Storm-0501 Expands Ransomware Attacks to Hybrid Cloud Environments

Microsoft has detected Storm-0501 using Cobalt Strike for lateral movement across networks and deploying Embargo ransomware on victim organizations in hybrid cloud setups.

Cyware News – Latest Cyber News – ​Read More

Worldcoin: Fighting Deepfakes and Bots With a Global Permissionless Blockchain Identity

That dream of a decentralized privacy-retaining identity system able to combat AI-driven bots and deepfakes may not be as elusive as feared – courtesy of Tools for Humanity (TfH) and Worldcoin.

The post Worldcoin: Fighting Deepfakes and Bots With a Global Permissionless Blockchain Identity appeared first on SecurityWeek.

SecurityWeek – ​Read More

Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy

KLogEXE is a C++ keylogger while FPSpy is a backdoor designed to collect system information and exfiltrate data from compromised devices. Both malware strains are primarily being distributed through spear-phishing emails.

Cyware News – Latest Cyber News – ​Read More

The Pig Butchering Invasion Has Begun

Scamming operations that once originated in Southeast Asia are now proliferating around the world, likely raking in billions of dollars in the process.

Security Latest – ​Read More

Microsoft: Cloud Environments of US Organizations Targeted in Ransomware Attacks

A threat actor has been compromising the hybrid cloud environments of US organizations in multiple sectors.

The post Microsoft: Cloud Environments of US Organizations Targeted in Ransomware Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

British National Arrested, Charged for Hacking US Companies

UK national Robert Westbrook was charged in the US for executing a hack-to-trade scheme against five public companies.

The post British National Arrested, Charged for Hacking US Companies appeared first on SecurityWeek.

SecurityWeek – ​Read More

First Mobile Crypto Drainer Found on Google Play

The malicious app, called WalletConnect, amassed over 10,000 downloads and stole around $70,000 in cryptocurrency from Android users before being removed from the Google Play Store.

Cyware News – Latest Cyber News – ​Read More

NIST Proposes Barring Some of the Most Nonsensical Password Rules

NIST is seeking public feedback on the draft guidelines, which can be submitted via email until October 7. The goal is to promote sensible password practices that enhance security without burdening users or compromising their online identity.

Cyware News – Latest Cyber News – ​Read More

Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware

A watering hole attack targeted Kurdish websites, distributing malicious APKs and spyware, compromising 25 sites for over a year. French cybersecurity firm Sekoia uncovered the campaign called SilentSelfie, delivering various info-stealers.

Cyware News – Latest Cyber News – ​Read More

Meta Fined €91 Million for Storing Millions of Facebook and Instagram Passwords in Plaintext

The Irish Data Protection Commission (DPC) has fined Meta €91 million ($101.56 million) as part of a probe into a security lapse in March 2019, when the company disclosed that it had mistakenly stored users’ passwords in plaintext in its systems.
The investigation, launched by the DPC the next month, found that the social media giant violated four different articles under the European Union’s

The Hacker News – ​Read More