Cyber (In)Securities – Issue 107

Contents: News Analysis Events News: Black Friday turning into Black Fraud Day, says UK cybersecurity chief https://www.theguardian.com/business/2024/nov/18/black-friday-turning-into-black-day-says-uk-cybersecurity-chief The UK’s cybersecurity chief has sounded an alarm over the growing risks of Black Friday, warning that cybercriminals are exploiting the shopping frenzy to conduct widespread online fraud. Tactics like phishing emails, counterfeit websites, and fraudulent ads are […]

Cyber (In)Securities – Issue 106

Contents: News Analysis Events News: NSO – not government clients – operates its spyware, legal documents https://www.theguardian.com/technology/2024/nov/14/nso-pegasus-spyware-whatsapp New legal documents suggest that NSO Group, not its government clients, operates the Pegasus spyware used to hack into devices. This claim contradicts NSO’s public stance that only authorised government entities handle its software, sparking fresh controversy over […]

Cyber (In)Securities – Issue 105

Contents: News Analysis Events News: Amazon confirms employee data breach after vendor hack https://www.bleepingcomputer.com/news/security/amazon-confirms-employee-data-breach-after-vendor-hack/ Amazon has confirmed that a data breach compromised employee information following a cyberattack on one of its third-party vendors. The breach exposed sensitive employee data, raising concerns about the security of Amazon’s vendor relationships and highlighting the broader risk posed by […]

Cyber (In)Securities – Issue 104

Contents: News Trust in Focus [Monthly Supplement] Events News: 24% of CISOs Actively Looking to Leave Their Jobs https://www.csoonline.com/article/3595796/24-of-cisos-actively-looking-to-leave-their-jobs.html A recent survey reveals that 24% of Chief Information Security Officers (CISOs) are actively seeking new job opportunities, with many others contemplating leaving within three years due to extreme stress, insufficient executive support, and intense workloads. […]

Cyber (In)Securities – Issue 103

Contents: News Analysis Events News: DocuSign’s Envelopes API abused to send realistic fake invoices https://www.bleepingcomputer.com/news/security/docusigns-envelopes-api-abused-to-send-realistic-fake-invoices/ Cybercriminals are exploiting DocuSign’s Envelopes API to deliver highly convincing fake invoices, tricking recipients into clicking on malicious links. By abusing this legitimate API, attackers are able to create phishing emails that appear authentic, bypassing traditional security filters and making […]

Cyber (In)Securities – Issue 102

Contents: News Events News: LottieFiles hacked in supply chain attack to steal users’ crypto https://www.bleepingcomputer.com/news/security/lottiefiles-hacked-in-supply-chain-attack-to-steal-users-crypto/ LottieFiles, a platform for animated graphics, recently suffered a supply chain attack compromising its ‘lottie-player’ library versions 2.0.5 to 2.0.7. The attackers injected malicious code designed to steal cryptocurrency by prompting users to connect their wallets, subsequently draining their assets. […]

Cyber (In)Securities – Issue 101

Contents: News Analysis Events News: 1. Cybercriminals Pose a Greater Threat of Disruptive US Election Hacks Than Russia or China https://www.wired.com/story/cybercriminals-disruptive-hacking-us-elections-dhs-report As the 2024 U.S. election season unfolds, the Department of Homeland Security highlights that cybercriminals, motivated by financial or ideological aims, pose a more direct risk to election infrastructure than state-backed actors. While nation-states […]

Cyber (In)Securities – Issue 100

Welcome to our 100th edition of the Cybersecurity Advisors Network newsletter—newly renamed Cyber (In)Securities! What began as a simple way to keep you informed has grown into a dynamic and evolving resource, all thanks to your engagement and feedback. Over time, we’ve refined our format (and our name!), and shared insights into the ever-changing world […]