New Prinz Eugen ransomware targets recent files, avoids ransom notes
The Prinz Eugen threat actor employs a hands-on-keyboard approach, leveraging legitimate remote monitoring and management (RMM) software and living-off-the-land tools, according to Threatdown.
Federal data center law set to expire without a replacement
The Federal Data Center Enhancement Act of 2023, which currently governs federal facilities nationwide, mandates protections for uptime, power reliability, physical security, cybersecurity, and resilience against natural disasters.
Stressors, AI Forcing Changes to Cybersecurity Teams
As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis.
Cloudflare blocked 38.5 billion cyberattacks against civil society organizations
The majority of attacks against these organizations were DDoS floods, with a notable difference in duration compared to attacks on Cloudflare's broader customer base.
Icarus threat actors exploit Klue OAuth breach to steal Salesforce data
The attack involved the theft of OAuth credentials from Klue's Battlecards integration, which threat actors then used to access and exfiltrate data from customer Salesforce instances.
Law enforcement disrupts SocGholish botnet and Evil Corp servers
Authorities from the Netherlands, Canada, the United States, and Germany removed the SocGholish malware and backdoors from 14,971 compromised WordPress websites, also taking 106 servers and domains offline.