top of page
man holding laptop in office

IT / OT Security News

Headlines: 2023

December 18, 2023

Iran confirms nationwide cyberattack on gas stations

A cyberattack has disrupted the operation of gas stations throughout Iran, authorities confirmed on Monday.

December 11, 2023

Two-day water outage in remote Irish region caused by pro-Iran hackers

Residents of a remote area on Ireland’s west coast were left without water last week due to a cyberattack perpetrated by a pro-Iran hacking group targeting a piece of equipment the hackers complained was made in Israel.

December 6, 2023

Researchers discover dozens of new bugs affecting Sierra Wireless routers

Researchers have discovered more than 20 security flaws affecting routers manufactured by the Canadian communications equipment vendor Sierra Wireless.

November 27, 2023

Hackers Hijack Industrial Control System at US Water Utility

Municipal Water Authority of Aliquippa in Pennsylvania confirms that hackers took control of a booster station, but says no risk to drinking water or water supply.

November 20, 2023

Greater Paris wastewater agency dealing with cyberattack

The organization that manages wastewater for nine million people in and around Paris was hit with a cyberattack on Friday.

November 14, 2023

Users of modded WhatsApp get more features than they bargained for

A malicious modified version of WhatsApp messenger predominantly targeting Arabic and Azeri speakers has been distributed on popular Telegram channels that have nearly two million subscribers.

November 9, 2023

Russian Hackers Used OT Attack to Disrupt Power in Ukraine Amid Mass Missile Strikes

Mandiant says Russia’s Sandworm hackers used a novel OT attack to cause power outages that coincided with mass missile strikes on critical infrastructure across Ukraine.

October 17, 2023

Five Eyes intelligence chiefs warn of ‘sharp rise’ in commercial espionage

The domestic intelligence chiefs of the Five Eyes alliance warned businesses on Tuesday that they were seeing a “sharp rise” in attempts by hostile states to steal intellectual property.

October 11, 2023

Mirai-based botnet updates ‘arsenal of exploits’ on routers, IoT devices

A Mirai-based malware botnet has expanded its payload arsenal to aggressively target routers and other internet-facing devices, researchers have discovered.

September 27, 2023

Chinese Gov Hackers Caught Hiding in Cisco Router Firmware

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently hop around the corporate networks of U.S. and Japanese companies.

September 12, 2023

China-Linked ‘Redfly’ Group Targeted Power Grid

Symantec has identified a new advanced persistent threat (APT) actor that appears to be focusing exclusively on targeting critical national infrastructure organizations.

September 11, 2023

Israel investigates potential breach of lawmakers’ phones

Israel's security agency is investigating a potential phone breach of opposition party lawmakers, according to local media reports.

September 7, 2023

Cisco Finds 8 Vulnerabilities in OAS Industrial IoT Data Platform

Vulnerabilities identified in the OAS Platform could be exploited to bypass authentication, leak sensitive information, and overwrite files.

August 24, 2023

Mysterious Malware Uses Wi-Fi Scanning to Get Location of Infected Device

Researchers at Secureworks have come across a mysterious piece of malware that scans for nearby Wi-Fi access points in an effort to obtain the location of the infected device.

August 17, 2023

Are you hell-bent on living a reckless digital life with your smartphone?

Here are three compelling reasons for a change of heart and mind—if not to protect yourself, then your loved ones. When we get a new phone, we automatic want to buy a protective case to protect its chassis.

August 8, 2023

US regulators fine Wall Street firms $549 mln in latest texting probe

U.S. regulators on Tuesday fined nine Wall Street companies, including Wells Fargo (WFC.N), opens new tab, BNP Paribas (BNPP.PA), opens new tab and Société Générale (SOGN.PA), opens new tab $549 million over employees' use of personal messaging apps to discuss deals, trades and other business.

August 1, 2023

200 Canon Printer Models May Expose Wi-Fi Connection Data

Japanese imaging and optical products giant Canon on Monday warned that more than 200 of its inkjet printer models fail to properly erase Wi-Fi configuration settings.

July 26, 2023

Researchers say more than 900,000 MikroTik routers vulnerable to hackers

More than 900,000 MikroTik routers are vulnerable to an issue that the company quietly patched late last week, according to researchers.

July 14, 2023

Honeywell, CISA warn of ‘Crit.IX’ vulnerabilities affecting manufacturing tools

Operational technology giant Honeywell joined the Cybersecurity and Infrastructure Security Agency (CISA) Thursday in warning of several serious vulnerabilities affecting a line of industrial control tools used widely within the manufacturing industry.

July 14, 2023

AVrecon malware infects 70,000 Linux routers to build botnet

Since at least May 2021, stealthy Linux malware called AVrecon was used to infect over 70,000 Linux-based small office/home office (SOHO) routers and add them to a botnet designed to steal bandwidth and provide a hidden residential proxy service.

July 11, 2023

Amid security concerns, IDF wants access to stationary cameras

Last month, emergency regulations were approved authorizing the IDF and the Shin Bet to penetrate the computers used to operate stationary cameras; Now the Ministry of Defense requests to extend those powers by at least six months.

July 3, 2023

Know the dangers of public or unsecured Wi-Fi connectivity

Here are 10 tips to keep ourselves paranoid even when a secure network is available during travel or itinerant work errands.

June 27, 2023

Swiss intelligence warns of fallout in cyberspace as West clamps down on spies

Switzerland’s Federal Intelligence Service (FIS) is warning that cyberattacks conducted for espionage purposes — including those targeting critical infrastructure operators — are going to increase as a result of Western efforts to degrade Russia’s human intelligence networks in Europe.

June 20, 2023

OT:Icefall: Vulnerabilities Identified in Wago Controllers

Forescout Technologies has disclosed the details of vulnerabilities impacting operational technology (OT) products from Wago and Schneider Electric.

June 13, 2023

Mobile threat vectors are growing in scale and sophistication

Here are four steps that organizations need to take and own to protect expanded corporate perimeters and guard against human error.

June 1, 2023

Russia accuses US of hacking thousands of Apple devices to spy on diplomats

Russia's Federal Security Service (FSB) is accusing U.S. intelligence of hacking “thousands of Apple phones” to spy on Russian diplomats. According to FSB’s statement published on Thursday, the U.S. used previously unknown malware to target iOS devices.

May 31, 2023

Spyware Found in Google Play Apps With Over 420 Million Downloads

Antivirus company Doctor Web has identified spyware in over 100 Android applications that had more that 421 million cumulative downloads in Google Play.

May 22, 2023

Samsung Smartphone Users Warned of Actively Exploited Vulnerability

Samsung smartphone users have been warned by the vendor and the US Cybersecurity and Infrastructure Security Agency (CISA) about a recently patched vulnerability being exploited in attacks.

May 19, 2023

FBI misused surveillance tool on Jan. 6 suspects, BLM arrestees and others

Crime victims, political donors and potential sources were targeted in digital searches that the FBI says have now been scaled back

May 16, 2023

US ‘strike force’ charges Chinese and Russian nationals with stealing sensitive tech

The Justice Department on Tuesday announced a round of indictments accusing foreign nationals of attempting to illegally gain access to sensitive U.S. technologies, including the source code for Apple's autonomous driving system.

May 9, 2023

China threat actors are targeting network security devices for a reason

In March this year, Fortinet had had to release a patch for a zero day vulnerability (CVE-2022-41328) after being notified of sudden system halts and boot failures in its devices.

May 5, 2023

New Android Trojans Infected Many Devices in Asia via Google Play, Phishing

Security researchers are warning that two new Android trojans have been observed targeting users in Southeast and East Asia. One of them has amassed hundreds of thousands of installs via Google Play.

April 19, 2023

More than 80 countries have purchased spyware, British cyber agency warns

More than 80 countries have purchased spyware over the past decade, Britain’s cyber agency revealed in an intelligence assessment released Wednesday.

April 17, 2023

IoT devices increasingly being targeted by cybercriminals

Over the past three years, one global cybersecurity firm has seen IoT attack levels surge by double digits despite experts’ warnings. In a three-year analysis of data from its own user base and threat intelligence telemetry, a cybersecurity firm has noted a sharp increase in cyberattacks targeting IoT devices.

April 15, 2023

Android malware infiltrates 60 Google Play apps with 100M installs

A new Android malware named 'Goldoson' has infiltrated Google Play through 60 legitimate apps that collectively have 100 million downloads.

April 13, 2023

STOP Buying ANDROID TV Boxes!

These Android TV boxes have been around just about as long as Android has. Odds are, you or someone you know has had one over the years.

April 6, 2023

FBI - "Avoid using free charging stations in airports, hotels or shopping centers

Avoid using free charging stations in airports, hotels or shopping centers. Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices. Carry your own charger and USB cord and use an electrical outlet instead.

March 28, 2023

WiFi protocol flaw allows attackers to hijack network traffic

Cybersecurity researchers have discovered a fundamental security flaw in the design of the IEEE 802.11 WiFi protocol standard, allowing attackers to trick access points into leaking network frames in plaintext form.

March 27, 2023

Android app from China executed 0-day exploit on millions of devices

Android apps digitally signed by China’s third-biggest e-commerce company exploited a zero-day vulnerability that allowed them to surreptitiously take control of millions of end-user devices to steal personal data and install malicious apps, researchers from security firm Lookout have confirmed.

March 22, 2023

PoC exploits released for Netgear Orbi router vulnerabilities

Proof-of-concept exploits for vulnerabilities in Netgear’s Orbi 750 series router and extender satellites have been released, with one flaw a critical severity remote command execution bug.

March 14, 2023

DNS data shows one in 10 organizations have malware traffic on their networks

Akamai report highlights how widespread malware threats remain, noting the dangers of threats specific to DNS infrastructure.

March 14, 2023

Is Public Wi-Fi Safe and What Can You Do to Use Public Wi-Fi Safely?

Public Wi-Fi hotspots are almost everywhere. Be it a hotel, café, restaurant, or airport, you can get a free Wi-Fi connection in most public places.

March 13, 2023

UK launches new agency to tackle state-sponsored threats to business

The British government has announced a new body to help businesses and organizations to defend themselves against national security threats, including Chinese attempts at intellectual property theft.

March 6, 2023

Threat actors are using advanced malware to backdoor business-grade routers

Researchers have uncovered advanced malware that’s turning business-grade routers into attacker-controlled listening posts that can sniff email and steal files in an ongoing campaign hitting North and South America and Europe.

March 1, 2023

Why TikTok Is Being Banned on Gov’t Phones in US and Beyond

The United States is ratcheting up national security concerns about TikTok, mandating that all federal employees delete the Chinese-owned social media app from government-issued mobile phones. Other Western governments are pursuing similar bans, citing espionage fears.

February 23, 2023

The Kremlin Has Entered the Chat

Russian antiwar activists placed their faith in Telegram, a supposedly secure messaging app. How does Putin's regime seem to know their every move?

February 23, 2023

TikTok Banned From EU Commission Phones Over Cybersecurity

The European Union’s executive branch said Thursday that it has temporarily banned TikTok from phones used by employees as a cybersecurity measure, reflecting widening worries from Western officials over the Chinese-owned video sharing app.

February 23, 2023

Mozilla: Nearly 80% of Google Play Store apps have discrepancies in privacy reporting

Nearly four out every five apps in Google’s Play Store are not accurately reporting how they handle user data despite filling out required forms intended to increase transparency, researchers have found.

February 21, 2023

Check your phone: Spyware found in apps impersonating WhatsApp, Facebook

A new version of the SpyNote spyware can impersonate other apps and steal your social media and banking information. How can you protect yourself?

February 15, 2023

The people who kill the truth

One evening last July, Mashy Meidan, 63 – a well-known figure in the corporate intelligence sphere – was contacted via an intermediary by an unknown foreign business adviser.

February 1, 2023

Fraudulent “CryptoRom” trading apps sneak into Apple and Google app stores

Using changing remote content, apps slide by official review process to deliver fraud through the Apple App Store and Google Play Store.

January 23, 2023

Apple Patches WebKit Code Execution in iPhones, MacBooks

Apple’s product security response team on Monday rolled out patches to cover numerous serious security vulnerabilities affecting users of its flagship iOS and macOS platforms.

January 23, 2023

South Dakota's Noem says cell phone number hacked

January 10, 2023

Messenger billed as better than Signal is riddled with vulnerabilities

Threema comes with unusually strong claims. They crumble under new research findings.

January 10, 2023

StrongPity Hackers Distribute Trojanized Telegram App to Target Android Users

The advanced persistent threat (APT) group known as StrongPity has targeted Android users with a trojanized version of the Telegram app through a fake website that impersonates a video chat service called Shagle.

January 5, 2023

SpyNote malware spies on Android users, steals banking credentials

Hackers are increasingly using a new variant of SpyNote malware to secretly observe and modify infected Android smartphones, according to research published by ThreatFabric on Monday.

January 4, 2023

Android’s First Security Updates for 2023 Patch 60 Vulnerabilities

Google announced on Tuesday the first Android security updates for 2023, which patch a total of 60 vulnerabilities.

January 3, 2023

Nearly 300 Vulnerabilities Patched in Huawei’s HarmonyOS in 2022

Chinese tech giant Huawei patched nearly 300 vulnerabilities in its HarmonyOS operating system in 2022.

Huawei smartphones and other devices ran Android until 2019, when the US government barred American companies from selling software and technology to the Chinese firm.

January 2, 2023

Phone and Laptop Seizures at Airports and Borders - Privacy Travel Guide

The world and its borders are slowly opening up after strict Covid lockdowns, and people are looking forward to travelling again. While this is great and fun, keep in mind that you might be subject to random searches and highly invasive and traumatic experiences.

bottom of page