Money Laundering Dominates UK Fraud Cases

The number of fraud cases heard in UK Crown Courts in the first half of the year was up 16% on the same period in 2023, with money laundering the most common type by value, according to KPMG. The consulting…

The number of fraud cases heard in UK Crown Courts in the first half of the year was up 16% on the same period in 2023, with money laundering the most common type by value, according to KPMG. The consulting…

Aug 28, 2024Ravie LakshmananPhishing Attack / Data Breach Cybersecurity researchers are calling attention to a new QR code phishing (aka quishing) campaign that leverages Microsoft Sway infrastructure to host fake pages, once again highlighting the abuse of legitimate cloud offerings…

Aug 28, 2024Ravie LakshmananSoftware Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw affecting the Apache OFBiz open-source enterprise resource planning (ERP) system to its Known Exploited Vulnerabilities (KEV) catalog, citing…

Aug 28, 2024Ravie LakshmananWordPress Security / Website Protection A critical security flaw has been disclosed in the WPML WordPress multilingual plugin that could allow authenticated users to execute arbitrary code remotely under certain circumstances. The vulnerability, tracked as CVE-2024-6386 (CVSS…

The Port of Seattle has been hit by a suspected cyber-attack, heavily disrupting airport and maritime services in the city ahead of Labor Day. The ongoing IT outage, which started on August 24, has led to significant delays to the…

Want to know what’s the latest and greatest in SecOps for 2024? Gartner’s recently released Hype Cycle for Security Operations report takes important steps to organize and mature the domain of Continuous Threat Exposure Management, aka CTEM. Three categories within…

In a recent disclosure to the Maine Attorney General’s Office, the Texas Dow Employees Credit Union (TDECU) has revealed that over 500,000 of its members had their personal information compromised due to a data breach involving the MOVEit file transfer…

Aug 27, 2024Ravie LakshmananCyber Espionage / Malware Users of Chinese instant messaging apps like DingTalk and WeChat are the target of an Apple macOS version of a backdoor named HZ RAT. The artifacts “almost exactly replicate the functionality of the…

In episode 13 of “The AI Fix””, meat avatar Cluley learns that AI doesn’t pose an existential threat to humanity and tells meat avatar Stockley how cybersex is about to get very, very weird. Our hosts also learn that men…

A vulnerability in Microsoft 365 Copilot that allowed attackers to steal users’ sensitive information has been disclosed by a cybersecurity researcher. Johann Rehberger, who discovered the flaw, described the exploit chain in a blog post published on August 26. The attack…