Wednesday, November 23, 2022

U.S. Authorities Seize Domains Used in 'Pig butchering' Cryptocurrency Scams

The U.S. Justice Department (DoJ) on Monday announced the takedown of seven domain names in connection to a "pig butchering" cryptocurrency scam. The fraudulent scheme, which operated from May to August 2022, netted the actors over $10 million from five victims, the DoJ said. Pig butchering, also called Sha Zhu Pan, is a type of scam in which swindlers lure unsuspecting investors into sending
https://thehackernews.com/2022/11/us-authorities-seize-domains-used-in.html?utm_source=dlvr.it&utm_medium=blogger

Tuesday, November 22, 2022

Google Wins Lawsuit Against Russians Linked to Blockchain-based Glupteba Botnet

Google has won a lawsuit filed against two Russian nationals in connection with the operation of a botnet called Glupteba, the company said last week. The U.S. District Court for the Southern District of New York imposed monetary sanctions against the defendants and their U.S.-based legal counsel. The defendants have also been asked to pay Google's attorney fees. The defendants' move to press
https://thehackernews.com/2022/11/google-wins-lawsuit-against-russians.html?utm_source=dlvr.it&utm_medium=blogger

Monday, November 21, 2022

Google Identifies 34 Cracked Versions of Popular Cobalt Strike Hacking Toolkit in the Wild

Google Cloud last week disclosed that it identified 34 different hacked release versions of the Cobalt Strike tool in the wild, the earliest of which shipped in November 2012. The versions, spanning 1.44 to 4.7, add up to a total of 275 unique JAR files, according to findings from the Google Cloud Threat Intelligence (GCTI) team. The latest version of Cobalt Strike is version 4.7.2. Cobalt
https://thehackernews.com/2022/11/google-identifies-34-cracked-versions.html?utm_source=dlvr.it&utm_medium=blogger

Sunday, November 20, 2022

Indian Government Publishes Draft of Digital Personal Data Protection Bill 2022

The Indian government on Friday released a draft version of the much-awaited data protection regulation, making it the fourth such effort since it was first proposed in July 2018. The Digital Personal Data Protection Bill, 2022, as it's called, aims to secure personal data, while also seeking users' consent in what the draft claims is "clear and plain language" describing the exact kinds of
https://thehackernews.com/2022/11/indian-government-publishes-draft-of.html?utm_source=dlvr.it&utm_medium=blogger

Saturday, November 19, 2022

Meta Fired Several Employees For Hijacking Facebook and Instagram User Accounts

As a result of hijacking the Facebook and Instagram accounts of users over the course of the last year, Meta has fired more than two dozen employees and contractors. A source familiar with the matter and internal documents indicate that some cases involved bribes being offered. On a regular basis, fraudsters target online platforms as […] The post Meta Fired Several Employees For Hijacking Facebook and Instagram User Accounts appeared first on Cyber Security News.
https://cybersecuritynews.com/meta-fired-several-employees-for-hijacking-facebook-and-instagram-user-accounts/?utm_source=dlvr.it&utm_medium=blogger

Friday, November 18, 2022

100 Apps, Endless Security Checks

On average, organizations report using 102 business-critical SaaS applications, enabling operations of most departments across an organization, such as IT and Security, Sales, Marketing, R&D, Product Management, HR, Legal, Finance, and Enablement. An attack can come from any app, no matter how robust the app is.Without visibility and control over a critical mass of an organization’s entire SaaS
https://thehackernews.com/2022/11/100-apps-endless-security-checks.html?utm_source=dlvr.it&utm_medium=blogger

Thursday, November 17, 2022

Warning: New RapperBot Campaign Aims to Launch DDoS Attacks at Game Servers

Cybersecurity researchers have unearthed new samples of malware called RapperBot that are being used to build a botnet capable of launching Distributed Denial of Service (DDoS) attacks against game servers. "In fact, it turns out that this campaign is less like RapperBot than an older campaign that appeared in February and then mysteriously disappeared in the middle of April," Fortinet
https://thehackernews.com/2022/11/warning-new-rapperbot-campaign-aims-to.html?utm_source=dlvr.it&utm_medium=blogger

Retesting: A Re-Pentesting Towards More Secure Products For Red & Blue Teamers

Let’s examine how rigorous retesting of products during a pentest engagement can make products more secure and what goes into performing efficient retesting. Introduction: Why Retesting? First of all, let’s clarify what retesting is. Basically, it’s the very last phase of pentesting and a quite crucial one. After the final report with all found vulnerabilities […] The post Retesting: A Re-Pentesting Towards More Secure Products For Red & Blue Teamers appeared first on Cyber Security News.
https://cybersecuritynews.com/retesting/?utm_source=dlvr.it&utm_medium=blogger

Wednesday, November 16, 2022

Researchers Say China State-backed Hackers Breached a Digital Certificate Authority

A suspected Chinese state-sponsored actor breached a digital certificate authority as well as government and defense agencies located in different countries in Asia as part of an ongoing campaign since at least March 2022. Symantec, by Broadcom Software, linked the attacks to an adversarial group it tracks under the name Billbug, citing the use of tools previously attributed to this actor. The
https://thehackernews.com/2022/11/researchers-say-china-state-backed.html?utm_source=dlvr.it&utm_medium=blogger

Billbug – APT Hackers Group Attack Digital Cert Authority to Intercept The HTTPS Traffic

Researchers uncovered that State-Sponsors APT hackers called “Billbug” attacked and compromise the digital certificate authority in multiple Asian countries along with other government and defense agencies. An ongoing campaign attributed to the infamous APT group Billbug, also known as Lotus Blossom and Thrip. This APT group has been active since 2009, and it has previous […] The post Billbug – APT Hackers Group Attack Digital Cert Authority to Intercept The HTTPS Traffic appeared first on Cyber Security News.
https://cybersecuritynews.com/billbug-apt-malware/?utm_source=dlvr.it&utm_medium=blogger