State and federal security experts weighed in on the impact that budgetary and personnel cuts to CISA will have on election security as a whole.
Автор: Alexander Culafi, Senior News Writer, Dark Reading
OPSEC Nightmare: Leaking US Military Plans to a Reporter
Experts say the leakage of US military plans to a reporter this month reflects a severe operational security failure on the part of US leadership.
China-Nexus APT ‘Weaver Ant’ Caught in Yearslong Web Shell Attack
The persistent threat actor was caught using sophisticated Web shell techniques against an unnamed telecommunications company in Asia.
VexTrio Using 20,000 Hacked WordPress Sites in Traffic Redirect Scheme
A massive cybercrime network known as "VexTrio" is using thousands of compromised WordPress sites to funnel traffic through a complex redirection scheme.
Nation-State Groups Abuse Microsoft Windows Shortcut Exploit
Trend Micro uncovered a method that nation-state threat actors are using to target victims via the Windows .Ink shortcut file extension.
Google to Acquire Wiz for $32B in Multicloud Security Play
The all-cash deal offers a path for Google to better support cloud customers who have assets spread across public environments, including Azure and others.
Denmark Warns of Increased Cyber Espionage Against Telecom Sector
A new threat assessment from the Danish Civil Protection Authority (SAMSIK) warned of cyberattacks targeting the telecommunications sector after citing a wave of incidents hitting European organizations the past few years.
How Economic Headwinds Influence the Ransomware Ecosystem
Inflation, cryptocurrency market volatility, and the ability to invest in defenses all influence the impact and severity of a ransomware attack, according to incident response efforts and ransomware negotiators.
Threat Actor Impersonates Booking.com in Phishing Scheme
Microsoft detailed a sophisticated campaign that relies on a social engineering technique, "ClickFix," in which a phisher uses security verification like captcha to give the target a false sense of safety.
OpenAI Operator Agent Used in Proof-of-Concept Phishing Attack
Researchers from Symantec showed how OpenAI’s Operator agent, currently in research preview, can be used to construct a basic phishing attack from start to finish.