You are here

Cybersecurity

Wiper Malware Impacting More Organizations Across the World and Other Findings from Fortinet’s Latest Threat Report

In the second half of 2022, security researchers at Fortinet observed destructive wiper malware attacks impacting more organizations around the world, as well as cybercriminals retooling existing botnets and reusing code to power more sophisticated attacks.

Cyber Resilience - U.K. National Cyber Security Centre Publishes Guidance on Supply Chain Mapping

The U.K.’s National Cyber Security Centre (NCSC) posted guidance for mapping an organization’s supply chain. The document is aimed at medium to large organizations who need to gain confidence or assurance that mitigations are in place for vulnerabilities associated with working with suppliers. Supply chain mapping (SCM) is the process of recording, storing, and using information gathered from suppliers who are involved in a company’s supply chain.

Threat Awareness – Multipurpose Malware Becoming Increasingly Popular to Deploy

Help Net Security has written an article covering research by Picus Security which found that multipurpose malware – or malware with multiple malicious capabilities – is becoming increasingly more popular to create and deploy. Researchers analyzed over 550,000 malware samples and mapped each one’s capabilities to the cyber kill chain.

Threat Awareness – Threat Actors Continuing the Trend of Targeting Victims Through Google Search Results

Bleeping Computer has written an article covering a malicious campaign abusing Google ads that was discovered by researchers from Sentinel Labs. The malvertising campaign redirected victims to a fake Amazon Web Services login page, registered to what is believed to be a Brazilian threat actor. The most notable thing to remember is that in many instances the bad ads rank very high in the search results. For instance, when searching for “aws,” this campaign’s malicious result appeared second, right behind Amazon’s own promoted search result.

Cyber Resilience – MFA is not a Substitute for Employee Training

Dark Reading has written an article about the recent reddit hack and how the details that have been released demonstrate the limitations of two-factor authentication and the benefits of employee training. Despite reddit requiring the use of two-factor authentication internally, attackers were still able to convince an employee to click on a malicious link and harvest their credentials.

Pages

Subscribe to Cybersecurity