Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for ISB Staff Reporter - Page 12

ISB Staff Reporter

ISB Staff Reporter

Tech Contractor Exposes Data of 4.6 Million US Voters

ISB Staff ReporterAugust 7, 20242 Mins Read

A US technology contractor has inadvertently exposed the personal data of 4.6 million voters and election documents from multiple counties in Illinois, sparking significant concerns over election security and voter privacy. The databases, managed by Platinum Technology Resource, were found to be unprotected by passwords and included sensitive information like full names, addresses, dates of birth, driver’s license numbers, and Social Security numbers. This breach was uncovered by cybersecurity researcher Jeremiah Fowler, who reported his findings to vpnMentor. “I discovered a variety of documents, including voting records, ballot templates, and voter registrations, all originating from a single county in Illinois,”…

Read More

Proficio Unveils ProBAS Breach and Attack Simulation Service

ISB Staff ReporterAugust 6, 20242 Mins Read

Proficio, a Managed Detection and Response (MDR) provider, has rolled out its ProBAS Breach and Attack Simulation service. The solution “rigorously” tests businesses’ security defenses, to ensure they can prevent compromise events and detect attacks throughout the entire threat detection and response process. From device alert logs to SIEM, SOC detection, and containment response actions, ProBAS covers all aspects. Brad Taylor, co-founder and CEO, Proficio, says threat actors only need to be lucky once, but cyber defenders must be vigilant and successful at countering attacks every time in order to protect their environment. ProBAS, he says, identifies potential threats, and implements…

Read More

LianSpy Spyware ‘LianSpy’ Targets Android Users

ISB Staff ReporterAugust 6, 20243 Mins Read

Security researchers at Kaspersky have uncovered a new Android spyware campaign called LianSpy, which has been used for cyberespionage against targeted Android device users in Russia. The malware, dubbed “LianSpy,” has been in operation since July 2021, quietly harvesting sensitive data and employing advanced evasion techniques to remain undetected. LianSpy is designed to capture screencasts, exfiltrate user files, and harvest call logs and app lists. The spyware leverages multiple evasive tactics, such as using the Russian cloud service Yandex Disk for command and control (C2) communications and avoiding dedicated infrastructure, to stay under the radar. Notably, LianSpy’s developers use techniques…

Read More

Wristband Releases Public Beta of its B2B Authentication Platform

ISB Staff ReporterAugust 5, 20242 Mins Read

Wristband, a developer-first authentication platform designed for B2B SaaS, has released the public beta launch of its B2B authentication platform. Jim Verducci, CEO of Wristband, says building robust B2B authentication in-house is a complex and time-consuming process that can take business leaders away from their core business. “Wristband eliminates the need for developers to reinvent the wheel, providing them with a secure-by-default, multi-tenant platform that can be easily customized and scaled,” he says. Wristband will democratize enterprise-grade authentication for millions of small businesses that are priced out of the most secure authentication platforms. “Small businesses have been locked out of…

Read More

Evasive Panda Compromises ISP to Distribute Malicious Software Updates

ISB Staff ReporterAugust 5, 20243 Mins Read

The cyber espionage group dubbed Evasive Panda (also known as StormBamboo and previously tracked as StromCloud) compromised an unnamed Internet Service Provider (ISP) in mid-2023 to push malicious software updates to target entities. This incident marks a significant escalation in the sophistication of the group’s tactics. StormBamboo, active since at least 2012, is known for using backdoors like MgBot (also known as POCOSTICK) and Nightdoor (NetMM and Suzafk) to collect sensitive information. The group has recently been linked to the macOS malware strain MACMA, observed in the wild since 2021. “StormBamboo is a highly skilled and aggressive threat actor who…

Read More

Infosec Institute Partners with Career.io to Help Students Launch Cybersecurity Careers

ISB Staff ReporterAugust 2, 20243 Mins Read

Infosec Institute, a cybersecurity education provider, is parterning with Career.io, a provider of professional career-development products and services. This collaboration aims to offer comprehensive career services to students enrolled in Infosec’s Immersive Boot Camps, equipping them with the skills and support needed to transition into entry-level cybersecurity roles successfully. Students enrolling in the Cybersecurity Foundations Immersive Boot Camp will receive 30-day access to premium career services from Career.io, including AI-assisted resume and cover letter tools, a salary analyzer, and a job tracker. They will also benefit from a professional resume rewrite, LinkedIn makeover, and expert interview preparation through career.io’s sister…

Read More

DNS Vulnerability: ‘Sitting Ducks’ Exposes Millions of Domains to Hijacking

ISB Staff ReporterAugust 2, 20243 Mins Read

A recently discovered vulnerability in the Domain Name System (DNS), dubbed ‘Sitting Ducks,’ has left millions of domains susceptible to hijacking. This attack vector, actively exploited since 2019, enables threat actors to deliver malware, phish, impersonate brands, and exfiltrate data. Researchers at Infoblox and Eclypsium identified the vulnerability, coordinating with law enforcement and national Computer Emergency Response Teams (CERTs) since June 2024. The issue arises when a registered domain or subdomain uses authoritative DNS services from a provider different from the domain registrar, a process known as name server delegation. If the authoritative name server lacks information about the domain,…

Read More

How AI is Shaping Fraud: VIPRE Reveals 40% of BEC Emails Are Now AI-Generated 

ISB Staff ReporterJuly 31, 20243 Mins Read

Nearly half (49%) of spam emails can be attributed to BEC scams, with the CEO, HR, and IT being the most common targets. Alarmingly, some 40% of BEC emails are AI-generated, and in some instances, AI more than likely created the entire message. These were two of the findings of the VIPRE Q2 2024 Email Threat Trends Report, which processed 1.8 billion emails globally, detecting 226.45 million spam emails and 16.91 million malicious URLs to identify the email threat trends that impact organizations the most. According to the company, the report shines the spotlight on the ingenuity of malicious actors…

Read More

Dark Angels gang scores a record-breaking $75 million ransom

ISB Staff ReporterJuly 31, 20243 Mins Read

Over the past year, ransomware attacks have reached unprecedented levels of ambition and boldness, highlighted by a significant increase in extortion attacks. In fact, research from Zscaler ThreatLabz revealed an unparalleled ransom payout of $75 million – the highest ever paid by a single company, nearly double the previously known record. Moreover, last year, ransomware payments surpassed $1 billion, emphasizing the growing financial impact of these cybercrimes. According to the security giant, ransomware actors have become increasingly sophisticated and daring. They’ve pushed beyond the typical corporate targets, even threatening the children of executives to secure faster and higher ransoms. No…

Read More
Previous 1 … 10 11 12
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}