Researchers report that because of increased use of multifactor authentication, attackers are developing phishing kits that steal tokens and bypass this trusted layer of security, enabling them to "man in the middle" a browser session and steal credentials and session cookies in real time.
Eset says it has patched a high-severity privilege escalation bug affecting its clients who use Windows-based systems. The company has released software updates for all affected versions of its product, as well as a workaround, and says no exploits have been reported.
U.S. lawmakers have introduced a bill that would bring "new transparency and oversight of software, algorithms and other automated systems" making "critical decisions" for American life. The bill - an updated version of a 2019 proposal - would also combat bias in the use of such technologies, its sponsors say.
ThycoticCentrify renames itself Delinea to grow as a "seamless" security solution. Other acquisitions focus on providing tools to developers to better secure applications and software, boost healthcare device security, fight against chargeback fraud and bring smaller organizations into compliance.
Some of the biggest cybercrime-focused darknet markets selling stolen payment card data, passwords, malware and more have retired in the past year, with administrators oftentimes boasting it's because they've gotten rich. As they exit, other players remain ready to grab their market share, experts say.
Multinational media company News Corp was the target of a cyberattack that exposed emails and employee documents - including those belonging to journalists, the company confirmed on Friday. To investigate, News Corp has hired cybersecurity firm Mandiant, which says the attack has a "China nexus."
Four ISMG editors discuss important cybersecurity issues, including misconceptions around Zero Trust implementation, lessons learned from the crippling NotPetya malware attack of 2017 that nearly sank logistics giant Maersk and how a Russian cyberwar in Ukraine could move beyond its borders.
The latest edition of the ISMG Security Report features an analysis of how Russia's escalation in Ukraine is raising cyber defense alarms. It also describes how a Dark Overlord collaborator received a three-year prison sentence and shares tips for Zero Trust implementation.
A New York federal court has recommended the dismissal of a class action lawsuit filed against medical practice management vendor Practicefirst in the aftermath of a 2020 ransomware attack that involved data exfiltration and affected the personal and health information of 1.2 million individuals.
Pharmaceutical giant Pfizer alleges in a federal lawsuit that two former executives stole documents containing trade secrets about diabetes, obesity and cancer treatments under development by the drugmaker to benefit two new biotech startups they had launched.
A popular British supplier of crisps revealed in a letter to grocery wholesaler Nisa on Wednesday that it had been the victim of a cyberattack. KP Snacks has stopped its orders, causing stores to worry that its products will be in short supply. Ransomware group Conti is allegedly behind the attack.
A new wave of Delphi malware called Micropsia, developed and operated by the Arid Viper APT group, is reported to be targeting Palestinian entities and activists using politically themed lures in an ongoing campaign, according to researchers at Cisco Talos.
Greek data protection authority Hellenic DPA has imposed fines totaling more than $10 million on two telecommunication companies for GDPR violations including inadequate information disclosure to subscribers in the wake of data breaches, illegal data processing and inadequate security measures.
India’s Union Budget 2022 resolves some of the uncertainty around the legitimacy of crypto assets. While crypto assets will not be considered as currency, Finance Minister Nirmala Sitharaman announced that the Reserve Bank of India will be launching a blockchain-based digital rupee this year.
A variety of underground markets exist to help malware-wielding criminals monetize their attacks, including via log marketplaces such as Genesis, Russian Market and 2easy, which offer for sale batches of data that can be used to emulate a victim, whether it's a consumer, an enterprise IT administrator or anyone in...
Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing databreachtoday.co.uk, you agree to our use of cookies.