Industry Spotlight - Security Boulevard https://securityboulevard.com/category/sb/sb-industry-spotlight/ The Home of the Security Bloggers Network Fri, 29 Mar 2024 18:55:00 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Industry Spotlight - Security Boulevard https://securityboulevard.com/category/sb/sb-industry-spotlight/ 32 32 133346385 ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims https://securityboulevard.com/2024/03/darcula-phaas-campaign-sinks-fangs-into-victims/ Fri, 29 Mar 2024 18:55:00 +0000 https://securityboulevard.com/?p=2013455 phishing cybersecurity

A sprawling phishing-as-a-service (PhaaS) campaign that has been running since at least last summer is using more than 20,000 fake domains to target a wide range of organizations in more than 100 countries, illustrating the capabilities of an increasingly popular tool among threat actors. The unknown hackers are using a platform called “Darcula” (sic) that..

The post ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims appeared first on Security Boulevard.

]]>
2013455
PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ Fri, 29 Mar 2024 17:19:26 +0000 https://securityboulevard.com/?p=2013426 Closeup of person going “Shhh!”

Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup.

The post PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found appeared first on Security Boulevard.

]]>
2013426
Apple OTP FAIL: ‘MFA Bomb’ Warning — Locks Accounts, Wipes iPhones https://securityboulevard.com/2024/03/mfa-bomb-apple-otp-richixbw/ Thu, 28 Mar 2024 18:46:58 +0000 https://securityboulevard.com/?p=2013312 Multiple, unskippable notifications

Rethink different: First, fatigue frightened users with multiple modal nighttime notifications. Next, call and pretend to be Apple support.

The post Apple OTP FAIL: ‘MFA Bomb’ Warning — Locks Accounts, Wipes iPhones appeared first on Security Boulevard.

]]>
2013312
Hundreds of Clusters Attacked Due to Unpatched Flaw in Ray AI Framework https://securityboulevard.com/2024/03/hundreds-of-clusters-attacked-due-to-unpatched-flaw-in-ray-ai-framework/ Thu, 28 Mar 2024 13:54:38 +0000 https://securityboulevard.com/?p=2013280 AI vulnerability

Thousands of servers running AI workloads are under attack by threat actors exploiting an unpatched vulnerability in the open-source Ray AI framework – widely used by such companies as OpenAI, Uber, Amazon, Netflix, and Cohere – giving hackers entrée to huge amounts of data and compute power. The campaign has been ongoing for at least..

The post Hundreds of Clusters Attacked Due to Unpatched Flaw in Ray AI Framework appeared first on Security Boulevard.

]]>
2013280
Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data https://securityboulevard.com/2024/03/ghostbusters-facebook-theft-snapchat-richixbw/ Wed, 27 Mar 2024 17:14:37 +0000 https://securityboulevard.com/?p=2013174 Smokey Bear / This-is-fine crossover

Meta MITM IAAP SSL bump: Zuck ordered “Project Ghostbusters”—with criminal consequences, says class action lawsuit.

The post Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data appeared first on Security Boulevard.

]]>
2013174
Complex Supply Chain Attack Targets GitHub Developers https://securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/ Tue, 26 Mar 2024 18:42:46 +0000 https://securityboulevard.com/?p=2013043 supply chain, SBOM, cybersecurity, SLSA organizations third party attacks supply chain supply chain ransomware The Kill Chain Model

Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform, including members of the popular Top.gg community that includes more than 170,000 members. The attackers used a range of tactics and techniques, from leveraging stolen browser cookies to take over accounts to contributing malicious code with..

The post Complex Supply Chain Attack Targets GitHub Developers appeared first on Security Boulevard.

]]>
2013043
Telegram Privacy Nightmare: Don’t Opt In to P2PL https://securityboulevard.com/2024/03/telegram-privacy-nightmare-p2pl-richixbw/ Tue, 26 Mar 2024 17:29:25 +0000 https://securityboulevard.com/?p=2012982 Scary skeletons

Scary SMS shenanigans: Avoid Telegram’s new “Peer-To-Peer Login” program if you value your privacy or your cellular service.

The post Telegram Privacy Nightmare: Don’t Opt In to P2PL appeared first on Security Boulevard.

]]>
2012982
China Steals Defense Secrets ‘on Industrial Scale’ https://securityboulevard.com/2024/03/china-steals-secrets-f5-connectwise-richixbw/ Mon, 25 Mar 2024 17:08:40 +0000 https://securityboulevard.com/?p=2012892 a PRC flag flies in a stiff breeze

UNC5174 ❤ UNC302: CVSS 10 and 9.8 vulnerabilities exploited by Chinese threat actor for People’s Republic.

The post China Steals Defense Secrets ‘on Industrial Scale’ appeared first on Security Boulevard.

]]>
2012892
Tax Scams Ramping Up as the April 15 Deadline Approaches https://securityboulevard.com/2024/03/tax-scams-ramping-up-as-the-april-15-deadline-approaches/ Mon, 25 Mar 2024 12:49:52 +0000 https://securityboulevard.com/?p=2012842 Tax season scams

With the IRS deadline only weeks away, businesses and individuals are racing to get their taxes filed, and bad actors are doing what they can to keep pace with them. Both Microsoft and Malwarebytes in recent days have outlined various scams being used to steal sensitive information, drop malicious payloads, or make payments to fake..

The post Tax Scams Ramping Up as the April 15 Deadline Approaches appeared first on Security Boulevard.

]]>
2012842
Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys https://securityboulevard.com/2024/03/apple-m-gofetch-richixbw/ Fri, 22 Mar 2024 18:56:32 +0000 https://securityboulevard.com/?p=2012710 A green worm on a juicy red apple

GoFAIL: Researchers worm their way into broken cache-filling microcode in most Macs and iPads.

The post Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys appeared first on Security Boulevard.

]]>
2012710