HomeCybersecurity NewsCybersecurity news weekly roundup January 8, 2024
January 8, 2024

Cybersecurity news weekly roundup January 8, 2024

    SAN MATEO, CA, January 8, 2024 — Cybersecurity news weekly roundup. Stories, news, politics, and events that impacted the network security industry last week. Brought to you by NetworkTigers.

    A new backdoor vulnerability in Apple MacOS has been discovered that shares similarities with KANDYKORN, which allows remote access Trojan capabilities to its host. This new malware, called SpectralBlur, has been linked to North Korean hacking groups and is predicted to be used to target cryptocurrency and blockchain industries. SpectralBlur can upload, download or delete files from its infected host, issue commands, and cause the system to hibernate or sleep. Read more

    Banking Trojans evolve to target mobile financial apps

    A new study reveals a significant rise in the development and implementation of Trojans attacking US-based banking institutions. The malware is designed to target mobile banking and commit financial fraud via social media, messaging apps, and cryptocurrency offers. Malware targeted as many as 109 US banks in 2023, with 1,103 apps compromised (a 61% success rate out of 1800 targets). The study names the 29 malware families most likely to target banks. Read more. 

    Iranian hackers attack small-town Pennsylvania water plant

    In the small water authority of Aliquippa, Western Pennsylvania, Iranian-based hacking groups managed to shut down the remotely controlled device that monitors and regulates water pressure throughout the pumping system. Authorities say the Unitronics machines were targeted because they were made in Israel. This international cyberattack affected the water and wastewater plant for a town of about 22,000 people outside of Pittsburgh, although the system could be switched onto manual override. Read more. 

    Government watchdog warns about existing vulnerabilities in medical devices

    A report has been issued from the US Government Accountability Office (GAO) that warns the FDA and CISA about the need to update cybersecurity protocols for medical devices. According to the report, up to 53% of internet-connected medical devices are known to have critical vulnerabilities as far back as January 2022. Examples include hospital-based MRI machines, vital monitors, infusion pumps, and wearable medical devices. Read more

    Radioactive waste management plant targeted by hackers through LinkedIn

    According to The Guardian, UK nuclear waste company RWM was subjected to a social engineering attack through LinkedIn. The company, part of a government-backed £50 billion project to build a nuclear waste storage repository underground, was targeted through fake business accounts, deceptive messages, malware-infected links, fake news, and attempts to threaten employee’s safety online and steal employee credentials. Read more

    NSO Group’s Pegasus spyware used to target prominent journalists in India

    The highly invasive Pegasus spyware, developed by Israeli surveillance company NSO Group, was discovered on the iPhones of several prominent Indian journalists. In October 2023, Apple notified more than 20 journalists and opposition politicians in India that their phones may have been infected by malware guided by “state-sponsored attackers”. The Amnesty International report details that the spyware had been installed via “zero-click exploit”, a technique that downloads spyware without any action from the user, such as clicking on a malicious link or opening a phishing email. Read more

    Study predicts AI in cybersecurity market will reach $60.6 billion by 2028

    The global appetite for using AI in cybersecurity is expected to grow exponentially over the coming years. Projections expect a combined annual growth rate (CAGR) of a whopping 21.9%, increasing from $22.4 billion in 2023 to $60.6 billion in 2028. The Asia-Pacific market is expected to see the most significant rise in AI-based cybersecurity investment, especially spending in India, China, Australia, Japan, and South Korea. Read more

    75% of US consumers say cyber incidents would prompt them to stop using brands

    A new study urges brands to prioritize cybersecurity, as 75% of American consumers say they would stop using brands and organizations affected by cybersecurity incidents. Additionally, 66% of consumers say they would not entrust their data to companies affected by past hacks or data leaks. Finally, 44% of consumers say inadequate cybersecurity protocols are the leading cause of successful hacks, illustrating an unwillingness to take a corporation’s side after their data has been compromised. Read more

    Russian-sponsored Sandworm reported to have access to Ukrainian telecom since at least May 2023

    Ukrainian cybersecurity professionals have revealed that the Russian state-sponsored threat actor Sandworm has had access to Ukrainian telecommunications since May 2023. The long-planned invasion, which only came to light in December 2023, shut down internet access and cellphone usage for millions. Denmark has also accused Sandworm of targeting 22 additional energy sector companies in 2023 alone. Read more

    Xerox subsidiary hit with ransomware attack

    A subsidiary of the billion-dollar printing company Xerox, XBS, was targeted in a ransomware attack that may have successfully stolen personal information from users. The ransomware gang INC, which claimed responsibility for the hack, has been previously linked to cyber incidents at Yamaha Motor and WellLife Network. Xerox plans to notify any consumers affected by the ransomware breach. Read more.

    More cybersecurity news

    Gabrielle West
    Gabrielle West
    Gabrielle West is an experienced tech and travel writer currently based in New York City. Her work has appeared on Ladders, Ultrahuman, and more.

    What do you think?

    Popular Articles