Tag: government
-
US Soldier Intends to Admit Hacking 15 Telecom Carriers
The federal government views the defendant as a flight risk and danger to the community due to his ability to access sensitive and private information. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/us-soldier-admits-hacking-15-telecom-carriers
-
Critical infrastructure at state, local levels at heightened risk of cyberattacks
State and local governments need additional resources, shared intelligence and coordination, an MS-ISAC report showed. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-state-local-cyber/741273/
-
German government denies foreign election interference was successful
The recent federal election in Germany “was not manipulated by foreign actors,” a government spokesperson said, following comments by a Bundestag member. First seen on therecord.media Jump to article: therecord.media/german-government-denies-election-interference-successful
-
Over 350 High-Profile Websites Hit by 360XSS Attack
360XSS campaign exploits Krpano XSS to hijack search results & distribute spam ads on 350+ sites, including government,… First seen on hackread.com Jump to article: hackread.com/over-350-high-profile-websites-hit-by-360xss-attack/
-
Hacktivist Groups Emerge With Powerful Tools for Large-Scale Cyber Operations
Hacktivism, once synonymous with symbolic website defacements and distributed denial-of-service (DDoS) attacks, has evolved into a sophisticated tool for cyber warfare and influence operations. Recent research highlights how state-sponsored actors are increasingly leveraging hacktivist tactics to conduct large-scale cyber campaigns, blurring the lines between grassroots activism and government-directed operations. These groups, often cloaked in anonymity…
-
The biggest data breaches of 2025, so far
School student records. Federal government data. Health records and more. Expect an unprecedented year for data breaches. First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/28/the-biggest-data-breaches-of-2025-so-far/
-
UK silence over Apple ‘back door’ is unsustainable and unjustifiable, say experts
Britain’s government risks its domestic and international standing as it refuses to either confirm or deny any details about a legal notice targeting Apple’s cryptographic protections for iCloud accounts, experts tell Recorded Future News. First seen on therecord.media Jump to article: therecord.media/apple-uk-back-door-request-privacy-security-experts
-
Gabbard Decries Britain’s Reported Demand for Apple to Provide Backdoor Access to Users’ Cloud Data
The Director of National Intelligence said such a demand would violate Americans’ rights and raise concerns about a foreign government pressuring a U.S.-based technology company. The post Gabbard Decries Britain’s Reported Demand for Apple to Provide Backdoor Access to Users’ Cloud Data appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/gabbard-decries-britains-reported-demand-for-apple-to-provide-backdoor-access-to-users-cloud-data/
-
CISA Appoints Karen Evans as New Cybersecurity Executive Assistant Director
Karen Evans has been appointed as the new Executive Assistant Director (EAD) for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA). In this new role, Evans brings an extensive portfolio of experience spanning decades in federal cyber policy, critical infrastructure protection, and government IT modernization. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/karen-evans-new-executive-assistant-director/
-
What is zero trust? The security model for a distributed and risky era
Tags: access, ai, authentication, best-practice, breach, business, ceo, cloud, compliance, computer, computing, control, corporate, credentials, cyberattack, data, detection, framework, government, guide, identity, infrastructure, intelligence, jobs, login, monitoring, network, nist, office, password, ransomware, regulation, risk, saas, service, technology, threat, tool, vpn, zero-trustHow zero trust works: To visualize how zero trust works, consider a simple case: a user accessing a shared web application. Under traditional security rules, if a user was on a corporate network, either because they were in the office or connected via a VPN, they could simply click the application and access it; because…
-
New White House Plan to Track Spending Raises Cyber Risks
Trump’s Procurement Tracking Directive Could Expose Vast Government Data to Threats. The White House is mandating federal agencies to track and justify every procurement, a move aimed at transparency but one that experts warn could expose troves of sensitive financial data to hacking, nation-state cyber threats and potential supply chain vulnerabilities across government systems. First…
-
2,850+ Ivanti Connect Secure Devices Exposed to Potential Cyberattacks
Tags: cyber, cyberattack, cybersecurity, data-breach, exploit, flaw, government, infrastructure, ivanti, network, risk, vpn, vulnerabilityA sweeping cybersecurity alert has emerged as researchers identify 2,850+ unpatched Ivanti Connect Secure devices worldwide, leaving organizations vulnerable to exploitation through the critical flaw designated CVE-2025-22467. The findings, published by cybersecurity watchdog Shadowserver Foundation, reveal systemic risks to virtual private network (VPN) infrastructures relied upon by enterprises and government agencies for secure remote access. Vulnerability Scope and…
-
Geopolitical tensions fuel surge in OT and ICS cyberattacks
New Russian group focused on Ukraine: The second new group to launch attack campaigns against industrial organizations last year, dubbed GRAPHITE, has overlaps with APT28 activities. Also known as Fancy Bear or Pawn Storm, APT28 is believed to be a unit inside Russia’s General Staff Main Intelligence Directorate (GRU).GRAPHITE launched constant phishing campaigns against hydroelectric,…
-
Elon Musk’s Federal Worker Email Sparks ‘Security Nightmare’
Federal Agencies and Experts Alike Say Musk’s Email Request Poses Security Threat. The Department of Government Efficiency-led effort to assess whether millions of federal jobs are necessary through a bulleted list of weekly activities is causing a major security threat, in addition to mass confusion across the federal government, experts told Information Security Media Group.…
-
UK Delays Plans for AI Regulation
Some Lawmakers Fear Regulation Could Stymie Innovation. The British Labour Government has reportedly delayed plans to put forward a draft bill on artificial intelligence over concerns that binding AI regulation could stifle the country’s AI growth potential. A spokesperson said the government remains committed to bringing forward a legislation. First seen on govinfosecurity.com Jump to…
-
Russian officials warn of potential compromise of major tech services provider
In an unusual public disclosure, the Russian government said that subsidiaries of LANIT, a major tech services provider, had potentially been breached. First seen on therecord.media Jump to article: therecord.media/lanit-russia-government-contractor-potential-compromise
-
DOGE must halt all ‘negligent cybersecurity practices,’ House Democrats tell Trump
The Trump administration should “cease all DOGE activities that create serious cybersecurity vulnerabilities, expose government networks to cyberattacks, and risk disclosures of sensitive and personal information,” Democrats from the House Oversight Committee said in a letter to the White House. First seen on therecord.media Jump to article: therecord.media/doge-cybersecurity-house-democrats-letter-trump
-
House Dems say DOGE is leaving publicly exposed entry points into government systems
A letter from a trio of lawmakers says the group has “left multiple government agencies vulnerable to cyberattacks” from foreign entities. First seen on cyberscoop.com Jump to article: cyberscoop.com/house-dems-say-doge-is-leaving-publicly-exposed-entry-points-into-government-systems/
-
New Auto-Color Linux backdoor targets North American govts, universities
A previously undocumented Linux backdoor dubbed ‘Auto-Color’ was observed in attacks between November and December 2024, targeting universities and government organizations in North America and Asia. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-auto-color-linux-backdoor-targets-north-american-govts-universities/
-
Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malware
Opposition activists in Belarus as well as Ukrainian military and government organizations are the target of a new campaign that employs malware-laced Microsoft Excel documents as lures to deliver a new variant of PicassoLoader. The threat cluster has been assessed to be an extension of a long-running campaign mounted by a Belarus-aligned threat actor dubbed…
-
China-based Silver Fox spoofs healthcare app to deliver malware
Silver Fox, a China-based threat actor that may or may not be backed by the Chinese government, has been delivering the ValleyRAT backdoor to unsuspecting users by disguising … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/02/25/china-based-silver-fox-spoofs-healthcare-apps-dicom-viewer-to-deliver-valleyrat-malware/
-
New Auto-Color Malware Attacking Linux Devices to Gain Full Remote Access
Researchers at Palo Alto Networks have identified a new Linux malware, dubbed >>Auto-Color,
-
Critical deserialization bugs in Adobe, Oracle software actively exploited, warns CISA
Oracle Agile PLM flaw open to N-days: The other vulnerability, fixed in January 2024, is a high severity (CVSS 8.8/10) flaw in the export component of the Oracle’s PLM software, and stems from the improper handling of serialized data. It’s tracked as CVE-2024-20953. Successful exploitation could enable a low-privileged attacker with network access via HTTP…
-
UK Home Office’s new vulnerability reporting mechanism leaves researchers open to prosecution
The Home Office is the latest British government department to encourage ethical hackers to report vulnerabilities in its systems. Experts are warning that participants could be open to criminal prosecution, though. First seen on therecord.media Jump to article: therecord.media/uk-home-office-vulnerability-disclosure-ethical-hackers
-
Concerns Over Apple’s UK iCloud Encryption Deactivation
Withdrawal of Advanced Data Protection for British Users Could Have Global Impact. Apple’s decision to withdraw iCloud end-to-end encryption in the United Kingdom has privacy and security advocates worried that the British government could scan and surveil sensitive information of Apple users worldwide. Apple on Friday deactivated its Advanced Data Protection feature in the U.K.…
-
Australia Bans Public Agencies From Using Kaspersky Software
Citing Security Concerns, Australia Joins Others in Banning Anti-Virus Products. The Australian Department of Home Affairs on Friday banned the use of Kaspersky Labs products in public offices citing an unacceptable security risk to the government networks and data. All government offices must uninstall all Kaspersky products and report the completion of the task to…
-
Australia Latest Domino to Fall in Gov’t Kaspersky Bans
This move comes less than a year after the United States banned Kaspersky products, out of the same fear that the company is under Russian government control. First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/australia-domino-fall-government-kaspersky-ban
-
Australia bans all Kaspersky products on government systems
The Australian government has banned all Kaspersky Lab products and web services from its systems and devices following an analysis that claims the company poses a significant security risk to the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/australia-bans-all-kaspersky-products-on-government-systems/

