Tag: government
-
Russian-Linked Hackers Using ‘Device Code Phishing’ to Hijack Accounts
Microsoft is calling attention to an emerging threat cluster it calls Storm-2372 that has been attributed to a new set of cyber attacks aimed at a variety of sectors since August 2024.The attacks have targeted government, non-governmental organizations (NGOs), information technology (IT) services and technology, defense, telecommunications, health, higher education, and energy/oil and gas First…
-
Device Code Phishing Attack Exploits Authentication Flow to Hijack Tokens
Tags: attack, authentication, cyber, defense, exploit, government, intelligence, microsoft, phishing, service, threatA sophisticated phishing campaign leveraging the device code authentication flow has been identified by Microsoft Threat Intelligence, targeting a wide range of sectors, including government, NGOs, IT services, and critical industries such as defense and energy. The campaign, attributed to a threat actor known as Storm-2372, has been active since August 2024 and is assessed…
-
New Australian Law Makes Banks, Telecoms Liable for Scams
Social Platforms Also Could Face Stiff Fines for Failing to Protect Users. The Australian government passed the Scams Prevention Framework law in Parliament to make social media companies, banks and telecommunication companies accountable for scammers using their networks, subjecting them to a maximum of AU$50 million in fines for violations. First seen on govinfosecurity.com Jump…
-
Energy Regulations Are Rising: Stay Ahead with Modern DCIM
As data centers continue to serve as the backbone of the digital economy, they face an escalating challenge: the tightening grip of global energy consumption regulations. Governments and regulatory bodies worldwide are implementing stricter policies to curb carbon footprints, optimize energy use, and enforce sustainability commitments. In this evolving landscape, modern Data Center Infrastructure Management…
-
Unusual attack linked to Chinese APT group combines espionage and ransomware
Tags: apt, attack, breach, china, cloud, country, credentials, crime, crimes, crypto, cyber, cybercrime, cyberespionage, data, encryption, espionage, exploit, finance, firewall, government, group, hacker, infection, insurance, intelligence, korea, microsoft, network, north-korea, ransom, ransomware, russia, software, tactics, technology, threat, veeam, vulnerabilityThe attacker demanded a $2-million ransom: The attack that resulted in the deployment of the RA World ransomware program, as well as data exfiltration, had the same chain: the toshdpdb.exe loading toshdpapi.dll then decrypting toshdp.dat which resulted in the PlugX variant being deployed. The difference is the attacker then chose to deploy the RA World…
-
Spyware maker caught distributing malicious Android apps for years
Italian company SIO, which sells to government customers, is behind an Android spyware campaign called Spyrtacus that spoofed popular apps like WhatsApp, per security researchers. First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/13/spyware-maker-caught-distributing-malicious-android-apps-for-years/
-
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
Tags: attack, business, crypto, cyberattack, government, group, hacking, korea, north-korea, powershell, threatA nation-state threat actor with ties to North Korea has been linked to an ongoing campaign targeting South Korean business, government, and cryptocurrency sectors.The attack campaign, dubbed DEEP#DRIVE by Securonix, has been attributed to a hacking group known as Kimsuky, which is also tracked under the names APT43, Black Banshee, Emerald Sleet, Sparkling Pisces, Springtail,…
-
UK government sanctions target Russian cyber crime network Zservers
The UK government has imposed sanctions on a Russian cyber crime syndicate responsible for aiding ransomware attacks, targeting the group and individual members First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366619219/UK-government-sanctions-target-Russian-cyber-crime-network-ZSERVERS
-
After Copilot trial, government staff rated Microsoft’s AI less useful than expected
Not all bad news for Redmond as Australian agency also found strong ROI and some unexpected upsides First seen on theregister.com Jump to article: www.theregister.com/2025/02/12/australian_treasury_copilot_pilot_assessment/
-
Threat Actors in Russia, China, and Iran Targeting Local communities in the U.S
Foreign adversaries, including Russia, China, and Iran, are intensifying their efforts to manipulate public opinion and destabilize local communities across the United States. These campaigns, once primarily focused on national-level politics, have increasingly targeted state and local governments, community groups, and individuals. Leveraging advanced technologies such as generative artificial intelligence (AI), these actors aim to…
-
Smashing Security podcast #404: Podcast not found
The story of how hackers managed to compromise the US Government’s official SEC Twitter account to boost the price of Bitcoins, AI isn’t helping reduce the rife conspiracy theories inside classrooms, and is the funeral bell tolling for ransomware? First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-404/
-
Italian Government Denies It Spied on Journalists and Migrant Activists Using Paragon Spyware
The Italian government denied it hacked seven cellphones with military-grade surveillance technology from Paragon Solutions. The post Italian Government Denies It Spied on Journalists and Migrant Activists Using Paragon Spyware appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/italian-government-denies-it-spied-on-journalists-and-migrant-activists-using-paragon-spyware/
-
Trump Order Gives DOGE Hiring Powers, Amid Security Concerns
Executive Order Gives Musk Team Hiring Authority Across Federal Government. President Donald Trump’s latest executive order grants hiring authority across the federal government to his billionaire adviser Elon Musk’s task force, raising concerns that the move could undermine federal cybersecurity efforts, weaken U.S. cyber defenses and leave key security positions unfilled. First seen on govinfosecurity.com…
-
The UK’s secret iCloud backdoor request: A dangerous step toward Orwellian mass surveillance
The United Kingdom government has secretly requested that Apple build a backdoor into its iCloud service, granting the government unrestricted access to users’ private data. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/02/13/uk-government-icloud-backdoor-request/
-
Treasury was ‘fully aware of the risks’ posed by DOGE access to payment systems, court filing says
A Department of Government Efficiency (DOGE) employee was accidentally given the ability to edit a sensitive Treasury payment database, but he never did so and the mistake was quickly corrected. First seen on therecord.media Jump to article: therecord.media/treasury-fully-aware-of-risks-posed-by-doge-access-to-database
-
BadPilot network hacking campaign fuels Russian SandWorm attacks
A subgroup of the Russian state-sponsored hacking group APT44, also known as ‘Seashell Blizzard’ and ‘Sandworm’, has been targeting critical organizations and governments in a multi-year campaign dubbed ‘BadPilot.’ First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/
-
CHERI Security Hardware Program Essential to UK Security, Says Government
NCSC CTO Ollie Whitehouse discussed a UK government-backed project designed to secure underlying computer hardware, preventing most vulnerabilities from occurring First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cheri-security-hardware-uk-security/
-
Paris AI Action Summit Abschlusserklärung nicht von USA und UK unterzeichnet
‘Ich bin keineswegs überrascht, dass die USA und Großbritannien das auf dem AI Action Summit in Paris vorgeschlagene Abkommen nicht unterzeichnet haben. Die Debatte über künstliche Intelligenz entwickelt sich rasant, und Regierungen weltweit ringen um Einfluss . In dieser kritischen Phase der Einführung und Entwicklung von KI möchte keine Regierung das Risiko eingehen, ins Hintertreffen…
-
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack
The North Korea-linked threat actor known as Kimsuky has been observed using a new tactic that involves deceiving targets into running PowerShell as an administrator and then instructing them to paste and run malicious code provided by them.”To execute this tactic, the threat actor masquerades as a South Korean government official and over time builds…
-
UK monitoring group to classify cyber incidents on earthquake-like scale
Risk management: The CMC hopes this increased understanding will spur the development of improved incident response planning. Experts quizzed by CSO on CMC welcomed its launch.Ivan Milenkovich, vice president of cyber risk technology in EMEA at Qualys, said data from the CMC has the potential to allow IT security professionals to make better risk assessments,…
-
The Rise of Typhoon Cyber Groups
Tags: access, attack, breach, communications, control, cyber, cyberattack, cybersecurity, data, defense, dns, endpoint, espionage, exploit, finance, government, group, infrastructure, intelligence, iot, military, monitoring, network, phone, resilience, supply-chain, tactics, threat, tool, vulnerability, zero-day -
The Alarming Backdoor Hiding in 2 Chinese Patient Monitors
Researcher Jason Sinchak on Recent Cyber Warnings About Contec CMS8000 Devices. A hidden reverse backdoor in low-cost patient vital sign monitors used globally is hardcoded with an IP address connecting to a Chinese government-funded education and research network, which poses both privacy and potential safety concerns, said security researcher Jason Sinchak of ELTON. First seen…
-
DeepSeek prohibited in New York government devices
Tags: governmentFirst seen on scworld.com Jump to article: www.scworld.com/brief/deepseek-prohibited-in-new-york-government-devices
-
Apple issues emergency patches to contain an ‘extremely sophisticated attack’ on targeted individuals
Security researcher uncovers the exploit: The vulnerability was discovered by Bill Marczak, a senior researcher at Citizen Lab, a digital rights research group at the University of Toronto’s Munk School.Marczak took to social media to urge users to update their devices immediately, stating: “Update your iPhones”¦ again! iOS 18.3.1 out today with a fix for…
-
New York Bans DeepSeek Over Potential Data Risks
New York Governor Kathy Hochul announced that the state has banned the use of the China-based AI startup DeepSeek on government-issued devices and networks. The decision stems from escalating concerns over potential foreign surveillance and censorship risks associated with the app, which has recently gained meteoric popularity. Governor Hochul issued a statement addressing the ban,…
-
British techies to advise on ‘devastating’ UK global crypto power grab
A hitherto unknown British organisation which even the government may have forgotten about is about to be drawn into a global technical and financial battle, facing threats from Apple to pull out of the UK First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366619028/Apple-British-techies-to-advise-on-devastating-UK-global-crypto-power-grab
-
DOGE’s Use of AI Raises Major Privacy Concerns, Legal Heat
Lawsuits Mounting Over Elon Musk’s Attempts to Slash Federal Government Spending. Lawsuits are mounting against President Donald Trump and Elon Musk’s task force for shrinking the federal government as reports indicate the group is feeding sensitive federal data into artificial intelligence systems to target budget cuts, potentially accessing Americans’ sensitive data. First seen on govinfosecurity.com…
-
[Corrected] Out of 6,000 non-IPA requests, Apple provided UK with iCloud data only four times since 2020
The figures suggest a potential motivation behind the British government’s reported legal order to require Apple to be capable of providing iCloud content upon receipt of a valid warrant. First seen on therecord.media Jump to article: therecord.media/requests-apple-provided-four-times
-
Revelations of Israeli spyware abuse raise fears over possible use by Trump
After WhatsApp claimed 90 users were targeted last year, experts concerned over how US could use cyberweaponsEven as WhatsApp <a href=”https://www.theguardian.com/technology/2024/dec/20/whatsapp-pegasus-spyware-nso-group-hacking”>celebrated a major legal victory in December against NSO Group, the Israeli maker of one of the world’s most powerful cyberweapons, <a href=”https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware”> a new threat was detected, this time involving another Israel-based company that…
-
Students suing Education Department worry data DOGE has accessed could be used for immigration enforcement
California students suing the Department of Education allege that the agency has potentially put their families at risk by allowing the Department of Government Efficiency (DOGE) to obtain information that could reveal they have undocumented family members. First seen on therecord.media Jump to article: therecord.media/students-suing-doe-fear-doge-access-to-immigration-data

