Tag: government
-
Yakuza Victim Data Leaked in Japanese Agency Attack
A local government resource for helping Japanese citizens cut ties with organized crime was successfully phished in a tech support scam, and could have dangerous consequences. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/yakuza-victim-data-leaked-japanese-attack
-
Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM Apps
Tags: access, advisory, ai, application-security, attack, backup, best-practice, breach, cisa, cloud, computer, cve, cyber, cyberattack, cybercrime, cybersecurity, data, exploit, extortion, firewall, framework, governance, government, group, guide, Hardware, incident, incident response, infrastructure, injection, intelligence, Internet, LLM, malicious, microsoft, mitigation, mitre, monitoring, network, nist, office, open-source, powershell, privacy, ransomware, regulation, risk, risk-management, russia, service, skills, software, sql, strategy, supply-chain, tactics, technology, theft, threat, tool, update, vulnerability, vulnerability-management, windowsDon’t miss OWASP’s update to its “Top 10 Risks for LLMs” list. Plus, the ranking of the most harmful software weaknesses is out. Meanwhile, critical infrastructure orgs have a new framework for using AI securely. And get the latest on the BianLian ransomware gang and on the challenges of protecting water and transportation systems against…
-
Russian TAG-110 Hacked 60+ Users With HTML Loaded Python Backdoor
The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in Central Asia, East Asia, and Europe by deploying custom malware, HATVIBE and CHERRYSPY, to compromise government entities, human rights groups, and educational institutions. Initial access is typically gained through phishing or exploiting vulnerable web services, as the campaign’s goal is to…
-
US Takes Down Stolen Credit Card Marketplace PopeyeTools
The US government has announced the seizure of stolen credit card marketplace PopeyeTools and charges against its administrators. The post US Takes Down Stolen Credit Card Marketplace PopeyeTools appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/us-takes-down-stolen-credit-card-marketplace-popeyetools/
-
Russian Cyber Spies Target Organizations with HatVibe and CherrySpy Malware
Russian-aligned TAG-110 uses custom tools to spy on governments, human rights groups and educational institutions in Europe and Asia First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-cyber-spies-hatvibe/
-
Russian Cyberespionage Group Hit 60 Victims in Asia, Europe
Russia-linked TAG-110 has targeted over 60 government, human rights, and educational entities in Asia and Europe. The post Russian Cyberespionage Group Hit 60 Victims in Asia, Europe appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/russian-cyberespionage-group-hit-60-victims-in-asia-europe/
-
Danish government reboots cyber security council amid AI expansion
First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366614294/Danish-government-reboots-cyber-security-council-amid-AI-expansion
-
Here’s what happens if you don’t layer network security or remove unused web shells
TL;DR: Attackers will break in and pwn you, as a US government red team demonstrated First seen on theregister.com Jump to article: www.theregister.com/2024/11/22/cisa_red_team_exercise/
-
British Lawmakers Leery of Losing EU Adequacy Status
Lawmakers Expressed Concerns Over Proposed Data Use and Access Bill. British lawmakers sought assurances Tuesday from the U.K. government that proposed data use reform legislation will not cause the country to lose its data-sharing rights with the European Union. Lawmakers also warned about potential AI risks arising from the bill. First seen on govinfosecurity.com Jump…
-
Ransomhub ransomware gang claims the hack of Mexican government Legal Affairs Office
Mexico is investigating a ransomware attack targeting its legal affairs office, as confirmed by the president amidst growing cybersecurity concerns. Mexico’s president announced the government is investigating an alleged ransomware hack that targeted the administration’s legal affairs office. “Today they are going to send me a report on the supposed hacking.” President Claudia Sheinbaum said…
-
The Dangerous Blend of Phishing for Government IDs and Facial Recognition Video
In an era where online convenience has become the norm, the risk of identity theft through scam websites has surged. The potential for exploitation grows as more services transition to conducting business online. These sites pose a significant risk to personal security and undermine public trust in the digital infrastructure we have in place. A…
-
Put Your Username And Passwords In Your Will, Advises Japan’s Government
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36625/Put-Your-Username-And-Passwords-In-Your-Will-Advises-Japans-Government.html
-
Feds Indict 5 Suspects Tied to Scattered Spider Cybercrime
FBI Ties Men to at Least 45 Attacks and Theft of Cryptocurrency Worth Millions. The U.S. government on Wednesday unsealed criminal charges against five suspected members of the loosely organized financially motivated cybercriminal group Scattered Spider. The suspects have been tied to 45 attacks, disrupting businesses and stealing cryptocurrency worth millions of dollars. First seen…
-
Mexico’s President Says Government Is Investigating Reported Ransomware Hack of Legal Affairs Office
Mexico’s president says the government is investigating a reported ransomware hack of the country’s legal affairs office. The post Mexico’s President Says Government Is Investigating Reported Ransomware Hack of Legal Affairs Office appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/mexicos-president-says-government-is-investigating-reported-ransomware-hack-of-legal-affairs-office/
-
China’s Surveillance State Is Selling Citizen Data as a Side Hustle
Chinese black market operators are openly recruiting government agency insiders, paying them for access to surveillance data and then reselling it online”, no questions asked. First seen on wired.com Jump to article: www.wired.com/story/chineses-surveillance-state-is-selling-citizens-data-as-a-side-hustle/
-
Put your usernames and passwords in your will, advises Japan’s government
Digital end of life planning saves your loved ones from a little extra anguish First seen on theregister.com Jump to article: www.theregister.com/2024/11/21/japan_digital_end_of_life/
-
Earth Kasha Expands Operations: New LODEINFO Malware Hits Government and High-Tech
In a detailed report by Trend Micro, the emergence of a new LODEINFO malware campaign has been linked to Earth Kasha, a threat group operating within what the researchers term... First seen on securityonline.info Jump to article: securityonline.info/earth-kasha-expands-operations-new-lodeinfo-malware-hits-government-and-high-tech/
-
UK open to social media ban for kids as government kicks off feasibility study
The U.K. government is not ruling out further beefing up of existing online safety rules by adding an Australian-style ban on social media for kids under 16 technology secretary Peter Kyle has said. Back in the summer, the government warned it may toughen laws for tech platforms in the wake of riots that were perceived…
-
Feds Fine Mental Health Clinic $100K in 2020 HIPAA Case
LA County Clinic Delayed Access to Patient’s Medical Records During Pandemic. Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government’s 51st HIPAA patient right-of-access enforcement action. First seen…
-
Bad Actors Impersonating Government Agencies in Latest DocuSign Scams
First seen on scworld.com Jump to article: www.scworld.com/news/bad-actors-impersonating-government-agencies-in-latest-docusign-scams
-
HHS facing challenges as lead agency for healthcare cybersecurity: GAO
The department hasn’t implemented some policies recommended by the watchdog, which could pose a risk to cybersecurity in the sector;as attacks increase, according to the Government Accountability Office. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/healthcare-cybersecurity-policy-challenges/733466/
-
UK open to social media ban for kids as gov’t kicks off feasibility study
The U.K. government is not ruling out further beefing up existing online safety rules by adding an Australian-style ban on social media for under 16s technology secretary, Peter Kyle, has said. Back in the summer the government warned it may toughen laws for tech platforms in the wake of riots that were perceived to have…
-
Gabagool: A Sophisticated Phishing Kit Exploiting Cloudflare R2
In a detailed analysis, TRAC Labs has exposed a phishing campaign named Gabagool that targets corporate and government employees. The campaign leverages the trusted reputation of Cloudflare’s R2 storage service... First seen on securityonline.info Jump to article: securityonline.info/gabagool-a-sophisticated-phishing-kit-exploiting-cloudflare-r2/
-
GAO recommends new agency to streamline how US government protects citizens’ data
First seen on therecord.media Jump to article: therecord.media/gao-recommends-new-agency-data-privacy-protections
-
US Agencies Urged to Combat Growing Chinese Cyberthreat
Experts Call on Feds to Step Up Defense Against Escalating Chinese Threats. A panel of cybersecurity experts and top industry officials pushed lawmakers and the federal government to step up their defenses against escalating cyberthreats from China, citing recent high-profile examples of evidence that Beijing is increasingly targeting the U.S. with sophisticated attacks. First seen…
-
China’s top messaging app WeChat banned from Hong Kong government computers
First seen on theregister.com Jump to article: www.theregister.com/2024/10/24/hong_kong_wechat_ban/
-
Phishing Alert: Government Impersonation Attacks Surge via DocuSign
Cybercriminals are leveraging the trusted reputation of government agencies to deceive businesses, with DocuSign phishing attacks on the rise. A new wave of phishing attacks is targeting businesses that frequently... First seen on securityonline.info Jump to article: securityonline.info/phishing-alert-government-impersonation-attacks-surge-via-docusign/
-
RansomHub lays claim on Mexican government website hack
Tags: governmentFirst seen on scworld.com Jump to article: www.scworld.com/brief/ransomhub-lays-claim-on-mexican-government-website-hack
-
US Government Agencies Impersonated in Aggressive DocuSign Phishing Scams
DocuSign phishing scams surged by 98%, with hundreds of daily attacks impersonating US government agencies like HHS and… First seen on hackread.com Jump to article: hackread.com/us-govt-agencies-impersonate-docusign-phishing-scams/
-
T-Mobile Hit by Chinese Cyber Spies; Sees Minimal Impact
Telco Giant’s Probe Finds ‘No Evidence’ of Customer or Sensitive Data Breach. The world’s largest telecommunications carrier, T-Mobile U.S., said it was targeted as part of a wide-ranging cyberespionage operation the U.S. government attributes to China but has found no sign of data access or theft. Other known victims of the campaign include AT&T, Verizon…

