Third Recent Ivanti Vulnerability Exploited in the Wild

September 25, 2024 at 07:18AM SecurityWeek Network provides cybersecurity news, webcasts, and virtual events. It covers a wide range of topics including malware, cyberwarfare, data breaches, ransomware, incident response, network security, risk management, and CISO strategy. It also offers insight into ICS/OT, industrial cybersecurity, cyber insurance, funding, and M&A. Based on the meeting notes, it … Read more

New Octo2 Android Banking Trojan Emerges with Device Takeover Capabilities

September 24, 2024 at 07:01AM Cybersecurity researchers have uncovered a new version of the Android banking trojan, Octo, named Octo2. It boasts enhanced capabilities for device takeover and fraudulent transactions. The malware has been observed in European countries and is distributed through apps like Europe Enterprise, Google Chrome, and NordVPN. Octo2 is a significant advancement … Read more

Deloitte Says No Threat to Sensitive Data After Hacker Claims Server Breach

September 24, 2024 at 05:15AM A hacker known as IntelBroker announced the theft of data from Deloitte’s improperly secured server on the BreachForums cybercrime forum. The stolen data includes email addresses, intranet communications, and internal settings and is available for download to forum users. Deloitte has confirmed the breach but states that client data is … Read more

Telegram Agrees to Share User Data With Authorities for Criminal Investigations

September 24, 2024 at 03:54AM Telegram has reversed its policy and will now disclose users’ IP addresses and phone numbers to authorities in response to valid legal requests. This change aims to combat criminal activity on the platform, including drug trafficking and child pornography. The update follows the arrest of CEO Pavel Durov in France … Read more

New Mallox ransomware Linux variant based on leaked Kryptina code

September 23, 2024 at 02:32PM A Mallox affiliate was found using a modified version of Kryptina ransomware to target Linux systems, signifying the ransomware’s shift from Windows to Linux and VMWare ESXi systems. Kryptina’s leaked source code was utilized to create the rebranded “Mallox Linux 1.0” encryptor. Various other tools, including a Kaspersky password reset … Read more

Europol Shuts Down Major Phishing Scheme Targeting Mobile Phone Credentials

September 20, 2024 at 09:51AM Law enforcement authorities conducted Operation Kaerb, dismantling an international criminal network leveraging the iServer phishing platform. This led to 17 arrests, 28 searches, and seizure of items, with an estimated 1.2 million mobile phones unlocked. Additionally, Ghost, an encrypted communications network, was dismantled, and 47 cryptocurrency exchanges in Germany were … Read more

Law Enforcement Dismantles Phishing Platform Used for Unlocking Stolen Phones

September 20, 2024 at 08:03AM Law enforcement agencies in Europe and Latin America dismantled the iServer phishing platform as part of Operation Kaerb, targeting over 1.2 million mobile phones and 480,000 victims. The operation resulted in 17 arrests in Argentina, Chile, Colombia, Ecuador, Peru, and Spain, including the platform’s administrator. iServer allowed low-skilled criminals to … Read more

CISA boss: Makers of insecure software are the real cyber villains

September 19, 2024 at 08:37PM Jen Easterly, head of the US government’s Cybersecurity and Infrastructure Security Agency, emphasizes that software vendors are to blame for cyber attacks due to shipping faulty code. She encourages the industry to stop glamorizing cyber crime and demands better quality, secure products. Easterly calls for using procurement power to pressure … Read more

Police dismantles phone unlocking ring linked to 483,000 victims

September 19, 2024 at 12:00PM An international law enforcement operation known as “Operation Kaerb” dismantled a criminal network using the iServer phishing platform to unlock stolen mobile phones, affecting 483,000 victims globally. Coordinated by Europol and Group-IB, the operation led to 17 arrests and the seizure of 921 items. This marked the first collaboration between … Read more

Germany seizes 47 crypto exchanges used by ransomware gangs

September 19, 2024 at 12:00PM German law enforcement seized 47 cryptocurrency exchanges in the country for facilitating illegal money laundering for cybercriminals, creating a low-risk environment for criminal transactions. The “Final Exchange” portal now redirects visitors to a warning page, revealing that extensive user and transaction data have been secured for future investigations. The operators … Read more