Saturday , January 25 2025

infosecbulletin

CISA released best practices to secure Microsoft 365 Cloud environments

Microsoft 365

CISA has issued Binding Operational Directive (BOD) 25-01, requiring federal civilian agencies to improve the security of their Microsoft 365 cloud environments. This directive is part of CISA’s effort to reduce risks from cloud misconfigurations and weak security controls that have been targeted in recent cyberattacks. BOD 25-01 introduces Secure …

Read More »

Data breach! Ireland fines Meta $264 million, Australia $50m

Meta

The Irish Data Protection Commission fined Meta €251 million ($263.6 million) for GDPR violations related to a 2018 data breach that affected 29 million Facebook accounts. The breach occurred when unauthorized parties exploited user access tokens, exposing sensitive information like names, email addresses, phone numbers, and physical locations, including data …

Read More »

Over 25K SonicWall VPN Firewalls exposed to critical flaws

sonicwall

More than 25,000 SonicWall SSL VPN devices are vulnerable to critical flaws, with 20,000 running outdated SonicOS/OSX firmware that is no longer supported. This analysis by cybersecurity firm Bishop Fox was prompted by key vulnerabilities disclosed this year in SonicWall devices. Ransomware groups, like Fog and Akira, have recently exploited …

Read More »

Over 4 lac files ‘leaked’: Telecom Namibia hit by major cyberattack

Telecom Namibia

Telecom Namibia experienced a cyber incident that leaked customer data. The company is working with local and international cybersecurity experts to evaluate the situation. CEO Stanley Shanapinda stated that Telecom Namibia will responsibly address the issue and will provide a detailed statement soon. “As cyber incidents have become widespread and …

Read More »

HSBC sued by ASIC: customers allegedly scammed of $23 million

HSBC

HSBC Bank Australia Limited did not sufficiently safeguard customers from scams that resulted in millions of dollars being lost, as stated in documents filed by The Australian Securities and Investments Commission (ASIC) ASIC in the Federal Court today. ASIC claims that HSBC Australia lacked sufficient controls to prevent unauthorized payments …

Read More »

Android malware attack Indian banks: Infected 419 devices

Android

Researchers discovered a new Android banking trojan aimed at Indian users. This malware pretends to be essential utility services to deceive users into sharing sensitive information. The malware has compromised 419 devices, intercepted 4,918 SMS messages, and stolen 623 banking credentials. The ongoing campaign is expected to affect more devices …

Read More »

Indian-American OpenAI whistleblower Suchir Balaji found dead in San Francisco

A whistleblower from OpenAI, Suchir Balaji, an Indian-American ex-researcher at OpenAI who criticized the company’s practices, was found dead in his San Francisco apartment on November 26. Anandabazar said, Primarily the police suspect it to be a case of suicide. Balaji, who left OpenAI in August after four years, was …

Read More »