The Breach News

New Study Highlights Insider Risks Linked to Poor Offboarding Practices

The Importance of Effective Offboarding Practices in Mitigating Insider Risks A recent analysis by Wing Security has revealed a concerning trend in corporate data security: approximately 63% of businesses might have former employees still authorized to access sensitive organizational data. This statistic underscores the pressing need for businesses to automate…

Read MoreNew Study Highlights Insider Risks Linked to Poor Offboarding Practices

Partners Must Embrace a Breach-Aware Mindset: Insights from Illumio – ARN

Illumio Advocates for Zero Trust Approach Amid Rising Cybersecurity Threats In the evolving landscape of cybersecurity, Illumio, a leading vendor specializing in zero trust segmentation, emphasizes the necessity of adopting an “assumed breach” mindset. This approach posits that organizations should act as if a breach has already occurred, regardless of…

Read MorePartners Must Embrace a Breach-Aware Mindset: Insights from Illumio – ARN

FlyingYeti Leverages WinRAR Vulnerability to Deploy COOKBOX Malware in Ukraine

Cloudflare Disrupts Phishing Campaign Targeting Ukrainian Entities On Thursday, Cloudflare announced that it has taken measures to disrupt an extensive phishing campaign that has been ongoing for a month. This operation is attributed to a Russia-aligned threat actor known as FlyingYeti, which has specifically targeted Ukraine amidst ongoing tensions in…

Read MoreFlyingYeti Leverages WinRAR Vulnerability to Deploy COOKBOX Malware in Ukraine

Arid Viper Targets Arabic Android Users with Spyware Masquerading as a Dating App

The cyber threat group known as Arid Viper, also referred to as APT-C-23 or Desert Falcon, has emerged as the perpetrator behind a recent Android spyware campaign aimed at Arabic-speaking individuals. This sophisticated operation involves the distribution of a fake dating application that is designed to infiltrate users’ devices, extracting…

Read MoreArid Viper Targets Arabic Android Users with Spyware Masquerading as a Dating App

New Xiū gǒu Phishing Kit Targets Key Sectors in the UK, US, Japan, and Australia

Cybersecurity experts at Netcraft have identified a sophisticated phishing kit named “Xiū gǒu,” which has been active since September 2024 and is specifically targeting users in multiple countries, including the UK, US, Spain, Australia, and Japan. This malicious toolkit exploits a range of public and private sector services, such as…

Read MoreNew Xiū gǒu Phishing Kit Targets Key Sectors in the UK, US, Japan, and Australia

Sophos Reveals Five Years of Ongoing Chinese Cyberattacks

Volt Typhoon, APT31, APT41 Target Sophos Firewall Devices: A Wake-Up Call for Cybersecurity In a significant disclosure, firewall manufacturer Sophos reported a sustained five-year assault by various Chinese state-sponsored hacking groups on its security appliances. The revelation, described by Sophos as a crucial wake-up call for the cybersecurity sector, highlights…

Read MoreSophos Reveals Five Years of Ongoing Chinese Cyberattacks

U.S. Takes Down the World’s Largest 911 S5 Botnet, Involving 19 Million Infected Devices

The United States Department of Justice (DoJ) announced on Wednesday the dismantling of what it claims to be “likely the world’s largest botnet,” which was composed of approximately 19 million compromised devices. These infected machines were made available to various malicious actors for a variety of cybercrimes. This extensive botnet,…

Read MoreU.S. Takes Down the World’s Largest 911 S5 Botnet, Involving 19 Million Infected Devices