⚡ THN Recap: Top Cybersecurity Threats, Tools and Tips (Dec 2 – 8)

December 9, 2024 at 08:16AM This week’s cyber recap highlights hacker stealing infrastructures and deploying AI-driven scams. Significant events include the arrest of a Scattered Spider member, turmoil caused by malicious Android malware, and law enforcement actions disrupting online fraud networks. Cybersecurity firms stress vigilance against evolving threats and emerging vulnerabilities in popular software. ### … Read more

Wanted Russian Cybercriminal Linked to Hive and LockBit Ransomware Has Been Arrested

November 30, 2024 at 02:42AM Russian cybercriminal Mikhail Pavlovich Matveev, linked to LockBit and Hive ransomware, has been arrested. He is charged with developing a malware program for encrypting files and demanding ransom. Matveev has been under U.S. indictment since May 2023, facing consequences for his extensive cybercrime activities. ### Meeting Takeaways – Ransomware / … Read more

Man accused of hilariously bad opsec as alleged cybercrime spree detailed

November 26, 2024 at 03:42PM Nicholas Michael Kloster, 31, appeared in court for alleged cybercrimes, including breaking and entering, credit card abuse, and manipulating computer systems of two companies shortly after his employment. Prosecutors claim he caused $5,000 in damages to a nonprofit and faces charges related to computer access and damage. Trial is scheduled … Read more

US Charges Five Alleged Scattered Spider Members

November 21, 2024 at 07:28AM Five individuals linked to the Scattered Spider cybercrime group have been charged with phishing and stealing millions of dollars in cryptocurrency, according to a report by SecurityWeek. **Meeting Takeaways:** 1. **Charges Filed**: The U.S. has charged five individuals alleged to be members of the Scattered Spider cybercrime group. 2. **Crimes … Read more

Hackers Hijack Unsecured Jupyter Notebooks to Stream Illegal Sports Broadcasts

November 19, 2024 at 09:42AM Malicious actors are exploiting misconfigured JupyterLab and Jupyter Notebooks to facilitate sports piracy by hijacking unauthenticated notebooks. They use FFmpeg to capture and illegally stream live sports events. The campaign poses serious risks, including data theft and operational disruption, according to a report by Aqua’s threat intelligence director. **Meeting Takeaways … Read more

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Oct 28 – Nov 03)

November 4, 2024 at 07:39AM This week in cybersecurity, numerous hacking incidents occurred, including North Korean collaborations on ransomware and exploits targeting browsers and cloud services. Highlights include vulnerabilities in PTZ cameras and OpenText software, a fraudulent scheme manipulating online shops, and security updates from various companies. Stay informed and proactive in safeguarding digital assets. … Read more

Report: The Dark Side of Phishing Protection

May 27, 2024 at 08:06AM The article discusses the increasing risk of phishing attacks due to cloud transition, poor password hygiene, and advancements in webpage technologies. LayerX’s report highlights the rising magnitude of phishing attacks and suggests methods for organizations to protect against them, focusing on browser security platforms and deep session inspection as effective … Read more

MITRE Corporation Breached by Nation-State Hackers Exploiting Ivanti Flaws

April 22, 2024 at 08:00AM MITRE Corporation was targeted by a nation-state cyber attack exploiting two zero-day flaws in Ivanti Connect Secure appliances, compromising the NERVE network. The attack bypassed multi-factor authentication and moved laterally to breach VMware infrastructure. MITRE contained the incident and attributed the attack to a nation-state actor, urging for improved cybersecurity … Read more

SASE Solutions Fall Short Without Enterprise Browser Extensions, New Report Reveals

March 27, 2024 at 07:03AM As SaaS applications become prevalent in business, the need for optimized network speed and strong security measures grows. However, a new report challenges SASE’s ability to provide comprehensive security against web-based threats. Secure browser extensions are presented as a solution to complement SASE and address its limitations in real-time protection … Read more

MFA Spamming and Fatigue: When Security Measures Go Wrong

January 18, 2024 at 08:03AM Multi-factor authentication (MFA) is increasingly used by organizations to bolster security, as traditional password-only systems are vulnerable to cyberattacks. However, MFA spamming, a tactic where attackers inundate users with verification requests, poses a threat. Mitigation strategies include strong password policies, end-user training, rate limiting, and monitoring systems. Strengthening security measures … Read more