Cyber (In)Securities – Issue 112

Contents: News Analysis CyAN Members Op Eds and Articles Events News: BT Group confirms attackers tried to break into Conferencing division https://www.theregister.com/2024/12/05/bt_group_confirms_attempted_attack/ BT Group recently disclosed an attempted cyberattack on its Conferencing division, thwarted before significant damage occurred. The attackers targeted vulnerabilities in communication systems, 

Cyber (In)Securities – Issue 111

Contents: News Analysis CyAN Members Op Eds and Articles Events News: Russia arrests one of its own – a cybercrime suspect on FBI’s most wanted list https://www.theregister.com/2024/12/02/russia_ransomware_arrest/ Russia has detained a high-profile cybercriminal who was on the FBI’s most-wanted list. This rare collaboration between the 

Cyber (In)Securities – Issue 110

Contents: News Analysis Statistics & Insights – Powered by evisec CyAN News Events News: Labor has passed its proposed social media ban for under-16s. Here’s what we know – and what we don’t https://www.theguardian.com/australia-news/2024/nov/21/labor-social-media-ban-under-16s-details-what-is-covered-which-platform The newly passed social media ban for under-16s without parental consent 

Cyber (In)Securities – Issue 109

Contents: News Analysis CyAN News Events News: Australia’s first Cyber Security Act becomes law https://ia.acs.org.au/article/2024/australia-s-first-cyber-security-act-becomes-law.html Australia’s inaugural Cyber Security Act has officially passed, mandating critical infrastructure providers to adopt stringent cybersecurity measures. The legislation focuses on protecting essential services like energy, health, and communications from 

Cyber (In)Securities – Issue 108

Contents: News Analysis Events News: Ransomhub ransomware gang claims the hack of Mexican government legal Affairs Office https://securityaffairs.com/171257/data-breach/mexico-suffers-ransomware-attack.html The Ransomhub ransomware group has claimed responsibility for a cyberattack targeting Mexico’s Legal Affairs Office, alleging it has exfiltrated critical government documents. The group is threatening to 

Cyber (In)Securities – Issue 107

Contents: News Analysis Events News: Black Friday turning into Black Fraud Day, says UK cybersecurity chief https://www.theguardian.com/business/2024/nov/18/black-friday-turning-into-black-day-says-uk-cybersecurity-chief The UK’s cybersecurity chief has sounded an alarm over the growing risks of Black Friday, warning that cybercriminals are exploiting the shopping frenzy to conduct widespread online fraud. 

Cyber (In)Securities – Issue 106

Contents: News Analysis Events News: NSO – not government clients – operates its spyware, legal documents https://www.theguardian.com/technology/2024/nov/14/nso-pegasus-spyware-whatsapp New legal documents suggest that NSO Group, not its government clients, operates the Pegasus spyware used to hack into devices. This claim contradicts NSO’s public stance that only 

Cyber (In)Securities – Issue 105

Contents: News Analysis Events News: Amazon confirms employee data breach after vendor hack https://www.bleepingcomputer.com/news/security/amazon-confirms-employee-data-breach-after-vendor-hack/ Amazon has confirmed that a data breach compromised employee information following a cyberattack on one of its third-party vendors. The breach exposed sensitive employee data, raising concerns about the security of 

Cyber (In)Securities – Issue 104

Contents: News Trust in Focus [Monthly Supplement] Events News: 24% of CISOs Actively Looking to Leave Their Jobs https://www.csoonline.com/article/3595796/24-of-cisos-actively-looking-to-leave-their-jobs.html A recent survey reveals that 24% of Chief Information Security Officers (CISOs) are actively seeking new job opportunities, with many others contemplating leaving within three years 

Cyber (In)Securities – Issue 103

Contents: News Analysis Events News: DocuSign’s Envelopes API abused to send realistic fake invoices https://www.bleepingcomputer.com/news/security/docusigns-envelopes-api-abused-to-send-realistic-fake-invoices/ Cybercriminals are exploiting DocuSign’s Envelopes API to deliver highly convincing fake invoices, tricking recipients into clicking on malicious links. By abusing this legitimate API, attackers are able to create phishing