Bitcoin ATM firm Byte Federal hacked via GitLab flaw, 58K users exposed

December 12, 2024 at 11:09AM Byte Federal, the largest U.S. Bitcoin ATM operator, experienced a data breach affecting 58,000 customers due to a GitLab vulnerability. Sensitive information like names, social security numbers, and contact details were accessed. The company has secured its systems and urges customers to monitor for fraud but does not offer identity … Read more

Russian cyber spies hide behind other hackers to target Ukraine

December 12, 2024 at 11:09AM Russian cyber-espionage group Turla is leveraging other threat actors’ infrastructure, specifically targeting Ukrainian military devices via Starlink. Utilizing malware from the Amadey botnet and other sources, Turla deploys custom malware like Tavdig and KazuarV2 to gather intelligence and perform reconnaissance on compromised systems. Microsoft recently highlighted these activities. ### Key … Read more

Silent Push Raises $10 Million for Preemptive Threat Intelligence Platform

December 12, 2024 at 10:47AM Silent Push, a detection-focused threat intelligence firm, has raised $10 million, bringing total funding to $22 million. Founded in 2020, the Virginia-based startup offers tools to counter cyberattacks by identifying malicious infrastructure and utilizing automated adversary intelligence. The funding will aid expansion into new regions and enhance marketing efforts. **Meeting … Read more

Sublime Snags $60M Series B for Email Security Tech

December 12, 2024 at 10:24AM Sublime Security, a D.C. startup offering email security solutions for Microsoft 365 and Google Workspace, has secured $60 million in funding, bringing total investments to $93.8 million. The company, gaining traction with major clients, provides AI-driven tools for threat detection and management, competing in the growing email security market. ### … Read more

Fortinet Acquires Perception Point Reportedly for $100 Million

December 12, 2024 at 10:10AM Fortinet announced the acquisition of Israeli security company Perception Point for approximately $100 million. Perception Point enhances Fortinet’s security offerings with advanced threat detection and cloud-native solutions for email and collaboration platforms. This marks Fortinet’s third acquisition in 2024, following Next DLP and Lacework. **Meeting Notes Takeaways:** 1. **Acquisition Announcement**: … Read more

Cultivating a Hacker Mindset in Cybersecurity Defense

December 12, 2024 at 10:06AM The commentary highlights the decline of the hacker spirit among security professionals, who now often lack genuine curiosity and creativity. Instead of using automated tools, security teams must understand attackers’ motivations and tactics. Building a hacker mindset through mentorship and hands-on experience is crucial for effective defense against evolving threats. … Read more

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online

December 12, 2024 at 09:51AM Cybersecurity researchers warn that numerous publicly accessible Prometheus servers are vulnerable to information leakage and attacks due to inadequate authentication. Sensitive data, including credentials, can be exposed, and denial-of-service attacks may occur via specific endpoints. Organizations should implement authentication, limit exposure, and monitor server activity to mitigate risks. **Meeting Takeaways … Read more

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States

December 12, 2024 at 09:51AM Gamaredon, a Russia-linked threat actor, has developed two Android spyware tools, BoneSpy and PlainGnome, targeting Russian-speaking victims in former Soviet states. These tools gather extensive data from infected devices. Their use marks the first instance of mobile-only malware in Gamaredon’s campaigns, which also includes attempts against NATO countries. ### Meeting … Read more

The Ghost of Christmas Past – AI’s Past, Present and Future

December 12, 2024 at 09:41AM The rapid growth of AI since GenAI’s emergence in 2022 has transformed operations and cybersecurity. However, despite its hype, GenAI hasn’t yet provided substantial business value. Moving forward, a focus on SynthAI, which synthesizes information for better decision-making, is essential, emphasizing the need for careful strategy and long-term ROI. ### … Read more

Mobile Surveillance Tool EagleMsgSpy Used by Chinese Law Enforcement

December 12, 2024 at 08:42AM Chinese law enforcement has utilized a surveillance tool called EagleMsgSpy since at least 2017 to collect data from Android devices via physical access. Developed by Wuhan Chinasoft Token Information Technology Co., it gathers sensitive information such as SMS, call logs, and GPS data, linked to public security bureaus in China. … Read more