,000 Vulnerability Reports Since 2016 - SecurityWeek 
Over 50,000 Vulnerabilities Discovered in DoD Systems Through Bug Bounty Program 
Remove WordPress miniOrange plugins, a critical flaw can allow site takeover 
Microsoft: 87% of UK Organizations Vulnerable to Costly Cyber-Attacks 
The Aviation and Aerospace Sectors Face Skyrocketing Cyber Threats 
Milady Founder Reports Hacker Attack, Over $3 Million Losses in ETH and NFTs - Coinpedia Fintech News 
Threat actors leaked 70,000,000+ records allegedly stolen from AT&T 
gitgub malware campaign targets Github users with RisePro info-stealer 
Security Affairs newsletter Round 463 by Pierluigi Paganini INTERNATIONAL EDITION 
Industry Benchmark Report, Issued by The FAIR Institute, Unveils the Dollar Impact of Cyber Incidents 
Scranton School District in Pennsylvania suffered a ransomware attack 
Video doorbells can be hacked: Consumer Reports CTV News - CTV News Toronto 
Organizations Are Vulnerable to Image-based and QR Code Phishing 
Lazarus APT group returned to Tornado Cash to launder stolen funds 
Bain: Indian startups raised $9.6B in 2023, down from $25.7B in 2022; over 35K Indian startups shut down in 2023 and leading startups laid off 20,000+ 
Microsoft security hacking incidents worry US customers - report - MSN 
Moldovan citizen sentenced in connection with the E-Root cybercrime marketplace case 
Polish Opposition Leader Refuses to Tell All to Phone-Hacking Commission - U.S. News & World Report 
Sophos: Cyber Security Professional Burnout Is Widespread, Creating Risk for APAC Organisations 
UK Defence Secretary jet hit by an electronic warfare attack in Poland 
Binance-incubated platform NFPrompt reports losses to hackers - Cointelegraph 
Recent DarkGate campaign exploited Microsoft Windows zero-day 
Keeping Customer Data Safe: AI’s Privacy Paradox 
FCC approves cybersecurity label for consumer devices 
Adobe reports Q1 revenue up 11% YoY to $5.18B, vs. $5.14B est., Digital Media revenue up 12% YoY to $3.82B, and Q2 revenue guidance below est.; ADBE d 
Training days: How officials are using AI to prepare election workers for voting chaos 
Report reveals 13,000 detected and blocked false investment domains 
New Report Suggests Surge in SaaS Assets, Employee Data Sharing 
Healthcare data breaches affect more than one million patients; Roku reports data breach 
Deliveroo reports adjusted EBITDA of £85M in 2023, its first-ever profit and up from a loss of £45M in 2022, after launching Deliv 
CrowdStrike and Intel Research Collaborate to Advance Endpoint Security Through AI and NPU Acceleration 
The Anatomy of an ALPHA SPIDER Ransomware Attack 
Does Your MDR Deliver Outcomes or Homework? 
CrowdStrike to Acquire Flow Security, Sets the Standard for Modern Cloud Data Security 
CrowdStrike a Research Participant in Two Latest Center for Threat-Informed Defense Projects 
March 2024 Patch Tuesday: Two Critical Bugs Among 60 Vulnerabilities Patched 
TikTok-funded Oxford Economics study of 1K US SMBs and 7.5K users: in 2023, TikTok drove $14.7B in SMB revenue, added $24.2B to US GDP, and supported  
Foxconn reports Q4 revenue down 5.7% YoY to $59B, as cloud and networking demand falls, net profit up 33% YoY to $1.69B, and expects flat 2024 consum 
US paid music subscribers hit a record 109M in 2023, rising to 136M including SiriusXM and Amazon Prime Music; seven of every 10 US millennials pay to 
Researchers found multiple flaws in ChatGPT plugins 
Security Flaws within ChatGPT Ecosystem Allowed Access to Accounts On Third-Party Websites and Sensitive Data 
Top cybersecurity officials stress more funding for federal agencies 
DDoS attacks reach critical levels in 14 seconds 
Fortinet fixes critical bugs in FortiOS, FortiProxy, and FortiClientEMS 
Investigation: 128 people complained to US law enforcement about non-consensual sexual content of them shared on OnlyFans between January 2019 and Nov 
An investigation finds 128 people complained to US law enforcement agencies over non-consensual sexual content being shared on OnlyFans between 2019 a 
Threat Intelligence for Financial Services 
PixPirate Android Banking Trojan Using New Evasion Tactic to Target Brazilian Users 
Threat actors leverage document publishing sites for ongoing credential and session token theft 
EquiLend Employee Data Breached After January Ransomware Attack 
Stanford University announced that 27,000 individuals were impacted in the 2023 ransomware attack 
How an infamous ransomware gang found itself hacked podcast 
RevenueCat survey of nearly 30K mobile subscription apps finds that only 17.2% of them will reach $1,000 in monthly revenue and only 3.5% will reach $ 
Tweaks Stealer Targets Roblox Users Through YouTube and Discord 
Microsoft Patch Tuesday security updates for March 2024 fixed 59 flaws 
Patch Tuesday, March 2024 Edition 
FakeUpdates Malware Campaign Targets WordPress – Millions of Sites at Risk 
Malicious Python Packages Target Crypto Wallet Recovery Passwords 
Russia’s Foreign Intelligence Service (SVR) alleges US is plotting to interfere in presidential election 
A survey of US teens: 38% say they spend too much time on their phone, vs. 27% for too much social media; girls are more likely to report too much tim 
A survey of US teens: 38% say they spend too much time on their phone, vs. 27% for too much social media; girls are more likely to report too much pho 
Insurance scams via QR codes: how to recognise and defend yourself 
The Rise of AI Worms in Cybersecurity 
South Korean Citizen Detained in Russia on Cyber Espionage Charges 
Massive cyberattacks hit French government agencies 
Intelligence officials warn pace of innovation in AI threatens US 
Oracle reports Q3 revenue up 7% YoY to $13.3B, meeting expectations, and cloud services and license support revenues up 12% YoY to $9.96B; ORCL jumps  
Biden’s budget proposal seeks funding boost for cybersecurity 
The Balancing Act for Mid-Market Firms: Navigating Digital Growth and Security Hurdles 
The 4 Big Questions the Pentagon s New UFO Report Fails to Answer 
The 4 Big Questions the Pentagon's New UFO Report Fails to Answer 
Incognito Darknet Market Mass-Extorts Buyers, Sellers 
Threat Groups Rush to Exploit JetBrains’ TeamCity CI CD Security Flaws 
BianLian group exploits JetBrains TeamCity bugs in ransomware attacks 
78% of MSPs state cybersecurity is a prominent IT challenge 
FBI's 2023 Internet Crime Report Highlights Alarming Trends on Ransomware 
Third-Party Breach and Missing MFA Contributed to British Library Cyber-Attack 
Experts released PoC exploit for critical Progress Software OpenEdge bug 
Magnet Goblin group used a new Linux variant of NerbianRAT malware 
BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks 
Cyber agency took systems offline after hack, report - Computing 
Hackers exploited WordPress Popup Builder plugin flaw to compromise 3,300 sites 
Looking back at "Deep Learning is Hitting a Wall", a 2022 article by Gary Marcus ridiculed by many, and how a paradigm shift is seemingly ne 
Looking back at "Deep Learning is Hitting a Wall", a 2022 article ridiculed by many, and how it still seems that a paradigm shift is needed  
Looking back at "Deep Learning is Hitting a Wall", a 2022 post ridiculed by Sam Altman and others, it still seems that a paradigm shift is n 
Lithuania security services warn of China’s espionage against the country 
Russian Hackers Continue To Exploit Microsoft's Internal Systems - The Tech Report 
Security Affairs newsletter Round 462 by Pierluigi Paganini INTERNATIONAL EDITION 
Threat actors breached two crucial systems of the US CISA 
FBI reports 22% increase in losses nationally to online hacking; Utah at mid-range - Gephardt Daily 
Report: Hackers used Ivanti vulnerabilities to breach two CISA systems - SiliconANGLE News 
What’s the cause of the problem part two 
Unsecured Video Doorbells Sold on Major Platforms: Millions at Risk of Hacking 
Understanding the White House Report on Secure and Measurable Software 
Russia-linked Midnight Blizzard breached Microsoft systems again 
A Close Up Look at the Consumer Data Broker Radaris 
UnitedHealth Sets Timeline to Restore Change Healthcare Systems After BlackCat Hit 
Play ransomware attack on Xplain exposed 65,000 files containing data relevant to the Swiss Federal Administration. 
What Happened in Cybersecurity in 2023: A Summary of Security Incidents, Vulnerability Information, and Cybersecurity Trends 
2023 FBI Internet Crime Report reported cybercrime losses reached $12.5 billion in 2023 
CISA needs better workforce planning to handle operational technology risks, GAO says 
Around We Go: Planet Stealer Emerges 
AI and Ransomware Top the List of Mid-Market IT Cyber Threats 
White House advisory group says market forces insufficient to drive cybersecurity in critical infrastructure 
$12.5 billion lost to cybercrime, amid tidal wave of crypto investment fraud 
The 3 most common post-compromise tactics on network infrastructure 
FBI: US Ransomware Losses Surge 74% to $59.6 Million in 2023 
Women s History Month: Celebration of Inspiration and Commitment 
Snake, a new Info Stealer spreads through Facebook messages 
National intelligence agency of Moldova warns of Russia attacks ahead of the presidential election 
A look at Apple's studio business: sources say the company spent $700M+ of its reported $1B+ annual 2023 spend on just three films, which earned  
New Python-Based Snake Info Stealer Spreading Through Facebook Messages 
Linux Malware targets misconfigured misconfigured Apache Hadoop, Confluence, Docker, and Redis servers 
CISA adds Apple iOS and iPadOS memory corruption bugs to its Known Exploited Vulnerabilities Catalog 
API Security in 2024: Imperva Report Uncovers Rising Threats and the Urgent Need for Action 
FBI: in 2023, Americans reported $12.5B+ in losses to online fraud, up 22% YoY; losses to investment fraud grew 38% YoY to $4.57B, with $3.94B related 
How To Fix Microsoft Teams Error CAA20003 Or CAA2000C 
Chicago Man Sentenced to Eight Years in Prison for Phishing Scheme 
Insurers report significant reduction in claims data following Change Healthcare hack - FierceHealthcare 
Proactive Intelligence: A Paradigm Shift In Cyber Defense 
Ukraine claims it hacked Russian Ministry of Defence, stole secrets and encryption ciphers 
White Hats on Offensive Against Black Hat Hackers: Report - TechNewsWorld 
Industrial cybersecurity startup Claroty raised $100M in a "pre-IPO round" at an estimated $2.5B valuation and reports $100M ARR, after rais 
69% of financial services consumers prioritize fraud protection 
ITRC Finds Online Job Scams on the Rise 
Watch out, GhostSec and Stourmous groups jointly conducting ransomware attacks 
JD reports Q4 revenue up 3.6% YoY to $42.6B, beating $41.7B est., after offering discounts and launches a $3B three-year stock buyback program; JD j 
Sources: ByteDance reports Q3 revenue up 43% YoY to $30.9B, $84.4B in January to September 2023 revenue, above 2022's $85.2B, and starts staff sh 
Canalys Q4 2023 smartphone chip shipments: MediaTek rose 21% YoY to 117M, Apple rose 7% YoY to 78M, Qualcomm rose 1% YoY to 69M; Samsung dropped 48% Y 
Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries 
What we know about reported healthcare hack ransom payment - KARE11.com 
What we know about reported hacker ransom possibly paid by United Health - KARE11.com 
Android and Windows RATs Distributed Via Online Meeting Lures 
Chat GPT and Nation-State Attackers: A New Era of AI-generated Attacks 
Apple emergency security updates fix two new iOS zero-days 
CrowdStrike reports Q4 revenue up 33% YoY to $845M, vs. $839M est., and agrees to buy cloud security company Flow Security for an undisclosed price; C 
Report Uncovers Massive Sale of Compromised ChatGPT Credentials 
Ransomware group behind Change Healthcare attack goes dark 
Hackers claim Minnesota-based UnitedHealth Group paid $22M ransom for patient, employee data, reports say - KSTP 
Report: Hackers Claim UnitedHealth Group Paid $22 Million in Ransomware Attack - PYMNTS.com 
Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware 
Is Facebook Down? Users Report Accounts 'Hacked' - Newsweek 
U.S. sanctions maker of Predator spyware 
Evolving Threats from Within: Insights from the 2024 Data Exposure Report 
AI Supply Chain Security: Hugging Face Malicious ML Models 
Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams 
Warning: Thread Hijacking Attack Targets IT Networks, Stealing NTLM Hashes 
Ukraine's Defence Intelligence reports on hacking Russian Defence Ministry servers: much information obtained - Yahoo! Voices 
Ukraine’s GUR hacked the Russian Ministry of Defense 
White House Recommends Memory-Safe Programming Languages and Security-by-Design 
Predator spyware infrastructure taken down after exposure 
Evolving cloud threats were observed in the last half of 2023 
86% of CIOS have implemented formal AI policies 
How Cybercriminals are Exploiting India's UPI for Money Laundering Operations 
Sea reports Q4 revenue up 4.8% to $3.6B, above $3.5B est., and adjusted EBITDA down 74% YoY to $126.7M, above $88M est., due to marketing costs; SE ju 
META hit with privacy complaints by EU consumer groups 
Heather Couk is here to keep your spirits up during a cyber emergency, even if it takes the Rocky music 
Report provides key insights into the energy and utilities sector 
Sea reports Q4 revenue up 4.8% to $3.6B, above $3.5B est., and adjusted EBITDA down 74% YoY to $126.7M, above $88M est., due to market expenses; SE ju 
New GTPDOOR backdoor is designed to target telecom carrier networks 
Ukraine's Defence Intelligence reports on hacking Russian Defence Ministry servers: obtained lot of information - Yahoo! Voices 
Threat actors hacked Taiwan-based Chunghwa Telecom 
Ukraine's Defence Intelligence reports on hacking Russian Defence Ministry servers: much information obtained - Ukrainska Pravda 
Popular doorbell camera brands contain security flaws, making them easy to hack: Report - The Hill 
New Linux variant of BIFROSE RAT uses deceptive domain strategies 
Ukraine's Defence Intelligence reports on hacking Russian Defence Ministry servers: obtained lot of information - Ukrainska Pravda 
Eken camera doorbells allow ill-intentioned individuals to spy on you 
Security Affairs newsletter Round 461 by Pierluigi Paganini INTERNATIONAL EDITION 
Inside "Are We Dating The Same Guy?" Facebook groups, which have a reported 3.5 million members, as some users say the dating forums cause m 
U.S. Judge ordered NSO Group to hand over the Pegasus spyware code to WhatsApp 
Amazon, Walmart, others are selling video doorbells that can be hacked, report finds - WPXI Pittsburgh 
A look at Elon Musk's claims in his OpenAI lawsuit, which seeks to open up GPT-4's source code, end Microsoft's exclusivity, and stop O 
ALPHV website goes down amid growing fallout from Change Healthcare attack 
An analysis of Musk's claims in his OpenAI lawsuit, which seeks to open up GPT-4's source code, end Microsoft exclusivity, and stop OpenAI&a 
Predator Spyware Operators Rebuild Multi-Tier Infrastructure to Target Mobile Devices 
Predator spyware endures even after widespread exposure, analysis shows 
Five Eyes alliance warns of attacks exploiting known Ivanti Gateway flaws 
Report: Average Initial Ransomware Demand in 2023 Reached $600K 
Cisco Live Melbourne SOC Report 
BEAST AI Jailbreak Language Models Within 1 Minute With High Accuracy 
Hacking cheap smart doorbells from Amazon is child's play: Report - Interesting Engineering 
Dell reports Q4 revenue down 11% YoY to $22.3B, vs. $22.2B est., Client revenue down 12% to $11.7B, and Infrastructure revenue down 6% to $9.3B; DELL  
HPE reports Q1 revenue down 14% YoY to $6.76B, vs. $7.1B est., Server revenue down 23% YoY to $3.4B, and reduces its FY 2024 outlook for sales growth  
Dell reports Q4 revenue down 11% YoY to $22.3B vs. $22.2B est., Client revenue down 12% to $11.7B, and Infrastructure revenue down 6% to $9.3B; DELL j 
Amazon recommends video doorbell vulnerable to hacking, report says - Business Insider 
Researchers found a zero-click Facebook account takeover 
Ivanti integrity checker tool needs latest update to work, Five Eyes alert warns 
How DSPM Can Help You to Safely Use Microsoft Copilot? 
5 Facts About File Integrity Monitoring and HIPAA Integrity Controls 
More than 60% of consumers would avoid a retailer post-breach 
Pharma Giant Cencora Reports Cybersecurity Breach 
Tools of the (Illegitimate) Trade: Mock API 
Russia Seeks to Exploit Western "War Fatigue" to Win in Ukraine 
New SPIKEDWINE APT group is targeting officials in Europe 
Researchers find serious security flaws in cheap video door bells sold by a Chinese company under various brands names on Amazon, Shein, and other sit 
How better key management can close cloud security gaps troubling US government 
Report: Iran s Mostazafan Foundation Website Hacked - Iran Front Page - Iran Front Page - IFP News 
New Backdoor Targeting European Officials Linked to Indian Diplomatic Events 
Lazarus APT exploited zero-day in Windows driver to gain kernel privileges 
UnitedHealth hit by antitrust probe and ransomware hacker report - TheStreet 
Hackers Threaten to Leak Trump Trial Docs If Ransom Isn't Paid: Report - The Daily Beast 
Notorious ransomware group claims responsibility for attacks roiling US pharmacies 
HP reports Q1 revenue down 4.4% YoY to $13.19B, vs. $13.56B est., Personal Systems revenue down 4% YoY to $8.8B, and Printing revenue down 5% YoY to $ 
Snowflake says that CEO Frank Slootman is retiring, and reports Q4 revenue up 32% YoY to $774.7M and Q1 product revenue guidance below est.; SNOW drop 
Salesforce reports Q4 revenue up 11% YoY to $9.29B, vs. $9.2B est., FY 2025 revenue guidance below est., and announces a $10B increase in its share bu 
Navigating the Waters of Generative AI 
Report Says Iranian Hackers Targeting Israeli Defense Sector - BankInfoSecurity.com 
Alleged renders of Samsung's Galaxy Z Fold 6 show a boxy frame, flat sides, and dimensions that make it slightly shorter and wider than its prede 
Tim Cook says Apple will "break new ground" on generative AI this year; Apple shareholders reject a request for report into whether Apple is 
Credential Theft Is Mostly Due To Phishing 
Track progress against SaaS security best practices with our new dashboard 
Calendar Meeting Links Used to Spread Mac Malware 
34 Million Roblox Credentials Exposed on Dark Web in Three Years 
Unmasking 2024’s Email Security Landscape 
UnitedHealth slumps on DoJ antitrust probe and ransomware hacker reports - TheStreet 
47% of cloud storage billing is allocated to data and usage fees 
What is Old is New Again: Lessons in Anti-Ransom Policy 
FBI, CISA, HHS warn of targeted ALPHV Blackcat ransomware attacks against the healthcare sector 
Third-party attack vectors are responsible for 29% of breaches 
Klarna reports 2023 revenue up 22% YoY to $2.28B, net loss down 76% YoY to $241M, credit losses down 32% YoY to $369M, and its workforce down 23% YoY 
Stop running security in passive mode 
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operations 
Klarna reports 2023 revenue up 22% YoY to $2.28B, a $241M net loss, down from $1.01B in 2022, with credit losses falling by 32% in 2023 to $369M (Fin 
Baidu reports Q4 revenue up 6% YoY to $4.9B and net income down 48% YoY to $366M, as chatbot Ernie, which has 100M+ users, began to augment its ads  
Bumble reports Q4 revenue up 13% YoY to $273.6M, a $32M net loss, vs. $159.2M YoY, and plans to eliminate 350 roles, about 37% of its workforce (Ashle 
Synopsys Report Exposes Extent of Open Source Software Security Risks 
Black Basta and Bl00dy ransomware gangs exploit recent ConnectWise ScreenConnect bugs 
Infamous ransomware gang caused pharmacy backlogs, report says - Business Insider 
Retail Cybersecurity: The Importance of Compliance and Risk Management 
eBay reports Q4 revenue up 2% YoY to $2.56B, vs. $2.51B est., GMV up 2% to $18.6B, and net income up 8% to $728M, and announces an additional $2B stoc 
Feds say AI favors defenders over attackers in cyberspace so far 
The average open source vulnerability is 2.5 years old 
Emails Are Responsible for 88% of Malicious File Deliveries 
White House to Software Developers: Use Memory Safe Languages 
Most Commercial Code Contains High-Risk Open Source Bugs 
Bumblebee Malware Targets US Businesses With New Methods 
US pharmacy outage caused by Blackcat ransomware attack on Optum Solutions 
Zoom reports Q4 revenue up 2.6% YoY to $1.15B, vs. $1.13B est., Enterprise revenue up 4.9% YoY to $667.3M, and announces a $1.5B stock buyback; ZM jum 
Kyberswap Hack: Blockchain Security Firm Reports Movement of 800 ETH From Exploiter's Address - TradingView 
Kyberswap Hack: Blockchain Security Firm Reports Movement of 800 ETH From Exploiter's Address Defi Bitcoin News - Bitcoin.com News 
Russia-tied hackers threaten to leak Georgia Trump trial docs if ransom isn't paid: report - Raw Story 
Report: Cyberattack at UnitedHealth Group launched by Blackcat ransomware group - Star Tribune 
Unity reports Q4 revenue up 35% YoY to $609M, vs. $551M est., but down 2% YoY to $510M excluding a Wētā FX deal, Q1 sales guidance  
Zoom reports Q4 revenue of $1.15B, up 2.6% YoY, vs. $1.13B est., Enterprise revenue of $667M, up 4.9% YoY, and announces a $1.5B stock buyback; ZM jum 
A cyber attack hit Thyssenkrupp Automotive Body Solutions business unit 
ONCD releases report on the adoption of memory-safe languages 
Leaked Data Shows China Cyber Firm Hacked Govt Agencies - The Tech Report 
48% of executives focus AI strategy on SaaS applications 
The UK has seen an increase in cyberattacks against higher education 
White House Urges Tech Industry to Eliminate Memory Safety Vulnerabilities 
Five Eyes nations warn of evolving Russian cyberespionage practices targeting cloud environments 
CrowdStrike 2024 Global Threat Report: 6 Key Takeaways 
Report: Cyberattacks Against Software Supply Chains Become More Targeted 
IntelBroker claimed the hack of the Los Angeles International Airport 
FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga. 
A consultant working for Rep. Dean Phillips, who challenged Biden in NH's primary, admits to producing the deepfake robocalls, saying anyone can  
The reported leak of Chinese hacking documents supports experts' warnings about how compromised the US could be - Yahoo News 
Report: Hackers accessed TSTT using admin s credentials - Trinidad & Tobago Express Newspapers 
The reported leak of Chinese hacking documents supports experts' warnings about how compromised the US could be - Yahoo! Voices 
Crooks stole $10 million from Axie Infinity co-founder 
Maldives' Home Ministry website hacked over 'anti-India actions': Report - Business Today 
Security Affairs newsletter Round 460 by Pierluigi Paganini INTERNATIONAL EDITION 
Ukrainian TV channel reports Russian hacker attack, broadcasting propaganda - Yahoo News 
Ukrainian TV channel reports Russian hacker attack, broadcasting propaganda - Ukrainska Pravda 
Russian hacker is set to face trial for the hack of a local power grid 
HP s Threat Report New Threats, Bigger Problems 
After LockBit takedown, police try to sow doubt in cybercrime community 
Face off: New Banking Trojan steals biometrics to access victims bank accounts 
Nearly One in Three Cyber Attacks In 2023 Involved The Abuse of Valid Accounts 
Organizations Unprepared to Face Cloud Security Threats 
Chinese hackers breached immigration data from Indian government: Report - Hindustan Times 
Indian immigration data worth nearly 100 GB stolen by Chinese hackers: Report Mint - Mint 
Improving domain discovery with new connectors 
Block reports Q4 revenue up 24% YoY to $5.77B, Square profit up 18% YoY, Cash App profit up 25% YoY, and forecasts Q1 adjusted EBITDA above est.; SQ j 
Beyond the border scam , pay attention to the instance of the new Nigerian fraud 
TikTok s latest actions to combat misinformation shows it s not just a U.S. problem 
IBM X-Force Report 2024: Cybercriminals Favor Valid Account Exploitation Over Hacking - Yahoo Lifestyle UK 
Year-over-year, the median initial ransom has risen by 20% 
Reported leak of Chinese hacking files supports US warnings - Business Insider 
Downdetector: AT&T users report ongoing cellular outages across the US, starting at around 4:30AM ET; AT&T promises a fix; T-Mobile and Verizo 
X reports taking down accounts and posts following an order by the Indian government, which local media tied to farmers' protests, but disagrees  
Multiple XSS flaws in Joomla can lead to remote code execution 
Report finds blocklists are still effective in mitigating attacks 
Strata Identity Named a Representative Vendor in the 2024 Gartner Reduce IAM Technical Debt Report 
Top 10 Tips To Protect Cryptocurrency From Hackers And How To Report A Cryptocurrency Hack - Blockchain Magazine 
Downdetector: users of AT&T, Verizon, and other networks report ongoing cellular outages across the US, starting at around 4:30AM ET; T-Mobile den 
New Leak Shows Business Side of China’s APT Menace 
Downdetector: users of AT&T, Verizon, and other networks report ongoing cellular outages across the US, starting around 4:30AM ET; T-Mobile denies 
Trust in biometric data is declining among consumers 
Downdetector: users of AT&T, Verizon, T-Mobile, and other networks report ongoing cellular outages across the US, starting at around 4:30AM ET (Re 
X reports taking down accounts and posts following an order by the Indian government, which local media tied to farmers' protests, and disagrees  
New Mustang Panda campaign targets Asia with a backdoor dubbed DOPLUGS 
Leaked files show Chinese agency involved in hacking efforts in India, Thailand, UK, says report - The Indian Express 
Lenovo beats estimates with Q3 revenue up 3% YoY to $15.72B after 5 quarters of decline and net income down 23% YoY to $337M; services revenue up 10%  
IBM X-Force Report 2024: Cybercriminals Favor Valid Account Exploitation Over Hacking - Yahoo Movies UK 
Leaked documents show how firm supports Chinese hacking operations 
Nvidia reports Q4 revenue up 265% YoY to $22.1B, vs. $20.62B est., Data Center revenue up 409% to $18.4B, Q1 revenue forecast above estimates; NVDA ju 
IBM report finds cybercriminals are increasingly exploiting legitimate user identities - SiliconANGLE News 
Nvidia reports Q4 revenue up 265% YoY to $22.1B, vs. $20.62B est., Data Center revenue up 409% to $18.4B, and FY 2024 revenue up 126% to $60.9B; NVDA  
BuzzFeed sells Complex, which it acquired for $300M in 2021, to livestream shopping platform Ntwrk for $108.6M; BuzzFeed plans to lay off 16% of its w 
Exposed: Global Espionage Unleashed by China's Police in Groundbreaking Leak 
Building a Better Perimeter Defense Strategy to Meet the Challenges of 2024 
IBM X-Force Report 2024: Cybercriminals Favor Valid Account Exploitation Over Hacking - Yahoo Life 
CrowdStrike's Global Threat Report: in 2023, cloud intrusions grew 75%, data theft victims named on data leak sites grew 76%, 34 new groups were  
Biden signs executive order to give Coast Guard added authority over maritime cyber threats 
IBM X-Force Report 2024: Cybercriminals Favor Valid Account Exploitation Over Hacking - Yahoo Movies Canada 
IBM X-Force Report 2024: Cybercriminals Favor Valid Account Exploitation Over Hacking - WWD 
Over 40% of Firms Struggle With Cybersecurity Talent Shortage 
New Redis miner Migo uses novel system weakening techniques 
CrowdStrike's 2024 Global Threat Report: cloud intrusions jumped 75%, a 76% rise in data theft victims named on data leak sites, 34 newly named g 
CVEs expected to increase 25% in 2024 
IBM: hackers are finding more opportunities to log in via legitimate credentials, rather than hacking into networks; info-stealing malware grew 266% Y 
How CVSS 4.0 changes (or doesn t) the way we see vulnerability severity 
IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the most-targeted sectors 
Report: Average breakout time for intrusive activity is 62 minutes 
IBM: Identity Compromises Surge as Top Initial Access Method for Cybercriminals 
Biden to sign executive order to give Coast Guard added authority over maritime cyber threats 
Critical flaw found in deprecated VMware EAP. Uninstall it immediately 
IBM: hackers are finding more opportunities to log in via legitimate credentials, rather than hacking into networks; infostealing malware jumped 266%  
Generative AI and elections are key focus for hackers in 2024, report warns - The Independent 
Filing: Samsung sold 1.58M ASML shares, or 0.4% of ASML, worth $930M in September 2023, reducing its stake to zero, as Samsung looks to new areas of  
Biden executive order gives Coast Guard added authority over maritime cyber threats 
Generative AI and elections are key focus for hackers in 2024, report warns - The Irish News 
Generative AI and elections are key focus for hackers in 2024, report warns - Yahoo News UK 
Microsoft Exchange flaw CVE-2024-21410 could impact up to 97,000 servers 
Palo Alto Networks reports Q2 revenue up 19% YoY to $1.98B, vs. $1.97B est., and lowers its full-year guidance for billings and revenue; PANW drops 19 
ConnectWise fixed critical flaws in ScreenConnect remote access tool 
Lockbit Hackers' Swagger on Display After Police Leak Identities Online - U.S. News & World Report 
Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates 
Industrial sector ransomware attacks increased by 50% in 2023 
More details about Operation Cronos that disrupted Lockbit operation 
Cycode Named in the 2024 Gartner Emerging Tech Impact Radar: Cloud-Native Platforms Report 
New Migo Malware Targeting Redis Servers for Cryptocurrency Mining 
About 13,000 Wyze Customers Affected by Camera Glitch 
Report: Malicious emails bypassing secure email gateways rose by 105% 
When is PCI Required? (+ 4 Tips for Maintainig Compliance) 
Cofense Annual Report Indicates 105% Increase in Malicious Emails Bypassing Secure Email Gateways 
Astaroth, Mekotio & Ousaban abusing Google Cloud Run in LATAM-focused malware campaigns 
Maryland Busts $9.5 Million #BEC Money Laundering Ring 
US adversaries employ generative AI in attempted cyberattack 
New Report Reveals North Korean Hackers Targeting Defense Firms Worldwide 
New Report Reveals North Korean Hackers Targeting Defense Firms Worldwide - The Hacker News 
Report: Manufacturing bears the brunt of industrial ransomware 
Cactus ransomware gang claims the theft of 1.5TB of data from Energy management and industrial automation firm Schneider Electric 
Report: Lazarus hacking group goes after defence sector - Cyber Daily 
Operation Cronos: law enforcement disrupted the LockBit operation 
State-Sponsored Threat Actors Targeting European Union Entities With Spear Phishing Campaigns 
State-Sponsored Hackers Employ ChatGPT in Cybercrime Schemes, Microsoft Reports - CybersecurityNews 
Anatsa Android banking Trojan expands to Slovakia, Slovenia, and Czechia 
Poland Starts Probe Into Allegations of Illegal Phone-Hacking - U.S. News & World Report 
Russia-linked APT TAG-70 targets European government and military mail servers exploiting Roundcube XSS 
The Attacker Behind Vermont Hospital's Malware Ambush Pleads Guilty - The Tech Report 
Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices 
How BRICS Got “Rug Pulled” Cryptocurrency Counterfeiting is on the Rise 
Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries 
Israeli Aircraft Survive Cyber-Hijacking Attempts 
Security Affairs newsletter Round 459 by Pierluigi Paganini INTERNATIONAL EDITION 
Ukrainian national faces up to 20 years in prison for his role in Zeus, IcedID malware schemes 
CISA: Cisco ASA FTD bug CVE-2020-3259 exploited in ransomware attacks 
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign 
Navigating 2024's Geopolitical Fault Lines 
US gov offers a reward of up to $10M for info on ALPHV Blackcat gang leaders 
CISA Warning: Akira Ransomware Exploiting Cisco ASA FTD Vulnerability 
Israeli NSO Group Suspected of “MMS Fingerprint” Attack on WhatsApp 
CrowdStrike Named the Only Customers’ Choice: 2024 Gartner Voice of the Customer for Vulnerability Assessment 
February 2024 Patch Tuesday: Two Zero-Days Amid 73 Vulnerabilities 
U.S. CISA: hackers breached a state government organization 
OpenAI and Microsoft Remove State-backed Hacker Groups From Their Apps - The Tech Report 
Hacker exposed weakness in German electronic ID, magazine reports - Yahoo News 
PDF Malware on the Rise, Used to Spread WikiLoader, Ursnif and DarkGate 
Russia-linked Turla APT uses new TinyTurla-NG backdoor to spy on Polish NGOs 
New London Couple Bilked Out Of $14K In Phantom Hacker Scam: Report - New London, CT Patch 
Learn the Most Essential Cybersecurity Protections for Schools 
Elon Musk s X Gave Check Marks to Terrorist Group Leaders, Report Says 
Coinbase reports Q4 revenue up 51% YoY to $953.8M, vs. $826M est., net income of $273M, its first profit in two years, vs. a loss of $557M YoY; COIN j 
Roku reports Q4 revenue up 14% YoY to $984.4M, vs. $968.2M est., and warns of a "challenging" environment for media and entertainment in 202 
DoorDash reports Q4 revenue up 27% YoY to $2.3B, vs. $2.24B est., total orders up 23% YoY to 574M, and Q1 profit forecast below estimates; DASH drops  
Microsoft says its Xbox Game Pass service now has 34M subscribers, up 36% from the 25M subscribers Microsoft reported more than two years ago (Tom War 
New London Couple Bilked Out Of $14K In Phantom Hacker Scam: Report - Patch 
Why the toothbrush DDoS story fooled us all 
A cyberattack halted operations at Varta production plants 
Bank of America, Integris Health experience data breaches 
US Justice Department Says It Disrupted Russian Intelligence Hacking Network - U.S. News & World Report 
Filings: Sam Altman is the sole owner of the OpenAI Startup Fund, which reported $175M in total commitments in May 2023; Microsoft is an outside limit 
Hackers got nearly 7 million people s data from 23andMe. The firm blamed users in very dumb move 
Microsoft and OpenAI Report on Hackers Using AI for Cyber Attacks - Digital Information World 
CISA adds Microsoft Windows bugs to its Known Exploited Vulnerabilities catalog 
Nation-state actors are using AI services and LLMs for cyberattacks 
Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyber Attacks 
X removes paid checkmarks from some accounts after a watchdog group found 28 verified accounts allegedly tied to Hezbollah and other US-sanctioned ent 
Cisco reports Q2 revenue down 6% YoY to $12.79B, vs. $12.71B est., and plans to cut 5% of its global workforce, or about 4,250 jobs; CSCO drops 5%+ af 
Network Security: A Top Priority for Healthcare Organizations 
Report reveals the 5 fraud threats to watch out for in 2024 
Abusing the Ubuntu ‘command-not-found’ utility to install malicious packages 
Microsoft, OpenAI report identifies hacker groups using AI - Yahoo Finance 
Twilio reports Q4 revenue up 5% YoY to $1.08B vs. $1.05B est., 305K+ active customer accounts vs. 290K+ YoY, and Q1 revenue forecast below est.; TWLO  
Cisco reports Q2 revenue down 6% YoY to $12.79B, vs. $12.71B est., and plans to cut 5% of its global workforce; Cisco had 85,000 employees as of July 
Phishing attacks increased 106% year over year 
State-Backed Hackers Exploit Microsoft-Backed OpenAI Tools, Report Reveals - PYMNTS.com 
Meta details actions against eight spyware firms 
PII Input Sparks Cybersecurity Alarm in 55% of DLP Events 
55% of Generative AI Inputs Include Sensitive Data: Menlo Security 
Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyberattacks 
Iranian Hackers Target Israel and US to Sway Public Opinion in Hamas Conflict 
2023 Ransomware Attack Report 
How are attackers using QR codes in phishing emails and lure documents? 
55% of generative AI inputs comprised personally identifiable data 
AI in Cyberspace: A Double-Edged Sword 
Sony reports Q3 revenue up 22% YoY to $25.11B, operating income up 10% YoY to $3.1B, meeting est., and 8.2M PS5 units sold, roughly 1M lower than pr 
Hackers for China, Russia and Others Used OpenAI Systems, Report Says - The New York Times 
Microsoft reports details AI use by China, Russia, North Korea, Iran - The Washington Post 
State-backed hackers are experimenting with OpenAI models 
ASML CFO Roger Dassen says the chip market "has now reached the lowest point of the dip" and "the recovery is nascent"; ASML' 
South Korea says presumed North Korean hackers breached personal emails of presidential staffer - Quartz 
Microsoft Patch Tuesday for February 2024 fixed 2 actively exploited 0-days 
Sony reports Q3 revenue up 22% YoY to $25.11B, operating income up 10% YoY to $3.1B, meeting est., and 8.2M PS5s sold, roughly 1M units lower than p 
The Next Evolution of Recorded Future AI: Powering the Future of Threat Intelligence 
Google: Iranian, regional hacking operations that target Israel remain opportunistic but focused 
Volt Typhoon targeted emergency management services, per report 
A ransomware attack took 100 Romanian hospitals down 
GlobalFoundries reports Q4 revenue down 12% YoY to $1.85B, vs. 1.85B est., net income down 58% YoY to $278M, forecasted sales of $1.52B in Q1, vs. $1. 
Instacart reports Q4 revenue up 6% YoY to $803M vs. $804M est., plans to lay off 250 workers, or 7% of staff; three top execs are leaving for person 
A researcher reported a bug in fertility tracking app Glow's forum in October that exposed the personal data of 25M users; Glow fixed the bug in 
Lyft reports Q4 revenue up 4% YoY to $1.2B, net loss of $26.3M, vs. $588.1M YoY, active riders up 10% to 22.4M, and Q1 forecast above est.; LYFT jumps 
Airbnb reports Q4 revenue up 17% YoY to $2.22B, vs. $2.16B est., Nights and Experiences Booked up 12% YoY to 98.8M, and announces a $6B share buyback  
Robinhood reports Q4 net revenue up 24% YoY to $471M, net interest revenue up 41% YoY to $236M, and net income of $30M, vs. a loss of $166M YoY; HOOD  
Shopify Q4: revenue up 24% YoY to $2.1B, vs. $2.08B est., $657M net income, vs. a $623M loss YoY, and GMV up 23% YoY to $75.1B, vs. $71.6B est.; SHOP  
CrowdStrike Named a Leader in Forrester Wave for Cloud Workload Security 
Beyond Compliance: Secure Your Business in the Cloud with Falcon Cloud Security 
4 Major Falcon LogScale Next-Gen SIEM Updates That Accelerate Time-to-Insights 
Architecture Drift: What It Is and How It Leads to Breaches 
Data Protection Day 2024: As Technology and Threats Evolve, Data Protection Is Paramount 
How to Secure Business-Critical Applications 
CrowdStrike Defends Against Azure Cross-Tenant Synchronization Attacks 
HijackLoader Expands Techniques to Improve Defense Evasion 
Key Findings from CrowdStrike s 2024 State of Application Security Report 
Bank of America customer data compromised after a third-party services provider data breach 
CISOs share 5 priorities for 2024 
Use of Hunter-Killer Malware on the Rise, Study Finds 
91% of organizations faced a software supply chain attack last year 
Reshaping the Focus of Cybersecurity 
Report: Over 1.76 billion phishing emails were sent in 2023 
Shopify reports Q4 revenue up 24% YoY to $2.1B, above $2.08B est., and Gross Merchandise Volume up 23% YoY to $75.1B, above $71.6B est.; SHOP drops 10 
Ransomfeed – Third Quarter Report 2023 is out! 
Global Malicious Activity Targeting Elections is Skyrocketing 
Researchers released a free decryption tool for the Rhysida Ransomware 
New Ivanti Secure VPN Zero-Day Vulnerabilities and Patches 
CISA adds Roundcube Webmail Persistent XSS bug to its Known Exploited Vulnerabilities catalog 
CISA releases 2024 priorities for the Joint Cyber Defense Collaborative 
Report: AI cybersecurity market projected to exceed $133 billion 
Ukraine's GUR military intelligence unit says Russian forces are using Starlink terminals on the front line, confirming media reports of Russia u 
What do auditors do all day? 
Raspberry Robin spotted using two new 1-day LPE exploits 
Security Affairs newsletter Round 458 by Pierluigi Paganini INTERNATIONAL EDITION 
Analysis: in 2023, 84.63% of TikTok videos contained music, up from 69.13% in 2019 and 83.06% in 2022, vs. 84% on YouTube, 58% on Instagram, and 49% o 
Scripps News Reports: Hacking America - WRTV Indianapolis 
Crypto Hack Weekly Report: FTX s $400 Million Finally Found? - Coinpedia Fintech News 
Analysis: in 2023, 85% of videos on TikTok contained music, up from 69% in 2019; 84% of videos on YouTube, 58% on Instagram, and 49% on Facebook conta 
Scripps News Reports: Hacking America - WPTV News Channel 5 West Palm 
Scripps News Reports: Hacking America - FOX 47 News Lansing - Jackson 
Scripps News Reports: Hacking America - KMTV 3 News Now Omaha 
macOS Backdoor RustDoor likely linked to Alphv BlackCat ransomware operations 
Scripps News Reports: Hacking America - Scripps News 
The FTC says Americans lost $10B+ to scammers in 2023, up 14% YoY, with 2.6M+ consumers filing fraud reports; email was the most commonly used method  
The FTC says Americans lost over $10B to scammers in 2023, up 14% YoY, with 2.6M+ consumers filing fraud reports; imposter scams were the most reporte 
Checkmarx Report Surfaces Software Supply Chain Compromises 
QR Code Phishing Attacks Target High-Level Executives: Report 
Raspberry Robin Malware Upgrades with Discord Spread and New Exploits 
Americans received 15 spam calls a month in Q4 2023 
Browser-Based Phishing Attacks Increase 198%, With Evasive Attacks Increasing 206% 
Calculating Materiality for SEC Rule 1.05 
Black Basta ransomware gang hacked Hyundai Motor Europe 
Cyber security threats are predominantly as-a-service attacks 
MoqHao Android Malware Evolves with Auto-Execution Capability 
Ransomware threats increased by twofold in 2023 
2024 Annual State of Email Security Report: What to Expect 
New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack 
Fortinet warns of a new actively exploited RCE flaw in FortiOS SSL VPN 
26 Cyber Security Stats Every User Should Be Aware Of in 2024 
A Nebraska bill would hire a hacker to probe the state s computer, elections systems - WKRN News 2 
Take-Two reports Q3 net bookings down 3% YoY to $1.34B, net revenue down 3% YoY to $1.37B, and plans cost reductions "more robust" than in 2 
Cloudflare reports Q4 revenue up 32% YoY to $362.5M, vs. $353.1M est., net loss of $27.9M, vs. $45.9M YoY, and Q1 revenue guidance above est.; NET jum 
US offers $10 million reward for info on Hive ransomware group leaders 
Pinterest reports Q4 revenue up 12% YoY to $981.3M, vs. $991M est., MAUs up 11% to 498M, vs. 487M est., and a weaker-than-expected Q1 forecast; PINS d 
Chinese Hackers Maintained Access to US Infrastructure for Years, Report Finds - The Citizen 
Arm closed up 47.89% after issuing a strong profit forecast, adding $38B to its market cap, with $34B+ of that accruing to SoftBank, which owns 90% o 
Pinterest Q4: revenue up 12% YoY to $981.3M, vs. $991M est., MAUs up 11% YoY to 498M, vs. 487M est., and a weaker-than-expected Q1 forecast; PINS drop 
Spyware isn t going anywhere, and neither are its tactics 
Unraveling the truth behind the DDoS attack from electric toothbrushes 
EC-Council CEH Threat Report 2024 Cybersecurity Report Latest Threat report with insights and guidance - EC-Council 
Report: Blocked IP addresses increased by 116.42% 
Report Details Scope of Global Threat to Elections 
Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017 2023 
Millions of hacked toothbrushes used in Swiss cyber attack, report says - MSN 
New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organization 
Unprecedented Rise of Malvertising as a Precursor to Ransomware 
Millions of hacked toothbrushes used in Swiss cyber attack, report says - msnNOW 
Amsterdam-based payments giant Adyen reports H2 2023 net revenue up 23% YoY to €887M and processed volume up 29% YoY to €544.1B; ADY 
SoftBank reports Q3 net profit of $6.4B, after four quarters of losses, lifted by a T-Mobile US shares windfall; the Vision Fund unit reported a $2.8 
Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea 
SoftBank reports Q3 net profit of $6.4B, after four quarters of losses, lifted by T-Mobile US shares windfall; the Vision Fund unit reported a $2.85B 
NSFOCUS WAF Security Reports 
Report: Lawsuit Accuses Anna's Archive of Hacking WorldCat, Stealing 2.2 TB Data - LJ INFOdocket 
Google Cybersecurity Action Team Threat Horizons Report #9 Is Out! 
Chinese spies hacked Dutch defense network last year, report says - Nikkei Asia 
DHS s initial AI inventory included a cybersecurity use case that wasn t AI, GAO says 
PayPal reports Q4 revenue up 9% YoY to $8B, vs. $7.87B est., and total payment volume up 15% YoY to $409.8B, vs. $404.45B est. (Manya Saini Reuters) 
Arm reports Q3 revenue up 14% YoY to $824M, vs. $761.6M est., and forecasts Q4 sales and adjusted profit above expectations; ARM jumps 21%+ (Reuters) 
Using Proactive Intelligence Against Adversary Infrastructure 
CISA adds Google Chromium V8 Type Confusion bug to its Known Exploited Vulnerabilities catalog 
A report from the US, UK, Australia, Canada, and New Zealand: China-backed hacking group Volt Typhoon has had access to some key US infrastructure for 
Chinese Hackers Have Been Secretly Embedded In Key US Infrastructure Systems For 'At Least Five Years': REPORT - Daily Caller 
Malicious PDFs, deepfakes, and romance scams were just some of the 10 billion cyber attacks we saw last year 
New intelligence report warns China has been in U.S. critical infrastructure for "at least five years" - Axios 
Feds: Chinese hacking operations have been in critical infrastructure networks for five years 
From Cybercrime Saul Goodman to the Russian GRU 
Alibaba reports Q3 revenue up 5% YoY to $36.7B, net income down 69% YoY to $2B, Taobao and Tmall revenue up 2% YoY to $18B, and approves a $25B sha 
Ransomware payments in 2023 hit a record $1.1B, up from $567M in 2022 and $983M in 2021, after a major escalation of the frequency, scope, and volume  
The Growing Threat of Ransomware Attacks 
Critical shim bug impacts every Linux boot loader signed in the past decade 
Ransomware payments in 2023 reached a record $1.1B, up from $567M in 2022 and $983M in 2021, as the frequency, scope, and volume of attacks escalated  
Google report reveals government hackers exploiting 0-day vulnerabilities to target iPhone users - India TV News 
Millions of hacked toothbrushes used in Swiss cyber attack, report says - The Independent 
Ransomware Payments Hit a Record $1.1 Billion in 2023 
Roblox reports Q4 revenue up 30% YoY to $749.9M, bookings up 25% YoY to a record $1.1B, DAUs up 22% YoY to 71.5M, and $2.8B in 2023 revenue; RBLX jump 
Chinese Hackers Spy on Dutch Ministry of Defense: A Story of Alarming Cyber Espionage 
Alibaba reports Q3 revenue up 5% YoY to $36.7B, net income down to $2B, Taobao and Tmall revenue up 2% YoY to $18B, and a $25B share buyback; BABA  
Uber reports Q4 revenue up 15% YoY to $9.9B, Gross Bookings up 22% YoY to $37.6B, a $1.9B net income, 150M MAUs, and first full-year operating profit  
Uber reports Q4 revenue up 15% YoY to $9.9B, Gross Bookings up 22% YoY to $37.6B, a $1.9B net income, up from a $9.1B loss YoY, and a record 150M MAUs 
Alibaba reports Q3 revenue up 5% YoY to $36.7B, net income down to $2B, Taobao and Tmall Group revenue up 2% YoY to $18B, and plans a $25B share bu 
China-linked APT deployed malware in a network of the Dutch Ministry of Defence 
Legit Security Named in the 2024 Gartner Emerging Tech Impact Radar: Cloud-Native Platforms report 
Researchers say 3M smart toothbrushes with a Java-based OS were compromised by hackers and incorporated into botnets used in DDoS attacks against a S 
Snap reports Q4 revenue up 5% YoY to $1.36B, vs. $1.38B est., DAUs up 10% YoY to 414M, a net loss of $248M, vs. $288M YoY; SNAP drops 30%+ after hours 
Commercial spyware vendors are behind most zero-day exploits discovered by Google TAG 
Snap reports Q4 revenue up 5% YoY to $1.36B, vs. $1.38B est., DAUs up 10% YoY to 414M, a net loss of $248M, vs. $288M YoY; SNAP drops 28%+ after hours 
SMIC reports unaudited Q4 revenue up 3.5% YoY to $1.68B, vs. $1.66B est., and profit attributable to owners at $174.68M, down from $385.53M YoY; SMIC  
The Netherlands says Chinese state-sponsored hackers broke into the Dutch Ministry of Defence's internal network in 2023, using a Fortinet vulner 
2024 K8s Benchmark Report: The Latest Trends in Workload Reliability 
Chinese Spies Hacked Dutch Defence Network Last Year - Intelligence Agencies - U.S. News & World Report 
Report Surfaces Extent of SaaS Application Insecurity 
A man faces up to 25 years in prison for his role in operating unlicensed crypto exchange BTC-e 
Malware-as-a-Service Now the Top Threat to Organizations 
China cyberspies hacked computers at Dutch defense ministry - report - The Jerusalem Post 
China cyberspies hacked computers at Dutch defense ministry -report - The Jerusalem Post 
China cyber spies hacked computers at Dutch defense ministry -report - The Jerusalem Post 
Beware: Fake Facebook Job Ads Spreading 'Ov3r_Stealer' to Steal Crypto and Credentials 
Britain, France Lead 35 Nation Agreement on Controlling Spyware, Mercenary Hackers - U.S. News & World Report 
SMIC reports unaudited Q4 revenue rose 3.5% YoY to $1.68B, below est., and $902.5M net income, down from $1.82B YoY; 2023 capex was up 17.6% YoY to $7 
Safer Internet Day: Two Million Brits Victims of Financial Identity Fraud 
Google's TAG publishes a report on commercial spyware, detailing 40 vendors, and says global governments should take more aggressive steps to co 
Spotify reports Q4 revenue up 16% YoY to €3.7B, MAUs up 23% YoY to 602M, subscribers up 15% YoY to 236M, a €75M operating loss, and  
U.S. Gov imposes visa restrictions on individuals misusing Commercial Spyware 
Google: Governments need to do more to combat commercial spyware 
How are user credentials stolen and used by threat actors? 
A look at the legal challenges of defining and prosecuting virtual crimes, after rising reports of attacks, harassment, and sexual assault in the meta 
Palantir reports Q4 revenue up 20% YoY to $608.4M, vs. $602.4M est., net income $93.4M, up from $30.9M YoY, and its LLMs saw "unrelenting" d 
Nintendo reports Q3 net sales down 6% YoY to $4B, net profit up 18% YoY to $919M, and forecasts 15.5M Switch sales in the current fiscal year, up fr 
Unit 42: the number of victims reported by ransomware leak sites grew 49% YoY in 2023, with 50% in the US, despite authorities taking down some servi 
Nintendo reports Q3 net sales of $4B and net profit of $919M, both above estimates, expects to sell 15.5M Switch consoles in current fiscal year, up 
CVE-2024-21893: Another Ivanti Vulnerability Exploited in the Wild. Verify with NodeZero Today! 
Palantir reports Q4 revenue up 20% YoY to $608.4M, vs. $602.4M est., net income $93.4M, up from $30.9M YoY, and LLM tech saw "unrelenting" d 
What the 6 Phases of the Threat Intelligence Lifecycle Mean for Your Team 
Vulnerability Summary for the Week of January 29, 2024 
Breach analysis: Cloudflare falls victim to Okta attack 
A look at the legal challenges of defining and prosecuting virtual crimes, amid rising reports of attacks, harassment, and sexual assault in the metav 
Meta s Oversight Board slams company policies for manipulated media 
What are Threat Intelligence Feeds? Definition & Meaning 
Graphika: the viral pornographic Taylor Swift deepfakes originated from a 4chan challenge to bypass anti-porn filters in Microsoft Designer and OpenAI 
State Department will not issue visas to individuals linked to spyware abuse 
Applying Threat Intelligence to the Diamond Model of Intrusion Analysis 
Hacked crypto funds falls 98% YoY to $1.9 billion as US leads attacks: Report - CryptoSlate 
How to hack the Airbus NAVBLUE Flysmart+ Manager 
Graphika: the viral pornographic deepfakes of Taylor Swift originated from a 4chan challenge to bypass anti-porn filters on Microsoft Designer and DAL 
Deepfakes, dollars and deep state fears: Inside the minds of election officials heading into 2024 
Crooks stole $25.5 million from a multinational firm using a ‘deepfake’ video call 
Ethical Hackers Reported 835 Vulnerabilities, Earned $450K in 2023 - HackRead 
Ethical Hackers Reported 835 Vulnerabilities, Earned $450K in 2023 
The ‘Mother of all Breaches’: Navigating the Aftermath and Fortifying Your Data with DSPM 
Philippines Wards off Cyber Attacks From China-Based Hackers - U.S. News & World Report 
Software firm AnyDesk disclosed a security breach 
New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw 
ThreatLabz Coverage Advisory: Ivanti s VPN Vulnerabilities Exploited by Hackers, New Zero-Days Pose Critical Risk 
A cyberattack impacted operations at Lurie Children’s Hospital 
Blocking Compromised Tokens with Wallarm 
Report: Identity Theft Indictments Include Conspirators in $400 Million FTX Hack - PYMNTS.com 
Former CIA Hacker Gets 40 Years In Prison For Leaking Documents To Wikileaks - The Tech Report 
Microsoft Breach How Can I See This In BloodHound? 
Iranian hackers breached Albania s Institute of Statistics (INSTAT) 
Apple's Vision Pro virtual reality headset launches in U.S. (Alex Koller CNBC) 
OpenSecrets: 450 orgs, including OpenAI and Tesla, reported participating in AI-related lobbying in 2023, up 185% YoY, spending $957M+ on AI and other 
Cloudflare breached on Thanksgiving Day, but the attack was promptly contained 
PurpleFox malware infected at least 2,000 computers in Ukraine 
How the EFF, Techdirt, MuckRock, and DDoSecrets are pushing back against legal threats aiming to censor reports on Appin's alleged hacker-for-hir 
Apple reports Q1 sales in Greater China fell 13% YoY to $20.82B, vs $23.5B est., its weakest December quarter in the region since Q1 2020 (Mark Gurman 
Apple reports Q1 revenue up 2% YoY to $119.6B, net income up 13% to $33.9B, Americas sales up 2% to $50.4B, Europe sales up 10% to $30.4B (Apple) 
Apple Q1 revenue: iPhone up 6% YoY to $69.7B, Mac up 1% to $7.78B, iPad down 25% to $7.02B, and Wearables, Home, and Accessories down 11% to $11.95B ( 
Amazon reports Q4 AWS revenue up 13% YoY to $24.2B, vs. $24.26B est., and operating income of $7.2B, up from $5.2B YoY (Akash Sriram Reuters) 
Apple reports first quarter results (Apple) 
Amazon reports Q4 ad revenue up 27% YoY to $14.7B, vs. $14.2B est., North America sales up 13% YoY to $105.5B, and International sales up 17% YoY to $ 
Meta reports Q4 revenue up 25% YoY to $40.1B, net income up 201% YoY to $14B, and family daily active people up 8% YoY to 3.19B for December 2023; MET 
Meta Reports Fourth Quarter and Full Year 2023 Results; Initiates Quarterly Dividend (Meta) 
Amazon reports Q4 revenue up 14% YoY to $170B, net income of $10.6B vs. $0.3B YoY, operating income of $13.2B, and subscription revenue up 14% to $10. 
CISA orders Ivanti devices targeted by Chinese hackers be disconnected 
National cybersecurity plans lack performance measures and estimated costs, GAO says 
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2 
Arrests in $400M SIM-Swap Tied to Heist at FTX? 
A Startup Allegedly Hacked the World. Then Came the Censorship and Now the Backlash 
US Agencies Failure to Oversee Ransomware Protections Threaten White House Goals 
Ripple's XRP falls amid reports it was likely hacked - CoinDesk - Yahoo Finance 
The State of Ransomware 2024 
Millions of additional victims discovered in medicine provider breach; 1.5M affected by insurance broker breach 
Exposed Docker APIs Under Attack in 'Commando Cat' Cryptojacking Campaign 
71% of businesses haven t incorporated AI into physical security 
At Least 30 Journalists, Lawyers and Activists Hacked With Pegasus in Jordan, Forensic Probe Finds - U.S. News & World Report 
Multiple malware used in attacks exploiting Ivanti VPN flaws 
CISA and FBI Warn of AndroxGh0st Malware Threat 
The True Cost of Employee Fraud 
Dozens in Jordan targeted by authorities using NSO spyware, report finds 
ESG Research Unearths Critical Insights for Future-Proofing Encryption and Key Management 
MediaTek reports Q4 revenue up 19.7% YoY to $4.1B and net profit up 38.9% YoY to $820M, posting its first YoY increases in revenue and profit in five  
How to Fix Tesla Black Screen or Stuck While Driving 
Hackers using Microsoft Teams for phishing attacks to spread malware: Report - Times of India 
A Recap of Cybersecurity in 2023 and What s Ahead for 2024 
Ripple Co-Founder Reports Personal XRP Accounts Hacked - PYMNTS.com 
Crooks stole around $112 million worth of XRP from Ripple s co-founder 
Qualcomm reports Q1 adjusted revenue up 5% YoY to $9.92B, vs. $9.51B est., handset chip sales up 16% YoY to $6.69B, and net income up 24% YoY to $2.77 
Meeting zero-trust mandates with strategic partnerships 
79% of organizations faced a ransomware attack in H2 2023 
CISA adds Apple improper authentication bug to its Known Exploited Vulnerabilities catalog 
US Disrupts Chinese Hacking Campaign Targeting Critical Infrastructure, Officials Say - U.S. News & World Report 
Tax Season is Upon Us, and So Are the Scammers 
Pawn Storm s Stealthy Net-NTLMv2 Assault Revealed 
Ripple chairman Chris Larsen hacked for reported 213M XRP worth approximately $112.5M - Cointelegraph 
Ripple co-founder Chris Larsen confirms "unauthorized access" to "a few of my personal XRP accounts", after ZachXBT noted outflows 
Ivanti warns of a new actively exploited zero-day 
Sysdig Report Exposes 91% Failure in Runtime Scans 
Threat actors exploit Ivanti VPN bugs to deploy KrustyLoader Malware 
EA reports Q3 net bookings up 1% YoY to $2.37B, vs. $2.39B est., EA Sports FC net bookings up 7% YoY, and $1.95B net revenue, up from $1.88B YoY (Jenn 
Samsung reports Q4 revenue down 3.8% YoY to $51B, vs. $52.1B est., operating profit down 35% YoY to $2.1B, vs. $2.6B est., and rising 2024 memory 
Exclusive: US disabled Chinese hacking network targeting critical infrastructure - Reuters.com 
Ofcom: 22% of search results around basic self-injury terms on Google, Bing, DuckDuckGo, Yahoo, and AOL produced single-click links to more harmful co 
AMD reports Q4 revenue down 10% YoY to $6.2B, net income up 3,076% to $667M, Data Center revenue up 38% to $2.3B, Q1 revenue forecast below est.; AMD  
Alphabet reports Q4 revenue up 13% YoY to $86B, net income up 52% to $20.7B, Google Cloud revenue up 26% to $9.2B, and headcount down 4%+; GOOG drops  
EA reports Q3 net bookings up 1% YoY to $2.37B, vs. $2.39B est., with EA Sports FC net bookings up 7% YoY, and net revenue of $1.95B, up from $1.88B Y 
EA reports Q3 net bookings up 1% YoY to $2.37B, vs. $2.39B est., with EA Sports FC net bookings up 7% YoY, and net revenue of $1.95B, up from $1.88B i 
Microsoft reports Q2 Intelligent Cloud revenue up 20% YoY to $25.88B, vs. $25.29B est., with Azure and other cloud services revenue up 30% YoY, vs. 27 
Alphabet reports Q4 Google advertising revenue up 11% YoY to $65.5B, vs. $66.1B estimated, with Google Search & other revenue up 13% YoY to $48B ( 
AMD reports Q4 revenue down 10% YoY to $6.2B, net income up 3,076% to $667M, Data Center revenue up 38% to $2.3B, and Q1 revenue forecast below estima 
Match Group reports Q4 revenue up 10% YoY to $866.2M, vs. $861.2M est., paying users fell 5% YoY, forecasts Q1 rev. below expectations, authorizes $1B 
Alphabet reports Q4 revenue rose 13% YoY to $86B, net income rose 52% to $20.7B, Google Cloud revenue rose 26% to $9.2B, and headcount dropped 4%+ to  
White House releases report on securing open-source software 
Microsoft reports Q2 revenue up 18% YoY to $62B, net income up 33% YoY to $21.9B, Office Commercial revenue up 15% YoY, and LinkedIn revenue up 9% YoY 
GAO: Federal agencies lack insight on ransomware protections for critical infrastructure 
Cyberattacks on state and local governments rose in 2023, says CIS report 
A Microsoft engineer tells WA's AG he found ways to exploit DALL-E 3 to make explicit images, reported it, but was then told to take down a publi 
Fewer companies are paying ransomware hackers: report - Axios 
Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider 
2023 witnessed 68% more ransomware attacks than 2022 
Microsoft Edge automatically imports open Chrome tabs after a Windows update, even with Edge's import tool disabled; users have reported the beha 
Codeium, whose AI tools help companies write code, raised a $65M Series B led by Kleiner Perkins, a source says at a $500M valuation, and reports 300K 
Juniper Networks released out-of-band updates to fix high-severity flaws 
There was a 39% surge in data exfiltration cyberattacks in 2023 
KuppingerCole Recognizes Cequence Unified API Protection Platform 
US Disrupted Chinese Hacking Operation Aimed at Critical Infrastructure: Report - SecurityWeek 
Research shows cybercriminals motivation shifts to data exfiltration 
Balada Injector Malware Compromises 7,000+ WordPress Sites 
US Took Down Chinese Hacking Network That Targeted Infrastructure, Utilities: Report - The Messenger 
Microsoft Edge imported open Chrome tabs after a Windows update despite Edge's import tool being disabled; Windows users have reported the behavi 
Cactus ransomware gang claims the Schneider Electric hack 
Barracuda's New Cybernomics 101 Report Reveals 48% of Australian Respondents Fear AI-Hacking Surge - Tech Business News 
Exclusive-US Disabled Chinese Hacking Network Targeting Critical Infrastructure, Sources Say - U.S. News & World Report 
Datadog Report Surfaces Pair of Sophisticated AWS Attacks 
HPE Security Breach: Company Reports Russian Hackers in Its Email Environment - CPO Magazine 
There was a 151% increase in government vulnerability submissions 
Introducing the Wallarm 2024 API ThreatStatsTM Report 
Microsoft adds safeguards to its AI text-to-image tool Designer, after fake AI images of Taylor Swift went viral and a report of 4chan users misusing  
Microsoft adds safeguards to AI text-to-image tool Designer, after fake AI images of Taylor Swift went viral and reports that 4chan users misused the  
Shortcut To Malice: URL Files 
Mitigate Enterprise Software Supply Chain Security Risks – Insights Into the Gartner Report 
Why CNAPP Will Be a Key Enabler for DevSecOps in 2024 
Ukraine s SBU arrested a member of Pro-Russia hackers group ‘Cyber Army of Russia’ 
'Mother of all data breaches' reported in latest large-scale hack - FOX 2 Detroit 
Ukraine Claims Destruction of 280 Russian Servers, 2 Petabytes Lost 
Multiple PoC exploits released for Jenkins flaw CVE-2024-23897 
US aid office in Colombia reports its Facebook page was hacked - ABC News 
Crypto Stealing PyPI Malware Hits Both Windows and Linux Users 
Medusa ransomware attack hit Kansas City Area Transportation Authority 
Security Affairs newsletter Round 456 by Pierluigi Paganini INTERNATIONAL EDITION 
A look at the US Copyright Office, which is in the spotlight as it plans to release three key reports in 2024 revealing its position on copyright law  
Top 12 Ways to Fix Steam Disk Write Error for Windows in 2024 
Supporters of Israel are using apps to mass report pro-Palestinian content online, raising questions for tech platforms over "citizen-led propaga 
A TrickBot malware developer sentenced to 64 months in prison 
New and challenging risks in 2024 
Who is Alleged Medibank Hacker Aleksandr Ermakov? 
90 Days of Learning, Good Surprises and Extreme Optimism 
Some Beeper users lost access to iMessage on their Mac and were told by Apple access was revoked due to irregular activity; Beeper: 3.5K users report 
QR Code Scammers are Changing Tactics to Evade Detection 
Russian Midnight Blizzard APT is targeting orgs worldwide, Microsoft warns 
Houston, We Have a 2024 China Problem 
Watch out, experts warn of a critical flaw in Jenkins 
Intel reports Q4 revenue up 10% YoY to $15.4B vs. $15.15B est., Data Center and AI down 10% YoY to $4B, and Q1 revenue guidance below estimates; INTC  
CI CD Pipeline Security: Best Practices Beyond Build and Deploy 
23andMe data breach: Hackers stole raw genotype data, health reports - BleepingComputer 
Yearly Intel Trend Review: The 2023 RedSense report 
Intel reports Q4 revenue up 10% YoY to $15.4B vs. $15.15B est., Data Center and AI down 10% YoY to $4B, and forecasts Q1 revenue below estimates; INTC 
IBM's stock closes up 9.49%, at its highest level since June 2013, adding $20B to its market cap and up nearly 20% year-to-date, on strong AI se 
A Cruise report finds its top executives' adversarial approach toward regulators led to a cascade of events that ended with a suspension of its a 
Cisco warns of a critical bug in Unified Communications products, patch it now! 
AI is already being used by ransomware gangs, warns NCSC 
Using Google Search to Find Software Can Be Risky 
US suffered cyberattacks from 168 threat actors in 2023 
AI Will Fuel Rise in Ransomware, UK Cyber Agency Says 
Bill seeks cyber protections for food and agriculture 
HP reports Russian December hack, but no 'material impact' - UPI News 
Government Security Vulnerabilities Surge By 151%, Report Finds 
HP Enterprise Reveals It was hacked by the same Russians that broke into Microsoft 
Leaks and Revelations: A Web of IRGC Networks and Cyber Companies 
Report: Crypto Hacking Losses Halve to $1.7 Billion Despite Rise in Attacks - Blockonomi 
Annual GRIT Ransomware Report 2023 
Social Engineering Attacks Rising in the Trucking Industry 
Report: Crypto Hacking Losses Halve to $1.7 Billion Despite Rise in Attacks - Blockonomi - CryptoDaily 
Cyber Threat Landscape: 7 Key Findings and Upcoming Trends for 2024 
SK Hynix reports Q4 revenue up 47% YoY to $8.4B, beating est., and a $295M operating profit, vs. estimates of a $127M loss, its first profit in ove 
Global Ethical Hacking Report: 83% of Ethical Hackers Experience AI-Driven Attacks - ThePrint 
Franco-Italian chipmaker STMicro reports Q4 revenue down 3.2% YoY to $4.28B, meeting est., and expects Q1 revenue to fall 15% YoY to $3.6B, below $4.1 
North Korean Hackers Weaponize Research Lures to Deliver RokRAT Backdoor 
North Korean-Linked Hacks Saw Less Value Despite More Exploits: Report - Yahoo Finance 
North Korean hackers targeting crypto more but stealing less: report - The Japan Times 
SK Hynix reports Q4 operating profit of $259M, versus estimates of a $127M loss, and revenue up 47% YoY to $8.4B, beating even the highest analyst  
N. Korea-linked hackers stole $1 billion worth of crypto from record 20 attacks last year: report - The Korea Herald 
New Hampshire robocall kicks off era of AI-enabled election disinformation 
Crypto hackers stole around $1.7 bln in 2023 - report - Reuters 
IBM reports Q4 revenue up 4% YoY to $17.38B, vs. $17.30B est., software revenue up 3% YoY to $7.51B, and net income of $3.29B, up from $2.71B YoY; IBM 
Crypto hackers stole around $1.7 bln in 2023 - report - Reuters.com 
North Korean Hackers Increased Attacks in 2023: Report - Milk Road 
N. Korea-linked hackers stole US$1 billion worth of crypto from record 20 attacks last year: report - Yonhap News Agency 
Crypto hackers stole around $1.7 billion in 2023 - report - AOL 
ADCS Attack Paths in BloodHound Part 1 
IBM Q4: revenue up 4% YoY to $17.38B vs. $17.30B est., net income of $3.29B, up from $2.71B YoY, software up 3% YoY to $7.51B, infrastructure up 3% Yo 
Crypto Hackers Stole Around $1.7 Billion in 2023 - Report - U.S. News & World Report 
5379 GitLab servers vulnerable to zero-click account takeover attacks 
Browser-based phishing attacks increased 198% in H2 2023 
Global Ethical Hacking Report: 83% of Ethical Hackers Experience AI-Driven Attacks - Yahoo Finance 
IEA: electricity used by data centers, crypto, and AI could grow 100%+ in the next three years; Ireland's data centers could use 32% of its elect 
There was a 198% increase in browser-based phishing attacks 
Crypto hackers stole around $1.7 billion in 2023 - report - Yahoo Finance 
Crypto hackers stole around $1.7 billion in 2023 - report - Yahoo! Voices 
North Korea-linked hackers attacked record number of crypto platforms: Report - The Hill 
Experts released PoC exploit for Fortra GoAnywhere MFT flaw CVE-2024-0204 
Global Ethical Hacking Report: 83% of Ethical Hackers Experience AI-Driven Attacks - GlobeNewswire 
Crypto Hackers Stole $1.7 Billion in 2023, Down 54% YOY, As DeFi Security Improves: Report - Unchained - Unchained 
IEA: electricity used by data centers, crypto, and AI may more than double in the next three years; Irish data centers will use 32% of its electricity 
North Korea crypto hacking activity soars to record high in 2023, new report shows - NBC Chicago 
North Korea crypto hacking activity soars to record high in 2023, new report shows - NBC 6 South Florida 
North Korea crypto hacking activity soars to record high in 2023, new report shows - CNBC 
ASML reports Q4 revenue of €7.2B and net profit up 9% YoY to €2B, both above est., orders grew 3x QoQ to €9B+, and expects  
CFPB’s proposed data rules would improve security, privacy and competition 
Akira ransomware attack on Tietoevry disrupted the services of many Swedish organizations 
IAE: electricity used by data centers, crypto, and AI may more than double in the next three years; Irish data centers will use 32% of its electricity 
SPECIAL REPORT: CYBER LEADERS ON 2023 TRENDS AND 2024 OUTLOOK 
AI Set to Supercharge Ransomware Threat, Says NCSC 
ASML reports Q4 revenue of €6.67B and net profit up 9% YoY to €2B, both above est., orders grew 3x QoQ to €9B+, and expects 
AiDash, which uses AI to search satellite images to spot fire and weather risks on power lines, raised a $50M Series C led by Lightrock (Peter Henders 
Iranian hackers target Middle East experts - Microsoft report - The Jerusalem Post 
Texas Instruments reports Q4 revenue down 13% YoY to $4.08B, vs. $4.13B est., and FY 2023 sales down 13% YoY, the company's biggest fall in over 
Watch out, a new critical flaw affects Fortra GoAnywhere MFT 
Unprecedented Cybersecurity Alert: 26 Billion Records Exposed in Mega Data Breach 
Netflix reports Q4 revenue up 12.5% YoY to $8.83B vs. $8.71B est., global paid memberships up 12.8% to 260.28M vs. 256M est., net income of $938M, up  
Identity-based incidents accounted for 64% of all incidents 
88% of organizations use passwords as primary authentication method 
Russian Is Sanctioned Over the Hacking Release of Australian Health Insurer Client Data - U.S. News & World Report 
LockBit Ransomware Gang Claims Subway as New Victim 
Browser Phishing Threats Grew 198% Last Year 
Hackers Target Atlassian Confluence With RCE Exploits 
From Megabits to Terabits: Gcore Radar Warns of a New Era of DDoS Attacks 
Black Basta gang claims the hack of the UK water utility Southern Water 
CISA adds VMware vCenter Server bug to its Known Exploited Vulnerabilities catalog 
Report: Hackers Scammed $7.5M From HHS Grant Payment System - BankInfoSecurity.com 
How to Use Context-Based Authentication to Improve Security 
Mother of all breaches – a historic data leak reveals 26 billion records: check what’s exposed 
SEC blames sim-swapping, lack of MFA for X account hijacking 
Apple fixed actively exploited zero-day CVE-2024-23222 
Cyberattack attempts increased 104% in 2023 
North Korean government hackers target individuals of interest, infosec professionals 
North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor 
Data Privacy Week: Lack of Understanding, Underfunding Threaten Data Privacy and Compliance 
Threat actors exploit Apache ActiveMQ flaw to deliver the Godzilla Web Shell 
Data Privacy: Why It Matters To The Rest Of Us 
Cybercriminals leaked massive volumes of stolen PII data from Thailand in Dark Web 
Backdoored pirated applications targets Apple macOS users 
Webinar: Join us for the latest in API Threats on January 24, 2024 
Security Affairs newsletter Round 455 by Pierluigi Paganini INTERNATIONAL EDITION 
An interview with crypto skeptic James Block, whose damning critique of Signature Bank on his newsletter, Dirty Bubble Media, became the best short ca 
An interview with crypto skeptic James Block, whose damning critique of Signature Bank on his blog, Dirty Bubble Media, became the best short call of  
Book Review: The Crypto Launderers: Crime and CryptoCurrencies 
Russian Hackers Win Big: Microsoft's Senior Exec Team Emails Breached 
Microsoft Email Accounts Breached by Russian Hacking Group - The Tech Report 
Microsoft Reports Hack by Nation-State Actor - The Wall Street Journal 
Protect Yourself and Freeze Your Credit 
VF Corp December data breach impacts 35 million customers 
CISA issues emergency directive for federal agencies to patch Ivanti VPN vulnerabilities 
China-linked APT UNC3886 exploits VMware zero-day since 2021 
Google says 404 Media's report claiming Google is "boosting" AI-written article is misleading since the writer sorted news content by d 
Ransomware attacks break records in 2023: the number of victims rose by 128% 
GAO Report Details FedRAMP ATO Challenges and Costs 
U.S. CISA warns of actively exploited Ivanti EPMM flaw CVE-2023-35082 
Ransomware Activity Surged in 2023, Likely to Evolve in 2024 
Homeland Security warns federal agencies of hackers targeting Google Chrome and Excel Spreadsheets - CyberGuy Report 
Kansas State University suffered a serious cybersecurity incident 
UC Irvine students hospitalized after hackers share gory mutilation videos to Discord groups: report - Fox News 
UC Irvine students hospitalized after hackers share gory mutilation videos to Discord groups: report - New York Post 
The Unseen Threats: Anticipating Cybersecurity Risks in 2024 
Ukrainian hackers steal construction plans for 500 Russian military sites report - Yahoo News 
Presidential council approves recommendations for cyber-physical resilience 
Defining Good: A Strategic Approach to API Risk Reduction 
CISA adds Chrome and Citrix NetScaler to its Known Exploited Vulnerabilities catalog 
Scammers Target Owners of Missing Pets 
Illicit crypto addresses received $24.2B in 2023, down 39% YoY from $39.6B, and stablecoins accounted for the majority of the transaction volume, repl 
Protect AI Report Surfaces MLflow Security Vulnerabilities 
TikTok details its plans for the 2024 US elections, including a ban on political ads, work with fact-checking organizations, and reports on influence  
49% of organizations cite poor training as cause for privacy concerns 
Google TAG warns that Russian COLDRIVER APT is using a custom backdoor 
Illicit crypto addresses received $24.2B in 2023, down from $39.6B in 2022, and stablecoins accounted for the majority of the transaction volume, repl 
Critical vulnerability in ManageEngine could lead to file creation, dozens of other vulnerabilities disclosed by Talos to start 2024 
Stablecoins Enabled $40 Billion in Crypto Crime Since 2022 
Prolific Russian hacking unit using custom backdoor for the first time 
Ninety-Four Percent of Organizations Sustained Phishing Attacks Last Year 
FBI: Androxgh0st Malware Building Mega-Botnet for Credential Theft 
iShutdown lightweight method allows to discover spyware infections on iPhones 
TSMC reports Q4 revenue down 1.5% YoY to $19.62B and net income down 19.3% YoY to $7.56B, both above estimates on the back of weaker macroeconomic c 
A Consumer Reports study involving 709 volunteers: a total of 186,892 companies shared the volunteers' data with Facebook, averaging 2,230 compan 
Taking on EvilProxy: Advancements in Phishing Protection 
Cyber Safety Review Board needs stronger authorities, more independence, experts say 
Pro-Russia group hit Swiss govt sites after Zelensky visit in Davos 
CISA, FBI warns of Chinese-manufactured drones 
It s Friday, I m [Writing That Typical CISO Email 
Github rotated credentials after the discovery of a vulnerability 
FBI, CISA warn of AndroxGh0st botnet for victim identification and exploitation 
The US Treasury and IRS say they are not enforcing a rule requiring businesses to report the receipt of digital assets worth $10K+ within 15 days of r 
How to Fix Hogwarts Legacy Texture Not Loading 
RetroHunt : Retrospective Analysis for Threat Hunters 
Google fixed the first actively exploited Chrome zero-day of 2024 
The Treasury and IRS say they aren't enforcing a rule requiring businesses to report the receipt of digital assets worth $10K+ within 15 days of  
Report: Hackers Post Gruesome Videos on Online Forum for UC Irvine Students - MyNewsLA.com 
Netcraft Report Surfaces Spike in Online Healthcare Product Scams 
Hackers lean on open-source code, hacking tools in supply chain attacks: report - Axios 
Cryptocurrency Drainer Distributed Through Phishing 
68% of IT workers feel overwhelmed with data access restrictions 
The State of Software Supply Chain Security 2024: Key takeaways 
Email Nightmare: 94% of Firms Hit by Phishing Attacks in 2023 
Experts warn of mass exploitation of Ivanti Connect Secure VPN flaws 
Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+ 
Experts warn of a vulnerability affecting Bosch BCC100 Thermostat 
Over 178,000 SonicWall next-generation firewalls (NGFW) online exposed to hack 
Report: Apple prepares to split its App Store in two to serve the EU, as the deadline for the DMA, which mandates sideloading support, looms on March  
Baidu's stock drops 10%+ after an SCMP report linked Ernie Bot, which Baidu said amassed 100M+ users four months after its launch, to Chinese mil 
A UN report says Tether's token is one of the leading payment methods for money launderers and fraudsters, including pig butchering scams, in Sou 
Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else… 
There were over 4,000 ransomware victims in 2023 
Phemedrone info stealer campaign exploits Windows smartScreen bypass 
Women CyberSecurity Society Targeted by Smishing Campaign 
Forescout Report Uncovers New Details in Danish Energy Hack 
Alert: New DLL Variant Used For Malicious Code Execution 
Balada Injector continues to infect thousands of WordPress sites 
Security Experts Urge IT to Lock Down GitHub Services 
A UN report says Tether's token is one of the leading payment methods for money laundering and frauds, including pig butchering scams, in Southea 
Attackers target Apache Hadoop and Flink to deliver cryptominers 
A UN report says Tether token is one of the leading payment methods for money laundering and frauds, including pig butchering scams, in Southeast Asia 
DDoS Attacks on the Environmental Services Industry Surge by 61,839% in 2023 
Baidu's stock drops 10%+ after an SCMP report linking Ernie Bot, which Baidu said amassed 70M users within three months of launch, to Chinese mil 
Attacks against Denmark ‘s energy sector were not carried out by Russia-linked APT 
Classic Baggie: A Delaware BEC Case calls him the leader of an International Criminal Organization 
Security Affairs newsletter Round 454 by Pierluigi Paganini INTERNATIONAL EDITION 
Akira ransomware targets Finnish organizations 
Growing pains at the Bureau of Cyberspace and Digital Policy, report finds 
Report: Sandworm hackers unlikely involved in Denmark cyberattacks - SC Media 
Waiting for Your Pay Raise? Cofense Warns Against HR-Related Scams 
Researchers created a PoC for Apache OFBiz flaw CVE-2023-51467 
Securing Public Sector Against IoT Malware in 2024 
Sandworm probably wasn't behind Danish critical infrastructure cyberattack, report says - CyberScoop 
Sandworm probably wasn t behind Danish critical infrastructure cyberattack, report says 
Cybercriminals target critical infrastructure in 2023 cyberattack 
Netskope Report Surfaces Raft of Cybersecurity Challenges 
Microsoft Takes the Lead in Q4 2023 for Alarming Phishing Attempts 
71% of drivers consider buying older cars due to data privacy concerns 
CISA adds Ivanti and Microsoft SharePoint bugs to its Known Exploited Vulnerabilities catalog 
Two zero-day bugs in Ivanti Connect Secure actively exploited 
Flying Under the Radar: Abusing GitHub for Malicious Infrastructure 
Google Cloud Patched Privilege Escalation Vulnerability 
KnowBe4 Named a Leader in the Winter 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) 
The Connection Between Alaska Airlines, Blown Out Windows, and IoT Security 
Wallarm Named a Leader in GigaOm Radar for API Security 
X Account of leading cybersecurity firm Mandiant was hacked because not adequately protected 
Two Ivanti Zero-Days Actively Exploited in the Wild 
Cisco fixed critical Unity Connection vulnerability CVE-2024-20272 
Top 8 Ways to Fix an Acer Monitor Showing ‘No Signal’ Issue 
Luminate's 2023 report: the global music industry passed 4T streams in 2023, a new record and up 34% YoY; Taylor Swift accounted for one in every 
HMG Healthcare disclosed a data breach 
2024 Kubernetes Benchmark Report: The Latest Analysis of Kubernetes Workloads 
First responders look to technology to prevent cyberattacks 
NoaBot: Latest Mirai-Based Botnet Targeting SSH Servers for Crypto Mining 
Luminate's 2023 report: the global music industry passed 4T streams in 2023, a new record and up 34% from 2022; Taylor Swift had one in every 78  
Only 4% of US States Fully Prepared for Cyber-Attacks Targeting Elections 
Here’s Some Bitcoin: Oh, and You’ve Been Served! 
With half of the world's adults set to vote in 2024, the WEF's Global Risks Report 2024 ranks AI mis- and disinformation ahead of war, clima 
KnowBe4 Named a Leader in the Winter 2024 G2 Grid Report for Security Awareness Training 
Valve's Steam plans to add an "AI disclosure section", asking developers to describe how their games use AI content, and to let gamers  
Entire population of Brazil possibly exposed in massive data leak 
Decryptor for Tortilla variant of Babuk ransomware released 
Key Events of 2023 for NSFOCUS WAF 
TSMC reports December 2023 revenue down 8.4% YoY to $5.7B, Q4 revenue flat YoY to $20.1B, beating estimates, and 2023 revenue down 4.5% YoY to $69. 
How to Fix Instagram Feed Not Refreshing Issue 
Bitcoin price jumps after hackers hijack SEC Twitter account 
Microsoft Patch Tuesday for January 2024 fixed 2 critical flaws 
Match Group names Tinder COO Faye Iosotaluno as CEO of Tinder, ending a nearly two-year vacancy during which Match Group's CEO held both titles ( 
Cybersecurity company ExtraHop raises $100M in new funding from existing investors and says it ended 2023 with $200M ARR, double what it reported in  
AI is helping US spies catch stealthy Chinese hacking ops, NSA official says 
82% of Companies Struggle to Manage Security Exposure 
2023 Adversary Infrastructure Report 
Cloudflare Report Surfaces Lots of API Insecurity 
Coming March 2024: How to Prepare for PCI DSS Version 4.0 Compliance 
Hackers Hit Moscow Internet Provider in Response to Kyivstar Cyber Attack - Source - U.S. News & World Report 
Cybersecurity Deals Boom as Investment Dips, Pinpoint Reports 
62% of IT and security teams are remediating exposures 
North Korean Hacking Groups Stole $600M In Crypto Last Year - Research Report - Crowdfund Insider 
Berlin-based Robinhood rival Trade Republic reported a "solid double-digit million euro" net profit in the year to September, a first, up fr 
Cybercriminals find new way to access Google accounts without password: report - The Economic Times 
Syrian group Anonymous Arabic distributes stealthy malware Silver RAT 
Malicious Insiders: Definition, Motivation and Examples 
Sexual assault in the metaverse investigated by British police 
Age-old problems to sharing cyber threat info remain, IG report finds 
Swiss Air Force sensitive files stolen in the hack of Ultra Intelligence & Communications 
AsyncRAT Infiltrates Key US Infrastructure Through GIFs and SVGs 
68% of organizations face risks due to cybersecurity skills shortage 
Security leaders weigh in on 23andme hack 
Stuxnet: The malware that cost a billion dollars to develop? 
Syrian Hackers Distributing Stealthy C#-Based Silver RAT to Cybercriminals 
DoJ charged 19 individuals in a transnational cybercrime investigation xDedic Marketplace 
Alert: Carbanak Malware Strikes Again With Updated Tactics 
Long-existing Bandook RAT targets Windows machines 
Anti-Iran, Hezbollah messages displayed in Beirut airport hack - report - The Jerusalem Post 
Security Affairs newsletter Round 453 by Pierluigi Paganini INTERNATIONAL EDITION 
Turkish Sea Turtle APT targets Dutch IT and Telecom firms 
Maldives president's office, other top official websites hacked, restored after hours: reports - Editorji 
Google downplays reports of malware abusing an undocumented Chrome API to generate new authentication cookies, saying such token theft attacks "a 
Experts spotted a new macOS Backdoor named SpectralBlur linked to North Korea 
Your Google Account May Be at Risk Hackers Find a Way to Gain Access Without a Password - The Tech Report 
Law firm Orrick data breach impacted 638,000 individuals 
Daniel Stenberg, founder of open-source project curl, says easy access to LLMs is resulting in junk AI-assisted bug reports, wasting developer time an 
North Korean hackers stole $600M in crypto in 2023: Report - TradingView 
66% of consumers would not trust a company following a data breach 
North Korean hackers stole $600M in crypto in 2023: Report - Cointelegraph 
Russian hackers were inside Ukraine's telecom systems for months: Report - MSN 
The source code of Zeppelin Ransomware sold on a hacking forum 
Russian hackers were inside Ukraine's telecom systems for months: Report - IndiaTimes 
Cyber-Attacks Drain $1.84bn from Web3 in 2023 
Russian hackers breached Ukraine's telecoms giant for months: Report - Hindustan Times 
Best of 2023: Enterprises Are Getting Better at Breach Prevention. But Attackers Are Getting Better, Too. 
Report: Russian hackers gained access to Kyivstar's system - WION 
Russian Hackers Had Covert Access to Ukraine's Telecom Giant for Months 
From Log4j to Long4j 
Structuring the Unstructured: Consolidating Reports into One Cohesive Record 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - Yahoo News Canada 
Crypto hack losses declined 51% in 2023: Report - Cointelegraph 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - Yahoo News 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - Yahoo News UK 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - Yahoo Singapore News 
Hacker hijacked Orange Spain RIPE account causing internet outage to company customers 
HealthEC data breach impacted more than 4.5 Million people 
Enhancing Web Security: NSFOCUS WAF Integration Solutions 
Experts found 3 malicious packages hiding crypto miners in PyPi repository 
Research: deliberate internet shutdowns affected 747M people globally in 2023, with a $9.01B cost; Russia accounted for $4.02B; X was the most blocked 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - Yahoo News Australia 
Russian Hackers Breached Ukraine Telecoms Giant Months Before Major Cyberattack: Report - The Daily Beast 
Hackers Stole 51% Less Funds Last Year: Report News - ihodl.com 
Research: deliberate internet shutdowns affected 747M people globally in 2023, costing $9.01B; Russia accounted for $4.02B; X was the most blocked pla 
Exclusive-Russian Hackers Were Inside Ukraine Telecoms Giant for Months - Cyber Spy Chief - U.S. News & World Report 
How to Fix DirectX Encountered an Unrecoverable Error in Modern Warfare 3 
The Salary of a Chief Security Officer 
Cybercriminals Implemented Artificial Intelligence (AI) for Invoice Fraud 
The Complete InfoSec Guide for Threat Intelligence 
What is the Digital Operations and Resilience Act (DORA)? 
The InfoSec Guide to HIPAA Compliance 
The Ultimate Guide to Cyber Resilience 
CISA ADDS CHROME AND PERL LIBRARY FLAWS TO ITS KNOWN EXPLOITED VULNERABILITIES CATALOG 
European parking app announces data breach 
European parking app announced data breach 
How Secure Code Signing Aligns With The Principles of DevSecOps 
Don t trust links with known domains: BMW affected by redirect vulnerability 
HTTP 2 Rapid Reset Mitigation With Imperva WAF 
New Research: Phishing Attacks Stole $295 Million In Crypto In 2023 
Navigating Election Risks: A Guide for Executives 
5 Ways to Reduce SaaS Security Risks 
Ukraine s SBU said that Russia’s intelligence hacked surveillance cameras to direct a missile strike on Kyiv 
How hackers can send text messages from your phone without you knowing - CyberGuy Report 
A deal by the 38 OECD members that took effect on January 1 says that platforms must report users' earnings made on their services to local tax a 
Researchers released a free decryptor for Black Basta ransomware 
Google Cloud Report Spotlights 2024 Cybersecurity Challenges 
Top 5 Cyber Predictions for 2024: A CISO Perspective 
FDA cybersecurity agreement on medical devices needs updating, watchdog finds 
How to Fix Volume Automatically Goes Down on Android 
A deal by OECD members, including the US and France, that took effect January 1 says platforms must report users' earnings made on their services 
Experts warn of JinxLoader loader used to spread Formbook and XLoader 
Web3 loses $1.7 billion from hacker attacks in 2023, says Salus report - Finbold - Finance in Bold 
Multiple organizations in Iran were breached by a mysterious hacker 
In his year-end report, SCOTUS Chief Justice John Roberts says AI is a mixed blessing for the legal field, urging "caution and humility" whe 
Alert: New Chrome Zero-Day Vulnerability Being Exploited 
Fix: Intel System Usage Report Uses too Much CPU 
In his year-end report, SCOTUS Chief Justice John Roberts says AI is a mixed blessing for the legal field, urging "caution and humility" as  
List of Secure Dark Web Email Providers in 2024 
Malware exploits undocumented Google OAuth endpoint to regenerate Google cookies 
Top 2023 Security Affairs cybersecurity stories 
Cactus RANSOMWARE gang hit the Swedish retail and grocery provider Coop 
MS Excel Vulnerability Exploited To Distribute Agent Tesla 
How to Fix USB Connector Connected Disconnected Notification 
In his year-end report, US Chief Justice John Roberts says AI is a mixed blessing for the legal field and urges "caution and humility" as th 
In his year-end report, US Chief Justice John Roberts says "any use of AI requires caution" and that the judicial system "will be signi 
In his year-end report, US Chief Justice John Roberts says any use of AI "requires caution" and that the judicial system "will be signi 
Security Affairs newsletter Round 452 by Pierluigi Paganini INTERNATIONAL EDITION 
Faced with dwindling bee colonies, scientists are arming queens with robots and smart hives 
Cyber attacks hit the Assembly of the Republic of Albania and telecom company One Albania 
Happy 14th Birthday, KrebsOnSecurity! 
I-Phone hacking: Mantri rebuts report of government pressure on co - timesofindia.com 
"Half Facts": Rajeev Chandrasekhar On Washington Post Report Accusing Indian Government Of Targeting Apple Over iPhone Hacking Alert - Swarajya 
New Version of Meduza Stealer Released in Dark Web 
Half facts, fully embellished : Centre disputes Washington Post report on Apple hacking alerts - Scroll.in 
Fully embellished : Centre disputes Washington Post report on Apple hacking alerts - Scroll.in 
Government refutes report that claimed India demanded Apple to soften iPhone hacking alerts - Times of India 
EASM in 2023 – shortcomings with CVE-overreliance and flaws in security scoring systems 
Detectify product highlights and other major developments in 2023 
Operation Triangulation attacks relied on an undocumented hardware feature 
I-Phone hacking: Mantri rebuts report of government pressure on co - IndiaTimes 
Cybercriminals launched Leaksmas event in the Dark Web exposing massive volumes of leaked PII and compromised data 
Minister slams report claiming Centre urged Apple to soften impact of iPhone hacking alerts - Hindustan Times 
Minister slams report claiming Centre urged Apple to soften impact of hack alert - Hindustan Times 
Indian government pressed Apple to soften hacking warning: report - The Hill 
U.K. Government 'Ill-Prepared' to Deal With High Risk of Catastrophic Ransomware Attacks 
Apple facing pressure from Indian government over state-sponsored hacking warning notifications, says report - iMore 
Best of 2023: Another Password Manager Leak Bug: But KeePass Denies CVE 
Govt demanded Apple soften political impact of iPhone hack warnings: Report - Hindustan Times 
Experts warn of critical Zero-Day in Apache OfBiz 
India targets Apple over its phone hacking notifications: Report - Gulf News 
India targets Apple over its phone hacking notifications: Report - Deccan Herald 
Xamalicious Android malware distributed through the Play Store 
NSFOCUS Zero Trust Solution Makes It Into The Security Service Edge Solutions Landscape Report 
Hackers stole $2bn in crypto in 2023 Report - Vanguard 
Elections 2024, artificial intelligence could upset world balances 
Report: Ubisoft was subject to hacking attempts last week - Gamereactor UK 
Experts analyzed attacks against poorly managed Linux SSH servers 
A look at the challenges Amazon faces in selling cars in the US: only 11% of its customers report buying $1,000+ items, dealerships sell most new cars 
A cyberattack hit Australian healthcare provider St Vincent s Health Australia 
Kyivstar Cyber Attack: Ukraine Telecom Operator Paralyzed 
Hackers stole $2 billion in crypto in 2023 Report - Punch Newspapers 
Report: Ubisoft was subjected to hacking attempts last week - Gamereactor UK 
Rhysida ransomware group hacked Abdali Hospital in Jordan 
Carbanak malware returned in ransomware attacks 
Hackers steal customer data from Europe s largest parking app operator 
Resecurity Released a 2024 Cyber Threat Landscape Forecast 
Daily Malicious Files Soar 3% in 2023, Kaspersky Finds 
Ledger Supply Chain Breach: $600,000 Theft Unveiled 
Report: Samsung delays chip production in its $17B Taylor, Texas fab, saying it couldn't confirm the schedule, a blow to US' local chip manu 
APT group UAC-0099 targets Ukraine exploiting a WinRAR flaw 
Teen who leaked Grand Theft Auto VI sentenced to indefinite stay in "secure hospital," report says - CBS News 
Iran-linked APT33 targets Defense Industrial Base sector with FalseFont backdoor 
Cloud Atlas' Spear-Phishing Attacks Target Russian Agro and Research Companies 
Security Affairs newsletter Round 451 by Pierluigi Paganini INTERNATIONAL EDITION 
Video game giant Ubisoft investigates reports of a data breach 
How to Fix Telegram Web Desktop Notifications Not Working 
The Top 24 Security Predictions for 2024 (Part 2) 
British LAPSUS$ Teen Members Sentenced for High-Profile Attacks 
Ubisoft is investigating reports of a new security breach after security research collective VX-Underground shared screenshots of the company's i 
Key findings from ESET Threat Report H2 2023 Week in security with Tony Anscombe 
Substack brands itself as avoiding value judgments, but its justification for allowing certain offensive speech is full of value judgments, chosen to  
ESET Threat Report: ChatGPT Name Abuses, Lumma Stealer Malware Increases, Android SpinOk SDK Spyware’s Prevalence 
Revolut publishes delayed 2022 accounts, removing a hurdle in its UK banking license bid, reporting revenue up 45% YoY to £922.5M and a & 
Leading with Intelligence: Winning Against Credential Theft 
Best of 2023: Watching a Crypto Investment Scam WhatsApp Group 
Member of Lapsus$ gang sentenced to an indefinite hospital order 
Revolut publishes delayed 2022 accounts, removing a hurdle in its UK banking license bid; revenue grew 45% YoY to £922.5M, while pretax loss 
BSNL suffers data breach, hacker posts data on dark web: Report - WION 
Real estate agency exposes details of 690k customers 
BSNL suffers data breach, hacker posted some data on dark web: Report - WION 
GTA 6 hacker Arion Kurtaj sentenced to indefinite hospital prison for leaking gameplay footage: Report - Sportskeeda 
Intellexa and Cytrox: From fixer-upper to Intel Agency-grade spyware 
Annual Payment Fraud Intelligence Report: 2023 
Phishing attacks use an old Microsoft Office flaw to spread Agent Tesla malware 
Cost of a Data Breach Report 2023: Insights, Mitigators and Best Practices 
Data leak exposes users of car-sharing service Blink Mobility 
Ukrainian hackers report successful attack on Russian Bitrix service - Yahoo News 
Fix My Singing Monsters Facebook Login Not Working or Down 
Google addressed a new actively exploited Chrome zero-day 
Micron reports Q1 revenue up 16% YoY to $4.73B, vs. $4.54B est., and forecasts Q2 revenue above est., as strong data center demand makes up for device 
Micron reports Q1 revenue up 16% YoY to $4.73B, vs. $4.54B est., and forecasts Q2 revenue above estimates, after strong data center demand (Ian King B 
How Congress can rein in data brokers 
Strata Identity Named in the 2023 Gartner Innovation Insight for Journey-Time Orchestration Report 
New Report: 85% Firms Face Cyber Incidents, 11% From Shadow IT 
Apple resolved an outage for Apple Card, Apple Cash, Apple Pay, and Wallet that started around 6:15AM ET; users had reported IAP issues and more (Tim  
Law enforcement Operation HAECHI IV led to the seizure of $300 Million 
Apple's System Status page reports an ongoing outage for Apple Card, Apple Cash, Apple Pay, and Wallet since 6:15AM ET; users have reported IAP i 
Apple's System Status page reports an ongoing outage for Apple Card, Apple Cash, Apple Pay, and Wallet since 6:15AM ET; users report issues with  
Sophisticated JaskaGO info stealer targets macOS and Windows 
ESET Threat Report H2 2023 
BlackCat Ransomware Raises Ante After FBI Disruption 
FBI claims to have dismantled AlphV Blackcat ransomware operation, but the group denies it 
Henry Schein reports 29K affected in September cyberattack 
2023 Cybersecurity Year in Review 
Chinese, Russian interference attempts on 2022 midterms didn t impact voting, intelligence agencies say 
EclecticIQ Retrospective: A Look at the Themes & Events That Shaped the 2023 Cyber Landscape 
More Than 26,000 Vulnerabilities Discovered in 2023 
2023 Cyber Threats: 26,000+ Vulnerabilities, 97 Beyond CISA List 
77% of financial organizations detected a cyberattack in the last year 
Year in Malware 2023: Recapping the major cybersecurity stories of the past year 
Henry Schein reports 29K affected in September cyber attack 
Smishing Triad: Cybercriminals Impersonate UAE Federal Authority for Identity and Citizenship on the Peak of Holidays Season 
The ransomware attack on Westpole is disrupting digital services for Italian public administration 
Report: Brand of crypto ATMs installed at H-E-B was hacked; grocer says none in its stores breached - San Antonio Express-News 
The US SEC sues New Jersey-based Tingo Group, which sells phones to African farmers, for allegedly booking billions in false transactions via two subs 
SEC disclosure rule for material cybersecurity incidents goes into effect 
The US SEC sues NJ-based Tingo Group, which sells credit and phones to Nigerian farmers, for allegedly booking billions in false transactions with sub 
Israel-linked hacking group claims attack on Iranian gas pumps 
Report: Crypto ATMs once installed at H-E-B stores were hacked; unclear which stores had them - San Antonio Express-News 
Israeli hacker group takes credit for cyberattack shutting down majority of Iran's gas stations: reports - Fox Business 
65% of organizations say ransomware concerns impact risk management 
Pro-Israel Predatory Sparrow hacker group disrupted services at around 70% of Iran s fuel stations 
ALPHV Second Most Prominent Ransomware Strain Before Reported Downtime 
Strobes 2023 Pentesting Recap: Trends, Stats, and How PTaaS is Transforming Cybersecurity 
Israel launches cyberattack against Iran, hackers paralyse gas stations: Report Mint - Mint 
MY TAKE: How decentralizing IoT could help save the planet by driving decarbonization 
A supply chain attack on crypto hardware wallet Ledger led to the theft of $600K 
How to Fix Samsung TV WiFi Keeps Disconnecting 
OpenAI says "ByteDance's use of our API was minimal", but suspends the account and investigates, after a report that ByteDance used Ope 
The Top 24 Security Predictions for 2024 (Part 1) 
Security Affairs newsletter Round 450 by Pierluigi Paganini INTERNATIONAL EDITION 
InfectedSlurs botnet targets QNAP VioStor NVR vulnerability 
Hunters International ransomware gang claims to have hacked the Fred Hutch Cancer Center 
OpenAI says ByteDance's use of its API was minimal, suspends ByteDance's account while it investigates a report that ByteDance used OpenAI&a 
New NKAbuse malware abuses NKN decentralized P2P network protocol 
Some X users report seeing ads for apps that use AI to "undress" women in photos; TikTok and Meta have started to block search terms related 
Some X users report seeing ads for apps that use AI to "undress" women in photos; TikTok and Meta blocked certain search terms related to su 
Daily Mirror Says Prince Harry Verdict Will Limit Its Phone-Hacking Bill - U.S. News & World Report 
BianLian, White Rabbit, and Mario Ransomware Gangs Spotted in a Joint Campaign 
How to Fix Vizio TV Won’t Turn ON 
Navigating the Trade-Offs Between Security Vendor Consolidation and Best-Of-Breed Solutions 
Ubiquiti users claim to have access to other people s devices 
A personal Year in Review to round out 2023 
66% of employees prioritize daily tasks over cybersecurity 
Below the Surface Winter 2023 
Ten Years Later, New Clues in the Target Breach 
Russia-linked APT29 spotted targeting JetBrains TeamCity servers 
Report: 29 malware families targeted 1800 banking apps in 61 countries 
Aggressive Malign Influence Threatens to Shape US 2024 Elections 
The U.S. Needs a Better AI Plan 
Sensor Tower: 51 of the top 100 US advertisers on X in October 2022, when Elon Musk bought the platform, have ceased ad spending on X as of November 2 
French authorities arrested a Russian national for his role in the Hive ransomware operation 
China targets US infrastructure through cyber attacks: Report - NewsNation Now 
China-linked APT Volt Typhoon linked to KV-Botnet 
Adobe reports Q4 revenue up 12% YoY to $5.05B, vs. $5.03B est., Digital Media revenue up 13% YoY to $3.72B, and FY 2024 guidance below est.; ADBE drop 
Adobe reports Q4 revenue up 12% YoY to $5.05B, vs. $5.03B est., Digital Media revenue up 13% YoY to $3.72B, FY 2024 revenue guidance below est.; ADBE  
Report says hackers from China targeted Texas infrastructure this year - mySA 
Crypto hacking losses plunge by nearly 50% in 2023: Report - Cointelegraph 
Taking a Proactive Approach to Mitigating Ransomware Part 2: Avoiding Vulnerabilities in SAP Applications 
39% of security leaders cite phishing as most feared cyberattack 
UK Home Office is ignoring the risk of ‘catastrophic ransomware attacks,’ report warns 
BazaCall Phishing Scammers Now Leveraging Google Forms for Deception 
Ukraine Says Russian Intelligence-Linked Hackers Claim Cyberattack on Mobile Network - U.S. News & World Report 
Chinese hackers target US infrastructure: Report - NewsNation Now 
OAuth apps used in cryptocurrency mining, phishing campaigns, and BEC attacks 
Report: 90% of energy companies experienced a third-party breach 
Cofense Adds Vishing Simulation to its Popular PhishMe Email Security Awareness Training 
UK at High Risk of Catastrophic Ransomware Attack, Government Ill-Prepared 
Open access to AI foundational models poses various security and compliance risks, report finds 
Sophos backports fix for CVE-2022-3236 for EOL firewall firmware versions due to ongoing attacks 
Major Cyber Attack Paralyzes Kyivstar - Ukraine's Largest Telecom Operator 
December 2023 Microsoft Patch Tuesday fixed 4 critical flaws 
Report: Insomniac hacked, Wolverine PS5 game content included in ransomware attack - TweakTown 
A parliamentary report warns the UK is vulnerable to a "catastrophic ransomware attack at any moment" because of the government's failu 
Crypto Hacking Losses Plunge by Nearly 50% in 2023 - RM Labs Report - Coinpedia Fintech News 
Crypto Hacking Losses Plunge by Nearly 50% in 2023 RM Labs Report - Coinpedia Fintech News 
Hackers Demand $2 Million in Bitcoin After Stealing Insomniac Games Data: Report - Decrypt 
News alert: Detectify s EASM research reveals top overlooked vulnerabilities from 2023 
AI threats pose great cyber risks to smaller companies, experts tell House panel 
Ukraine’s largest mobile communications provider down after apparent cyber attack 
Netflix publishes its first What We Watched report, detailing the most-watched content from January to June 2023; The Night Agent was #1 with 812M+ ho 
OpenAI's nonprofit arm reports $44,485 in 2022 revenue, despite the company being valued at $86B, avoiding California's $2M threshold for a 
Harry Coker confirmed to be the next National Cyber Director 
Massive cyberattack reported on Ukrainian bank, phone operator - Kyiv Independent 
Kyivstar, Ukraine’s largest mobile carrier brought down by a cyber attack 
Crypto Hacking in 2023 Drops to $1.7B: Report - CoinGape 
Netflix posts its first ever What We Watched report, detailing the most-watched content from January to June 2023; The Night Agent was #1 with 812M ho 
CISA Unveils Tools to Strengthen Google Cloud Services 
Ukrainian intelligence reports hacking Russia's federal tax service Meduza - Meduza 
Ukrainian intelligence reports hacking Russia s federal tax service - Meduza 
81% of companies had malware, phishing and password attacks in 2023 
A US GAO review of nearly 24 agencies' AI usage catalogs 200+ current applications and 500+ planned uses of AI and ML, despite the lack of govern 
OpenAI's nonprofit arm reports $44,485 in revenue in 2022, even though the company is worth billions, avoiding California's $2M threshold fo 
SAP Patch Day: December 2023 
How to Fix Disney Plus Error Code 41 
A US GAO review of nearly two-dozen agencies' AI usage details 200+ current applications and 500+ planned uses of AI, despite little guidance or  
Operation Blacksmith: Lazarus exploits Log4j flaws to deploy DLang malware 
Toyota Ransomware Attack Exposes Customers Personal Data 
Lazarus Cryptocurrency Hacks Estimated To Be $3 Billion 
Understanding SBOMs 
Oracle reports Q2 revenue up 5% YoY to $12.94B, vs. $13.05B est., net income up 44% to $2.5B, and cloud and on-premise revenue down 18% to $1.18B; ORC 
Chinese hackers invade critical US power and water systems: Report - India Today 
Chinese Hackers Gained Access To Critical US Systems Under Volt Typhoon Campaign: Report - NDTV 
Fix Your iOS Network Preferences Prevent Content from Loading Privately 
Chinese hackers infiltrate critical U.S. infrastructure systems, report says - wpde.com 
Report: hackers target third-party suppliers in automakers' supply chains - DC Velocity 
Toyota Financial Services discloses a data breach 
Chinese hackers have infiltrated critical U.S. infrastructure systems, report says - wpde.com 
Oracle Q2: revenue up 5% YoY to $12.94B, vs. $13.05B est., net income up 44% to $2.5B, and cloud and on-prem license revenue down 18% to $1.18B; ORCL  
Report: Chinese hackers targeted Texas power grid, Hawaii water utility, other critical infrastructure - Spectrum News 
September 2023 saw more ransomware attacks than all of 2022 
Vietnamese media reports that Nvidia CEO Jensen Huang sees Vietnam as a potential second home for the company and plans to open a design center in the 
Europol Raises Alarm on Criminal Misuse of Bluetooth Trackers 
Apache fixed Critical RCE flaw CVE-2023-50164 in Struts 2 
Deepfakes: The New Face of Fraud 
Report Sees Chinese Threat Actors Embracing Sandman APT 
North Korean hacking ops continue to exploit Log4Shell 
MrAnon Stealer Attacking Windows Users Via Weaponized PDF Files 
2024 IT Spending Surge: Surprising Insights from Piper Sandler's CIO Survey 
Vietnamese media reports Nvidia CEO Jensen Huang sees Vietnam as a potential second home for the Silicon Valley company and plans to open a design cen 
India on high alert as hacker group plans Cyber Party targeting critical digital infrastructure: Report - Business Today 
How to Fix When Apple TV Stuck and Could Not Sign In 
54-year-old Wayanad woman takes own life after hacking friend to death: Report - Mathrubhumi English 
Researcher discovered a new lock screen bypass bug for Android 14 and 13 
Security Affairs newsletter Round 449 by Pierluigi Paganini INTERNATIONAL EDITION 
Hacktivists hacked an Irish water utility and interrupted the water supply 
OctoML ends its deal with text-to-image AI model sharing platform Civitai, after a report found some images made by Civitai users "could be categ 
OctoML ends its business with text-to-image AI model sharing platform Civitai, after a report found some images by Civitai users "could be catego 
5Ghoul flaws impact hundreds of 5G devices with Qualcomm, MediaTek chips 
How to Fix Samsung TV Internet or WiFi Connection Problem 
Norton Healthcare disclosed a data breach after a ransomware attack 
Gartner Strategic Technology Trends for 2024 
Employee burnout is on the rise 
GTA 6 leak hacker is motivated to offending again: Report - Sportskeeda 
Source: the US FTC is examining the nature of Microsoft's investment in OpenAI and potentially antitrust law violations but hasn't opened a  
Source: the US FTC is examining the nature of Microsoft's investment in OpenAI and whether it violates antitrust laws (Leah Nylen Bloomberg) 
Your Phone App Not Working On Windows 11 
Bypassing major EDRs using Pool Party process injection techniques 
How to Disable Windows 11 Feedback Hub Notifications 
Android barcode scanner app exposes user passwords 
Incident Reporting and Response Procedures Policy 
Welltok Data Breach: 8.5M US Patients Information Exposed 
Russia-linked APT8 exploited Outlook zero-day to target European NATO members 
UK and US expose Russia Callisto Group’s activity and sanction members 
US and British authorities sanction, indict Russian hackers 
Russian information operation uses US celebrity Cameos to attack Zelensky 
Cybersecurity considerations to have when shopping for holiday gifts 
CISA to Developers: Adopt Memory Safe Programming Languages 
LogoFAIL vulnerabilities impact vast majority of devices 
New Report: Over 40% of Google Drive Files Contain Sensitive Info 
Securities and Exchange Commission Cyber Disclosure Rules: How to Prepare for December Deadlines 
Russian information operation uses U.S. celebrity Cameos to attack Zelensky 
Fix Explorer.exe Error Class Not Registered in Windows 11 
47% of organizations monitored supply chain risks monthly or more 
Report shows rise in threat actors exploiting remote access software 
New Krasue Linux RAT targets telecom companies in Thailand 
Sydney-based Leonardo.Ai, which lets users generate AI images for use in creative industries, raised $31M, and reports 7M users and generating 700M+ i 
Reuters temporarily removes its article titled "How an Indian startup hacked the world" to comply with an Indian court order, and plans to a 
New Stealthy 'Krasue' Linux Trojan Targeting Telecom Firms in Thailand 
Google posts instructions for restoring files in Google Drive for desktop, after users reported last week that some of their files disappeared from th 
Google posts instructions for restoring files in Google Drive for desktop, after users reported that some of their files disappeared (Emma Roth The Ve 
Dangerous vulnerability in fleet management software seemingly ignored by vendor 
90% of global energy companies experienced a third-party data breach 
CISA adds Qualcomm flaws to its Known Exploited Vulnerabilities catalog 
The Alarming Threat of Ransomware: Insights from the Secureworks State of the Threat Report 2023 
Remote code execution vulnerabilities found in Buildroot, Foxit PDF Reader 
69% of organizations facing ransomware attacks paid the ransom 
78% of CISOs Concerned About AppSec Manageability 
ICANN Launches Service to Help With WHOIS Lookups 
40% of Google Drive files contain sensitive information 
42% of flagged messages are impersonation warnings 
Cisco Talos Report: New Trends in Ransomware, Network Infrastructure Attacks, Commodity Loader Malware 
New Report: Unveiling the Threat of Malicious Browser Extensions 
North Korea Hackers May Have Stolen Data on Laser Weapon -Police - U.S. News & World Report 
Asana reports Q3 revenue up 18% YoY to $166.5M, vs. $164.09M est., but warns macroeconomic headwinds continue to impact its net retention rates; ASAN  
Imperva Named an Overall Leader in the KuppingerCole Leadership Compass: API Security and Management Report 
Asana reports Q3 revenue up 18% YoY to $166.5M, vs. $164.1M est., but warns of macroeconomic headwinds; ASAN drops 10%+ (Duncan Riley SiliconANGLE) 
ENISA published the ENISA Threat Landscape for DoS Attacks Report 
95% of executives say AI initiatives will fail without training 
Keeping pace with endpoint and vulnerability management 
UK denies reported hacking of Sellafield nuclear site - SC Media 
Debunking MFA Myths: How to Stay Secure 
US Federal Agencies Miss Deadline for Incident Response Requirements 
Obfuscation and AI Content in the Russian Influence Network Doppelg nger Signals Evolving Tactics 
ENISA published ENISA Threat Landscape for DoS Attacks 
The Internet Enabled Mass Surveillance. AI Will Enable Mass Spying. 
Warning for iPhone Users: Experts Warn of Sneaky Fake Lockdown Mode Attack 
75% of sports-related passwords are reused across accounts 
Russian AI-generated propaganda struggles to find an audience 
Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accounts 
Britain dismisses report claiming Sellafield nuclear site hacking, says no malware exists on our system - DataBreaches.net 
15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack 
Was UK s Sellafield nuclear plant hacked? Rishi Sunak govt tries to paper over explosive report - WION 
Porn Age Checks Threaten Security and Privacy, Report Warns 
Foxconn reports November revenue up 18% YoY to $20.6B, the first YoY improvement since January 2023, and forecasts Q4 revenue to be better than expec 
Fix Virtualbox Kernel Driver Not Installed (rc=-1908) On Mac 
Fix Xbox One That Won t Connect to Live in Windows 11 
Britain dismisses report claiming Sellafield nuclear site hacking, says no malware exists on our system - Firstpost 
New P2PInfect bot targets routers and IoT devices 
Suspected digital shopping fraud up 12% during Cyber Five holiday 
Mobile payment fraud increased in 2023 
The Rise of Business Email Compromise and How To Protect Your Organization 
Exposed Hugging Face APIs Opened AI Models to Cyberattacks 
Cybercriminals Escalate Microsoft Office Attacks By 53% in 2023 
LockBit on a Roll – ICBC Ransomware Attack Strikes at the Heart of the Global Financial Order 
New Agent Raccoon malware targets the Middle East, Africa and the US 
Employee Stress Puts Data in Danger 
Security Affairs newsletter Round 448 by Pierluigi Paganini INTERNATIONAL EDITION 
Ghost-hacking: How to protect yourself from scams from beyond the grave of those you knew - CyberGuy Report 
North Korean hackers have pilfered $3B of crypto over past six years: Report - Cointelegraph 
Researchers devised an attack technique to extract ChatGPT training data 
Cooking Intelligent Detections from Threat Intelligence (Part 6) 
Meta says it is updating child safety features after a series of WSJ reports, including expanding its list of terms, phrases, and emojis related to ch 
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities 
Filing: hackers accessed 0.1% of user accounts in 23andMe's data breach that the company disclosed in October 2023; 23andMe reported 14M+ custome 
Filing: 23andMe says hackers accessed accounts of 0.1% of its customer base in the company's recent data breach; 23andMe reported 14M+ customers  
U.S. government sanctions prolific North Korean cyber espionage unit 
In a letter to two US Senators, Circle denies a report alleging the company helped fund Hamas and Hezbollah and has an "ongoing relationship" 
US govt sanctioned North Korea-linked APT Kimsuky 
Threat Sequencing from the Darkside 
Coinbase reports receiving 13,079 law enforcement requests from October 1, 2022 to September 30, 2023, up 6% YoY and 3x since 2020; almost 50% were fr 
CrowdStrike Demonstrates Cloud Security Leadership at AWS re:Invent 2023 
Black Basta Ransomware gang accumulated at least $107 million in Bitcoin ransom payments since early 2022 
CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalog 
Coinbase reports receiving 13,079 law enforcement requests between October 1, 2022 and September 30, 2023, up 6% YoY and 3x since 2020; 50% were from 
Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks 
Prepare, Prevent, and Response: A Comprehensive Ransomware Protection Guide 
Dell reports Q3 revenue down 10% YoY to $22.3B, vs. $23B est., Client Solutions revenue down 11% YoY to $12.3B, and projects Q4 revenue of $22B, vs. $ 
Anti-Israel hacking campaign highlights danger of internet-connected devices 
Apple addressed 2 new iOS zero-day vulnerabilities 
Google Workspace Security: DeleFriend Vulnerability Could Allow Unwanted Access to APIs 
US Issues New North Korea Sanctions Targeting 8 People and ... - U.S. News & World Report 
Overcoming Cloud Security Challenges: The Power of Cloud-Native AI-Driven Solutions 
Critical Zoom Room bug allowed to gain access to Zoom Tenants 
$19 Stanely cups, fake Amazon Prime memberships all part of holiday shopping scams circulating 
Mississippi received the most spam calls per month in 2023 
88% of IT leaders have met compliance requirements 
BitCoins To Bombs: North Korea Funds Military With Billions In Stolen Cryptocurrency 
Meta officials say the US stopped proactively sharing information on foreign influence operations, as the company releases its Q3 Adversarial Threat R 
Ahead of 2024 election, Meta worries about lack of information on top-tier nation-state covert operations 
Crypto Country: North Korea s Targeting of Cryptocurrency 
Rhysida ransomware group hacked King Edward VII s Hospital in London 
2 municipal water facilities report falling to hackers in separate breaches - Ars Technica 
How To Download and Install Realtek HD Audio Manager 
Report: FBI Struggles With Casino Hacking Investigation - Poker News - CardPlayer.com 
Salesforce reports Q3 revenue up 11% YoY to $8.72B, vs. $8.72B est., and raises its FY 2024 forecast for operating cash flow growth; CRM jumps 6%+ (Ar 
Snowflake reports Q3 revenue up 32% YoY to $734.2M, vs. $714M est., and projects Q4 product revenue of $716M to $721M, vs. $696M est.; SNOW jumps 6%+  
56% of companies educate workers on AI risks 
Google addressed the sixth Chrome Zero-Day vulnerability in 2023 
Okta: Breach Affected All Customer Support Users 
News alert: Kiteworks forecast lays out risk predictions, strategies for sensitive content in 2024 
North Texas Municipal Water District suffers cyberattack 
Meta pauses shipments of the Quest 3's Elite Strap with Battery after users report a charging fault renders the battery useless, and starts makin 
Meta pauses shipments of the Quest 3's Elite Strap with Battery after widespread user reports of a charging fault that renders the battery useles 
Mastering Your Risk Assessment Report: Steps for Effective Analysis 
Okta reveals additional attackers’ activities in October 2023 Breach 
200+ Malicious Android Apps Targeting Iranian Banks: Experts Warn 
Discover Why Proactive Web Security Outsmarts Traditional Antivirus Solutions 
200+ Malicious Apps on Iranian Android Store Installed by Millions of Banking Users 
Adalytics: Google ads appear on many compromising sites that make up its Search Partners network; Google attacks Adalytics but plans to review its fin 
Pennsylvania water facility hit by Iran-linked hackers 
Toyota subsidiary held ransom for $8 million by hackers report - Drive 
CrowdStrike reports Q3 revenue up 35% YoY to $786M, vs. $777M est., ARR up 35% YoY to $3.15B, and a $26.7M net income, vs. a $55M net loss in Q3 2022  
HPE reports Q4 revenue down 7% YoY to $7.4B, including Compute down 31% YoY to $2.6B, HPC & AI up 37% YoY to $1.2B, and Intelligent Edge up 41% Yo 
Adalytics: Google ads appear on many compromising sites that make up its Search Partners network; Google attacks Adalytics but says it'll review  
CrowdStrike reports Q3 revenue up 35% YoY to $786M, vs. $777M est., ARR up 35% YoY to $3.15B, and net income of $26.7M, vs. a net loss of $55M a year  
HPE reports Q4 revenue down 7% YoY to $7.4B, Compute revenue down 31% YoY to $2.6B, HPC & AI revenue up 37% YoY to $1.2B, Intelligent Edge revenue 
Threat actors started exploiting critical ownCloud flaw CVE-2023-49103 
Bots make up 30% of internet traffic 
Phishing makes up 43% of email attacks 
ID Theft Service Resold Access to USInfoSearch Data 
Reports: NXP was hacked by China for years ... - eeNews Europe 
Deepfake Digital Identity Fraud Surges Tenfold, Sumsub Report Finds 
IMPERIAL KITTEN Deploys Novel Malware Families in Middle East-Focused Operations 
November 2023 Patch Tuesday: 58 Vulnerabilities Including Three Actively Exploited Zero-Days 
Endpoint and Identity Security: A Critical Combination to Stop Modern Attacks 
5 Tips to Defend Against Access Brokers This Holiday Season 
Eliminate Repetitive Tasks and Accelerate Response with Falcon Fusion 
Adobe: US Cyber Monday sales rose 9.6% YoY to a record $12.4B, driven by deep discounts that peaked at 31% in electronics and 23% for apparel (Reuters 
Digital fatigue is increasing cyber risks in modern workplaces 
Daixin Team group claimed the hack of North Texas Municipal Water District 
PDD, which runs Temu and Pinduoduo, reports Q3 revenue up 94% YoY to $9.6B vs. $7.7B est., and net income up 47%, after grabbing Shein users; PDD ju 
How Hackers Phish for Your Users' Credentials and Sell Them 
Meituan reports Q3 revenue up 22% YoY to $10.7B, narrowly beating est., and net income up nearly 3x to $507M, boosted by strong Chinese travel deman 
Healthcare provider Ardent Health Services disclosed a ransomware attack 
SenseTime's shares fell as much as 9.7% in Hong Kong, after a short seller accused the AI company of inflating its revenue; SenseTime refutes the 
Shares of SenseTime fell as much as 9.7% in Hong Kong, after a short seller accused the AI company of inflating its revenue; SenseTime refutes the all 
IndiHome - 12,629,245 breached accounts 
Google says it is investigating an issue caused by Google Drive's desktop app, after users' reports in recent days that some of their files  
GE investigates alleged data breach into confidential projects: Report - CSO Online 
Ukraine’s intelligence service hacked Russia’s Federal Air Transport Agency, Rosaviatsia 
Huntress Finds Business Email Compromise (BEC) Increases In Q3, 2024 
Pa. water system hacked by Iranian-backed cyber group: reports - PennLive 
Apple Finally Adopts RCS, AI Powered Scams Targeting the Elderly 
E-commerce is used a lure for 43% of phishing attacks 
PyPI Malicious Packages with Thousands of Downloads Targeting Python Developers 
Shadowy hacking group targeting Israel shows outsized capabilities 
Unsealed documents in a lawsuit by 30+ state AGs: Meta received 1.1M+ reports of under-13s on Instagram since early 2019 yet "disabled only a fra 
The hack of MSP provider CTS potentially impacted hundreds of UK law firms 
A Comprehensive Guide to Writing a Cyber Security Audit Report 
Fix: Windows Can’t Connect To This Network Error in Windows 11 
Fix: Windows 11 Not Showing Up In Windows 10 8 Update Settings 
ByteDance Is Said to Shut Main Gaming Arm in Business Retreat (Bloomberg) 
Hackers using Telegram bot to pull off large-scale phishing scams: Report - Business Insider India 
Rhysida ransomware gang claimed China Energy hack 
Unsealed docs in a lawsuit by 30+ state AGs: Meta received 1.1M+ reports of under-13s on Instagram since early 2019 yet it "disabled only a fract 
North Korea-linked APT Lazarus is using a MagicLine4NX zero-day flaw in supply chain attack 
Chinese spies had acces to Dutch chip maker NXP's systems for over two years: report - NL Times 
What is a System Audit Report (SAR)? A Brief Guide 
Cybersecurity Insurance is Missing the Risk 
9 Ways to Fix Widgets Added on Sonoma Saying “Open App on iPhone to Continue” 
Hamas-linked APT uses Rust-based SysJoker backdoor against Israel 
TikTok-funded report: TikTok users are much likelier to pay for a music streamer than the average consumer and spend more on concerts than the average 
App used by hundreds of schools leaking children’s data 
Microsoft launched its new Microsoft Defender Bounty Program 
Scammers Exploit Crypto Hype with Fake Token Factory, Stealing Millions 
Exposed Kubernetes configuration secrets can fuel supply chain attacks 
Apple Experts Fly To India After Politicians Report Hacking Threats ... - Benzinga India 
North Korea-linked Konni APT uses Russian-language weaponized documents 
Security violations by employees as harmful as hacking: Report - The Statesman 
Security violations by employees as harmful as hacking: Report - Investing.com India 
Security violations by employees as harmful as hacking: Report - Daijiworld.com 
Fortifying Finance: Navigating the Cybersecurity Landscape in Banking 
Denver-based healthcare software provider Welltok reports a July 2023 data breach exposed 8.5M US patients' data, making it the second largest M 
ClearFake campaign spreads macOS AMOS information stealer 
Welltok data breach impacted 8.5 million patients in the U.S. 
North Korea-linked APT Diamond Sleet supply chain attack relies on CyberLink software 
British Library: Ransomware Attack Led to Data Breach 
Automotive parts giant AutoZone disclosed data breach after MOVEit hack 
New InfectedSlurs Mirai-based botnet exploits two zero-days 
Visa Warns of Increased Phishing Scams During Holiday Season 
As Black Friday Approaches, 3 Key Trends Offer Insights for Mitigating Online Shopping Scams 
Researchers want more detail on industrial control system alerts 
10 Holiday Cybersecurity Tips for CISOs 
A look at Changpeng Zhao's rapid downfall, from triggering FTX's collapse a year ago and posting a dismissive "4" to news of break 
Citrix provides additional measures to address Citrix Bleed 
A study of tech suppliers' decarbonization efforts: Intel, Foxconn, Luxshare, Samsung, and TSMC's emissions rose from 2020 to 2022; Foxconn  
Ransomware groups rack up victims among corporate America 
HP reports Q4 revenue down 6.5% YoY to $13.8B, vs. $13.8B est., Personal Systems revenue down 8% YoY to $9.4B, and Printing revenue down 3% YoY to $4. 
Nvidia reports Q3 revenue up 206% YoY to $18.12B, vs. $16.18B est., Data Center revenue up 279% YoY to $14.51B, and net income up 1,259% YoY to $9.2B  
Compromised Bloomberg Crypto Channel Phishes for Thousands of Discord Users' Login Details 
Tor Project removed several relays associated with a suspicious cryptocurrency scheme 
CISA, FBI, MS-ISAC, and ASD s ACSC Release Advisory on LockBit Affiliates Exploiting Citrix Bleed 
Don’t let CVEs distract you: Shift your AppSec team’s focus to malware 
MAR-10478915-1.v1 Citrix Bleed 
66% of employees will shop on mobile phones this holiday season 
AI Helps Uncover Russian State-Sponsored Disinformation in Hungary 
Chinese game streaming firm DouYu says police arrested founder Chen Shaojie on unspecified charges on or around November 16, confirming reports; DOYU  
YouTube confirms that "users who have ad blockers installed may experience suboptimal viewing", after users reported five-second delays on n 
Experts warn of a surge in NetSupport RAT attacks against education and government sectors 
Baidu reports Q3 revenue up 6% YoY to $4.8B and a $940M net income, both above est., as its new AI tools shield the company from China's econom 
ForgeRock Recognized as a Leader in the 2023 Gartner Magic Quadrant for Access Management 
Zoom reports Q3 revenue up 3.2% YoY to $1.14B, vs. $1.12B est., enterprise revenue up 7.5% to $661M, above estimates, and enterprise customers up 5% t 
Detailed data on employees of U.S. national security lab leak online 
Rhysida ransomware gang is auctioning data stolen from the British Library 
NetSupport RAT Infections on the Rise - Targeting Government and Business Sectors 
DarkGate and PikaBot Malware Resurrect QakBot's Tactics in New Phishing Attacks 
The Ultimate ESG Audits Checklist 
Russia-linked APT29 group exploited WinRAR 0day in attacks against embassies 
Orange County District Attorney's Office Reports Hacking Attack - GovTech 
Xiaomi reports Q3 revenue up 0.6% YoY to $9.9B, its first gain in almost two years, and a $684M net income, both above est., buoyed by rising smartp 
DarkCasino joins the list of APT groups exploiting WinRAR zero-day 
What Is Small Business Endpoint Security: Meeting your Business Needs 
Security Affairs newsletter Round 446 by Pierluigi Paganini INTERNATIONAL EDITION 
8Base ransomware operators use a new variant of the Phobos ransomware 
Israeli man sentenced to 80 months in prison for providing hacker-for-hire services 
Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine 
An investigation details how New Delhi-based Appin grew from an edtech startup into a provider of cyberespionage services for private investigators gl 
Ransomware Group Reports Victim It Breached To SEC Regulators - Slashdot 
Convicted Sex Offender Found Guilty of Hacking Jumbotron at the ... - U.S. News & World Report 
Hacker chutzpah: Ransomware group says it reported victim to SEC - American Banker 
Avast researchers detect a September surge in malvertising 
Cybersecurity Insights with Contrast CISO David Lindner | 11 17 
Securities watchdog IOSCO releases its crypto rules report, making 18 recommendations in six areas, across market manipulation, insider trading, fraud 
40% of organizations have a clear understanding of their AI use 
Bots and fraud make up 73% of website and app traffic 
A deep dive into Phobos ransomware, recently deployed by 8Base group 
Businesses that eliminate passwords report better security outcomes 
Securities watchdog IOSCO concludes its report on crypto rules, identifying six critical domains covering market manipulation, insider trading, fraud, 
A critical OS command injection flaw affects Fortinet FortiSIEM 
Top 8 Ways to Fix Google NFL Scores Not Showing or Working 
Microsoft downplays damaging report on Chinese hacking its own ... - CyberScoop 
Zimbra zero-day exploited to steal government emails by four groups 
Israeli Private Detective Sentenced in US to 6-2 3 Years for Hacker-For-Hire Scheme - U.S. News & World Report 
Alleged Extortioner of Psychotherapy Patients Faces Trial 
U.S. officials urge more information sharing on prolific cybercrime group 
TikTok removes videos promoting Osama Bin Laden's "Letter to America" that justified the 9 11 attacks, but calls reports that they were 
MeridianLink confirms a cyberattack after a ransomware gang claimed to have reported the financial software company to the US SEC for not disclosing t 
TikTok says it is removing videos promoting Osama Bin Laden's justification for the 9 11 attack but calls reports of the videos going viral " 
Financial software company MeridianLink confirms a cyberattack after a ransomware gang claimed that it reported the company to SEC for not disclosing  
US Congress Report Calls for Privacy Reforms After FBI Surveillance 'Abuses' 
Exclusive Report: The State of Online Consumer Brand Impersonations in 2023 
Report: 46% of SMBs have experienced a ransomware attack 
Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups 
SPECIAL REPORT-How an Indian startup hacked the world - Nasdaq 
23% of organizations report little to no AI scalability 
Source: ByteDance's Douyin tests letting some creators with 100K+ followers add paywalls to parts of their videos; Chinese media reports Douyin t 
ManageEngine Information Disclosure Flaw Exposes Encryption Keys 
29% of organizations cite data loss as top security breach result 
Russian Hacking Group Sandworm Linked to Unprecedented Attack on Danish Critical Infrastructure 
46% of SMBs and enterprises have experienced a ransomware attack 
7 common mistakes companies make when creating an incident response plan and how to avoid them 
Source: ByteDance's Douyin tests letting creators with 100K+ followers add paywalls to their videos; local Chinese media reports Douyin takes a 3 
Alibaba reports Q2 revenue up 9% YoY to $31B, beating $30.9B est., a $3.8B net income, up from a $3B loss in Q2 2022, and calls off its cloud spin 
Embracer reports Q2 net sales up 13% YoY to $1B, layoffs impacted 900 employees, or 5% of its workforce, and 36 fewer games are in development than Q 
BlackCat Ransomware Group Reports Victim to SEC 
Half of Ransomware Groups Operating in 2023 Are New 
Ransomware Group Reports Victim to SEC 
Lenovo reports Q2 revenue down 16% YoY to $14.4B, meeting estimates but marking the fifth straight quarterly sales decline, and net income down 60% Yo 
FBI and CISA warn of attacks by Rhysida ransomware gang 
Lenovo reports Q2 revenue down 16% YoY to $14.4B, meeting estimates but marking the fifth straight quarterly sales decline, net income down 60% YoY to 
Pew: 30% of US adults regularly get their news from Facebook; 26%, from YouTube; 16%, Instagram; 14%, TikTok; 12%, X; 8%, Reddit; and 5%, Nextdoor and 
Pew: 30% of US adults regularly get their news from Facebook; 26%, YouTube; 16%, Instagram; 14%, TikTok; 12%, X; 8%, Reddit; and 5%, Nextdoor; 5%, Lin 
Pew: 30% of US adults say they regularly get news from Facebook, 26% say YouTube; 16%, Instagram; 14%, TikTok; 12%, X; 8%, Reddit; and 5%, Nextdoor an 
Cisco reports Q1 revenue up 8% YoY to $14.7B, vs. $14.6B est., net income up 36% YoY to $3.6B, and forecasts Q2 revenue far short of estimates; CSCO d 
Cisco reports Q1 revenue up 8% YoY to $14.7B, vs. $14.6B est., net income up 36% YoY to $3.6B, and forecasts Q2 revenue below estimates; CSCO drops 9% 
Senate panel advances Coker s nomination to head ONCD 
New ASD Cyber Threats Report Shows A Cybercrime Incident Is Reported in Australia Every Six Minutes 
AI-Manipulated Media Through Deepfakes and Voice Clones: Their Potential for Deception 
The holiday season sees a rise in credit card skimming 
Q3 2023 sees a rise in botnet activity 
Tencent reports Q3 revenue up 10% YoY to $21.5B, in line with estimates, and net profit down 9% YoY to $5B, as games sales recovered from China&apos 
JD.com reports Q3 revenue up 1.7% YoY to $34B and net income up 33% YoY to $1.1B, helped by a better performance in its main business lines and cost 
Law enforcement agencies dismantled the illegal botnet proxy service IPStorm 
JD.com reports Q3 revenue up 1.7% YoY to $33.98B, beating $33.81B est., and net profit up 33% YoY to $1.09B, beating $952M est., aided by cost con 
Tencent reports Q3 revenue up 10% YoY to $21.4B, in line with $21.37B est., and net profit down 9% YoY to $5B, beating $4.7B est., as game sales r 
VMware disclosed a critical and unpatched authentication bypass flaw in VMware Cloud Director Appliance 
Top 5 Ways to Fix Error Code 403 Forbidden NFL App on Roku 
Obstacles and Opportunities: The Move to Cloud IAM 
Rubrik Report Surfaces Scope of Data Security Challenge 
Danish critical infrastructure hit by the largest cyber attack in Denmark’s history 
Ransomware reported as a top concern for 64% of consumers 
Online Scammer Poses as Skype, Swindles Victims Through Cryptocurrency Scam 
61% of organizations store sensitive data in multiple locations 
Our audit of PyPI 
82% of Attacks Show Cyber-Criminals Targeting Telemetry Data 
SAP Patch Day: November 2023 
Improving Automation and Accessibility Drive $100 Billion in Projected Ad Fraud Losses 
FBI Struggles to Bring Hacking Gang to Justice - Crime Report 
Foxconn reports Q3 revenue down 12% YoY to $47.7B, net income up 11% YoY to $1.3B, and lowers the outlook for its components business to flat YoY (B 
Pro-Palestinian hacking group evolves tactics amid war 
Nuclear and Oil & Gas are Major Targets of Ransomware Groups in 2024 
DOH: Data security measures in place amid reported hacking of ... - Inquirer.net 
How Many Cyber Attacks Happen Per Day in 2023? 
Information-Stealing Malware Escalates in Online Gaming 
Didi reports Q3 revenue up 25% YoY to $7B, a $14.7M net income, up from a $274M loss YoY, and plans to buy back up to $1B in shares over the next 2 
LockBit ransomware gang leaked data stolen from Boeing 
Didi reports Q3 revenue up 25% YoY to $7B, a $14.7M net income, up from a $274M loss in Q3 2022, and plans to buy back $1B in shares over the next  
North Korea-linked APT Sapphire Sleet targets IT job seekers with bogus skills assessment portals 
Hackers claim to have compromised bankrupt Bitcoin ATM firm Coin Cloud: Report - The Block - Crypto News 
Top 7 Ways to Fix F1 TV AirPlay Not Working 2024 
Chinese Hackers Launch Covert Espionage Attacks on 24 Cambodian Organizations 
Many Threads users report that the app now has a privacy option that lets them opt out of having their posts show up on Instagram and Facebook (Wes Da 
Many Threads users report that they now have the ability to opt out of having their posts shown on Instagram and Facebook (Wes Davis The Verge) 
The State of Maine disclosed a data breach that impacted 1.3M people 
Security Affairs newsletter Round 445 by Pierluigi Paganini INTERNATIONAL EDITION 
Alibaba and JD.com reported YoY sales increases for Singles Day, but neither company provided overall revenue figures for the event for the second str 
Hackers Hit World s Largest Bank, Forcing Financial Giant to Rely on USB Stick to Settle Trades: Report - The Daily Hodl 
Police seized BulletProftLink phishing-as-a-service (PhaaS) platform 
It’s Still Easy for Anyone to Become You at Experian 
EC official: X had just 2,294 EU content moderators, versus 16,974 at YouTube and 6,125 at TikTok, according to reports submitted by the companies in  
Report: Apple product and search result pages on Amazon have few, if any, rival ads, after Apple asked for preferential treatment, leading to their 20 
Report: Apple search results and product pages on Amazon have few, if any, rival ads, after Apple asked Amazon for special treatment before their 2018 
McLaren Health Care revealed that a data breach impacted 2.2 million people 
Unraveling the Complexities of Word Documents 
72% of security leaders are concerned about the adverse effects of AI 
OpenAI: DDoS Attack the Cause of ChatGPT Outages 
6% of companies have not had a digital risk cyberattack since 2020 
'CitrixBleed' Linked to Ransomware Hit on China's State-Owned Bank 
Boeing Data Published by Lockbit Hacking Gang - U.S News & World Report Money 
After ChatGPT, Anonymous Sudan took down the Cloudflare website 
Sumo Logic Breach Shows Leaked Credentials Still a Persistent Threat 
Downtime cost of an application DDoS attack averages $6130 per minute 
Industrial and Commercial Bank of China (ICBC) suffered a ransomware attack 
MPs Dangerously Uninformed About Facial Recognition Report 
SysAid zero-day exploited by Clop ransomware group 
Unity reports Q3 revenue up 69% YoY to $544.2M, missing estimates of $553.7M partly because of the fallout from new rules on video games in China; U d 
DDoS attack leads to significant disruption in ChatGPT services 
Cyber ops linked to Israel-Hamas conflict largely improvised, researchers say 
Russian Sandworm disrupts power in Ukraine with a new OT attack 
Microsoft now requires that Windows users choose a listed reason for closing the OneDrive app, like "I do not use OneDrive" or "I don&a 
37% of organizations will increase cybersecurity spending 
Ukraine updates: Russia hacked Kyiv's power grid report DW 11 09 2023 - DW 
Google Cloud s Cybersecurity Trends to Watch in 2024 Include Generative AI-Based Attacks 
New report shows 51% rise in QR code phishing for September 
39% of software developers say supply chain security is essential 
Microsoft now asks users to provide a reason for closing the OneDrive app on Windows from a list, including "I don't know what OneDrive is&q 
What is NIS2, and how can you best prepare for the new cybersecurity requirements in the EU? 
CISA adds SLP flaw to its Known Exploited Vulnerabilities catalog 
Ukraine updates: Russia hacked Kyiv's power grid report DW 11 09 2023 - DW (English) 
Study shows data breaches decreased 84% in US during Q3 
SMIC reports Q3 revenue down 15% YoY to $1.62B, missing $1.64B est., and net income down 80% YoY to $94M, missing $178.1M est., despite Huawei's  
Chinese state-affiliated outlet Chinastarmarket says Nvidia plans to release three new H100-based AI chips in the country in the coming days, after US 
MuddyC2Go: New C2 Framework Iranian Hackers Using Against Israel 
The largest Russian bank Sberbank hit by a massive DDoS attack 
SoftBank reports an adjusted $300M investment gain for its Vision Funds in Q2, as Vision Fund 1 gained $2.5B thanks Arm's IPO while Vision Fund  
Sony reports Q2 revenue up 8% YoY to $18.5B, operating profit down 29% YoY to $1.74B, chips division profit down 38%, and 4.9M PS5 sales, vs. 3.3M i 
Is Your Disney Account at Risk? Magic Band Reported Hacked by ... - Disney Dining 
Russian hackers disrupted Ukrainian electrical grid last year 
Sony reports Q2 revenue of $18.5B, up 8% YoY, operating profit down 29% YoY to $1.74B, chips division profit down 38%, PS5 sales of 4.9M vs. 3.3M in 
SNAP scam: Mother reports EBT card hacked - KTVI Fox 2 St. Louis 
Twilio reports Q3 revenue up 5% YoY to $1.03B, vs. $985M est., 306K+ active customer accounts, vs. 280K+ YoY, and a Q4 guidance above estimates; TWLO  
Arm reports Q2 revenue up 28% YoY to $806M, vs. $744.3M est., license revenue up 106% YoY to $388M, and a Q3 guidance short of expectations; ARM drops 
Instacart reports Q3 revenue up 14% YoY to $764M, adjusted EBITDA up 120% to $163M vs. $119.5M est., and gross transaction value up 6% to $7.49B vs. $ 
Take-Two reports Q2 net bookings down 4% YoY to $1.44B, net revenue down 7% YoY to $1.3B, and forecasts Q3 net bookings below expectations (Zaheer Kac 
US DHS OIG report covering April 27 to August 17: "thousands" of apps installed on ICE-managed devices, likely including TikTok, puts govern 
Lyft reports Q3 revenue up 10% YoY to $1.16B vs. $1.14B est., a $12.1M net loss, active riders up 10% to 22.4M, and forecasts Q4 adjusted core profit  
Arm reports Q2 revenue up 28% YoY to $806M, vs. $744.3M est., and license revenue up 106% YoY to $388M, but its Q3 guidance falls short of expectation 
FBI: Ransomware actors abuse third parties and legitimate system tools for initial access 
Organizations spend almost 8 hours a week on security compliance 
Roblox reports Q3 bookings up 20% YoY to $839.5M, beating $822M est., revenue up 38% YoY to $713.2M, and average DAUs up 20% YoY to 70.2M; RBLX jumps  
US DHS OIG report covering April 27 to August 17: "thousands" of apps installed on ICE-managed devices, likely including TikTok, may comprom 
US DHS OIG report covering April 27 and August 17: "thousands" of apps installed on ICE-managed devices, likely including TikTok, may compro 
Indian hackers launch cyber attacks on Qatar to avenge the death penalty of Indian Navy officers: Report Mint - Mint 
OpenAI reports a ChatGPT and API "major outage", ongoing since 6AM PT, and plans a fix; users were greeted with a "ChatGPT is at capaci 
90% of cybersecurity professionals work on vacation 
Five Canadian Hospitals impacted by a ransomware attack on TransForm provider 
Roblox reports Q3 bookings up 20% YoY to $839.5M, beating $822M est., $81.1M EBITDA, revenue up 38% YoY to $713.2M, and DAUs up 20% YoY to 70.2M; RBLX 
Report: Business see rise in cyber insurance costs and requirements 
Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPI 
North Korea-linked APT BlueNoroff used new macOS malware ObjCShellz 
Securing Remote Workers Through Zero Trust 
Touch ID Stopped Working to Unlock by Single Touch in macOS Sonoma 
Coupang reports Q3 net revenue up 21% YoY to $6.2B, vs. $5.9B est., net income of $91.3M, vs. $119M est., and active customers up 14% YoY to a record  
Toast reports Q3 revenue up 37% YoY to $1.03B, matching estimates, and lowers the upper range of its FY 2023 revenue forecast; TOST drops 18%+ (Emily  
Bumble reports Q3 revenue up 18.4% YoY to $275.5M, vs. $277M est., net earnings down 13% YoY to $23.1M, and forecasts Q4 revenue below estimates; BMBL 
Bumble reports Q3 revenue up 18.4% YoY to $275.5M, vs. $277M est., and forecasts Q4 revenue below estimates; BMBL drops 6%+ (Reuters) 
Robinhood reports Q3 revenue up 29% YoY to $467M, vs. $478.9M est., trading revenue down 11% YoY to $185M, including crypto trading down 55% YoY; HOOD 
Robinhood reports Q3 revenue up 29% YoY to $467M, vs. $478.9M est., trading revenue down 11% YoY to $185M, with crypto volumes down 55% YoY; HOOD drop 
eBay reports Q3 revenue up 5% YoY to $2.5B, gross merchandise volume up 2% YoY to $18B, and forecasts its Q4 revenue and profit below estimates; EBAY  
eBay reports Q3 revenue up 5% YoY to $2.5B, gross merchandise volume up 2% YoY to $18B, and forecasts Q4 revenue below estimates; EBAY falls 5%+ (Chav 
Marina Bay Sands Luxury Hotel in Singapore Suffers a Data Breach 
Hackers Exploit Atlassian Flaw in Cerber Ransomware Attacks 
Cloud monitoring company Datadog's stock jumps 30% after reporting Q3 revenue up 25% YoY to $547.5M, vs. $524.1M est., and forecasting Q4 sales  
New State of Phishing Report 2023: An Alarming Surge in Phishing Threats 
Cloud monitoring company Datadog's stock jumps 30% after reporting Q3 revenue rose 25% YoY to $547.5M, vs. $524M est., and forecasted Q4 sales b 
Publisher s Trip Report: Black Hat USA 2023 
Confidence in File Upload Security is Alarmingly Low. Why? 
Uber reports Q3 revenue up 11% YoY to $9.3B, a $221M net income, gross bookings up 21% YoY to $35.3B, trips up 25% YoY to 2.4B, and a record 6.5M driv 
Charting China s Climb as a Leading Global Cyber Power 
Moving Beyond CVSS Scores for Vulnerability Prioritization 
NXP Semiconductors reports Q3 revenue down 0.3% YoY to $3.43B, beating $3.4B est., and forecasts strong Q4 profit due to strong automotive and industr 
Nintendo reports Q2 revenue down 4% YoY to $2.2B and profit down 19% YoY to $603M, both above est.; Switch sales in April to September rose 2.4% YoY 
Iranian Agonizing Serpens APT is targeting Israeli entities with destructive cyber attacks 
A major cyber attack: $3.5 Trillion Loss can occur! 
ESPN Fantasy Sports App Not Working? Here’s How to Fix Quickly 
WeWork, valued at $47B in 2019, files for Chapter 11 bankruptcy protection for its locations in the US and Canada, and reports liabilities between $10 
Domain of Thrones: Part II 
Data breach and identity protection concerns are at an all-time high 
Organizations face an average of 86 ransomware attacks annually 
Critical Confluence flaw exploited in ransomware attacks 
Data breach and identity protection concerns are at a all time high 
GUEST ESSAY: How to mitigate the latest, greatest phishing variant spoofed QR codes 
Klarna Bank reports Q3 revenue up 30% YoY to $550M, a $12M operating profit, the first since Q2 2019, and GMV up 22% YoY to $22.3B, ahead of a pote 
70% of security leaders see software supply chain as top blind spot 
QNAP fixed two critical vulnerabilities in QTS OS and apps 
Klarna reports Q3 revenue up 30% YoY to $550M, a $12M operating profit, the first in four years, and value of goods sold up 22% YoY, ahead of a pote 
Amazon, Microsoft, and Alphabet reported $42B in combined capital spending in Q3, up 10% from Q2 and almost 20% from Q3 2021, to expand generative AI  
Over Half of Users Report Kubernetes Container Security Incidents 
Some visitors to Yuga Labs' ApeFest event in Hong Kong report experiencing eye burn and blame the lighting; the Bored Ape creator acknowledges th 
Attackers use Google Calendar RAT to abuse Calendar service as C2 infrastructure 
iPhone iOS 17 Hack Attack Reported In The Wild: How To Stop It - Forbes 
Socks5Systemz proxy service delivered via PrivateLoader and Amadey 
9 Ways to Fix macOS Sonoma Crashes when Playbacking Videos in QuickTime 
Google Cybersecurity Action Team Threat Horizons Report #8 Is Out! [Medium Backup] 
Frameworks for DE-Friendly CTI (Part 5) [Medium Backup] 
US govt sanctioned a Russian woman for laundering virtual currency on behalf of threat actors 
Okta's autopsy report on its support system breach understated the role of a badly configured service account, the biggest contributing factor to 
Security Affairs newsletter Round 444 by Pierluigi Paganini INTERNATIONAL EDITION 
Lazarus targets blockchain engineers with new KandyKorn macOS Malware 
Okta's autopsy report on its support system breach understated the role of a badly configured service account, the biggest contributing factor fo 
Attackers use JavaScript URLs, API forms and more to scam users in popular online game Roblox  
You d be surprised to know what devices are still using Windows CE 
Kinsing threat actors probed the Looney Tunables flaws in recent attacks 
Byju files much-delayed financial results, reports $270.9M operating loss and revenue of $429.18M for FY ending March 2022, missing revenue projection 
Top 3 Ways to Clear the Cache on Mac or MacBook 
ZDI discloses four zero-day flaws in Microsoft Exchange 
DOE hosting simulated cyberattack for students 
Prolific Mozi Botnet Deliberately Shut Down with Kill Switch 
Almost 70% of children & adolescents have been exposed to cyber risks 
CISA sees increase in zero-day exploitation, official says 
Multiple WhatsApp mods spotted containing the CanesSpy Spyware 
Russian FSB arrested Russian hackers who supported Ukrainian cyber operations 
MuddyWater has been spotted targeting two Israeli entities 
Top 7 Ways to Fix Adidas CONFIRMED App Not Working 
Google Cybersecurity Action Team Threat Horizons Report #8 Is Out! 
Apple reports Q4 revenue down 2.5% YoY to $15.1B in Greater China, down 3.4% YoY to $5.5B in Japan, and down 0.7% YoY to $6.3B in the rest of Asia-Pac 
Apple reports Q4 revenue down 1% YoY to $89.5B, vs. $89.3B est., net income up 11% to $22.9B, Americas sales up 0.8% to $40.1B, Europe sales down 1.5% 
Cloudflare reports Q3 revenue up 32% YoY to $335.6M, vs. $330.5M est., and forecasts Q4 revenue below estimates (Reuters) 
Block reports Q3 revenue up 24% YoY to $5.62B, vs. $5.4B est., profit up 21% YoY to $1.9B, Square profit up 15% YoY, and Cash App profit up 27% YoY; S 
Coinbase reports Q3 revenue up 14% YoY to $674M, vs. $654.7M est., net loss down 99.6% YoY to $2.3M from $545M YoY, and $76B in trading volume, vs. $8 
Clop group obtained access to the email addresses of about 632,000 US federal employees 
Apple reports Q4 revenue down 1% YoY to $89.5B, vs. $89.3B est., and net income up 11% YoY to $22.9B (Apple) 
Apple reports Q4 revenue down 1% YoY to $89.5B, vs. $89.3B est., net income up 11% YoY to $22.9B, and Services revenue up 16% YoY to a record $22.3B ( 
Apple Q4 revenue: iPhone up 3% YoY to $43.81B, Mac down 34% to $7.61B, iPad down 10% to $6.44B, and Wearables, Home, and Accessories down 3% to $9.32B 
Coinbase reports Q3 revenue up 14% YoY to $674M vs. $654.7M est., net loss down to $2.3M from $545M YoY, $76B in trading volume vs. $80.4B est.; COIN  
Apple reports fourth quarter results (Apple) 
Block Q3: revenue up 24% YoY to $5.62B, vs. $5.4B est., gross profit up 21% to $1.9B, Square gross profit up 15%, Cash App gross profit up 27%; SQ jum 
Coker tells Senate committee that he d follow ONCD s current path if confirmed to top cyber position 
Security and privacy ranked second among AI concerns 
Investigate User-Reported Emails with Ease Through the Powerful Combination of CrowdStrike Falcon Sandbox and KnowBe4 PhishER Plus 
Suspected exploitation of Apache ActiveMQ flaw CVE-2023-46604 to install HelloKitty ransomware 
Shopify reports Q3 revenue up 25% YoY to $1.71B, beating $1.68B est., a $56.2B GMV, beating $54.42B est., and projects 25% 2023 revenue growth; SHOP  
Shopify reports Q3 revenue up 25% YoY to $1.71B, beating $1.68B est., a $56.2B GMV, beating $54.42B est., and expects 25% 2023 revenue growth; SHOP j 
Palantir reports Q3 revenue up 17% YoY to $558M, a $72M net income, the fourth straight profitable quarter, and projects 2023 income above est.; PLTR  
Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign 
Resecurity: Insecurity of 3rd-parties leads to Aadhaar data leaks in India 
Who is behind the Mozi Botnet kill switch? 
Fix Apple CarPlay Not Working in iOS 17 iPhone 
Frameworks for DE-Friendly CTI (Part 5) 
How to Select a Protective DNS Solution 
Airbnb Q3: revenue up 18% YoY to $3.4B, vs. $3.37B est., Nights and Experiences Booked up 14% YoY to 113.2M, vs. 112.9M est., and Q4 revenue forecast  
DoorDash reports Q3 revenue up 27% YoY to $2.16B, vs. $2.09B est., total orders up 24% YoY to 543M, and net loss down 75% YoY to $75M; DASH jumps 7%+  
PayPal reports Q3 revenue up 9% YoY to $7.4B, vs. $7.38B est., total payment volume up 13% YoY to $387.7B, vs. $377.9B, and forecasts FY 2023 profit a 
EA reports Q2 net bookings up 4% YoY to $1.82B, vs. $1.78B est., revenue of $1.91B, up from $1.9B in Q2 2022, and raises its annual profit forecast (R 
Roku reports Q3 revenue up 20% YoY to $912M, vs. $853.2M est., net loss up 170% YoY to $330M, and forecasts a "similar" YoY ad growth for Q4 
Roku reports Q3 revenue up 20% YoY to $912M vs. $853.2M est., a net loss of $330M, more than double a year ago, and issues "uncertain" guida 
Airbnb Q3: revenue up 18% YoY to $3.4B vs. $3.37B est., Nights and Experiences Booked up 14% YoY to 113.2M vs. 112.9M est., and a Q4 revenue forecast  
DoorDash reports Q3 revenue up 27% YoY to $2.16B, vs. $2.09B est., total orders up 24% YoY to 543M, net loss of $75M, down from $296M in Q3 2022, DASH 
Qualcomm Q4: adjusted revenue down 24% YoY to $8.67B, vs. $8.51B est., handset chip sales down 27% YoY to $5.46B, vs. $5.34B est., and a strong Q1 202 
Threat actors actively exploit F5 BIG-IP flaws CVE-2023-46747 and CVE-2023-46748 
Pro-Hamas hacktivist group targets Israel with BiBi-Linux wiper 
Reports of cellphone hacking bids confirm BJP is scared of INDIA alliance: Stalin - Times of India 
Parliament panel may summon Apple officials over leaders' hacking attempt alerts, says report - Business Today 
Twitter Blue Not Showing? Here are Top 5 Ways to Fix it 
Check Point details a monthslong espionage campaign by Iranian hackers targeting countries, including Israel, underscoring Iran's improved hackin 
How To Fix Origin Error Code 327683:0 
Google, Temasek, and Bain report: Southeast Asia online spending will rise 11% in 2023 to $218B, down from 20% in 2022, slowing to its lowest rate si 
Securing Australia s Critical Infrastructure: The Role of Asset Visibility in Meeting SOCI Obligations 
News alert: Ivanti reports reveals 49% of CXOs have requested bypassing security measures 
Match Group reports Q3 revenue up 9% YoY to $882M, vs. $880.6M est., paying users down 5% YoY to 15.7M, and forecasts Q4 revenue below estimates; MTCH 
India’s biggest data breach? Hacking gang claims to have stolen 815 million people’s personal information 
SEC sues SolarWinds and CISO for fraud 
Survey: AppSec Maturity Hindered by Staffing, Budgets, Vulnerabilities 
Palo Alto Networks acquires Tel Aviv-based Dig Security, which helps organizations manage and protect data assets in the cloud, sources say for $400M  
A look at some of the creators who report and aggregate news on TikTok, YouTube, Instagram, and more, as people under 35 move away from traditional ne 
WiHD leak exposes details of all torrent users 
One in five executives have shared work passwords outside the company 
A look at the creators who report and aggregate news on TikTok, YouTube, Instagram, and others, as people under 35 move away from traditional news sou 
.US Harbors Prolific Malicious Link Shortening Service 
Palo Alto Networks acquires Tel Aviv-based Dig Security, which helps organizations track cloud assets, sources say for $400M (Ingrid Lunden TechCrunch 
Apple's stock dropped 11% since its Q3 results on August 3, erasing nearly $400B in value, the first year since 2015 that AAPL slid between WWDC  
Brazilian banking-as-a-service startup QI Tech raised a $200M Series B led by General Atlantic, for $262M in total funding, and reports $21M H1 2023 n 
Arid Viper disguising mobile spyware as updates for non-malicious Android applications 
Regulator Reveals Large Disparity in APP Fraud Reimbursement 
US Regulators Sue SolarWinds and Its Security Chief for Alleged Cyber Neglect Ahead of Russian Hack - U.S. News & World Report 
Cyber workforce demand is outpacing supply, survey finds 
Four dozen countries declare they won’t pay ransomware ransoms 
Hacking attempts: Opposition leaders share iPhone alerts and report hacking attempt amid controversy - PTC News 
The CISO Report: Emerging Trends, Threats, and Strategies for Security Leaders 
Samsung reports Q3 revenue down 12% YoY to $50B, net income down 40% YoY to $4.1B vs. an 86% decline in Q2 2023, and a chip division operating loss  
Pinterest Q3: revenue up 11% YoY to $763.2M, vs. $743.5M est., MAUs up 8% YoY to 482M, vs. 473M est., ARPU up 3% YoY to $1.61, vs. $1.59 est.; $PINS j 
US Office of Personnel Management report: 632K DOD and DOJ employees had their emails compromised on May 28 and 29, 2023, as part of the sprawling MO 
Five Reasons Why Legacy Data Loss Prevention Tools Fail to Deliver 
Protecting Users from Malicious Sites with Falcon for Mobile 
US Office of Personnel Management report: about 632K employees at the DOD and DOJ had their emails compromised as part of the MOVEit hacks in May 2023 
Pinterest Q3: revenue up 11% YoY to $763.2M vs. $743.5M est., global MAUs up 8% YoY to 482M vs. 473M est., ARPU up 3% YoY to $1.61 vs. $1.59 est.; $PI 
Report: Russian-Speaking Hacking Group Breached 632,000 US Government Email Addresses - PYMNTS.com 
Report: Russian-Speaking Hacking Group Breached 632,000 US ... - PYMNTS.com 
FTC says financial institutions must disclose data breaches in 30 days 
Russian Hackers Breached 632,000 DOJ And Pentagon Email Addresses In Massive MOVEit Cyberattack, Report Says - Forbes 
White House executive order on AI seeks to address security risks 
Pro-Palestinian Threat Groups Expand Cyberwar Beyond Israel 
Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware 
Report Links ChatGPT to 1265% Rise in Phishing Emails 
Report shows 1265% increase in phishing emails since ChatGPT launched 
HackerOne awarded over $300 million bug hunters 
StripedFly, a complex malware that infected one million devices without being noticed 
3 unique ways hackers are stealing your crypto: Bitrace Report - Cointelegraph 
Fix S MIME Control Isn t Available: The Content Can t Be Displayed Error 
Top 6 Ways to Fix Honeywell Thermostat Display Not Working 
How to Fix Disney Speedstorm Stuck on Initializing Screen Error 
ChatGPT Plus users report an "All Tools" feature and capabilities for analyzing docs like PDFs have been added, potentially sidelining 3rd-p 
IT Army of Ukraine disrupted internet providers in territories occupied by Russia 
Security Affairs newsletter Round 443 by Pierluigi Paganini INTERNATIONAL EDITION 
UN report: N.Korea hackers stole $1.7 billion in cryptocurrency last ... - NHK WORLD 
A US executive order, expected to be issued as soon as October 30, will require firms building powerful AI models to report how they plan to protect t 
Sources: Humane timed its $1K Ai Pin launch to the October 14 eclipse, but moved it to November 9 after reports broke about Sam Altman and Jony Ive&a 
Charting New Terrain: The Shift to Resilience and Proximity in Cyber Risk 
Daily malware activity doubled year over year for small businesses 
Sources: Humane set its $1K Ai Pin launch for the October 14 solar eclipse, but rescheduled to November 9 as a report of Sam Altman and Jony Ive&apos 
Three new NGINX ingress controller vulnerabilities reported and how they affect Kubernetes 
Sources: Humane set its $1K Ai Pin launch for Oct. 14, during the solar eclipse, but moved it to Nov. 9 as reports of Sam Altman and Jony Ive's  
Folsom incident report: Hacked Apple ID, retail theft arrests, BB gun ... - Gold Country Media 
France agency ANSSI warns of Russia-linked APT28 attacks on French entities 
Huawei reports Q3 revenue up 1% YoY to $19.9B, revenue for Q1 to Q3 2023 up 2.4% YoY to $62.3B, and a 16% profit margin in Q1 to Q3, up from 15% in  
F5 urges to address a critical flaw in BIG-IP 
ESET APT Activity Report Q2 Q3 2023 
CCSD cooperating with FBI on cyberattack investigation, students report emails from hackers - Fox 5 Las Vegas 
How to Stop TV Remote From Controlling Two TVs 2023 
Orange County District Attorney's Office Reports Hacking Attack - Insider Homepage Redirects 
Orange County District Attorney s Office Reports Hacking Attack - Insider Homepage Redirects 
Amazon reports Q3 revenue up 13% YoY to $143.1B, net income up 244% to $9.9B, operating income up 343% to $11.2B, and subscription revenue up 14% to $ 
AWS Q3: sales up 12% YoY to $23.06B, vs. $23.2B est., operating income up 29% YoY to $6.98B, vs. $5.63B est., operating margin of 30.3%, the widest in 
Intel reports Q3 revenue down 8% YoY to $14.2B, Data Center and AI Group revenue down 10% YoY to $3.8B, and forecasts Q4 revenue above estimates; INTC 
Embracing ethical hackers could strengthen cybersecurity, says HackerOne report - SecurityBrief Australia 
Amazon reports Q3 revenue up 13% YoY to $143.1B, net income up 241% YoY to $9.9B, AWS sales up 12% YoY to $23.1B, and subscription revenue up 14% YoY  
Amazon Q3: ad services revenue up 26% YoY to $12.1B, vs. $11.6B est., North American sales up 11% YoY to $87.9B, and International sales up 16% YoY to 
Intel reports Q3 revenue down 8% YoY to $14.2B, Data Center and AI revenue down 10% YoY to $3.8B, and forecasts Q4 revenue above estimates; INTC jumps 
Hackers want to catch you pirating Barbie, Oppenheimer: McAfee report - Fast Company 
Amazon Q3: ad revenue up 26% YoY to $12.1B, vs. $11.6B est., subscription revenue up 14% YoY to $10.2B, and North America segment sales up 11% YoY to  
Amazon reports Q3 revenue up 13% YoY to $143.1B, a $9.9B net income, vs. $2.9B in Q3 2022, AWS segment sales up 12% YoY to $23.1B (Amazon) 
Cloudflare mitigated 89 hyper-volumetric HTTP distributed DDoS attacks exceeding 100 million rps 
Kaspersky reveals ‘elegant’ malware resembling NSA code 
How Machine Identity Management Bolsters IoT Security 
75% of Americans want government regulations for AI 
The holiday season leads to a rise in business payment fraud 
D.C. Voter Data Leak: What We Know So Far 
Seiko confirmed a data breach after BlackCat attack 
Franco-Italian chipmaker STMicro reports Q3 revenue up 2.5% to $4.43B, beating $4.38B est., net income down 0.8% YoY to $1B, and predicts demand risi 
Europol: Police Must Start Planning For Post-Quantum Future 
SK Hynix reports Q3 revenue down 17% YoY to $6.69B, beating average estimates of $6B, and a $1.32B operating loss, above estimates of $1.25B (Bloo 
Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacks 
SK Hynix reports Q3 revenue down 17% YoY to $6.69B, beating average estimates of $6B, and a $1.32B operating loss, versus estimates of $1.25B (Blo 
Hackers that breached Las Vegas casinos rely on violent threats, research shows 
Meta's Reality Labs reports Q3 revenue down 26% YoY to $210M, vs. $299.3M est., and operating loss up 2% YoY to $3.74B, vs. $3.9B est. (Jonathan  
IBM Q3: revenue up 5% YoY to $14.75B, vs. $14.73B est., a $1.7B net income, vs. a $3.2B net loss YoY, and software revenue up 8% YoY to $6.27B, vs. $6 
Hackers that breached Las Vegas casinos rely on violent threats 
78% of fintech leaders report concern over compliance training 
IBM reports Q3 revenue up 4.6% YoY to $14.75B, vs. $14.73B est., net income of $1.7B, vs. a $3.20B net loss YoY, and software revenue up 7.8% YoY to $ 
Meta's Reality Labs reports Q3 revenue down 26% YoY to $210M, vs. $299.3M est., and operating loss of $3.74B, vs. $3.9B est. (Jonathan Vanian CNB 
Meta reports Q3 revenue up 23% YoY to $34.15B, net income up 164% YoY to $11.58B, and family daily active people up 7% YoY to 3.14B for September 2023 
Cl0p named 'nastiest' malware of 2023 
The Differences Between DNS Protection and Protective DNS 
Winter Vivern: Zero-Day XSS Exploit Targets Roundcube Servers 
French payments group Worldline reports Q3 revenue up 4.8% YoY to €1.18B and warns of a 2023 revenue hit due to a deteriorating economic outl 
VMware addressed critical vCenter flaw also for End-of-Life products 
Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software 
Security provider Okta reports hack to its own support system - KGUN 9 Tucson News 
Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan 
French payments group Worldline reports Q3 sales up 4.8% YoY to €1.18B and warns of 2023 revenue hit by high interest rates; WLN drops 55%+ t 
Zscaler Report Surfaces Spike in IoT Cyberattacks 
In its first transparency EU DSA report, Amazon discloses 181M users in the EU, directly employs 150K+ people, and more; Germany has 60M MAUs and Fran 
Citrix warns admins to patch NetScaler CVE-2023-4966 bug immediately 
Texas Instruments reports Q3 revenue down 14% YoY to $4.53B, vs. $4.58B est., and forecasts Q4 revenue and profit below estimates as industrial demand 
Handling SaaS Data Exposure Risks Due to Potential ServiceNow Misconfigurations 
Texas Instruments reports Q3 revenue down 14% YoY to $4.53B v. $4.58B est., and forecasts Q4 revenue and profit below estimates as its industrial dema 
Alphabet reports Q3 revenue up 11% YoY to $77B, net income up 42% YoY to $19.7B, and Google ad revenue up 9% YoY to $59.65B; GOOG drops 6% on cloud s 
Alphabet reports Q3 revenue up 11% YoY to $77B, net income up 42% YoY to $19.7B, and Google advertising revenue up 9% YoY to $59.65B; GOOG drops 6% ( 
Microsoft Q1: devices revenue down 22% YoY, Windows revenue up 5% YoY, Xbox content and services revenue up 13% YoY, search and news ad revenue up 10% 
Microsoft reports Q1 devices revenue down 22% YoY, Windows revenue up 5%, Xbox content and services revenue up 13% YoY, search and news ad revenue up  
Alphabet reports Q3 revenue up 11% YoY to $77B, net income up 42% YoY to $19.7B, and Google advertising revenue up 9% YoY to $59.65B; GOOG drops 5% ( 
Alphabet reports Google Cloud Q3 revenue up 22.5% YoY to $8.41B, vs. $8.62B est., and Google Cloud operating income of $266M, vs. an operating loss of 
Snap reports Q3 revenue up 5% YoY to $1.19B, vs. $1.11B est., net loss up 2% YoY to $368M, DAUs up 12% YoY to 406M, vs. 405.7M est., and won't gi 
Snap reports Q3 revenue up 5% YoY to $1.19B, vs. $1.11B est., net loss up 2% YoY to $368M, and DAUs up 12% YoY to 406M, vs. 405.7M est. (Jonathan Vani 
Snap reports Q3 revenue up 5% YoY to $1.19B, vs. $1.11B est., net loss up 2% YoY to $368M, and DAUs up 12% YoY to 406M, vs. 405.7M est.; SNAP jumps 5% 
Alphabet reports Q3 revenue of $77B, up 11% YoY, net income of $19.7B, up from $13.9B YoY, Google Cloud revenue of $8.4B, up from $6.9B YoY; GOOG drop 
Microsoft reports Q1 Intelligent Cloud revenue up 19% YoY to $24.26B, vs. $23.49B est., with Azure and other cloud services revenue up 29% YoY, vs. 26 
Microsoft reports Q1 revenue up 13% YoY to $56.5B, net income up 27% YoY to $22.3B, Office Commercial revenue up 15% YoY, and LinkedIn revenue up 8% Y 
Domain of Thrones: Part I 
Over 80% of security leaders have already received AI email attacks 
Philadelphia cyberattack compromised health data of city employees 
There were 11% more ransomware attacks in Q3 than Q2 2023 
Insights and Trends from Gartner Emerging Tech Impact Radar: Security 
Experts released PoC exploit code for VMware Aria Operations for Logs flaw. Patch it now! 
62% of organizations perform vulnerability assessments and audits 
Spotify Q3: revenue up 11% YoY to €3.4B, MAUs up 26% to 574M, subscribers up 16% YoY to 226M, and €32M operating income, vs. a & 
Three Recommendations for a Next-Generation Cybersecurity Framework 
Enabling Breach Prevention on Red Hat OpenShift Service on AWS (ROSA) 
How Well Do You Know Your Attack Surface? Five Tips to Reduce the Risk of Exposure 
CrowdStrike Partners with Box to Add Automated Protections Against Security Breaches and Data Loss 
October 2023 Patch Tuesday: 104 Vulnerabilities Including Three Actively Exploited Zero-Days 
CrowdStrike Recognized by Forrester as a Leader in Endpoint Security with the Highest Score in the Current Offering Category 
Patch Tuesday Turns 20: The Growth and Impact of Microsoft s Vulnerability Problem 
Small Screens, Big Risks: Falcon for Mobile Releases New Innovations to Accelerate Detection and Response for Mobile Threats 
Sources: RISC-V chip designer SiFive, which has raised $365M+, lays off 100 to 300+ employees, mostly in its engineering team, and guts its product po 
A Powerful Tool US Spies Misused to Stalk Women Faces Its Potential Demise 
Sources: prominent RISC-V startup SiFive, which raised $365M+, lays off 100 to 300+ employees, mostly in its engineering team, and guts its product po 
Spotify reports Q3 revenue up 11% YoY to €3.4B, MAUs up 26% to 574M, Premium users up 16% YoY to 226M, and a €32M profit, beating es 
Open Source Security: Trends and Predictions for 2024 
How did the Okta Support breach impact 1Password? 
PII Belonging to Indian Citizens, Including their Aadhaar IDs, Offered for Sale on the Dark Web 
How To Fix Samsung Galaxy Z Flip 4 Not Charging Issue 
Security provider Okta reports hack to its own support system - Scripps News 
Examining Predator Mercenary Spyware 
DC Board of Elections breach may include entire voter roll 
Security provider Okta reports hack to its own support system - 25 News KXXV and KRHD 
Amsterdam-based Adyen, a Stripe and PayPal rival, has seen its stock fall 25% since August 17's drop of 35%+, after Adyen reported lower-than-ex 
Security provider Okta reports hack to its own support system - KMTV 3 News Now Omaha 
Cisco warns of a second IOS XE zero-day used to infect devices worldwide 
Quasar RAT Leverages DLL Side-Loading to Fly Under the Radar 
DoNot Team's New Firebird Backdoor Hits Pakistan and Afghanistan 
Adyen, an Amsterdam-based PayPal rival, has had its stock fall 25% since August 17, when it dropped 35%+ following its report of lower-than-expected  
Dutch media reports that a former ASML employee in China accused of stealing data went to work for Huawei in 2022; it's unclear if they still wor 
From July 2022 to June 2023, the US led the world with $1T+ in "value received on chain", but most stablecoin inflows to top services went v 
Report: CISOs big worry in new role is inaccurate data on security posture 
FTC works to reduce cross-border fraud 
City of Philadelphia suffers a data breach 
Dutch media reports that a former ASML employee accused of stealing data went to work for Huawei in China in 2022; it's unclear if they still wor 
Incident Workflow to streamline ITGC testing 
SolarWinds fixed three critical RCE flaws in its Access Rights Manager product 
Safeguarding the End-User: Cybersecurity Awareness Month 2023 
Japan's FTC opens an investigation into Google over alleged antitrust violations; a report says the focus will be if Google asked OEMs to priorit 
Don’t use AI-based apps, Philippine defense ordered its personnel 
Vietnamese threat actors linked to DarkGate malware campaign 
Japan's FTC probes into Google over alleged antitrust violations; report: the agency plans to examine if Google asked smartphone OEMs to prioriti 
Defending federal networks requires more than money, CSIS study finds 
MI5 chief warns of Chinese cyber espionage reached an unprecedented scale 
Gurman: Apple is planning a "Mac-centered product launch" by the end of October that could see the release of an updated 24-inch iMac (Hartl 
Security Affairs newsletter Round 442 by Pierluigi Paganini INTERNATIONAL EDITION 
Report: seven unreliable X accounts, some promoted by Elon Musk, dominated English-language news on X around the Israel-Hamas war from October 7 to Oc 
Report: seven unreliable X accounts, some promoted by Elon Musk, are dominating news on X around the Israel-Hamas war, outpacing mainstream news outle 
A threat actor is selling access to Facebook and Instagram’s Police Portal 
Belco report pulled from RA site after redacted parts hacked - Royal Gazette 
News alert: AI-powered web scrapers from Oxylabs are breaking new ground in fraud detection 
Hugging Face confirms "regrettable accessibility issues in China", after a report says the country fully blocked access to the AI model plat 
Hugging Face confirms "regrettable accessibility issues in China", after a report that the platform has been unavailable in the country sinc 
48% of organizations predict cyberattack recovery to take weeks 
On Detection: Tactical to Functional 
Hackers Stole Access Tokens from Okta’s Support Unit 
VMware Aria Operations for Logs CVE-2023-34051 Technical Deep Dive and IOCs 
Over 200 million malicious emails were detected in Q3 2023 
Vietnamese Hackers Target U.K., U.S., and India with DarkGate Malware 
CISA adds Cisco IOS XE flaw to its Known Exploited Vulnerabilities catalog 
Tens of thousands Cisco IOS XE devices were hacked by exploiting CVE-2023-20198 
Elon Musk says X plans to launch two new premium tiers: a lower cost tier with all features, but no reduction in ads, and a more expensive tier with n 
Sphero - 832,255 breached accounts 
Musk: X to launch two new Premium tiers, one for less than the current $8 mo one with all features and no reduction in ads, the other more expensive w 
Elon Musk confirms two new X Premium tiers, a lower than the current $8 per month with all the features but no reduction in ads and an expensive one w 
Cisco IOS XE Web UI Vulnerability: A Glimpse into CVE-2023-20198 
The US Treasury's FinCEN proposes labeling international crypto mixing as a "primary money laundering concern", citing its use by Hamas 
How to Defend Against a DDoS Attack: 2023 Guide to Outsmart Cybercriminals 
House cybersecurity subcommittee chairman says GOP speaker drama is impacting cyber legislation 
More helpful resources for users of all skill levels to help you Take a Security Action 
Tips for a Successful SecOps Game Plan 
Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activity 
Hamas-linked app offers window into cyber infrastructure, possible links to Iran 
Phishing emails impersonating HR are on the rise 
Russia Creates No-Win Situation for Western Companies 
Manufacturing is the top industry affected by ransomware in 2023 
Former Uber CISO Appealing His Conviction 
THE 11TH EDITION OF THE ENISA THREAT LANDSCAPE REPORT IS OUT! 
Report: Cyberattacks No. 1 cause of downtime and data loss 
Cybersecurity Spending Slows as Investment Patterns Shift 
Hackers Exploit QR Codes with QRLJacking for Malware Distribution 
What is an island hopping cybersecurity attack? | Cyber Bank Heists Report | Contrast Security 
Iran-Linked OilRig Targets Middle East Governments in 8-Month Cyber Campaign 
Lam Research reports Q1 revenue down 31% YoY to $3.48B, vs. $3.42B est., the third straight quarter of decline, as the chipmaking tools market remains 
Chainalysis says recent media reports about the supposed use of crypto by terrorist organizations might be overstating metrics and using "flawed  
TSMC reports Q3 revenue down 14.6% YoY to $17.28B, net income down 24.9% YoY to $6.5B, and expects to spend $32B on growing and upgrading capacity i 
Nokia plans to cut up to 14,000 jobs, or 16% of its 86,000 workforce, and reports Q3 2023 net sales down 20% YoY to €4.98B and profit down 6 
6 Ways to Fix ‘A Required Network Service has Failed’ in MW2 
Multiple APT groups exploited WinRAR flaw CVE-2023-38831 
Netflix raises its US prices for its basic plan from $9.99 to $11.99, its premium plan from $19.99 to $22.99, and some of its prices in the UK and Fra 
Netflix reports Q3 revenue up 7.8% YoY to $8.54B, vs. $8.54B est., and global paid memberships up 10.8% YoY to 247.15M, vs. 243.88M est.; NFLX jumps 1 
Netflix raises US prices for its basic plan to $11.99 from $9.99 and its premium plan to $22.99 from $19.99; it is also raising some prices in the UK  
Netflix reports Q3 revenue up 7.8% YoY to $8.54B, vs. $8.54B est., and global paid memberships up 10.8% YoY to 247.15M, vs. 243.88M est.; NFLX jumps 9 
Phishing Attacks Surge By 173% In Q3, 2023; Malware Threats Soar By 110% 
Why Mutual TLS (Mtls) Is Critical For Securing Microservices Communications In A Service Mesh 
Unidentified attackers breach tens of thousands of Cisco devices 
Unknown attacker breaches tens of thousands of Cisco devices 
Russian hackers offered phony drone training to exploit WinRar vulnerability 
6% of financial firms are confident in communications compliance 
The Fake Browser Update Scam Gets a Makeover 
Threat actors have been exploiting CVE-2023-4966 in Citrix NetScaler ADC Gateway devices since August 
A flaw in Synology DiskStation Manager allows admin account takeover 
Filing: Invesco marked up Swiggy's valuation to $7.85B on July 31, up 42% from $5.5B in January 2023 but down from a reported $10.7B valuation i 
DTEX and ServiceNow: A Powerful Integration for Maturing Insider Risk Capability 
ASML reports Q3 revenue up 15.5% YoY to €6.67B, vs. €6.71B est., net profit up 11% YoY to €1.89B, vs. €1.8B est.,  
Filing: Invesco marked up Swiggy's valuation to $7.85B on July 31 2023, up 42% from $5.5B in January 2023 but still down from a reported $10.7B  
Similarweb: in September, X's global monthly website traffic fell 14% YoY, Facebook's dropped 10.4%, while traffic to Instagram, WhatsApp, a 
Fairwinds Insights Release Notes 13.11-14.3: Action Items Report & More 
Rossen Reports: The pumpkin carving hack that really doesn't work ... - WBAL TV Baltimore 
New Netskope Report Exposes Increasing Use of Cloud Apps to Spread Malware 
New Netskope Report Exposes Increasing Use of Cloud Apps for Spreading Malware 
CSC Report Highlights Cybersecurity Threats .AI Domains Pose 
Similarweb: X's global monthly website traffic declined 14% YoY in September, US traffic dropped 19% YoY, while traffic to Musk's profile pa 
Silk Road Hacker Accidentally Showed Feds $70,000,000 Worth of Bitcoin on His Laptop Before Being Arrested: Report - The Daily Hodl 
63% of organizations restore data after a ransomware attack 
Why logging is one of the most overlooked aspects of incident response, and how Cisco Talos IR can help 
Fantom Foundation hacked for an estimated $6.7M: Report - Cointelegraph 
32% of organizations have banned the use of generative AI tools 
New ESG Research Report Outlines Best Practices for Effective Application Security Programs 
Russia-linked Sandworm APT compromised 11 Ukrainian telecommunications providers 
Permission Control for Third Parties 
Report finds majority of enterprises expect an imminent cyberattack 
Federal agencies are falling behind on meeting key privacy goal set five years ago 
A look at sexism in the video games industry; State of the Game Industry 2023 report: 23% are women, up from 20% in 2022, 5% are non-binary, and 70%  
CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks 
Stand.earth: Apple is ahead of Microsoft, Google, Nvidia, Dell, and HP in climate initiatives and is the only one that has renewable targets for its s 
Top 6 Ways to Fix Audio Sound Crackling Issues in Dolphin Emulator 
7 Ways to Fix Valorant Queue is Disabled or Not Working Issue 
Best 5 Ways to Fix League of Legends Error Code 900 
Snap's stock closes up 11.98% after a report that the company's internal "stretch" goal was to pass 475M DAUs in 2024, above Wall  
More Aggressive Time-to-Exploit Vulnerability Trends Affect Oracle and SAP Security Too 
Snap shares jumped 11%+ following a report that Snap's internal "stretch" goal was to have over 475M DAUs in 2024, above Wall St. expec 
A survey of 1,567 US adolescents: 51% spend at least four hours on social media apps per day; 13-year-olds spent 4.1 hours, rising to 5.8 hours for 17 
Data privacy among top concerns for workplace generative AI use 
Following reports from Patreon users, analysis shows X slowing down traffic on links to Patreon, WhatsApp, and, at times Meta's Messenger, by 2. 
92% of business plan to move to passwordless technology 
Signal denies claims of an alleged zero-day flaw in its platform 
Signal Disputes Alleged Zero-Day Flaw 
A survey of 1,500 US adolescents: 51% spend at least four hours on social media apps daily; 13-year-olds spent 4.1 hours, rising to 5.8 hours for 17-y 
Signal Debunks Zero-Day Vulnerability Reports, Finds No Evidence - The Hacker News 
Sources: Goldman wants to exit consumer lending and offload its Apple partnership, possibly to Amex, which has balked at Apple Card's loss rate a 
Signal Debunks Zero-Day Vulnerability Reports, Finds No Evidence 
Microsoft Defender thwarted Akira ransomware attack on an industrial engineering firm 
DarkGate malware campaign abuses Skype and Teams 
Security Affairs newsletter Round 441 by Pierluigi Paganini INTERNATIONAL EDITION 
Royal family website targeted by hackers to instill fear: report - Geo News 
Hackers are waging a digital battle in the Israel-Hamas conflict - CyberGuy Report 
As China-linked Bitcoin mines open across the US, officials raise national security concerns, like about a Wyoming mine that is close to a nuclear mis 
60% of Organizations are Very Concerned About the Potential Impact of Ransomware Attacks 
9 in 10 CISOs Report at Least One Disruptive Cyberattack in the Last Year 
Microsoft completes its Activision Blizzard acquisition after a 20-month battle with regulators in the UK and the US; Bobby Kotick will remain CEO thr 
Stayin’ Alive campaign targets high-profile Asian government and telecom entities. Is it linked to ToddyCat APT? 
18% of African banking apps have vulnerable high severity secrets 
Microsoft completes Activision Blizzard acquisition after a 20-month battle with regulators in the UK and US; Bobby Kotick will remain CEO until the e 
Microsoft completes Activision Blizzard acquisition after a 20-month battle with regulators in the UK and US (Tom Warren The Verge) 
Report uncovers critical cyber threats facing financial industry 
Hackers infiltrate Israeli smart billboards to post pro-Hamas messages: reports - Business Insider 
KnowBe4 Named a Leader in the Fall 2023 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) 
After hackers distribute malware in game updates, Steam adds SMS-based security check for developers 
More than 17,000 WordPress websites infected with the Balada Injector in September 
PitchBook and NVCA report: in Q3 2023, US VC deal value fell to its lowest level since Q2 2018, and US deal count is on track for its lowest year sinc 
Organisations fail to see benefit of ethical hacking - report - SecurityBrief New Zealand 
Mercenary Hackers Stole Data That Exxon Later Cited in Climate ... - U.S. News & World Report 
Organisations fail to see benefit of ethical hacking - report - IT Brief Australia 
Organisations fail to see benefit of ethical hacking - report - SecurityBrief Australia 
EPA calls off cyber regulations for water sector 
FTX hacker moves $120M amid Sam Bankman-Fried trial: Report - TradingView 
23andMe distances itself from reports of hacked accounts of Jewish ... - Washington Examiner 
Apple releases iOS 16 update to fix CVE-2023-42824 on older devices 
Top resources for Cybersecurity Awareness Month 
79% of organizations say bots are more difficult to detect 
New Research: Phishing Remains the Most Popular Technique for Bad Actors 
N. Korean hacking groups target defectors group's head: report - The Korea Herald 
Encrypted pager use on the rise in healthcare since 2022 
FTX hacker moves $120M amid Sam Bankman-Fried trial: Report - Cointelegraph 
Malicious NuGet Package Targeting .NET Developers with SeroXen RAT 
Approov Publishes Carnegie-Mellon University CyLab-Africa Report on Mobile App Security in Africa 
Business Email Compromise Attempts Skyrocket in the Last Year 
Phishing, the campaigns that are targeting Italy 
A new Magecart campaign hides the malicious code in 404 error page 
N. Korean hacking groups target defectors group's head: report - Yonhap News Agency 
Vietnam tried hacking US politicians, journalists: Report - American Military News 
Top 10 Ways to Fix Forza Motorsport Crashing Issues 
Internal memo: NPR lost a negligible amount of traffic in the six months since leaving Twitter, after the service labeled the outlet "US state-af 
Fix: Forza Motorsport Won t Launch on Startup PC, PlayStation, Xbox 
A Paramedic s Top 2 Tips for Cloud Incident Response 
What Is a SOC 2 Bridge Letter? With Examples! 
Internal memo: NPR traffic loss has been negligible in the six months since it left Twitter, after the platform labeled NPR "US state-affiliated  
First half of 2023 sees more ransomware victims than all of 2022 
A look at Ring's Neighbors app, which lets users report local activity and forwarded 13,053 posts to the LAPD over two years, some about non-crim 
KnowBe4 Named a Leader in the Fall 2023 G2 Grid Report for Security Awareness Training 
Data Anonymization: What Is It and 6 Best Practices You Should Know 
10 zero-day vulnerabilities in industrial cell router could lead to code execution, buffer overflows 
A look at Ring's Neighbors, which lets owners report local activity; over 13K posts were forwarded to the LAPD in two years, some about non-crimi 
Mirai-based DDoS botnet IZ1H9 added 13 payloads to target routers 
Exploitation Accounts For 29% of Education Sector Attacks 
Survey reveals critical security issues lead to DevOps delays 
Samsung reports Q3 operating income fell 78% QoQ to $1.8B and revenue fell 13% QoQ to $49.6B, suggesting the global chip market may have started to  
A Frontline Report of Chinese Threat Actor Tactics and Techniques 
New ‘HTTP 2 Rapid Reset’ technique behind record-breaking DDoS attacks 
Largest-ever DDoS leverages zero-day vulnerability 
Savvy Israel-linked hacking group reemerges amid Gaza fighting 
CA Gov. Newsom signs a bill into law forcing VC firms to report on the diversity of founders they back; some worry about liability from releasing sens 
90% of CISOs faced at least one cyberattack in 2022 
Survey: 97% face challenges securing IoT & connected devices 
74% of CEOs Concerned About Their Organization's Ability to Protect Against Cyber Attacks, Despite Seeing Cybersecurity as Critical 
Half of CISOs Now Report to CEO as Influence Grows 
Five Key Takeaways From the New NSA and CISA IAM Guidance 
New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise 
Hacktivists in Palestine and Israel after SCADA and other industrial control systems 
How to Fix Touchscreen Not Working in Windows 11 
Top 8 Ways to Fix Android System WebView Won t Update 
Large-scale Citrix NetScaler Gateway credential harvesting campaign exploits CVE-2023-3519 
Phishers Spoof USPS, 12 Other Natl’ Postal Services 
FTC: Americans lost $2.7 Billion Since 2021 to Social Media Scams 
MGM Resorts cyberattack cost could exceed $100M 
Upbit deflected nearly 160000 hacking attempts in Q1 2023: Report ... - Cryptopolitan 
MGM Resort cyberattack cost could exceed $100M 
Survey Sees Many Cybersecurity Professionals Willing to Jump Ship 
The source code of the 2020 variant of HelloKitty ransomware was leaked on a cybercrime forum 
How looking at decades of spam led Jaeson Schultz from Y2K to the metaverse and cryptocurrency 
Gaza-linked hackers and Pro-Russia groups are targeting Israel 
Stay a Step Ahead of your #1 Downtime Threat - Business Email Compromise 
Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again 
Android devices shipped with backdoored firmware as part of the BADBOX network 
Crypto exchange Upbit targeted by hackers 159K times in H1: Report - Cointelegraph 
Crypto exchange Upbit was targeted by hackers 159K times in H1: Report - Cointelegraph 
Gaza-Linked Cyber Threat Actor Targets Israeli Energy and Defense Sectors 
One in four people in the US who reported losing money to fraud from January 2021 to June 2023 said the contact started on social media, causing $2.7B 
Security Affairs newsletter Round 440 by Pierluigi Paganini International edition 
One in four people in the US who reported losing money to fraud between January 2021-June 2023 said it started on social media, resulting in losses wo 
Top 10 Ways to Fix macOS Sonoma WiFi Problems 
North Korea-linked Lazarus APT laundered over $900 million through cross-chain crime 
Top 11 Ways to Fix Assassin’s Creed Mirage Crashing Problem 
Report: Hacker Group Scattered Spider Behind Clorox ... - PYMNTS.com 
QakBot threat actors are still operational after the August takedown 
[Risky New Data] More than Half of Phishing Scams Now Use Obfuscation 
How to Fix Instagram ‘Not Posted Yet. Try Again’ Error 2023 
Breaking: Web3 platform Galxe is hacked, multiple users report lost ... - crypto.news 
China-based spies are hacking East Asian semiconductor companies, report says - The Record from Recorded Future News 
Ransomware attack on MGM Resorts costs $110 Million 
Hackers Advertise Sale of 23andMe Data on Leaked Data Forum - U.S. News & World Report 
X appears to be rolling out a new mobile ad format that can't be reported or blocked, lacks an ad label and user profile, and doesn't disclo 
X appears to be rolling out new mobile ads that can't be reported or blocked, lack ad labels, have no user profiles, and don't disclose the  
Elliptic: the total value of crypto laundered via decentralized exchanges, bridges, and coin swaps hits $7B; Lazarus Group is the top culprit, launder 
Multiple experts released exploits for Linux local privilege escalation flaw Looney Tunables 
Elliptic: total value of crypto laundered via decentralized exchanges, bridges, and coin swaps hits $7B; Lazarus Group was the top culprit, laundering 
Belgian intelligence service VSSE accused Alibaba of possible espionage at European hub in Liege 
Report: the US DHS finds that ICE, CBP, and the Secret Service illegally used phone location data; a CBP official tracked coworkers for no investigati 
Report: a US DHS oversight body finds that ICE, CBP, and the Secret Service illegally accessed smartphone location data; CBP tracked coworkers without 
A WhatsApp zero-day exploit can cost several million dollars 
[New Report] Over Half of Phishing Emails Use Obfuscation 
Is it bad to have a major security incident on your r sum ? (Seriously I don t know) 
Sources: some US FTX staff found and internally reported Alameda's backdoor used to allegedly withdraw billions in client funds, months before FT 
Report: Hacker Group Scattered Spider Behind Clorox Cybersecurity Breach - PYMNTS.com 
CISA and NSA Tackle IAM Security Challenges in New Report 
False Amazon callers one of the top phone scams in 2023 
Las Vegas Casinos Under Siege: The Urgent Need for Advanced Ransomware Protection 
Microsoft: State-backed hackers grow in sophistication, aggressiveness 
China Poised to Disrupt US Critical Infrastructure with Cyber-Attacks, Microsoft Warns 
Report: Ransomware dwell time hits low of 24 hours 
Sources: FTX employees in the US found and reported the backdoor Alameda used to allegedly withdraw billions in customer funds, months before FTX&apos 
Record Numbers of Ransomware Victims Named on Leak Sites 
10 Bot Detection Tools for 2023: Features & Mitigation Methods 
Global CRM Provider Exposed Millions of Clients Files Online 
Chinese State-Sponsored Cyber Espionage Activity Targeting Semiconductor Industry in East Asia 
Exclusive Report: The Rise of Credit Union Brand Impersonations Online in 2023 
Apple Rolls Out Security Patches for Actively Exploited iOS Zero-Day Flaw 
BetMGM Account Issues Solved, Unrelated To MGM Hack - Legal Sports Report 
Atlassian Confluence zero-day CVE-2023-22515 actively exploited in attacks 
Apple fixed the 17th zero-day flaw exploited in attacks 
Available Now: Java Endpoint Analyzer from Onapsis Research Labs 
69% of generative AI users are concerned their data might be misused 
Stream-Jacking: Malicious YouTube Livestreams Aid Malware, Crypto Scams 
Fix: Can t Save Audio on my Instagram Reels Problem 2023 
Ransomware double-extortion attacks increased 72% 
A cyberattack disrupted Lyca Mobile services 
Chipmaker Qualcomm warns of three actively exploited zero-days 
Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance 
DRM Report Q2 2023 – Ransomware threat landscape 
Phishing campaign targeted US executives exploiting a flaw in Indeed job search platform 
The European Commission starts collective risk assessments on advanced chips, AI, quantum, and biotech, the most sensitive areas for security and tech 
Royal Family Website Crashed Over the Weekend After Cyberattack by Pro-Russia Hackers: Reports - Yahoo Entertainment 
Report: Apple should explain what "carbon-neutral products" mean after the company in 2023 stopped requiring suppliers to disclose greenhous 
Report: Apple should explain how it defines product "carbon neutrality" after it stopped requiring suppliers to disclose greenhouse gas emis 
AWS MadPot Honeypot Operation Corrals Threat Actors 
81% of security leaders say that API security is a higher priority 
Akamai Sees Surge of Cyberattacks Aimed at Financial Services 
Keeping SEC-ure: Using Threat Intelligence to Stay Ahead of the New SEC Regulations 
BunnyLoader, a new Malware-as-a-Service advertised in cybercrime forums 
Introducing our 9th annual State of the Software Supply Chain report 
Half of Cybersecurity Professionals Report Increase in Cyber-Attacks 
Exclusive: Lighting the Exfiltration Infrastructure of a LockBit Affiliate (and more) 
Two hacker groups are back in the news, LockBit 3.0 Black and BlackCat AlphV 
How to Fix Ticketmaster Think You re A Bot Issues 2023 
European Telecommunications Standards Institute (ETSI) suffered a data breach 
Top 8 Ways to Fix McDonald’s App Not Working or Crashing 
Sources: ByteDance offers to buy back staff shares at a $223.5B valuation, down nearly 26% YoY, and made $20B+ in 2022 operating profit as revenue gro 
The sinister Russian hackers who've claimed responsibility for crashing Buckingham Palace website: How pro-Put - Daily Mail 
Sources: ByteDance plans a buyback from employees at a $223.5B valuation, down 26% YoY, and made $20B+ in operating profit in 2022, but revenue growth 
Sources: ByteDance plans a buyback from employees at a $223.5B valuation, down 26% YoY; it made $20B+ in operating profit in 2022, but revenue growth  
Sources: ByteDance plans a buyback from employees that values itself at $223.5B, down 26% YoY; last year it made $20B+ in operating profit but saw rev 
Financial sector sees rise in digital identity verification 
WS_FTP flaw CVE-2023-40044 actively exploited in the wild 
How to Stop Phishing Attacks with Protective DNS 
Crypto Industry Lost $685 Million in Q3 2023, 30% by Lazarus Group 
Which DFIR Challenges Does the Middle East Face? 
Royal Family Website Crashed Over the Weekend After Cyberattack by Pro-Russia Hackers: Reports - PEOPLE 
Healthcare top infrastructure target for cyberattacks 
Pro-Russia hackers claim responsibility for crashing British royal family's website - ABC News 
AI-Generated Phishing Emails Almost Impossible to Detect, Report Finds 
Nearly 100,000 Industrial Control Systems Exposed to the Internet 
Royal family website 'targeted in Russian cyber attack' - The Telegraph 
Russian hackers 'crash Royal Family website' just days after King Charles condemned invasion of Ukraine: Pro-P - Daily Mail 
Royal family s official website at the centre of a Russian hacking mystery - New Zealand Herald 
North Korea-linked Lazarus targeted a Spanish aerospace company 
World Robotics 2023 report: Asia ahead of Europe and the Americas 
Ransomware attack on Johnson Controls may have exposed sensitive DHS data 
A thief stole gas worth $3,000 from a filling station by hacking the pump with his phone's Bluetooth, report says - Yahoo News 
Royal Family Website Faces Cyber Attack By Russian Hackers: Report - NDTV 
BlackCat gang claims they stole data of 2.5 million patients of McLaren Health Care 
Security Affairs newsletter Round 439 by Pierluigi Paganini International edition 
A thief stole gas worth $3,000 from a filling station by hacking the pump with his phone's Bluetooth, report says - Yahoo Canada Finance 
Canadian Armed Forces website temporarily disabled by 'Indian' hackers: Report - Business Today 
ALPHV BlackCat ransomware gang hacked the hotel chain Motel One 
A Closer Look at the Snatch Data Ransom Group 
How Zero-Point Fonts in Phishing Emails Make Them Look Safe 
A thief stole gas worth $3,000 from a filling station by hacking the pump with his phone's Bluetooth, report s - Business Insider India 
Thief stole gas worth $3,000 with a Bluetooth hack: report - Business Insider 
New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks 
Researchers report critical vulnerabilities in the Exim mail transfer agent allowing remote code execution; Exim is used by as many as 253K servers (D 
A still unpatched zero-day RCE impacts more than 3.5M Exim servers 
Mozilla Rushes to Fix Critical Vulnerability in Firefox and Thunderbird 
Anticipating File-Borne Threats: How Deep File Inspection Technology Will Shape the Future of Cyber Defense 
Lazarus APT Exploiting LinkedIn to Target Spanish Aerospace Firm 
Beyond Risk Mitigation: The Business Benefits of Strong Cybersecurity 
BeReal says its app has 25M+ DAUs, up from 20M in October 2022, disputing a Similarweb report estimating that BeReal's MAUs declined to 16.06M in 
BeReal says it has 25M DAUs, up from 20M about a year ago, disputing a Similarweb report that BeReal's MAUs declined to 16.06M in August (Sarah P 
Cybersecurity Gaps Plague US State Department, GAO Report Warns 
India cyberattack: Hackers target websites of military, Parliament - CTV News 
Report: Apple uses two microscopic QR codes on iPhone displays to track defects, which has helped cut its suppliers' faulty screen report rates f 
Report: Apple uses microscopic QR codes on iPhone screens to track defects, which helped reduce faulty screen report rates from its suppliers from 30% 
Gartner s Calling for a Human-Centric Approach to Cybersecurity – Here s How to Implement It 
Recorded Future Announces Keynote Lineup for PREDICT 2023 
National Cybersecurity Infrastructure Efforts Bearing Fruit 
Chinese threat actors stole around 60,000 emails from US State Department in Microsoft breach 
North Korean hackers posed as Meta recruiter on LinkedIn 
Misconfigured WBSC server leaks thousands of passports 
Various Canadian govt agencies report cyberattacks from Indian ... - Telangana Today 
Hackers target websites of Canadian military, Parliament - CTV News 
Third-Party Risk Management: Best Practices for Protecting Your Business 
Threat Report: High Tech Industry targeted the most with 46% of attack traffic tagged by NLX 
India hacker group claims responsibility for cyberattacks that hit federal government - CP24 
What You Need to Know About the libwebp Exploit 
Pharma Industry Seeing Reduction in Data Breach Costs, But Still Have Much to Do 
Anticipating File-Borne Threats: How Deep File Inspection Technology Will Shape the Future of Cyber Defense 
Chinese hackers stole 60,000 emails from senior State Department officials in May - CNN 
The security pitfalls of social media sites offering ID-based authentication 
Mayorkas warns Latin American leaders of Beijing’s technology influence 
Epic Games lays off 16% of its workforce, or 830 employees, divests from music storefront Bandcamp, and intends to spin off "kid-tech" comp 
Epic Games lays off 16% of its workforce, or 830 employees, and intends to divest from music storefront Bandcamp and spin off "kid-tech" co 
Zero-Point Fonts in Phishing Emails 
Cyber Insurance Claims Increased by 12% in First Half of 2023, Attacks More Frequent and Severe Than Ever 
Email: Serve Robotics, used by Uber Eats in Los Angeles, shared video filmed by one of its food delivery robots to the LAPD as part of a criminal inve 
Epic Games confirms it is laying off 16% of its workforce, or about 830 people, and intends to divest from Bandcamp and spin off "kid-tech"  
Email: Serve Robotics, which delivers for Uber Eats in LA, provided video filmed by one of its food delivery robots to LAPD as part of a criminal inve 
Google patches a zero-day in Chrome that was exploited by a commercial spyware vendor, just two days after it was reported by Google's Threat Ana 
Chinese Hackers Stole 60000 State Dept. Emails in Breach Reported in July - The New York Times 
Dark Angels Team ransomware group hit Johnson Controls 
Indian hackers take down Canada Army website amid soaring tensions: Report - Hindustan Times 
US businesses see cyberattacks decrease; Still too high to sustain 
Privacy watchdog recommends court approval for FBI searches of spy data 
Canadian Army website temporarily disabled by 'Indian' hackers: Report - India Today 
Report: Bank for International Settlements and French, Swiss, and Singaporean central banks successfully tested cross-border wholesale CBDC trading us 
Insider Threat Awareness Month 2023 Roundup 
New working group to probe AI risks and applications 
GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023 
US, Japan Authorities Warn of China-Linked Hacking Group ... - U.S. News & World Report 
Micron reports Q4 revenue down 40% YoY to $4.01B, vs. $3.91B est., and forecasts Q1 revenue above est., driven by memory chip demand, and a net loss b 
Smashing Security podcast #341: Another T-Mobile breach, ThemeBleed, and farewell Naked Security 
RATs, rootkits, and ransomware (oh my!) 
China-linked APT BlackTech was spotted hiding in Cisco router firmware 
Micron reports Q4 revenue of $4.01B., vs. $3.91B est., down from $6.64B in Q4 2022, and forecasts Q1 revenue above estimates, driven by demand for mem 
Millions of files with potentially sensitive information exposed online, researchers say 
Researchers say X removed a feature letting users to report election misinformation, launched in the US, Australia, and South Korea in 2021 and expand 
10 new vulnerabilities disclosed by Talos, including use-after-free issue in Google Chrome 
Watch out! CVE-2023-5129 in libwebp library affects millions applications 
40% of U.S. security leaders cite malware as threat focus 
What Is LSASS.EXE? Fix Lsass.exe High CPU Usage Issue Windows 11 
DarkBeam leaks billions of email and password combinations 
Researchers say X removed the ability for users to report election misinformation, a feature launched in the US, Australia, and some other countries i 
‘Ransomed.vc’ in the Spotlight – What is Known About the Ransomware Group Targeting Sony and NTT Docomo 
New ZenRAT Malware Targeting Windows Users via Fake Password Manager Software 
Canadian Flair Airlines left user data leaking for months 
First EU DSA report: Twitter had the highest disinformation rate in H1 2023, followed by Facebook; TikTok closed 6M fake accounts; YouTube closed 400 
Is Your Workforce Ready for Passwordless MFA? 
ShadowSyndicate: A New Cybercrime Group Linked to 7 Ransomware Families 
Russian hacking operations target Ukrainian law enforcement 
North Korean Hackers Lazarus Group Holds USD 47 Million in Cryptocurrency, Mostly Bitcoin: Report - LatestLY 
Report shows cybersecurity budgets increased 6% for 2022-2023 cycle 
85% of IT anticipate leaving their role due to burnout 
Sony is "investigating" a report all of its systems have been hacked - Gamesradar 
Near-Space in China s Military Strategy: Strategic Reconnaissance, Precision Strike, and Battlefield Advantage 
40% of organizations have hybrid cloud environments 
How a private company helps ICE track migrants every move 
75% who didn't report cyber attack to leadership, felt guilty about it 
EU's first DSA report: Twitter had the highest rate of disinfo in H1 2023, followed by Facebook; TikTok removed 6M fake accounts; YouTube remove 
Half of Cyber-Attacks Go Unreported 
Threat Report: The High Tech Industry Targeted the Most with 46% of NLX-Tagged Attack Traffic 
Xenomorph malware is back after months of hiatus and expands the list of targets 
New Report Uncovers 3 Distinct Clusters of China-Nexus Attacks on Southeast Asian Government - The Hacker News 
Pension Firms Report 4000% Surge in Breaches 
$16.2M: The High Cost of Insider Risks  
Many users report that their iPhone 15 series devices, including the 15 Pro and 15 Pro Max, get too hot to hold, especially during charging or prolong 
Crooks stole $200 million worth of assets from Mixin Network 
Many users report that their iPhone 15 series devices, including the 15 Pro and 15 Pro Max, are overheating, especially during charging or prolonged u 
Several users report that their iPhone 15 series devices, including the 15 Pro and 15 Pro Max, are overheating, especially during charging or prolonge 
A phishing campaign targets Ukrainian military entities with drone manual lures 
Report: 79% of organizations confident in ransomware defenses 
Huobi Global hacked for $7.9M: Report - Cointelegraph 
Organizations Starting to Understand the Impact of Ransomware, But Their Efforts Not Enough to Overcome Infostealer Malware 
Tools From Cybercrime Software Vendor W3LL Found to be Behind the Compromise of 56K Microsoft 365 Accounts 
New Report Uncovers 3 Distinct Clusters of China-Nexus Attacks on Southeast Asian Government 
New Report Uncovers Three Distinct Clusters of China-Nexus Attacks on Southeast Asian Government 
New variant of BBTok Trojan targets users of +40 banks in LATAM 
Deadglyph, a very sophisticated and unknown backdoor targets the Middle East 
National Student Clearinghouse data breach impacted approximately 900 US schools 
Criminals are Bypassing Authentication with Stolen Session Cookies 
Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics 
City of Dallas has set a budget of $8.5 million to mitigate the May Royal ransomware attack 
Recently patched Apple and Chrome zero-days exploited to infect devices in Egypt with Predator spyware 
Do CISOs Have to Report Security Flaws to the SEC? 
Sources: The White House is weighing requiring cloud companies to disclose when a client buys computing resources above a set threshold, as part of an 
Sources: White House considers requiring cloud companies to disclose when a customer purchases computing resources beyond a threshold, as part of an E 
Youth hacking ring at the center of cybercrime spree 
S&P 500 companies find gaps in their cybersecurity leadership 
57% of LockBit victims were organizations with 200 employees or fewer 
Information of Air Canada employees exposed in recent cyberattack 
Dallas ransomware: Hackers used stolen credentials to access city data, report says - The Dallas Morning News 
Sandman APT targets telcos with LuaDream backdoor 
Coalition: ransomware victims reported an average $365K+ loss in H1 2023, up from $227K+ in H2 2022; the average ransom demand was $1.62M, up 74% from 
Mexican diocese denounces hacking of several of its social media accounts - Catholic World Report 
Experts warn of a 600X increase in P2Pinfect traffic 
Apple rolled out emergency updates to address 3 new actively exploited zero-day flaws 
The State of Cloud Security: New MixMode Report Finds Enterprises Are Struggling to Keep Pace with Security As Cloud Adoption Accelerates 
New Capabilities with the September Release of the HYAS Platform 
97% of organizations take over a month to respond to bot attacks 
Vague in the Hague: Who Is Behind the ICC Data Breach? 
19% of organizations are prioritizing data visibility and remediation 
Ukrainian hackers are behind the Free Download Manager supply chain attack 
New threat intel effort to study ‘undermonitered’ regions 
ICC War Crimes Tribunal Hobbles on Despite Hacking - U.S. News & World Report 
Cloud adoption is driving up IT budgets 
Gaming, Financial Services Apps Under Attack 
ICC War Crimes Tribunal Hobbled by Hacking Incident - U.S. News & World Report 
New Ransomware Victims Surge by 47% with Gangs Targeting Small Businesses 
Siemens ALM 0-Day Vulnerabilities Posed Full Remote Takeover Risk 
Scams Now Make Up 75% of Cyber-Threats 
Pro-Russia hacker group NoName launched a DDoS attack on Canadian airports causing severe disruptions 
MotherDuck, which is commercializing the database platform DuckDB, raised a $52.5M Series B at a $400M post-money valuation, taking its total funding  
Barracuda Networks Issues Email Inbox Rules Manipulation Warning 
Ransomware cyber insurance claims rose by 27% 
Coalition Report Reveals Ransomware Resurgence 
Homeland Security report details how teen hackers exploited security weaknesses in some of the world s biggest companies - CNN 
August 2023 Healthcare Data Breach Report - HIPAA Journal 
55% of insider threats come from a negligent or mistaken insider 
#NITAM: Average Annual Cost of Insider Incidents Reaches $16.2m Per Organization 
TikTok Impersonations of Elon Musk Scam Victims of Their Bitcoin 
Data Breach Costs Rise, But Cybersecurity Pros Still Take Risks 
International Criminal Court hit with a cyber attack 
Sophisticated Phishing Campaign Targeting Chinese Users with ValleyRAT and Gh0st RAT 
GitLab addressed critical vulnerability CVE-2023-5009 
MGM and Caesars hackers targeted three other companies: report ... - Asia Gaming Brief 
How Airbnb Head of Trust and Safety Naba Banerjee cut parties reported on the service by 55% from 2020 to 2022 and launched an anti-party AI system in 
The Expel Quarterly Threat Report distills the threats and trends the Expel SOC saw in Q2. Download it now. 
Apptega Lands 39 Badges, including GRC Momentum Leader, in Fall G2 Reports 
ShroudedSnooper threat actors target telecom companies in the Middle East 
MixMode Releases State of Cloud Security 2023 Survey and Cloud Detection and Response for AWS 
57% of small and medium enterprises experienced a cybersecurity breach 
War crimes tribunal ICC reports hacking incident - TVP World 
DHS council seeks to simplify cyber incident reporting rules 
Crowdstrike confirms acquiring Bionic, which analyzes a company's tech and IT to find vulnerabilities, sources say for $350M; Bionic has raised  
Energy sector faces 39% of critical infrastructure attacks 
International Criminal Court reports cybersecurity 'incident' - Reuters 
After Hong Kong's police arrested six following allegations of fraud at unlicensed crypto exchange JPEX, the government plans to tighten its cryp 
Multi-year Chinese APT Campaign Targets South Korean Academic, Government, and Political Entities 
51% of healthcare committed to investing more in cybersecurity 
Gaming and financial service applications most likely to be attacked 
Crowdstrike confirms acquiring Bionic, which analyzes a company's tech and IT to find vulnerabilities, sources say for $350M; Bionic has raised $ 
New ShroudedSnooper actor targets telecommunications firms in the Middle East with Novel Implants 
Live Webinar: Overcoming Generative AI Data Leakage Risks 
Solarium Commission wants action on stalled cybersecurity recommendations 
Earth Lusca expands its arsenal with SprySOCKS Linux malware 
Analysis: SMIC's gross margins halved in H1 2023 as the company poured $345M, or its 11.4% of revenue, into R&D; SMIC reported $111M in state 
10 Ways to Fix Payday 3 Keeps Crashing on PC Quickly 
Top 8 Ways to Fix Payday 3 Stuck on Loading PC, PS4, Xbox, PS5 
How to Fix Payday 3 Won t Launch On PC or Not Launching 
SMIC's gross margins halved in H1 2023, as it poured $345M, or 11.4% of revenue, into research and development; SMIC reported $111M in state gran 
FBI Chief Says China Has Bigger Hacking Program Than the ... - U.S. News & World Report 
Microsoft AI research division accidentally exposed 38TB of sensitive data 
Microsoft AI researchers exposed sensitive signing keys, internal messages 
White House grapples with harmonizing thicket of cybersecurity rules 
The UK CMA lists seven AI foundation model regulating principles and plans to engage Google, Meta, OpenAI, Microsoft, Nvidia, and Anthropic before a 2 
The International Joint Commission Falls Victim to Ransomware Attack; 80GB Of Data Stolen 
Spectrum App Not Working? Here’s 10 Ways to Fix 
OSINT Round-Up of Russia-Based High-Profile Cybercriminals 
[New PhishER Feature] Immediately Add User-Reported Email Threats to Your M365 Blocklist 
German intelligence warns cyberattacks could target liquefied natural gas (LNG) terminals 
Think Your MFA and PAM Solutions Protect You? Think Again 
The UK CMA outlines seven principles for regulating AI foundation models and plans to speak to Meta, Google, OpenAI, Nvidia, and others before a repor 
Deepfake and smishing. How hackers compromised the accounts of 27 Retool customers in the crypto industry 
FBI hacker USDoD leaks highly sensitive TransUnion data 
North Korea’s Lazarus APT stole almost $240 million in crypto assets since June 
How to fight back against debit card hackers who are after your money - CyberGuy Report 
Clop gang stolen data from major North Carolina hospitals 
CardX released a data leak notification impacting their customers in Thailand 
Security Affairs newsletter Round 437 by Pierluigi Paganini International edition 
North Korea's Lazarus Group Suspected in $31 Million CoinEx Heist 
TikTok fined 345M by Irish DPC for violating children s privacy 
Iranian Peach Sandstorm group behind recent password spray attacks 
Iranian hackers are targeting U.S. defense, satellite firms: Microsoft report - Axios 
Google Account Sync Vulnerability Exploited to Steal $15M 
Google Account Sync Vulnerability Used to Steal $15 Million 
California passes first-in-the-nation data broker deletion tool 
Board Members' Lack of Security Awareness Puts Businesses at Risk of Cyber Attacks, Finds Savanti Report 
Deepfakes More Common So Bolster Your Defenses 
91% of Cybersecurity Professionals Have Experienced Cyber Attacks that Use AI 
Caesars Entertainment paid a ransom to avoid stolen data leaks 
China's Malicious Cyber Activity Informing War Preparations, Pentagon Says 
MS report: North Korea hacked Finnish defence industries - YLE News 
Free Download Manager backdoored to serve Linux malware for more than 3 years 
Top 8 Ways to Fix Error Code 4B538E50 in NBA 2k24 
Lockbit ransomware gang hit the Carthage Area Hospital and the Clayton-Hepburn Medical Center in New York 
Adobe reports Q3 revenue up 10% YoY to $4.89B, vs. $4.87B est., Digital Media revenue up 11% YoY to $3.59B, and Digital Experience revenue up 10% YoY  
Shifting Perspectives and Regulations Relating to Consent Management 
MGM, Caesars File SEC Disclosures on Cybersecurity Incidents 
Hackers Claiming to Jailbreak AI Chatbots to Write Phishing Emails 
UK Greater Manchester Police disclosed a data breach 
Caesars Entertainment paid about $15M to hackers who stole customer social security numbers, other info: report - New York Post 
Turns out even the NFL is worried about deepfakes 
DHS warns of malicious AI use against critical infrastructure 
Groups linked to Las Vegas cyber attacks are prolific criminal hacking gangs 
Microsoft: Iranian espionage campaign targeted satellite and defense sectors 
Databricks raised a $500M+ Series I at a $43B valuation, after raising $1.6B at a $38B valuation in August 2021, before a possible IPO, and reports 10 
Automation is key to effective and efficient pentest reporting 
Pixis, which sells AI tools for marketing campaigns, raised an $85M Series C1 led by Touring Capital, taking its total funding to $209M, and reports $ 
Ransomware in top three threats for 65% of organizations 
Pixis, which offers AI tools for marketing campaigns, raised an $85M Series C1 led by Touring, taking its total funding to $209M, and reports $50M in  
Databricks raised a $500M Series I at a $43B valuation, after raising $1.6B at a $38B valuation in August 2021, ahead of an IPO, and reports 10K+ cust 
The iPhone of a Russian journalist was infected with the Pegasus spyware 
Report Surfaces Root Causes of Cloud Security Issues 
5 Strategies for Reliable Protection Against BEC Scams 
NSFOCUS Ranked No. 2 in China Network Detection and Response Market 2022 
Threat actor leaks sensitive data belonging to Airbus 
CISA advisory committee urges action on cyber alerts and corporate boards 
The White House says it is monitoring reports of a growing Chinese government ban of iPhones and that the move seems to be a reprisal against the US ( 
North Korea's Lazarus Group responsible for $55M CoinEx hack: Report - Cointelegraph 
A new ransomware family called 3AM appears in the threat landscape 
Russian Journalist's Phone Hacked With Israeli Spyware ... - U.S. News & World Report 
Docs: Starlink reported $1.4B in 2022 revenue, up from $222M in 2021, falling short of projections in 2015, as some question satellite internet's 
Q2 Report: Hackers Persistently Target Healthcare - IT News Africa 
Documents: Starlink reported $1.4B in revenue in 2022, up from $222M in 2021, falling short of Elon Musk's 2015 projections, as some question its 
Global Crypto Adoption Index: India, Nigeria, Vietnam, the US, and Ukraine rank as the top five for grassroots adoption, as Central and Southern Asia  
Global Crypto Adoption Index: India, Nigeria, Vietnam, the US, and Ukraine make the top five for grassroots adoption, as Central and Southern Asia dom 
XRP Heist: CoinEx Allegedly Hit by North Korean Hackers, Recent Report Shows - U.Today 
Storm-0324 Exploits MS Teams Chats to Facilitate Ransomware Attacks 
44% of IT leaders describe their organization as secure 
How to Fix KB5003173 Error causing 0x800f0922 
Redfly group infiltrated an Asian national grid as long as six months  
ESET APT Activity Report Q4 2022 Q1 2023 
6 Ways Passwords Can be Stolen and How Passwordless Can Stop Them All 
Huawei signs a global patent cross-licensing deal with Xiaomi, covering 5G and other communication tech; Chinese media reported in March that Huawei s 
Mozilla fixed a critical zero-day in Firefox and Thunderbird 
Microsoft September 2023 Patch Tuesday fixed 2 actively exploited zero-day flaws 
SANS DevSecOps report: 5 key takeaways 
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs 
Microsoft Patch Tuesday for September 2023 Unusually low 5 critical vulnerabilities included in Microsoft Patch Tuesday, along with two zero-days 
Cyber Attacks on NGOs: The Underreported Threat to Global Humanitarian Work 
AP Stylebook Data Breach Compromises Customer Personal Information 
Bhopal: 257 Cases Of Social Media ID Hacking Reported This Year - Free Press Journal 
Crypto hackers shift additional $328M in stolen funds- Reports ... - Cryptopolitan 
A new Repojacking attack exposed over 4,000 GitHub repositories to hack 
Financial sector leading industry for generative AI adoption 
47% report economic unrest as greatest security-impacting hazard 
SAP Patch Day: September 2023 
News Alert: Traceable AI report exposes true scale of API-related data breaches, top challenges 
Critical GitHub Vulnerability Exposes 4,000+ Repositories to Repojacking Attack 
MGM Resorts hit by a cyber attack 
Chinese Redfly Group Compromised a Nation's Critical Grid in 6-Month ShadowPad Campaign 
Oracle reports Q1 revenue up 9% YoY to $12.45B, cloud services and license support revenue up 13% YoY to $9.5B, and net income up 56% YoY; ORCL drops  
Fighting Individual Ransomware Strains Fruitless, UK Agencies Suggest 
The Top 7 Insider Threats Every Company Should Be Aware Of 
Anonymous Sudan launched a DDoS attack against Telegram 
Europol: Financial Crime Makes Billions and Impacts Millions  
Iranian Charming Kitten APT targets various entities in Brazil, Israel, and the U.A.E. using a new backdoor 
GOOGLE FIXED THE FOURTH CHROME ZERO-DAY OF 2023 
Oracle Q1: revenue up 9% YoY to $12.45B, vs. $12.47B est., cloud services and license support revenue up 13% YoY to $9.5B, net income up 56% YoY; ORCL 
Do you really need to tell FedEx your Social Security number? How to avoid package-delivery scams 
CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities Catalog 
How To Fix League Of Legends Reconnect Error 
Identity Protection Can t be Taken for Granted Anymore 
Board Members Struggling to Understand Cyber Risks 
You can try to hide your firmware from Kelly Patterson, but she ll find it (and break it) 
New HijackLoader malware is rapidly growing in popularity in the cybercrime community 
Some of TOP universities wouldn t pass cybersecurity exam: left websites vulnerable 
Fix Star Citizen Error Code 16008: Fix, Causes and Solutions 
Evil Telegram campaign: Trojanized Telegram apps found on Google Play 
Rhysida Ransomware gang claims to have hacked three more US hospitals 
Akamai prevented the largest DDoS attack on a US financial company 
Research: ChatGPT consumes up to an estimated 500ml of water for every five to 50 prompts; Microsoft reported its water use spiked 34% YoY in 2022, Go 
Security Affairs newsletter Round 436 by Pierluigi Paganini International edition 
Vitalik Buterin's X account hacked, drains $691K+ from victims : Report - Cointelegraph 
You are a hacker target whether you know it or not - CyberGuy Report 
Some Wyze security camera owners report that they were briefly able to see feeds from cameras they didn't own or recognize; Wyze blames "a w 
Some Wyze security camera owners report briefly seeing feeds from cameras they didn't own or recognize; Wyze blames "a web caching issue&quo 
US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog 
Hackers target Mac users via new malvertising campaign on Google: Report - The Siasat Daily 
Fiber-infused ink enables 3D-printed heart muscle to beat 
G20 Summit 2023 Hackers From Pakistan, Indonesia Plotting Cyberattacks On Govts Digital Infrastructure Report - Jagran English 
Identity Verification vs. Authentication 
North Korea-linked threat actors target cybersecurity experts with a zero-day 
60% of organizations faced at least one API related breach 
Zero-day in Cisco ASA and FTD is actively exploited in ransomware attacks 
China Unleashes AI-Powered Image Generation for Influence Operations 
Cyber-criminals Exploit GPUs in Graphic Design Software 
Zero-Trust: 5 Steps to Transition From Hype to Reality 
[dot]US Domain Exploited for Phishing 
Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warns 
Zero-days fixed by Apple were used to deliver NSO Group s Pegasus spyware 
Fix Apple Card Savings Account Not Showing Up on iPhone, iPad 
Rezilion Recognized in Four Gartner Hype Cycle Reports and the 2023 Gartner Market Guide for Vulnerability Assessment 
Microsoft reports on Outlook email hacking investigation - here's what went wrong - OnMSFT.com 
Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs 
CVE-2023-41061 
48% of CISOs claim AI security is their biggest concern 
From Direct to Distant: The Challenge of Third and Fourth-Party Digital Risk Management 
A secondhand account of the worst possible timing for a scammer to strike 
US, UK take action against members of the Russian-linked Trickbot hacker syndicate 
Beyond the Code: Unearthing the Subtle Business Ramifications of Six Months in Vulnerabilities 
A malvertising campaign is delivering a new version of the macOS Atomic Stealer 
API Vulnerabilities: 74% of Organizations Report Multiple Breaches 
Riot Blockchain reports earning $31.7M in energy credits from Texas' power grid to curtail its usage in August, dwarfing the $8.9M worth of bitc 
26% of hospitality industry cyberattacks included credential access 
Wealthy Russian With Kremlin Ties Gets 9 Years in Prison for ... - U.S. News & World Report 
Two flaws in Apache SuperSet allow to remotely hack servers 
Attention CISOs: Closing Your Identity Protection Gaps is Urgent 
IBM Reports Patient Data Breach at Johnson & Johnson Subsidiary 
China turns to AI in hopes of creating viral online propaganda, Microsoft researchers say 
The State of the Virtual CISO Report: MSP MSSP Security Strategies for 2024 
New report analyses ransomware activity for past 6 months 
Riot reports earning $31.7M in energy credits from Texas power grid operator ERCOT to curtail its usage in August, dwarfing the $8.9M worth of bitcoi 
Fix: Apple Card Saving Account Not Showing Up on iPhone, iPad 
4 Key Trends from the Cloudflare 2023 Phishing Threats Report 
Molly Holzschlag, aka "mollydotcom", a longtime advocate for the open web and accessible, inclusive online design standards, died at 60 on S 
Chinese cyberspies obtained Microsoft signing key from Windows crash dump due to a mistake 
Star Citizen Error Code 30000: Causes and Solutions 
UNESCO report: overreliance on online learning during COVID-19 led to "staggering" education inequality and hindered discussion on equitable 
Staying ahead of threats: 5 cybercrime trends to watch 
Intelligence community to meet with civil liberties groups on controversial surveillance tool 
UK lawmakers back down on encryption-busting ‘spy clause’ 
94% of organizations don't have full visibility into service accounts 
Eight vulnerabilities in Open Automation Software Platform could lead to information disclosure, improper authentication 
A zero-day in Atlas VPN Linux Client leaks users’ IP address 
Crypto Wealth Report: 88,200 people have crypto worth $1M+, or <1% of all users, 182 have $100M+, and 22 have $1B+, of which six hold their investm 
Star Citizen Error Code 30013: Top Fixes and Solutions 
How to Fix Star Citizen Error Code 30012: Step-by-Step Guide 
Alert: Phishing Campaigns Deliver New SideTwist Backdoor and Agent Tesla Variant 
Cyber professionals say industry urgently needs to confront mental health crisis 
Crypto Wealth Report: 88,200 people have crypto worth $1M+, or <1% of all users, 182 have $100M+, and 22 have $1B+, of which six hold the funds in  
9 Alarming Vulnerabilities Uncovered in SEL's Power Management Products 
ASUS routers are affected by three critical remote code execution flaws 
Mozilla finds that 25 major car brands examined fail to adhere to the most basic privacy and security standards in their new internet-connected models 
Researchers identify high-grade phishing kits attacking nearly 60,000 Microsoft 365 accounts 
Mozilla finds that 25 of the major car brands it examined fail to adhere to the most basic privacy and security standards in their new internet-connec 
Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach 
71% of organizations are impacted by cybersecurity skills shortage 
Hackers stole $41M worth of crypto assets from crypto gambling firm Stake 
65% of organizations prioritize vulnerabilities based on risk 
Microsoft rolls out a new Xbox dashboard that lets users stream Xbox gameplay to anyone on Discord one-way, a new way to report Xbox audio clips, and  
Bilyana Lilly on Western cybersecurity assistance to Ukraine 
NSFOCUS Included in Gartner 2023 Hype Cycle for Smart City and Sustainability in China Report Again 
Key Cybersecurity Tools That Can Mitigate the Cost of a Breach 
Meta disrupted two influence campaigns from China and Russia 
Korean media report: Meta partnered with LG to launch a new Quest Pro in 2025 to compete with Apple's Vision Pro; Meta also plans a sub-$200 head 
Top 5 Ways to Fix Roblox Error KB4534310 [SOLVED] 
A massive DDoS attack took down the site of the German financial agency BaFin 
Report: Meta has partnered with LG to launch a new Quest Pro in 2025 to compete with Apple's Vision Pro; Meta also plans to release a sub-$200 he 
Report: Meta has partnered with LG to launch a new Quest Pro in 2025 to compete with Apple's Vision Pro; Meta plans to release a sub-$200 headset 
Xiaomi users report they found browser hacking malware on their phones - gizmochina 
X will collect biometric data from its premium users 
Xiaomi users report they found browser hacking malware on their ... - gizmochina 
“Smishing Triad” Targeted USPS and US Citizens for Data Theft 
Publicly available Evil_MinIO exploit used in attacks on MinIO Storage Systems 
The San Francisco Fire Department says two Cruise driverless taxis blocked an ambulance carrying a patient who later died at a hospital; Cruise denies 
Security Affairs newsletter Round 435 by Pierluigi Paganini International edition 
Ransomware and Data Breaches: Impacts Continue to Grow Louder 
Robo-Insight #4 
The SF Fire Department says two Cruise driverless taxis blocked an ambulance carrying a patient who later died at a hospital; Cruise claims it was not 
Report of Colombians hacking Facebook accounts in Yucat n - The Yucatan Times 
Child advocacy group Heat Initiative is starting a $2M US ad campaign calling on Apple to detect, report, and remove child sexual abuse materials from 
Social engineering attacks target Okta customers to achieve a highly privileged role 
A Media Matters for America report on PragerU Kids: Meta isn't consistently enforcing transparency rules for ads around "social issues, elec 
Norfolk Southern Says a Software Defect -- Not a Hacker -- Forced It to Park Its Trains This Week - U.S. News & World Report 
Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges 
Child advocacy group Heat Initiative is starting a $2M campaign calling on Apple to detect, report, and remove child sexual abuse materials from iClou 
Talos wars of customizations of the open-source info stealer SapphireStealer 
Norfolk Southern Says a Software Defect -- Not a Hacker -- Forced It ... - U.S. News & World Report 
NYC Subway Disables Trip-History Feature Over Tap-and-Go Privacy Concerns 
Why is .US Being Used to Phish So Many of Us? 
Malware top consumer threat from May to July 2023 
Researchers released a free decryptor for the Key Group ransomware 
CISA report: Russian cyber actors using Infamous Chisel malware 
North Korea-linked APT Labyrinth Chollima behind PyPI supply chain attacks 
Google Mandiant Adds Additional Cybersecurity Services Using AI 
Nisos Completes SOC 2 Type 2 Report 
Why is Ticketmaster Not Letting me Sign in? 6 Ways to Reset Password 
New SuperBear Trojan Emerges in Targeted Phishing Attack on South Korean Activists 
Classiscam Scam-as-a-Service Raked $64.5 Million During the COVID-19 Pandemic 
Fix Apple CarPlay Not Working in iOS 16.6 iPhone 
SentinelOne CEO Tomer Weingarten says the cybersecurity company is not for sale, following an August report claiming the company was looking to sell ( 
Threat-informed Defense Is Hard, So We Are Still Not Doing It! 
Russia-linked hackers target Ukrainian military with Infamous Chisel Android malware 
Dell reports Q2 revenue down 13% YoY to $22.9B, vs. $20.8B est., Client Solutions down 16% to $12.9B, Infrastructure Solutions down 11% to $8.5B; DELL 
New open-source infostealer, and reflections on 2023 so far 
LogicMonitor customers hacked in reported ransomware attacks - BleepingComputer 
Labor Day Alert: Mobile Phishing Attacks on the Rise for Remote Employees 
‘Five Eyes’ nations release technical details of Sandworm malware ‘Infamous Chisel’ 
Breaches Galore Means it s Time for Data-Centric Security 
Twitter, now X, will begin collecting users’ biometric data 
Akira Ransomware gang targets Cisco ASA without Multi-Factor Authentication 
Customers of Cryptocurrency FTX are Target of Phishing Emails 
13% of employees admit to falling for phishing attacks working at home 
Infamous Chisel Malware Analysis Report 
Numbers Don't Lie: Exposing the Harsh Truths of Cyberattacks in New Report 
Paramount Global disclosed a data breach 
Stockholm-based Klarna reports H1 2023 revenue up 15% YoY to $963M and a $185M adjusted loss, down from a $570M loss in H1 2022, as the company cut 
Sources: Apple plans to eliminate social media support adviser roles across X, YouTube, and the Apple Support Community website starting later in 2023 
Abusing Windows Container Isolation Framework to avoid detection by security products 
BMW ConnectedDrive Keeps Asking Password? Here’s How to Fix 
Sources: Apple plans to eliminate social media support adviser roles across X, YouTube, and the Apple Support Community website starting later this ye 
Hyperview Integrates RF Code Technology to Automate IT Asset Tracking 
Salesforce reports Q2 revenue up 11% YoY to $8.6B, vs. $8.53B est., $1.27B net income, and forecasts Q3 and FY 2024 earnings above expectations; CRM j 
CrowdStrike reports Q2 revenue up 37% YoY to $731.6M, vs. $724.2M est., ARR up 37% YoY to $2.93B, and forecasts Q3 and FY 2024 earnings above expectat 
CrowdStrike reports Q2 revenue up 37% YoY to $731.6M, vs. $724.2M est., ARR up 37% YoY to $2.93B, and forecasts Q3 and FY 2024 revenue above expectati 
Salesforce reports Q2 revenue up 11% YoY to $8.6B, vs. $8.53B est., and forecasts Q3 and FY 2024 revenue above expectations; CRM jumps 5%+ (Wallace Wi 
Chinese GREF APT distributes spyware via trojanized Signal and Telegram apps on Google Play and Samsung Galaxy stores 
58% of malicious emails contained spoof content 
Sift named a Leader in the 2023 Forrester Wave(TM) for Digital Fraud Management | Key report insights 
DOE launches cyber contest to benefit rural utilities 
Cyber defense makes up majority of cybersecurity budgets 
Data.ai and IDC project that consumers will spend $108B on mobile games in 2023, or 55% of game spending globally, $43B on consoles, and $40B on PC a 
Successful Hybrid Identity Deployments 
Threat actors started exploiting Juniper flaws shortly after PoC release 
Empire Dragon Accelerates Covert Information Operations, Converges with Russian Narratives 
Security leaders report need to balance human and machine identities 
Converging Narratives on Hawaii Wildfires Advance Different Influencers Objectives 
Hackers Exploiting Juniper RCE Flaw Following PoC Release 
Data.ai and IDC expect consumers to spend $108B on mobile games in 2023, or 55% of global spending on games, followed by $43B on consoles and $40B on  
Malicious npm Packages Aim to Target Developers for Source Code Theft 
Alert: Juniper Firewalls, Openfire, and Apache RocketMQ Under Attack from New Exploits 
Critical RCE flaw impacts VMware Aria Operations Networks 
Xiaomi reports Q2 revenue down 4% YoY to $9.25B and a $504M net profit, beating analyst estimates of $440.9M and more than doubling from a year ear 
Xiaomi reports Q2 revenue down 4% YoY to $9.25B and a net profit of $504M, vs. $440.9M est., more than doubling from a year earlier (Kosaku Narioka 
HP Q3: revenue down 10% YoY to $13.2B, vs. $13.4B est., Personal Systems revenue down 11% YoY to $8.9B, and Printing revenue down 7% YoY to $4.3B; HPQ 
UNC4841 threat actors hacked US government email servers exploiting Barracuda ESG flaw 
HPE reports Q3 revenue up 1% YoY to $7B, HPC & AI revenue up 1% YoY to $836M, Intelligent Edge revenue up 50% YoY to $1.4B, and bumps its FY 2023  
Microsoft joins a growing chorus of organizations criticizing a UN cybercrime treaty 
Bachelorette Contestant Josh Seiter Is Alive Despite Death Reports, Says Instagram Was Hacked in New Video - Variety 
Former Bachelorette contestant Josh Seiter says hacker posted false death report to Instagram - NBC News 
BTS Private Information Sold On Telegram By Indonesian Hacking Team. REPORT - Times Now 
US Says It Has Disrupted Notorious 'Qakbot' Hacking Network - U.S. News & World Report 
80% of organizations expect ransomware spending to increase 
Abnormal Security: Microsoft Tops List of Most-Impersonated Brands in Phishing Exploits 
Hackers infiltrated Japan s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) for months 
DarkGate Malware Activity Spikes as Developer Rents Out Malware to Affiliates 
Report Reveals Growing Disparity in Cyber Insurance Landscape 
Japan's cybersecurity agency breached by suspected Chinese hackers: report - The Record from Recorded Future News 
Study finds increase in cybersecurity attacks fueled by generative AI 
Meta: Pro-Chinese influence operation was the largest in history 
A look at Disney's shifting India strategy, after the unit reported a $41.5M loss on $390M revenue in the year to March 2022, including free cric 
What Are Executive Impersonation Attacks, and What Do They Look Like? 
FIN8-linked actor targets Citrix NetScaler systems 
Problems with DMARC RUF Reports and How We Fix Them 
Healthcare remains the top target of hackers, reports Cisco - Omnia Health Insights 
Japan’s JPCERT warns of new ‘MalDoc in PDF’ attack technique 
Attackers can discover IP address by sending a link over the Skype mobile app 
Presidential council recommends launching a Department of Water to confront cyberthreats, climate change 
Indonesian Hacking Operation Reported To Be Selling BTS's Private Information - Koreaboo 
Doc: Lenovo plans to unveil a &euro;799 Legion Go gaming handheld, with an 8.8" 144Hz 2560&times;1600 display and 16GB of RAM, and &e 
Document: Lenovo plans to unveil on September 1 a &euro;799 Legion Go gaming handheld, with an 8.8" 144Hz 2560&times;1600 display and 16G 
Black Hat USA 2023 NOC: Network Assurance 
Criminal hackers 'very likely' to pose threat to national security, economy in near term: report - CBC News 
Criminal hackers 'very likely' to pose threat to national security, economy in near term: report - CBC.ca 
Developers Beware: Malicious Rust Libraries Caught Transmitting OS Info to Telegram Channel 
Indonesian Hacking Operation Reported To Be Selling BTS's Private ... - Koreaboo 
Malign Narratives Oppose the Voice Ahead of Australia s Referendum 
Reply URL Flaw Allowed Unauthorized MS Power Platform API Access 
Rhysida ransomware group claims the hack of Prospect Medical 
Trends in Business Email Compromise 
Back To School Reminder – Keep Your Mac Clean! 
Updated Kmsdx botnet targets IoT devices 
Massive MOVEit campaign already impacted at least 1,000 organizations and 60 million individuals 
Malware Unleashed: Public Sector Hit in Sudden Surge, Reveals New Research 
How to Fix Facebook App that Won t Open, Doesn t Work on Your iPhone 
Fix: The Texas Chain Saw Massacre Controller Not Working (PS5) 
Poland’s authorities investigate a hacking attack on country’s railways 
Leaked LockBit 3.0 ransomware builder used by multiple threat actors 
Met police on high alert after IT system holding officers details hacked 
Poland Investigates Hacking Attack on State Railway Network - U.S. News & World Report 
FIA, police agencies using Israeli hacking tools since 2012: report - Colombo Gazette 
Top 10 Ways to Fix MovieBox Pro Videos Not Loading on Chrome 
Cisco Talos Research: New Lazarus Group Attack Malware Campaign Hits UK & US Businesses 
E-commerce marketing company Klaviyo files for a US IPO and reports H1 2023 revenue of $321M, vs. $208M YoY, and $15.2M net income, vs. a $24.6M net 
API Abuse Lessons from the Duolingo Data Scraping Attack 
E-commerce marketing platform Klaviyo files for a US IPO and reports H1 2023 revenue of $321M, vs. $208M YoY, and net income of $15.2M, vs. a loss of  
There was a 387% increase in attack activity from Q1 to Q2 2023 
Instacart files for a US IPO, reports 2022 revenue up 39% YoY to $2.55B, $428M net income, up from a $73M loss in 2021, and H1 2023 revenue up 31% YoY 
What to Do If Your Instagram Account Gets Hacked - Consumer Reports 
32% of security leaders struggle with prioritizing improvements 
Instacart files for a US IPO, set for September; the company was valued at $39B in 2021 but has repeatedly reset its valuation, most recently to a rep 
Adversary On The Defense: ANTIBOT.PW 
The US Treasury proposes new rules that would treat crypto exchanges more like stockbrokers, requiring them to report gross proceeds to the IRS starti 
China-linked Flax Typhoon APT targets Taiwan 
US Treasury proposes new rules treating crypto exchanges more like stockbrokers, requiring them to report crypto gains to the IRS, starting in 2026 (W 
Why are CEOs Cyber Resilient? 
Demystifying Duo APIs: Advanced Security with Duo Integrations 
Akira Ransomware Targeting VPNs without Multi-Factor Authentication 
Whiffy Recon malware triangulates the position of infected systems via Wi-Fi 
TransUnion Report Highlights Increasing Risk from Synthetic Identity Fraud 
Ransomware Surges in Nuspire s Q2 2023 Threat Report 
Microsoft says Chinese hacking crew is targeting Taiwan 
Affirm reports Q4 revenue up 22% YoY to $446M, vs. $406M est., net loss up 11% YoY to $206M, and GMV up 25% YoY to $5.5B, vs. $5.3B est.; AFRM jumps 5 
IT leaders report concern over generative AI in SaaS applications 
Years into these games histories, attackers are still creating Fortnite and Roblox -related scams 
Lazarus APT exploits Zoho ManageEngine flaw to target an Internet backbone infrastructure provider 
OnlyFans reports revenue up 17% YoY to $1.1B in the FY to November 30, 2022, profit up 24% YoY to $404M, creators up 47% YoY to 3.2M, and users spent  
OnlyFans reports revenue up 17% YoY to $1.1B in the FY to November 30, 2022, profit up 24% YoY to $404M, creators up 47% to 3.2M, and users spent $5. 
Sources: Vietnamese internet company VNG aims to raise $150M in a US IPO and targets a debut by the end of September; VNG reported $166.3M in H1 2023 
Hugging Face confirms raising a $235M Series D from Salesforce, Google, Amazon, Nvidia, Intel, AMD, Qualcomm, and others, bringing its total funding t 
Hugging Face confirms raising a $235M Series D from Salesforce, Google, Amazon, Nvidia, Intel, AMD, Qualcomm, and others, bringing its total raised to 
Armored Core 6 Freezing, Lagging, Stuttering: Fix it Easily [11 Methods] 
Malicious web application transactions increased by 500% in 2023 
Hugging Face confirms it raised a $235M Series D from Salesforce, Google, Amazon, Nvidia, Intel, AMD, Qualcomm, and others, bringing its total raised  
Behind the eight-ball: Why companies struggle with penetration risk 
Armored Core 6 Stuck on Loading Screen: 10 Quick Ways to Fix 
Social Security Numbers were exposed in 69% of breaches in 2023 
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT 
Lazarus Group's infrastructure reuse leads to discovery of new malware 
91% of security pros say cybercriminals are using AI in email attacks 
Bangladeshi hacker group targeting these sectors in India, claims report - Times of India 
Sources: Vietnamese internet company VNG aims to raise $150M in its US IPO and targets a debut at the end of September; VNG reported $166.3M in H1 20 
Thousands of Unpatched Openfire XMPP Servers Still Exposed to High-Severity Flaw 
Lapsus$ member has been convicted of having hacked multiple high-profile companies 
Attack Dwell Times Fall but Threat Actors Are Moving Faster 
More than 3,000 Openfire servers exposed to attacks using a new exploit 
Snowflake reports Q2 revenue up 36% YoY to $674M, vs. $662M est., net loss up 2% YoY to $227M, and projects Q3 product revenue of $670M to $675M, vs.  
Snowflake reports Q2 revenue up 36% YoY to $674M vs. $662M est., net loss of $227M vs. $223M in Q2 2022, and forecasts Q3 product revenue in line with 
Nvidia reports Q2 revenue up 101% YoY to $13.51B, vs. $11.22B est., Data Center revenue up 171% YoY to $10.32B, and authorizes a $25B buyback; NVDA ju 
Data Breaches Involving Social Engineering Attacks Take Longer to Identify and Contain 
Security leaders report misalignment of investments and risk reduction 
Three vulnerabilities in NVIDIA graphics driver could cause memory corruption 
Ransomware Attacks Rise 69% and 1500 Organizations Feel the Hurt 
Enterprises Eyeing More Proactive Cybersecurity Strategies, Survey Finds 
Artificial Intelligence and USBs Drive 8% Rise in Cyber-Attacks 
Healthcare delivery organizations report concern over malware 
HP Report Details Tactics Used to Evade Detection Tools 
Atomic Wallet faces lawsuit over $100M crypto hack losses: Report - Cointelegraph 
Scammers Impersonate the Australian Tax Office 
Bruce Schneier gets inside the hacker’s mind 
Report reveals insights on cybersecurity conversations with children 
Syrian Threat Actor EVLF Unmasked as Creator of CypherRAT and CraxsRAT Android Malware 
Barracuda Networks Report Details Benefits of Cybersecurity AI 
A Hacker s Dozen: 11 New Security Vulns Reported in IBM i - IT Jungle 
Tech advocacy groups press FTC to investigate Google for alleged children’s privacy violations 
Carderbee APT targets Hong Kong orgs via supply chain attacks 
Cybersecurity risks found in browser extensions 
What is Cyber Asset and Attack Surface Management? 
Defense contractor Belcan leaks admin password with a list of flaws 
Akira ransomware gang spotted targeting Cisco VPN products to hack organizations 
Critical Insight Report: 15% Drop in Breaches, 31% Surge in Victims 
How to Fix Huuuge Casino Error Code 229 
Report: North Korean Hackers Stolen $200M So Far in 2023 - Yahoo Finance 
Baidu reports Q2 revenue up 15% YoY to $4.7B, vs. $4.6B est., and net income up 43% YoY to $714M, and awaits Beijing's approval to roll out it 
Press Release: The Cyber Hut Release Report on ITDR 
Understanding the Fragility of Digital Identities 
New NCUA Rule Requires Credit Unions to Report Cyberattacks Within 3 Days 
Baidu reports Q2 revenue up 15% YoY to $4.7B, beating $4.6B est., and net income up 43% YoY to $714M, as China boosts its private sector; BIDU rise 
CISOs Tout SaaS Cybersecurity Confidence, But 79% Admit to SaaS Incidents, New Report Finds 
Previously unknown hacking group targets Hong Kong organizations in supply chain cyberattack 
How to Fix Product Activation Failed in Office 2019 [6 Working Ways] 
Report suggests roughly 50% of Pok mon VGC teams were hacked - GoNintendo 
SoftBank's Arm files to list on the Nasdaq and reports $524M net income on $2.68B in FY 2023 revenue, down 1% YoY from $2.7B; the company wants t 
Triller's S-1 filing claims the short-form video app has had 550M lifetime signups, but Apptopia estimates the app has had 73.2M downloads since  
Zoom Q2: revenue up 3.6% YoY to $1.14B, vs. $1.12B est., net income up 298% YoY to $182M, enterprise customers up 1% QoQ to 218.1K, and raises FY 202 
Ivanti Issues Fix for Critical Vuln In Its Sentry Gateway Technology 
Customer data used for unwanted romantic contact, UK poll shows 
Akamai Report: LockBit, Cl0P Expand Ransomware Efforts 
Filing: SoftBank's Arm files to list on Nasdaq and reports $524M in net income on $2.68B in revenue in its fiscal 2023, with sales slightly down  
Zoom reports Q2 revenue up 3.6% YoY to $1.14B, vs. $1.12B est., net income of $182M, up from $46M YoY, and raises its FY 2024 guidance; ZM jumps 5%+ ( 
Triller's S-1 filing claims the short-form video app has had 550M signups, but Apptopia estimates it has been downloaded just 73.2M times since i 
Tesla Data Breach Investigation Reveals Inside Job 
Detecting malware cited as a challenge for organizations 
Report: before tweeting a pro-Russia Ukraine peace plan, Elon Musk said he had Kremlin consultations; he also told the US of a Putin call but publicly 
New HiatusRAT campaign targets Taiwan and U.S. military procurement system 
Top 8 Ways Fix Immortals of Aveum Low FPS Issues 
White House Announces AI Cybersecurity Challenge 
41% of organizations said they can enforce consistent access policies 
[Eye-Opening] Increase of Phishing Attacks in Australia Should Alarm Organizations 
New report shows mobile devices are the top endpoint choice for SLED 
US Space Industry Under Threat from Foreign Cyber Espionage 
Immortals of Aveum Won t Launch On PC: Quick Ways to Fix 
Homeland Security Report Details How Teen Hackers Exploited ... - Slashdot 
Hacking conference evacuated after reports of a suspicious package - Las Vegas Review-Journal 
Exposing a Currently Active Personally Identifiable Cybercriminals XMPP Jabber Account IDs Portfolio 
North Korean Hackers Stole $180M in First 6 Months of 2023: Report - CryptoPotato 
Homeland Security report details how teen hackers exploited ... - CNN 
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection 
N. Korean Kimsuky APT targets S. Korea-US military exercises 
Vulnerability Summary for the Week of July 10, 2023 
US Cyber Command publishes concept for integrating new capabilities 
Biden signs memorandum to secure sensitive national security systems 
DoD must focus on skilled cyber defenders, not just new tech, warns weapons tester 
Demilitarize civilian cyber defense, and you ll gain deterrence 
Russia and China devote more cyber forces to offensive operations than US, says new report 
DoD needs to improve how it tests cyber weapons architecture, weapons tester says 
Experts urge caution in assessing Ukraine cyberattacks 
European Union cyber defense team deploys to aid Ukraine 
New US sanctions target Russia s multibillion-dollar defense sector 
New InsightCloudSec Compliance Pack for CIS AWS Benchmark 2.0.0 
The Mystery of Chernobyl s Post-Invasion Radiation Spikes 
Themes and Failures of Russia s War Against Ukraine 
In Before The Lock: ESXi 
Black History Month: ERG Employee Stories, Impact, Community & Celebration 
CVE-2022-39952: Pre-authentication Code-execution Vulnerability 
2022 Annual Report 
Russia s War Against Ukraine Disrupts the Cybercriminal Ecosystem 
IRS Cyberattack Highlights Risk of Tax Refund Fraud 
On Ukraine, China Prioritizes Its International Ambitions 
Introducing the Intelligence to Risk Pyramid 
With KEYPLUG, China s RedGolf Spies On, Steals From Wide Field of Targets 
Russian Sanctions Evasion Puts Merchants and Banks at Risk 
The Cloud Has Complicated Attack Surface Management 
What is Threat Intelligence? 
Joker DPR and the Information War 
Introducing Recorded Future AI: AI-driven intelligence to elevate your security defenses 
Xiaoqiying Genesis Day Threat Actor Group Targets South Korea, Taiwan 
News & Intelligence When You Need It Now on Our Mobile App 
Recorded Future News Recap: The Biggest Stories Coming Out of RSAC 2023 
From Speed to Consistency: The Power of Automation for Your SOC 
Latin America's Second "Pink Tide" Opens Avenues for Iranian Influence 
OilAlpha: A Likely Pro-Houthi Group Targeting Entities Across the Arabian Peninsula 
Attack Surface Intelligence: A Vital Piece of the Critical Infrastructure Protection Puzzle 
Private Eyes: China s Embrace of Open-Source Military Intelligence 
APIDA Heritage Month: ERG Employee Stories, Community, and Support 
I Have No Mouth, and I Must Do Crime 
Ransomware Is Changing: Why Threat Intelligence is Essential 
North Korea-Aligned TAG-71 Spoofs Financial Institutions in Asia and US 
Fortinet CVE-2023-27997: Impact and Mitigation Techniques 
North Korea s Cyber Strategy 
The Escalating Global Risk Environment for Submarine Cables 
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities 
Recorded Future Threat Intelligence Delivers Measurable Outcomes for Security Teams 
Threat Intelligence to Elevate Your Security Defenses 
BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware 
China's Targeting of International Companies in Geopolitical Competition 
Reducing Operational Risk with Threat Intelligence 
Putin s Potential Successors Part 2: Aleksey Dyumin 
Threat Actors Leverage Internet Services to Enhance Data Theft and Weaken Security Defenses 
RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale 
BlueCharlie, Previously Tracked as TAG-53, Continues to Deploy New Infrastructure in 2023 
H1 2023: Ransomware's Pivot to Linux and Vulnerable Drivers 
Talking with Stewart Baker 
A Skeleton Key of Unknown Strength 
Hacking the Universe with Quantum Encraption 
Electoral Chaos 
Organizations concerned about enterprise security from unsafe VPNs 
Financial sector saw an 80% increase in interactive intrusions 
Large-user applications vulnerable to dependency confusion attacks 
Q2 of 2023 saw a rise in spam calls featuring family impersonations 
77% of financial firms saw an increase in cyberattack frequency 
The rise in e-commerce forces retailers to adjust IT procedures 
67% of government agencies claim confidence in adopting zero trust 
Report finds exposed sensitive data in more than 30% of cloud assets 
70% of web applications have severe security gaps 
Over 74% of organizations see a rise in AI use by cybercriminals 
Synthetic identity fraud fastest growing financial crime in U.S. 
New Statc Stealer Malware Emerges: Your Sensitive Data at Risk 
Malware Unleashed: Public Sector Hit in Sudden Surge, Reveals New Report 
Critical Security Flaws Affect Ivanti Avalanche, Threatening 30,000 Organizations 
What's the State of Credential theft in 2023? 
Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks 
Zacks - 8,929,503 breached accounts 
Manipulated Caiman - 39,901,389 breached accounts 
Robot Talk Episode 44 – Kat Thiel 
Robot assistants in the operating room promise safer surgery 
Drones navigate unseen environments with liquid neural networks 
India’s robot boom hits all-time high 
[UPDATE] A list of resources, articles, and opinion pieces relating to large language models & robotics 
Automate 2023 recap and the receding horizon problem 
Flowstate: Intrinsic s app to simplify the creation of robotics applications 
July 2023 Patch Tuesday: Six Actively Exploited Zero-Days and Nine Critical Vulnerabilities Identified 
How to Augment or Replace Your SIEM with the CrowdStrike Falcon Platform 
Why Customers Are Consolidating Cybersecurity with CrowdStrike 
Adversaries Can Log In with Microsoft through the nOAuth Azure Active Directory Vulnerability 
CrowdStrike Expands XDR Ecosystem to Give Customers a Data Advantage 
CrowdStrike Named a Leader that Delivers World-Class Threat Intelligence in 2023 Forrester Wave 
Prevention Is the Best Preparation for the SEC s New Breach Disclosure Rules 
CrowdStrike Scores 100% in SE Labs Q2 2023 Enterprise Advanced Security Detection Test, Wins AAA Award 
ESET APT Activity Report Q4&nbsp;2022 Q1 2023 
Key findings from ESET's new APT Activity Report Week in security with Tony Anscombe 
ESET Threat Report H1 2023 
Key findings from ESET Threat Report H1 2023 Week in security with Tony Anscombe 
APT29 is targeting Ministries of Foreign Affairs of NATO-aligned countries 
Bronze Starlight targets the Southeast Asian gambling sector 
WinRAR flaw enables remote code execution of arbitrary code 
#OpFukushima: Anonymous group protests against the plan to dump Fukushima RADIOACTIVE wastewater into Pacific 
Africa Cyber Surge II law enforcement operation has led to the arrest of 14 suspects 
Massive phishing campaign targets users of the Zimbra Collaboration email server 
Over 3,000 Android Malware spotted using unsupported unknown compression methods to avoid detection 
Four Juniper Junos OS flaws can be chained to remotely hack devices 
Smuggler - An HTTP Request Smuggling Desync Testing Tool 
How SSPM Simplifies Your SOC2 SaaS Security Posture Audit 
Ransomware Surges With 1500 Confirmed Victims This Year 
Cybersecurity Study Reveals Web App Vulnerability Crisis 
Ransomware attacks cost manufacturing sector $46 billion in downtime since 2018, report claims 
How to write a killer pentest report 
LinkedIn Suffers 'Significant' Wave of Account Hacks 
Confusion Surrounds SEC's New Cybersecurity Material Rule 
Bugcrowd Unleashes Hacker Ingenuity for Proactive, Crowdsourced Security 
Who and What is Behind the Malware Proxy Service SocksEscort? 
LeakedSource Owner Quit Ashley Madison a Month Before 2015 Hack 
Few Fortune 100 Firms List Security Pros in Their Executive Ranks 
Russia Sends Cybersecurity CEO to Jail for 14 Years 
How Malicious Android Apps Slip Into Disguise 
Teach a Man to Phish and He’s Set for Life 
Pegasus Spyware Explained: Biggest Questions Answered 
What do you mean by Crypto Jacking? 
U.S. State Department and Diplomat’s iPhones were Reportedly Hacked by Pegasus Spyware 
This New Apple Safari Browser Bug Allows Cross-Site User Tracking 
Two Zero-Day Bugs Reported in Zoom Clients and MMR Servers Details Google 
Apple Sacks it’s Server Supplier After Finding Infected Firmware in Siri Servers 
List of Secure Dark Web Email Providers in 2023 
Release 2015-05-13: New report layout and large changes under the hood 
Release: New report view and verification through Google Tag Manager 
Release: Improved PDF report and new WordPress vulnerabilities 
GUIDE: The false positive report process 
Release – Now available to accept risks for future reports 
Meet the Hacker: Peter Jaric, Software Developer: I got two board games for the first bug I reported  
Fix Hogwarts Legacy Missing Component Error on Epic Games 
10 Quick Ways to Fix Baldur s Gate 3 Stuck on Loading Screen 
Baldur s Gate 3 High Ping Issues: 9 Ways to Fix it Quickly 
APT trends report Q2 2023 
Ransomware Distributed by Fake Tripadvisor Reviews 
Ransomware's Paradox: Why Falling Monetization Rates Are Accompanied by Soaring Ransom Payments - A Must-Read Analysis. 
Ransomware Attacks Surge as Generative AI Becomes a Commodity Tool in the Threat Actor s Arsenal 
[Must Know] Cybercriminals May Already Have Hacked Your LinkedIn Account. How To Secure. 
Bloomberg Reports: Stealth QR Code Phishing Attack On Major US Energy Company 
North Korean hackers have stolen $2B of crypto since 2018: Report - Cointelegraph 
Every company has its own version of ChatGPT now 
Incident Response trends Q2 2023: Data theft extortion rises, while healthcare is still most-targeted vertical 
The many vulnerabilities Talos discovered in SOHO and industrial wireless routers post-VPNFilter 
Previewing Talos at BlackHat 2023 
Half-Year in Review: Recapping the top threats and security trends so far in 2023 
What is commercial spyware? 
What Cisco Talos knows about the Rhysida ransomware 
Recapping the top stories from Black Hat and DEF CON 
Out-of-bounds write vulnerabilities in popular chemistry software; Foxit PDF Reader issues could lead to remote code execution 
Reflecting on supply chain attacks halfway through 2023 
At Least 4 New Reasons Every Day To Check Your Email Security Stack 
You ve Got Malware: The Rise of Threat Actors Using Microsoft OneNote for Malicious Campaigns 
ThreatIngestor Release v1.0.2 
Shifting Left in Cyber Security - Part 1 
100 Days of YARA: Everything You Need to Know 
Shifting Left in Cybersecurity: Balancing Detection and Prevention - Part 2 
Mystic Stealer: The New Kid on the Block 
Data centers at risk due to flaws in power management software 
White House hosts roundtable on harmful data broker practices 
Feds to hackers in Vegas: Help us, you’re our only hope 
Fifty minutes to hack ChatGPT: Inside the DEF CON competition to break AI 
Two dozen arrested, hundreds of malicious IPs taken down in African cybercrime operation 
Senators urge FTC probe of alleged children’s privacy violations by Google 
 
Forum
Attacks



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.