Incident Response Ransomware Security

FBI Cyber Strategy goes from defense to disruption

The FBI’s new cyber strategy shifts the focus toward actively disrupting adversaries, dismantling infrastructure, seizing funds and imposing real costs on attackers. Four pillars drive the strategy: disrupt cyber adversaries, support victims, strengthen partnerships, and enhance the FBI’s own cyber capabilities. Rapid intelligence sharing and closer public-private cooperation should help organizations detect attacks earlier, contain […]

AI Compliance Cybersecurity Infrastructure Security Risk management Security

AI lowers the barrier for attacks on industrial systems

U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]

Privacy Security Surveillance

Does security Ring a bell?

Amazon’s surveillance doorbell company Ring has reached a settlement with the U.S. Federal Trade Commission which will require the company to pay $5.8 million over its inability to keep private footage and audio collected from users’ homes. This action stems from a collection of privacy violations that occurred between 2017 and 2020. Ring customers brought […]

Data Breaches Security Vulnerability

Almost half of websites vulnerable to cyber attack

Almost half of all Dutch company websites are vulnerable to attacks by cyber criminals due to vulnerabilities in software, configurations and web services. The result is often data theft or extortion through ransomware. “Entrepreneurs are insufficiently aware of the risks,” says cybersecurity specialist ID Control based on three studies of web shops, government websites and […]

Multifactor Authentication Password Management Security

Gambling platform DraftKings theft of $300,000 via credential stuffing

Online gambling platform DraftKings has been hit by a credential stuffing attack in which attackers managed to break into users’ accounts and steal some $300,000. Credential stuffing uses previously leaked email addresses and passwords to gain automated account access. Attackers check whether they can also log in to website B with credentials stolen from website […]

Privacy Security

5 Chrome Extensions with 14 million installs steal track users’ browsing activity

All five extensions discovered by McAfee behave with the web app manifest (“manifest.json” file), which dictates how the extension should behave on the system, loads a multifunctional script (B0.js) that sends the browsing data to a domain the attackers control (“langhort[.]com”).The data is delivered through via POST requests each time the user visits a new URL. The info reaching […]