Tag: data
-
Hackers Exploited Windows Event Logs Tool log Manipulation, And Data Exfiltration
wevtutil.exe, a Windows Event Log management tool, can be abused for LOLBAS attacks. By manipulating its capabilities, attackers can execute arbitrary commands, download malicious payloads, and establish persistence, all while evading traditional security measures. It is a Windows tool for event log management that can be exploited by attackers to manipulate system logs, potentially concealing…
-
FTC bans two data brokers from collecting and selling Americans’ sensitive location data
US-based Gravy Analytics and Mobilewalla must also delete historic data collected on millions of Americans. First seen on techcrunch.com Jump to article: techcrunch.com/2024/12/03/ftc-bans-two-data-brokers-from-collecting-and-selling-americans-sensitive-location-data/
-
‘White FAANG’ Data Export Attack: A Gold Mine for PII Threats
Websites these days know everything about you, even some details you might not realize. Hackers can take advantage of that with a sharp-toothed attack that exploits Europe’s GDPR-mandated data portability rules. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/white-faang-data-export-attack-pii-threats
-
SmokeLoader picks up ancient MS Office bugs to pack fresh credential stealer
Threat actors are using a well-known modular malware loader, SmokeLoader, to exploit known Microsoft Office vulnerabilities and steal sensitive browser credentials.The loader which runs a framework to deploy multiple malware modules, was observed by Fortinet’s FortiGuard Labs in attacks targeting manufacturing, healthcare, and IT companies in Taiwan.”SmokeLoader, known for its ability to deliver other malicious…
-
Top US Consumer Watchdog Has a Plan to Fight Predatory Data Brokers
A new proposal by the Consumer Financial Protection Bureau would use a 54-year-old privacy law to impose new oversight of the data broker industry. But first, the agency must survive Elon Musk. First seen on wired.com Jump to article: www.wired.com/story/cfpb-fcra-data-broker-oversight/
-
Discover the future of Linux security
Explore open source strategies to safeguard critical systems and data First seen on theregister.com Jump to article: www.theregister.com/2024/12/02/discover_the_future_of_linux/
-
Threat Actors Allegedly Claims Breach of EazyDiner Reservation Platform
Reports have emerged of a potential data breach involving EazyDiner, a leading restaurant reservation platform. Alleged by a tweet from DailyDarkWeb, the breach is said to have compromised sensitive user data, including names, email addresses, phone numbers, and reservation details. This incident has raised significant alarm over the security and privacy measures in place to…
-
EU enacts new laws to strengthen cybersecurity defenses and coordination
Tags: ai, compliance, cyber, cybersecurity, data, defense, framework, healthcare, infrastructure, law, network, penetration-testing, privacy, regulation, risk, service, soc, technology, threat, vulnerabilityThe European Union has enacted two new laws to bolster its cybersecurity defenses and coordination mechanisms. The measures, part of the cybersecurity legislative package, include the Cyber Solidarity Act and amendments to the Cybersecurity Act (CSA).These steps aim to improve the EU’s ability to detect, prepare for, and respond to cyber threats while fostering uniformity…
-
CFPB proposes new rule to regulate expansive data broker industry
In an era where personal data is increasingly commodified, the Consumer Financial Protection Bureau (CFPB) is attempting to regulate the sprawling industry of data brokers. A newly proposed rule released Tuesday aims to put data brokers in line with the Fair Credit Reporting Act (FCRA), ensuring accountability and consumer privacy amid widespread security issues. Initially…
-
US agency proposes new rule blocking data brokers from selling Americans’ sensitive personal data
The U.S. consumer protection agency said it’s closing the loophole to block the “widespread evasion” of federal law by data brokers. First seen on techcrunch.com Jump to article: techcrunch.com/2024/12/03/us-agency-proposes-new-rule-blocking-data-brokers-from-selling-americans-sensitive-personal-data/
-
US government, energy sector contractor hit by ransomware
ENGlobal, a Texas-based engineering and automation contractor for companies in the energy sector, has had its data encrypted by attackers. >>On November 25, 2024, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/12/03/englobal-ransomware-attack/
-
Salesforce Applications Vulnerability Could Allow Full Account Takeover
A critical vulnerability has been discovered in Salesforce applications that could potentially allow a full account takeover. The vulnerability, uncovered during a penetration testing exercise, hinges on misconfigurations within Salesforce Communities, particularly exploiting the Salesforce Lightning component framework. The implications of this vulnerability are severe, affecting both data security and privacy. Attackers could gain access…
-
Thales stellt seine Data Risk Intelligence-Lösung vor
In der modernen digitalen Landschaft stehen Unternehmen vor der Herausforderung, die Sicherheit über eine ständig wachsende Angriffsfläche zu verwalten und gleichzeitig die Einhaltung gesetzlicher Standards zu gewährleisten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/thales-stellt-seine-data-risk-intelligence-loesung-vor/a39121/
-
CIO POV: Building trust in cyberspace
Tags: access, ai, attack, best-practice, business, cio, cisa, cloud, cyber, data, deep-fake, encryption, framework, GDPR, group, identity, infrastructure, intelligence, Internet, mfa, mitre, nist, privacy, regulation, resilience, risk, service, software, strategy, technology, threat, tool, update, windowsTrust lies at the heart of every relationship, transaction, and encounter. Yet in cyberspace”, where we work, live, learn, and play”, trust can become elusive.Since the dawn of the internet nearly 50 years ago, we’ve witnessed incredible digital transformations paired with increasingly formidable threats. Knowing who and what to trust has become so difficult that…
-
Data on 760K workers from Xerox, Nokia, BofA, Morgan Stanley and more dumped online
Yet another result of the MOVEit mess First seen on theregister.com Jump to article: www.theregister.com/2024/12/03/760k_xerox_nokia_bofa_morgan/
-
Why identity security is your best companion for uncharted compliance challenges
Tags: access, ai, attack, authentication, automation, business, cloud, compliance, control, cyberattack, cybersecurity, data, detection, exploit, finance, framework, GDPR, governance, government, healthcare, HIPAA, identity, india, law, least-privilege, mitigation, monitoring, privacy, regulation, risk, risk-management, service, strategy, supply-chain, technology, threat, tool, zero-trustIn today’s rapidly evolving global regulatory landscape, new technologies, environments, and threats are heightening cybersecurity and data privacy concerns. In the last year, governing bodies have taken significant steps to enact stricter compliance measures”, and more than ever, they are focusing on identity-related threats.Some notable changes include: The National Institute of Standards and Technology (NIST)…
-
Hundreds of UK Ministry of Defence passwords found circulating on the dark web
Tags: 2fa, access, attack, authentication, banking, breach, credentials, cyber, cybercrime, cybersecurity, dark-web, data, data-breach, email, government, hacker, intelligence, iraq, login, malware, mfa, password, phishing, risk, russia, theft, warfareThe login credentials of nearly 600 employees accessing a key British Ministry of Defence (MOD) employee portal have been discovered circulating on the dark web in the last four years, it has been reported.According to the i news site, the stolen credentials were for the MOD’s Defence Gateway website, a non-classified portal used by employees…
-
Cyber Incidents Hit 3 NHS Hospitals in U.K.
Inc Ransom is Leaking Stolen Data in At Least 2 Attacks, Including Pediatric Info. At least three United Kingdom National Health Service hospitals are responding to recent cyber incidents, including a children’s hospital and a heart and chest specialty hospital are both located in Liverpool and share IT systems. Inc Ransom claims to have stolen…
-
RansomHub attack compromises Bologna FC data
First seen on scworld.com Jump to article: www.scworld.com/brief/ransomhub-attack-compromises-bologna-fc-data
-
More than 600K sensitive records leaked by data broker
First seen on scworld.com Jump to article: www.scworld.com/brief/more-than-600k-sensitive-records-leaked-by-data-broker
-
Data Breaches in the USA in November 2024: 5,266,320 People Impacted
Analyzing the Maine Attorney General’s data For November 2024, IT Governance USA’s analysis of the Office of the Maine Attorney General’s data breach notifications found the following: We look at what’s reported to a regulator to help us identify significant real-world trends and patterns. We chose the Office of the Maine Attorney General as this…
-
Submarine cable resilience board announced on same day maybe-cut-by-China Baltic cable repaired
ITU thinks time is now for more talk about how to keep data moving beneath the waves First seen on theregister.com Jump to article: www.theregister.com/2024/12/02/cable_advisory_board/
-
New CleverSoar Malware Attacking Windows Users Bypassing Security Mechanisms
CleverSoar, a new malware installer, targets Chinese and Vietnamese users to deploy advanced tools like Winos4.0 and Nidhogg rootkit. These tools enable keylogging, data theft, security circumvention, and stealthy system control for potential long-term espionage. It was initially uploaded to VirusTotal in July 2024 and began distribution in November 2024 as an .msi installer, extracting…
-
Will arresting the National Public Data threat actor make a difference?
The arrest of USDoD, the mastermind behind the colossal National Public Data breach, was a victory for law enforcement. It also raises some fundamental questions. Do arrests and takedowns truly deter cyberattacks? Or do they merely mark the end of… First seen on securityintelligence.com Jump to article: securityintelligence.com/news/will-arresting-the-national-public-data-threat-actor-make-a-difference/
-
How AI Is Enhancing Security in Ridesharing
Whether it’s detecting fraudulent activity, preventing phishing, or protecting sensitive data, AI is transforming cybersecurity in ridesharing. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/ai-enhancing-ridesharing-security
-
AWS launches tools to tackle evolving cloud security threats
The increasing sophistication and scale of cyber threats pose a growing challenge for enterprises managing complex cloud environments. Security teams often face overwhelming volumes of alerts, fragmented workflows, and limited tools to identify and respond to attack patterns spanning multiple events.Amazon Web Services (AWS) is addressing these challenges with two significant updates to its cloud…

