News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Grinex Exchange Suspends Operations After $13.74 Million Hack
Crypto Scams

Grinex Exchange Suspends Operations After $13.74 Million Hack

Grinex, a cryptocurrency exchange based in Kyrgyzstan and sanctioned by the U.S. and U.K., has suspended its operations following a significant cyber attack. The exchange reported that hackers stole $13.74 million, attributing the breach to involvement from foreign intelligence agencies. This attack, which was described as extensive, points to potential threats that could affect other platforms in the crypto space. Grinex's shutdown highlights the ongoing risks faced by cryptocurrency exchanges amid increasing scrutiny from regulators and law enforcement. Such incidents serve as a reminder for users to remain cautious and informed about the security of their investments. Source: [publication name].

via The Hacker NewsRead source
Digital Payment Fraud Grows as India's Transaction Volume Surges
UPI Fraud

Digital Payment Fraud Grows as India's Transaction Volume Surges

India's rapid expansion in digital payment adoption is creating new opportunities for fraudsters. As more citizens embrace online transactions through various platforms, reports indicate a corresponding rise in payment-related crimes. Fraudsters are exploiting vulnerabilities in digital payment systems to steal funds and personal information from users. The surge in transactions has outpaced security infrastructure development, leaving many users vulnerable to scams. Cybercriminals are using sophisticated techniques to intercept payments and compromise account credentials. Financial institutions and payment service providers are working to enhance security measures, but awareness among users remains crucial. Experts recommend implementing two-factor authentication and verifying transaction details before confirming payments. Source: India Today.

via GoogleNews: UPI fraudRead source
Mirai Variant Targets TBK DVRs Using CVE-2024-3721 Vulnerability
Malware

Mirai Variant Targets TBK DVRs Using CVE-2024-3721 Vulnerability

Cybercriminals are exploiting vulnerabilities in TBK DVRs and outdated TP-Link Wi-Fi routers to deploy a variant of the Mirai botnet. Research from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42 reveals that the attacks leverage CVE-2024-3721, a command injection vulnerability with a medium severity score of 6.3. This vulnerability allows attackers to hijack devices to create a DDoS botnet, increasing the risk for users with unpatched security flaws. Users are advised to secure their devices and ensure they are up to date to prevent such attacks. Source: Fortinet FortiGuard Labs, Palo Alto Networks Unit 42.

via The Hacker NewsRead source
Barclays CEO Warns About Threats from AI Cyber Attacks
Malware

Barclays CEO Warns About Threats from AI Cyber Attacks

C S Venkatakrishnan, the CEO of Barclays, has expressed concerns about the potential impact of Anthropic's AI model, Mythos, on the global banking sector. He highlighted that Mythos poses a significant risk and is just the beginning, as more advanced cyber threats are expected to emerge in the future. This warning emphasizes the increasing role of artificial intelligence in cybercrime, which could pose challenges to financial institutions. As the technology evolves, it might bring about new vulnerabilities that could be exploited by cybercriminals, urging businesses to strengthen their cybersecurity measures. Source: [publication name].

via Economic Times TechRead source
NIST's Reduced CVE Support and Its Effect on Cybersecurity Teams
Malware

NIST's Reduced CVE Support and Its Effect on Cybersecurity Teams

The National Institute of Standards and Technology (NIST) has decided to reduce its support for Common Vulnerabilities and Exposures (CVE) data enrichment. This change could impact cybersecurity teams as they rely on CVE data to manage and respond to vulnerabilities effectively. In response to this gap, various industry groups and coalitions are stepping in to provide additional resources and support. The collaboration among these organizations may help maintain the quality and accessibility of data that cybersecurity professionals need to protect systems and respond to threats. This situation highlights the ongoing need for cooperation in the cybersecurity field to address vulnerabilities and strengthen defenses. Source: [publication name].

via Dark ReadingRead source
Payouts King Ransomware Uses QEMU to Evade Security Measures
Ransomware

Payouts King Ransomware Uses QEMU to Evade Security Measures

The Payouts King ransomware has been found using the QEMU emulator to create hidden virtual machines on infected computers. By establishing a reverse SSH backdoor, the malware can operate undetected, circumventing traditional endpoint security mechanisms. This sophisticated approach poses a significant risk, as organizations may not easily identify the presence of this ransomware, allowing it to execute its malicious activities effectively. Keeping antivirus software updated and enhancing security protocols is crucial for organizations to defend against such advanced threats.

via BleepingComputerRead source
Phishers Shift Tactics to Device Code Scams
Phishing

Phishers Shift Tactics to Device Code Scams

Cybercriminals are increasingly using device code phishing to deceive victims into providing access to their online accounts. This method leverages a legitimate login process that occurs when a service prompts users to verify new device access. By making the scenario appear authentic, attackers manipulate users into sharing sensitive information, leading to unauthorized access. As this tactic gains popularity among phishers, it underscores the importance for individuals to stay vigilant and cautious about sharing verification codes and personal data. It is crucial for users to verify any login prompts directly through the service's official channels. Source: [publication name].

via Dark ReadingRead source
Grinex Exchange Halts Operations After $13.7 Million Hack
Crypto Scams

Grinex Exchange Halts Operations After $13.7 Million Hack

Grinex, a cryptocurrency exchange based in Kyrgyzstan, has suspended its services following a significant hack that resulted in a loss of $13.7 million. The company has suggested that Western intelligence agencies may be responsible for the breach, an assertion which highlights the complexity of security threats faced by cryptocurrency platforms. This incident adds to growing concerns about the security of digital currency exchanges and the risks associated with cryptocurrency trading. Following the breach, Grinex is taking measures to reassess its security frameworks to prevent future incidents. Customers and stakeholders are advised to stay updated and exercise caution in their crypto transactions. Source: [publication name].

via BleepingComputerRead source
AI Amplifies Existing Cybersecurity Vulnerabilities
Malware

AI Amplifies Existing Cybersecurity Vulnerabilities

Recent discussions highlight that the primary danger posed by artificial intelligence (AI) is not the introduction of new bugs but the escalation of existing vulnerabilities. As AI technologies become more widespread, they can inadvertently intensify flaws in software, leading to greater potential for exploitation. This means older vulnerabilities, which may have been previously manageable, can become significantly riskier when AI systems interact with them. This growing concern emphasizes the importance of updating security measures and addressing known vulnerabilities as AI continues to evolve and integrate into various systems. It is crucial for organizations to remain vigilant and proactive in cybersecurity practices to mitigate these risks. Source: [publication name].

via Dark ReadingRead source
Understanding Trust in Underground Credit Card Markets
Dark Web

Understanding Trust in Underground Credit Card Markets

In the realm of cybercrime, particularly credit card theft, trust is critically cultivated. Research has uncovered that underground guides instruct actors on how to assess the reliability of 'carding' shops. These assessments are based on factors such as the quality of stolen card data, the shop's reputation, and its ability to remain operational without being shut down. This method of verification is essential for criminals to minimize risks in their fraudulent activities. Understanding these dynamics sheds light on the mechanisms that sustain illicit credit card markets. Source: [publication name].

via BleepingComputerRead source
Three Vulnerabilities in Microsoft Defender Being Exploited
Malware

Three Vulnerabilities in Microsoft Defender Being Exploited

Huntress has issued a warning about three security vulnerabilities in Microsoft Defender that are currently being exploited by cybercriminals. These flaws, identified as BlueHammer, RedSun, and UnDefend, allow attackers to elevate their privileges on compromised systems. The vulnerabilities were disclosed as zero-days by a researcher named Chaotic Eclipse, meaning that they had not been patched at the time of warning, raising concerns about the potential for further exploitation. It is important for users to ensure their systems are updated and fortified against such threats to protect their data and security. Source: [publication name].

via The Hacker NewsRead source
Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs
Cyber Law (India)

Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs

The Maritime Transportation Security Act (MTSA) outlines new cybersecurity regulations for maritime operations, focusing on the protection of Operational Technology (OT) systems. These regulations mandate that organizations create comprehensive cybersecurity plans and undergo audits by independent third parties. Additionally, the Act emphasizes the importance of a hybrid security role that combines both IT and OT security responsibilities. Indian Chief Information Security Officers (CISOs) can draw valuable lessons from these guidelines to enhance their own cybersecurity frameworks and risk management strategies. Adopting a proactive approach in safeguarding critical infrastructure is essential for combating emerging cyber threats. Source: [publication name].

via Dark ReadingRead source