Tuesday , January 28 2025

infosecbulletin

CISA, NSI, FBI released critical infrastructure defense tips against Volt Typhoon

logo

CISA, NSA, FBI, and other US and international partners released a joint fact sheet called “People’s Republic of China State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders.” This publication includes contributions from various partners. U.S. Department of Energy (DOE) U.S. Environmental Protection Agency (EPA) U.S. Transportation Security Administration (TSA) U.S. …

Read More »

Trend Micro report
Earth Krahang hackers breach 70 orgs in 23 countries

hacker

The APT group ‘Earth Krahang’ has hacked 70 organizations and attacked at least 116 in 45 countries. Trend Micro researchers have been monitoring a campaign targeting government organizations since early 2022. The group targeted 116 organizations in 35 countries and confirmed at least 70 compromises, including organizations linked to world …

Read More »

IBM X-Force report
APT28 Hacker Group Targeting Asia in Widespread Phishing Scheme

Networking

As of March 2024, X-Force is tracking the APT28 group is carrying out phishing campaigns using fake government and non-governmental organization documents to target different regions around the world, including Central Asia, Europe, the South Caucasus, and North and South America. The discovered lures include a mix of public and …

Read More »

‘Hell Paradise’ Claims
Government Websites in 49 Countries at Risk

dark web

According to FalconFeeds x post, a threat actor has listed 49 countries as part of an experiment. They also claim that over 1000 government sites are vulnerable. According to Cyber Express, the threat actor is promoting an onion website called ‘Hell Paradise’ which aims to obtain vulnerable government sites and …

Read More »

EU Parliament Approves Artificial Intelligence Act

EU

* Safeguards on general purpose artificial intelligence * Limits on the use of biometric identification systems by law enforcement * Bans on social scoring and AI used to manipulate or exploit user vulnerabilities * Right of consumers to launch complaints and receive meaningful explanations On Wednesday, Parliament approved the Artificial …

Read More »

Brilliant Cloud: A public cloud service provider in Bangladesh

brilliant cloud

InterCloud Limited is a company in Bangladesh that is part of a group with businesses in garment manufacturing, aviation, and telecommunications. Tusuka is known for making denim products in Bangladesh. Novoair is a premium passenger airline in Bangladesh with seven ATR-72 aircraft. In 2008, Novotel Limited started in the telecommunications …

Read More »

CISA Releases Fifteen Industrial Control Systems Advisories

industry

CISA released 15 advisories about Industrial Control Systems (ICS) on March 14, 2024. The advisories include important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-074-01 Siemens SENTRON 7KM PAC3x20 ICSA-24-074-02 Siemens Solid Edge ICSA-24-074-03 Siemens SINEMA Remote Connect Server ICSA-24-074-04 Siemens SINEMA Remote Connect Client ICSA-24-074-05 Siemens …

Read More »

IMF email account compromised: Investigates ongoing

IMF

The International Monetary Fund (IMF) recently experienced a cyber incident, which was detected on February 16, 2024. After further investigation with help from cybersecurity experts, the breach was identified, and steps were taken to fix it. The investigation found that 11 IMF email accounts were hacked. The affected accounts have …

Read More »

StopCrypt: Most widely distributed ransomware evades detection

StopCrypt

The SonicWall Capture Labs threat research team recently observed a new variant of StopCrypt ransomware. The ransomware executes its malicious activities by utilizing multi-stage shellcodes before launching a final payload that contains the file encryption code. StopCrypt, also known as STOP Djvu, is a widely spread ransomware, as reported by …

Read More »