y

Cyber Threats That Could Impact the Retail Industry This Holiday Season (and What to Do About It)

As the holiday season approaches, retail businesses are gearing up for their annual surge in online (and in-store) traffic. Unfortunately, this increase in activity also attracts cybercriminals looking to exploit vulnerabilities for their gain.  Imperva, a Thales company, recently published its annual holiday shopping cybersecurity guide. Data from the Imperva Threat Research team’s




y

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Oct 28 - Nov 03)

This week was a total digital dumpster fire! Hackers were like, "Let's cause some chaos!" and went after everything from our browsers to those fancy cameras that zoom and spin. (You know, the ones they use in spy movies? ????️‍♀️) We're talking password-stealing bots, sneaky extensions that spy on you, and even cloud-hacking ninjas! ???? It's enough to make you want to chuck your phone in the ocean.




y

Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System

Google has warned that a security flaw impacting its Android operating system has come under active exploitation in the wild. The vulnerability, tracked as CVE-2024-43093, has been described as a privilege escalation flaw in the Android Framework component that could result in unauthorized access to "Android/data," "Android/obb," and "Android/sandbox" directories, and their respective




y

Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages

An ongoing campaign is targeting npm developers with hundreds of typosquat versions of their legitimate counterparts in an attempt to trick them into running cross-platform malware. The attack is notable for utilizing Ethereum smart contracts for command-and-control (C2) server address distribution, according to independent findings from Checkmarx, Phylum, and Socket published over the past few




y

Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices

Taiwanese network-attached storage (NAS) appliance maker Synology has addressed a critical security flaw impacting DiskStation and BeePhotos that could lead to remote code execution. Tracked as CVE-2024-10443 and dubbed RISK:STATION by Midnight Blue, the zero-day flaw was demonstrated at the Pwn2Own Ireland 2024 hacking contest by security researcher Rick de Jager. RISK:STATION is an "




y

Leveraging Wazuh for Zero Trust security

Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeter-based security, users within an environment are not automatically trusted upon gaining access. Zero Trust security encourages continuous monitoring of every device and user, which ensures sustained protection after




y

New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers

Over 1,500 Android devices have been infected by a new strain of Android banking malware called ToxicPanda that allows threat actors to conduct fraudulent banking transactions. "ToxicPanda's main goal is to initiate money transfers from compromised devices via account takeover (ATO) using a well-known technique called on-device fraud (ODF)," Cleafy researchers Michele Roviello, Alessandro Strino




y

FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions

The U.S. Federal Bureau of Investigation (FBI) has sought assistance from the public in connection with an investigation involving the breach of edge devices and computer networks belonging to companies and government entities. "An Advanced Persistent Threat group allegedly created and deployed malware (CVE-2020-12271) as part of a widespread series of indiscriminate computer intrusions designed




y

Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users

Google's cloud division has announced that it will enforce mandatory multi-factor authentication (MFA) for all users by the end of 2025 as part of its efforts to improve account security. "We will be implementing mandatory MFA for Google Cloud in a phased approach that will roll out to all users worldwide during 2025," Mayank Upadhyay, vice president of engineering and distinguished engineer at




y

South Korea Fines Meta $15.67M for Illegally Sharing Sensitive User Data with Advertisers

Meta has been fined 21.62 billion won ($15.67 million) by South Korea's data privacy watchdog for illegally collecting sensitive personal information from Facebook users, including data about their political views and sexual orientation, and sharing it with advertisers without their consent. The country's Personal Information Protection Commission (PIPC) said Meta gathered information such as




y

INTERPOL Disrupts Over 22,000 Malicious Servers in Global Crackdown on Cybercrime

INTERPOL on Tuesday said it took down more than 22,000 malicious servers linked to various cyber threats as part of a global operation. Dubbed Operation Synergia II, the coordinated effort ran from April 1 to August 31, 2024, targeting phishing, ransomware, and information stealer infrastructure. "Of the approximately 30,000 suspicious IP addresses identified, 76 per cent were taken down and 59




y

9 Steps to Get CTEM on Your 2025 Budgetary Radar

Budget season is upon us, and everyone in your organization is vying for their slice of the pie. Every year, every department has a pet project that they present as absolutely essential to profitability, business continuity, and quite possibly the future of humanity itself. And no doubt that some of these actually may be mission critical. But as cybersecurity professionals, we understand that




y

Canada Orders TikTok to Shut Down Canadian Operations Over Security Concerns

The Canadian government on Wednesday ordered ByteDance-owned TikTok to dissolve its operations in the country, citing national security risks, but stopped short of instituting a ban on the popular video-sharing platform. "The decision was based on the information and evidence collected over the course of the review and on the advice of Canada's security and intelligence community and other




y

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) that has racked up thousands of downloads for over three years while stealthily exfiltrating developers' Amazon Web Services (AWS) credentials. The package in question is "fabrice," which typosquats a popular Python library known as "fabric," which is designed to execute shell commands remotely over




y

Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems

Cisco has released security updates to address a maximum severity security flaw impacting Ultra-Reliable Wireless Backhaul (URWB) Access Points that could permit unauthenticated, remote attackers to run commands with elevated privileges. Tracked as CVE-2024-20418 (CVS score: 10.0), the vulnerability has been described as stemming from a lack of input validation to the web-based management




y

SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims

An ongoing phishing campaign is employing copyright infringement-related themes to trick victims into downloading a newer version of the Rhadamanthys information stealer since July 2024. Cybersecurity firm Check Point is tracking the large-scale campaign under the name CopyRh(ight)adamantys. Targeted regions include the United States, Europe, East Asia, and South America. "The campaign




y

North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS

A threat actor with ties to the Democratic People's Republic of Korea (DPRK) has been observed targeting cryptocurrency-related businesses with a multi-stage malware capable of infecting Apple macOS devices. Cybersecurity company SentinelOne, which dubbed the campaign Hidden Risk, attributed it with high confidence to BlueNoroff, which has been previously linked to malware families such as




y

CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical security flaw impacting Palo Alto Networks Expedition to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2024-5910 (CVSS score: 9.3), concerns a case of missing authentication in the Expedition migration tool that




y

New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus

Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the compromised hosts. The "intriguing" campaign, codenamed CRON#TRAP, starts with a malicious Windows shortcut (LNK) file likely distributed in the form of a ZIP archive via a phishing email. "What makes the CRON#




y

The vCISO Academy: Transforming MSPs and MSSPs into Cybersecurity Powerhouses

We’ve all heard a million times: growing demand for robust cybersecurity in the face of rising cyber threats is undeniable. Globally small and medium-sized businesses (SMBs) are increasingly targeted by cyberattacks but often lack the resources for full-time Chief Information Security Officers (CISOs). This gap is driving the rise of the virtual CISO (vCISO) model, offering a cost-effective




y

IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools

High-profile entities in India have become the target of malicious campaigns orchestrated by the Pakistan-based Transparent Tribe threat actor and a previously unknown China-nexus cyber espionage group dubbed IcePeony. The intrusions linked to Transparent Tribe involve the use of a malware called ElizaRAT and a new stealer payload dubbed ApoloStealer on specific victims of interest, Check Point




y

Webinar: Learn How Storytelling Can Make Cybersecurity Training Fun and Effective

Let’s face it—traditional security training can feel as thrilling as reading the fine print on a software update. It’s routine, predictable, and, let’s be honest, often forgotten the moment it's over. Now, imagine cybersecurity training that’s as unforgettable as your favorite show. Remember how "Hamilton" made history come alive, or how "The Office" taught us CPR (Staying Alive beat, anyone?)?




y

Bitcoin Fog Founder Sentenced to 12 Years for Cryptocurrency Money Laundering

The 36-year-old founder of the Bitcoin Fog cryptocurrency mixer has been sentenced to 12 years and six months in prison for facilitating money laundering activities between 2011 and 2021. Roman Sterlingov, a dual Russian-Swedish national, pleaded guilty to charges of money laundering and operating an unlicensed money-transmitting business earlier this March. The U.S. Department of Justice (DoJ)




y

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware

Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT "provides purchases with a wide range of advanced features to remotely control computers belonging to the buyer," Fortinet FortiGuard Labs researcher Xiaopeng Zhang said in an analysis published last week. "However, threat actors have




y

HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities

Hewlett Packard Enterprise (HPE) has released security updates to address multiple vulnerabilities impacting Aruba Networking Access Point products, including two critical bugs that could result in unauthenticated command execution. The flaws affect Access Points running Instant AOS-8 and AOS-10 - AOS-10.4.x.x: 10.4.1.4 and below Instant AOS-8.12.x.x: 8.12.0.2 and below Instant AOS-8.10.x.x:




y

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation

Cybersecurity researchers have uncovered nearly two dozen security flaws spanning 15 different machine learning (ML) related open-source projects. These comprise vulnerabilities discovered both on the server- and client-side, software supply chain security firm JFrog said in an analysis published last week. The server-side weaknesses "allow attackers to hijack important servers in the




y

The ROI of Security Investments: How Cybersecurity Leaders Prove It

Cyber threats are intensifying, and cybersecurity has become critical to business operations. As security budgets grow, CEOs and boardrooms are demanding concrete evidence that cybersecurity initiatives deliver value beyond regulation compliance. Just like you wouldn’t buy a car without knowing it was first put through a crash test, security systems must also be validated to confirm their value.




y

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 04 - Nov 10)

⚠️ Imagine this: the very tools you trust to protect you online—your two-factor authentication, your car’s tech system, even your security software—turned into silent allies for hackers. Sounds like a scene from a thriller, right? Yet, in 2024, this isn’t fiction; it’s the new cyber reality. Today’s attackers have become so sophisticated that they’re using our trusted tools as secret pathways,




y

New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate Networks

Cybersecurity researchers have flagged a new ransomware family called Ymir that was deployed in an attack two days after systems were compromised by a stealer malware called RustyStealer. "Ymir ransomware introduces a unique combination of technical features and tactics that enhance its effectiveness," Russian cybersecurity vendor Kaspersky said. "Threat actors leveraged an unconventional blend




y

5 Ways Behavioral Analytics is Revolutionizing Incident Response

Behavioral analytics, long associated with threat detection (i.e. UEBA or UBA), is experiencing a renaissance. Once primarily used to identify suspicious activity, it’s now being reimagined as a powerful post-detection technology that enhances incident response processes. By leveraging behavioral insights during alert triage and investigation, SOCs can transform their workflows to become more




y

Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs

Microsoft on Tuesday revealed that two security flaws impacting Windows NT LAN Manager (NTLM) and Task Scheduler have come under active exploitation in the wild. The security vulnerabilities are among the 90 security bugs the tech giant addressed as part of its Patch Tuesday update for November 2024. Of the 90 flaws, four are rated Critical, 85 are rated Important, and one is rated Moderate in




y

Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks

The Iranian threat actor known as TA455 has been observed taking a leaf out of a North Korean hacking group's playbook to orchestrate its own version of the Dream Job campaign targeting the aerospace industry by offering fake jobs since at least September 2023. "The campaign distributed the SnailResin malware, which activates the SlugResin backdoor," Israeli cybersecurity company ClearSky said




y

AWFUL VERSUS EMPTY

Why is it that in every recent Presidential election I’ve found myself saying, “We’re a nation of (now) some 330 million people, and these are the best two we can pick from to lead us?” In a recent piece, Wall Street Journal defined the choice as Awful versus Empty. (Google will get you there, though […]




y

ANOTHER GREAT GUN GUY PASSES

I was saddened to be told of the recent death of my old friend Ed Lovette. He had a long and distinguished career in military, law enforcement, and the CIA. Ed was a thinking man’s instructor. We took each other’s classes. He went through my LFI-I course back in the day , and about thirty […]




y

WHY COMPETITION IS RELEVANT TO SELF-DEFENSE

Recently saw this on YouTube, from a grandmaster competition shooter who is also in law enforcement. I agree with him. I’ve said for years that while a shooting match is not a gunfight, a gunfight most certainly is a shooting match. Competition experience makes shooting under pressure the norm. Wyatt Earp competed in the informal […]




y

THE NEXT TIME AN ANTI-GUNNER SAYS CITIZENS’ RIFLES ARE USELESS AGAINST ARMIES…

…remind them of this. I was recently reading “Andrew Jackson and the Miracle of New Orleans” by Brian Kilmeade and Don Yeager. The War of 1812 was going badly for the Americans. The British had burned the White House, and a huge contingent of British troops was in Louisiana planning to march north in conquest. […]




y

Bripe and the world Bripes with you

This is, without doubt, the stupidest coffee device I have ever bought. But I have bought it.




y

Hot takes on an 11 year old game: Mass Effect 2

I completed Mass Effect 2 a couple of days ago for the first time. This article contains spoilers…




y

Typo in Trump’s Name on Ballot Review Screen Is Not ‘Election Fraud’

A misspelling of former President Donald Trump's name occurred on an optional ballot review screen in Virginia, prompting an unfounded claim on social media of "election fraud." The error was a typo that appeared only on the ballot review screen, not on actual ballots, and would not affect any votes, election officials said.

The post Typo in Trump’s Name on Ballot Review Screen Is Not ‘Election Fraud’ appeared first on FactCheck.org.




y

Raskin Didn’t Say He ‘Won’t Be Certifying the Election’

Social media users have spread a quote attributed to Democratic Rep. Jamie Raskin, claiming he said "we won’t be certifying the election" if former President Donald Trump wins. Raskin responded, saying the quote is "100% fabricated" and that "America is having a free and fair election and Congress will certify the winner." The origin of the posts appears to be a misleading account of Raskin's comments in February.

The post Raskin Didn’t Say He ‘Won’t Be Certifying the Election’ appeared first on FactCheck.org.




y

Trump’s New York Case: What Happens Now?

Q: What will happen in Donald Trump’s New York state criminal case now that he is president-elect?

A: Trump is scheduled to be sentenced on Nov. 26, but the judge could decide that sentencing is no longer appropriate. If Trump does receive a sentence, it could be appealed, or the judgment could be deferred until 2029, when Trump would be out of office.

FULL QUESTION

What happens if Trump wins the election and then he gets sentenced at the end of the month?

The post Trump’s New York Case: What Happens Now? appeared first on FactCheck.org.




y

Posts Falsely Claim CBS News Reported ‘Cheating’ in Election

Some social media posts falsely claimed that CBS News reported there was "cheating" in the 2024 presidential election that benefitted President-elect Donald Trump. We found no evidence of such a report, and a CBS News spokesperson said the outlet "did not report or say there was cheating in the election."

The post Posts Falsely Claim CBS News Reported ‘Cheating’ in Election appeared first on FactCheck.org.




y

Building community offline

I was overwhelmed by the response to my last post, and so grateful for the reminder that there is still connection to be found online, I just need to push through my own self-consciousness to find it. And I have many good models for this behavior, people who are quick with a kind and supportive word, people who do not shy away from nuance.

Today I spent the day offline in the company of people like this, a small group of friends that gathers once a month to share our love of stationery: pens, ink, paper, notebooks, planners, postal mail, and the like. We sit around a big table and journal together while chatting, snacking, and drinking lattes carefully crafted by FunkyPlaid. The middle of the table soon fills with stickers, stamps, inks, and washi tapes that we’ve brought to share with each other.

As I look around the table at these treasured people, I think about how much work goes into building community. Healthy communities take intention, upkeep, energy, and shared values. This gathering happens every month because we invest all of this into making it happen. As hosts, FunkyPlaid and I make sure people feel cared for with food and drink in a clean and welcoming space. As guests, everyone brings what they want to share, and expresses interest in what they are interested in (and refrains from expressing disdain for what they aren’t).

It’s a lot of work, joyful work. And this work results in a day each month to anticipate, and memories to hold close the rest of the month. I hope never to take this community for granted.




y

Quote of the Day

Brother Diaz had no words. Honestly, he was finding it difficult to breathe down here. He was feeling dizzy. As if the ground might suddenly fall away. He struggled to loosen his collar once again. All he'd wanted was a comfortable living, somewhere sunny. To be taken seriously by the frivolous, regarded as wise by the unwise, and considered important by the unimportant. Instead, for reasons he couldn't comprehend, he found himself called on to consort with scarred knights and part-time painter's models, to face unspecified perils dire enough to threaten creation, all while not getting too close to the cages in which his congregation were kept.

- JOE ABERCROMBIE, The Devils

For more info about this title, follow this Amazon Associate link.

Oh, this is going to be good!!!




y

Quote of the Day

Balthazar delivered a weighty sigh, but nobody noticed.

His current predicament gave him a great deal to sigh about: the ghastly mattress, the dreadful food, the frigid damp and unspeakable odour of his lodgings, the outrageous denial of clothing, the abominable absence of intelligent conversation, the heart-rending loss of his beautiful, beautiful books. But after long reflection he had come to the conclusion that the very worst thing about being forced to join the Chapel of the Holy Expediency . . . was the mortifying embarrassment.

That
he, Balthazar Sham Ivam Draxi, learned adept of the nine circles, suzerain of the secret keys, conjurer of unearthly powers, the man they dubbed the Terror of Damietta--or at least had dubbed himself the Terror of Damietta in the hope that it would stick--one of the top three necromancers in Europe, mark you--possibly four, depending on your opinion of Sukastra of Bivort, who he personally considered an absolute hack--should have been apprehended by buffoons, tried and condemned by dullards, then pressed into humiliating servitude alongside such abject morons as these.

He glanced sideways with an expression eloquently communicating his utter disgust, but nobody was looking. The ancient vampire, presumably rendered decrepit by being starved of blood, slumped in a chair looking as fashionably bored as a wisp-haired skeleton could. The elf stood, thin as a length of pale wire, face obscured by a shag of unnaturally ashen hair, motionless but for a constant and deeply irritating nervous twitching of her long right forefinger. Their chief jailer, Jakob of Thorn, looked on from the corner with arms tightly folded: a war-worn old knight who appeared to have spent a sizeable portion of his life being crushed in a mangle, an experience that had clearly squeezed all sense of humour out of the man. Then there was the supposed spiritual shepherd of this congregation of the disappointing: Brother Diaz, a perpetually panicked young idiot from a little-known and less-regarded monastic order, who wore the expression of a man who cannot swim on the deck of a rapidly foundering ship.

An ineffectual priest, an enervated knight, a misanthropic elf, and an antique vampire. It sounded like the start of a bad joke to which the tragic punchline was yet to be revealed. One might at least have hoped for an awe-inspiring venue: some sculpture-crusted sanctum whose marble floor was inset with the ideograms of saints and angels. Instead, they got a draughty little box in the guts of the Celestial Palace, whose one window had a view of a nearby wall sporting a muddle of leaky drainpipes.

The choice of Balthazar's farce of a trial had been atonement for his trespasses through service to Her Holiness or burning at the stake. At the time it had seemed a no-brainer, but he was beginning to suspect that, in the long run, immolation might prove to have been the less painful option.


- JOE ABERCROMBIE, The Devils

For more info about this title, follow this Amazon Associate link.

Balthazar's POV is by far my favorite thus far. He's the most entertaining necromancer in speculative fiction since Steven Erikson's Bauchelain and Korbal Broach!




y

This week's New York Times Bestsellers (October 6th)

In hardcover:

TJ Klune's Somewhere Beyond the Sea is down four positions, ending the week at number 5. For more info about this title, follow this Amazon Associate link.

Abigail Owen's The Games Gods Play is down one spot, finishing the week at number 6. For more info about this title, follow this Amazon Associate link.

Rebecca Yarros' Iron Flame is down one position, ending the week at number 9. For more info about this title, follow this Amazon Associate link.

Rebecca Yarros' Fourth Wing is down four positions, ending the week at number 15. For more info about this title, follow this Amazon Associate link.

In paperback:

Rebecca Yarros' Fourth Wing debuts at number 1. For more info about this title, follow this Amazon Associate link.

Sarah J. Maas' A Court of Thorns and Roses is up one position, ending the week at number 3. For more info about this title, follow this Amazon Associate link.

Sarah J. Maas' A Court of Mist and Fury is up five positions, ending the week at number 7. For more info about this title, follow this Amazon Associate link.

Stephen King's Holly is down four spots, finishing the week at number 15. For more info about this title, follow this Amazon Associate link.




y

This week's New York Times Bestsellers (October 13th)

In hardcover:

Rebecca Yarros' Iron Flame is up three positions, ending the week at number 6. For more info about this title, follow this Amazon Associate link.

TJ Klune's Somewhere Beyond the Sea is down three positions, ending the week at number 8. For more info about this title, follow this Amazon Associate link.

Abigail Owen's The Games Gods Play is down five spots, finishing the week at number 11. For more info about this title, follow this Amazon Associate link.

In paperback:

Rebecca Yarros' Fourth Wing mtaintains its position at number 1. For more info about this title, follow this Amazon Associate link.

Sarah J. Maas' A Court of Thorns and Roses maintains its position at number 3. For more info about this title, follow this Amazon Associate link.

Sarah J. Maas' A Court of Mist and Fury is down four positions, ending the week at number 11. For more info about this title, follow this Amazon Associate link.

Raven Kennedy's Goldfinch debuts at number 14. For more info about this title, follow this Amazon Associate link.

Stephen King's Holly maintains its position at number 15. For more info about this title, follow this Amazon Associate link.




y

Intel Floundry -> Solyntel




y

Yet another danger of cryptocurrencies ...




y

LA man wearing GPS ankle monitor is accused of a robbery string. Officials can't track him