The Breach News

New Android Trojan ‘SoumniBot’ Outwits Detection with Smart Techniques

A new Android Trojan, named SoumniBot, has been uncovered, specifically targeting users in South Korea by exploiting vulnerabilities in the Android manifest extraction and parsing procedures. This malware is distinctive for its unconventional methods of evasion, particularly through the obfuscation of the Android manifest, as revealed by Kaspersky researcher Dmitry…

Read MoreNew Android Trojan ‘SoumniBot’ Outwits Detection with Smart Techniques

Majority of Cybersecurity Breaches Originate from Third-Party Vendors – Medical Buyer

In a recent address at the HIMSS Healthcare Cybersecurity Forum, cybersecurity experts John Riggi and Richard Staynings emphasized the significant cybersecurity threats that arise from third-party vendors and associated organizations. Riggi, a former FBI special agent and a national advisor for Cybersecurity and Risk at the American Hospital Association, highlighted…

Read MoreMajority of Cybersecurity Breaches Originate from Third-Party Vendors – Medical Buyer

Google Addresses Another Actively Exploited Chrome Zero-Day Vulnerability

Google Addresses Critical Security Flaws in Chrome Browser In a proactive response to ongoing security concerns, Google has deployed patches to rectify nine significant vulnerabilities in its Chrome web browser, one of which is a serious zero-day flaw that has reportedly been exploited in the wild. This vulnerability, designated as…

Read MoreGoogle Addresses Another Actively Exploited Chrome Zero-Day Vulnerability

Cybercriminals Leverage Phishing and EV Certificates to Distribute Ransomware

The cyber threat landscape continues to evolve as researchers from Trend Micro report that the perpetrators behind the RedLine and Vidar information stealers are shifting their tactics to include ransomware attacks. This alarming trend has been facilitated through phishing campaigns that distribute malware utilizing Extended Validation (EV) code signing certificates,…

Read MoreCybercriminals Leverage Phishing and EV Certificates to Distribute Ransomware

Three UK Local Council Websites Targeted by DDoS Cyber Attacks

DDoS Attack Disrupts Three UK Councils: NoSensitive Data Compromised In a recent cybersecurity incident, three councils in the United Kingdom—Salford, Portsmouth, and Middlesbrough—experienced significant disruptions due to a Distributed Denial of Service (DDoS) attack. These attacks led to temporary outages, rendering the councils’ websites inaccessible to users and hampering public…

Read MoreThree UK Local Council Websites Targeted by DDoS Cyber Attacks

Leading Financial and Cybersecurity Experts to Converge at ISMG’s NYC Summit

Finance & Banking, Industry Specific, Next-Generation Technologies & Secure Development Summit on Nov. 7 to Address Evolving Cyber Risks in Finance Chris Riotta (@chrisriotta) • November 4, 2024 Leading cybersecurity professionals will gather on November 7 for ISMG’s Financial Services Summit to address financial sector vulnerabilities. (Image: Shutterstock) The 2024…

Read MoreLeading Financial and Cybersecurity Experts to Converge at ISMG’s NYC Summit

Urgent: Zero-Day Vulnerability in CrushFTP Exploited in Targeted Attacks

CrushFTP Users Urged to Update Following Newly Discovered Vulnerability The CrushFTP enterprise file transfer software has been hit by a security vulnerability that is reportedly being exploited in active attacks. In a recent advisory, CrushFTP informed its users that versions of the software prior to 11.1 are susceptible to a…

Read MoreUrgent: Zero-Day Vulnerability in CrushFTP Exploited in Targeted Attacks