Blog
-
MFA Log Theft at Cisco Duo Caused by Third Party Breach, Customers at Risk of Follow-up Scams
Customers of Cisco Duo are advised to be on heightened alert for phishing and identity theft attempts, as the authentication service has revealed that a third party breach resulted in some MFA logs being stolen.
-
Attempted Audio Deepfake on LastPass is “The New Normal” for Voice Phishing
Employee targeted in the voice phishing attack received several different deepfake call attempts and at least one voicemail message, but did not respond as it’s exceedingly rare for anyone to communicate internally via WhatsApp, let alone for the CEO to randomly start peppering an employee with messages after business hours.
-
Change Healthcare Caught up in Another Cyber Extortion Attempt
A Februrary attack on Change Healthcare was enough of a national disruption to prompt federal government action, and now the company is dealing with a second cyber extortion attempt that may involve some of the perpetrators from the first.
-
Microsoft Faces Harsh Criticism as DHS Report Finds Company at Fault for 2023 Security Breach by Chinese Hackers
Microsoft’s security breach, which essentially gave the Chinese hackers the ability to walk into any Exchange Online email account and ended up impacting at least 500 people in high-ranking positions, would have been unthinkable at one time.
-
2021 AT&T Data Leak Revealed to be Legitimate, 73 Million Records Uploaded to Public Forum
While about 7.6 million current AT&T customers are impacted by the data leak, the vast majority (65.4 million) are former customers from before the start of 2020. Aside from partial SSNs, the most worrying item in the data leak is the account passcodes.
-
U.S. Federal Agencies Face New Wave of AI Rules
The AI rules require federal agencies to not just conduct ongoing testing and audits, but also to make much of their internal workings transparent to the public. That will include annual inventories of AI use cases, data used to train and support models, and also code.
-
Apple’s Privacy and Security Branding Scrutinized in New DOJ Antitrust Lawsuits
The antitrust lawsuit is perhaps best summed up in its characterization of Apple’s privacy and security policies as an “elastic shield” that it can selectively move when a business opportunity suits it.
-
Phishing Attacks Available to More Non-Technical Actors as MFA Bypass Kits Surface
A group called Tycoon is offering an MFA bypass tool, and it appears to be a popular option selling at $120 to $320 depending on the length of time the client wants to access it. This subscription also provides email templates for use in phishing attacks.
-
Chinese Hacking Group’s Decade of Cyber Espionage and Cyber Attacks Draws Sanctions From US, UK
Both the US and UK slapped sanctions on a company called Wuhan Xiaoruizhi Science and Technology that is believed to be a front for Chinese cyber attacks. The US accused APT31 of a decade-long cyber espionage campaign.
-
Loop DoS Attack Exploits UDP Protocol, Can Cripple Vulnerable Systems Without the Use of a Botnet
Attacker can initiate an essentially endless error message string against a target that will eventually result in a DoS attack consuming all available resources. The study’s authors believe that there are about 300,000 vulnerable systems.










