The latest Gone Phishin' event, finds that about 20% of the subjects were compromised by a simulated phishing email; almost 15% did not recognize a malicious download site. Larger organizations, or those that would be expected to have more robust security training programs, tended to fare the worst.
BitMart crypto exchange was victimized with a total loss of about $196 million. BitMart has said that it will compensate victims of the crypto theft, but it is using its own internal estimate of $150 million in losses as a guideline.
Pernicious botnet used for cryptojacking has taken a major blow thanks to Google. Glupteba has been operating for some months and was thought to be compromising thousands of people per day at its peak.
Many organizations affected by Log4j’s zero-day vulnerability with mass internet scanning detected, suggesting the remote code execution flaw was actively targeted in the wild.
The Tor network will no longer be officially available to residents of Russia after a government ban. Taking a path that somewhat resembles China's program of internet control, the Russian government has made a series of moves to restrict access to websites.
Apple's privacy rules will still block developers from the convenience of using each device's unique identifying number without permission, but it appears a number of anonymized device-level "signals" will now be fair game for ad tracking purposes.
noyb has leaked documents that show Facebook approached the EDPB with their concept of “user contracts” that sidestep GDPR rules for user consent after numerous receptive meetings with the Irish DPC.
Botnet discovered by Chinese researchers introduced a backdoor and a web shell on compromised AT&T VoIP servers, mostly in the US, for DDoS attacks and data exfiltration.
Colorado Energy Company, Delta-Montrose Electric Association (DMEA), suffered a malicious cyber attack that shut down 90% of its internal controls and wiped 25 years of historical data.
A new survey reveals deepening frustration with legacy IT vendors such as Microsoft, as supply chain attacks and ransomware attacks fed by vulnerabilities in their software become the "new normal.”










