India’s telecom regulator has ordered service providers to block all unwanted calls from unregistered senders in a major move “to curb the increasing number of spam calls.” In case of a violation, the service providers will face disconnection of their networks for up to two years, India’s Telecom Regulatory Authority …
Read More »Microsoft 365 anti-phishing protection can be bypassed with CSS
Researchers found a way to get around a security measure in Microsoft 365, making it more likely for users to open harmful emails. Outlook has a hidden anti-phishing measure called the ‘First Contact Safety Tip.’ It warns recipients when they receive an email from an unfamiliar address. Outlook displays an …
Read More »EU’s World-First Artificial Intelligence Rules Officially Taking Effect
The European Union’s artificial intelligence law, the first of its kind in the world, officially came into effect on Thursday. This is a significant step in the EU’s efforts to regulate this technology. The Artificial Intelligence Act aims to protect the “fundamental rights” of citizens in the 27-nation bloc and …
Read More »CISA issues nine industrial control system advisories
CISA released nine advisories about Industrial Control Systems (ICS) on August 1, 2024. They give important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-214-01 Johnson Controls exacqVision Client and exacqVision Server ICSA-24-214-02 Johnson Controls exacqVision Web Service ICSA-24-214-03 Johnson Controls exacqVision Web Service ICSA-24-214-04 Johnson Controls exacqVision …
Read More »India’s central bank fines Visa for unauthorised payment transfer
The Reserve Bank of India fined Visa 24.1 million rupees (nearly $288,000) for using an unauthorized payment transfer system. The central bank made this announcement on Friday (July 26). “It was discovered that the entity (Visa) had implemented a payment authentication solution without regulatory clearance from the RBI,” the central …
Read More »EU 109 Banks, Cyber Stress Test; “room for improvement”
Stress test gauged how banks would respond to and recover from severe but plausible cybersecurity incident 109 banks tested, of which 28 underwent more extensive testing Results to feed into ECB’s 2024 Supervisory Review and Evaluation Process The European Central Bank (ECB) is set to conduct its first thematic stress …
Read More »New DNS Vulnerability “TuDoor” Threatens Internet Security
A new critical vulnerability in the Domain Name System (DNS) has been found. This vulnerability allows a specialized attack called “TuDoor” that can poison DNS caches, cause denial-of-service (DoS) attacks, and deplete resources, posing a significant threat to internet security. Specialists have conducted experiments that confirm the feasibility of the …
Read More »Threat Actor announce new DDoS Panel “Cliver”
A threat actor has announced a new DDoS tool called Cliver, which offers strong attack methods for disrupting web services, including HTTP/2 and TLS floods, Cloudflare bypass, and browser emulation for bypassing CAPTCHA. The threat actor shared more information in a FAQ section. Cliver is a strong Layer 7 (L7) …
Read More »
Nacsa investigates
Malaysia Telco U Mobile Four Million user data allegedly Breached
Malyasian National Cyber Security Agency (Nacsa) is investigating a possible data breach that exposed the data of four million U Mobile subscribers. The data, which claimed to contain personal information like names, addresses, MyKad numbers, andThe data, which may include personal information like names, addresses, MyKad numbers, and mobile phone …
Read More »Kaspersky offers free security software for six months
Kaspersky is offering free security products and safety tips for six months to consumers in the United States. The company decided to close its business and lay off employees in the U.S. after the U.S. government added Kaspersky to the Entity List, a catalog of “foreign individuals, companies, and organizations …
Read More »