|
|
|
|
|
Cargo ships were anchored Monday in the Strait of Hormuz near Bandar Abbas, Iran. PHOTO: AMIRHOSEIN KHORGOOI/SNA/AP
|
|
|
|
|
Hackers linked to the Iranian government operated a months-long social-engineering campaign posing as a criminal ransomware group, according to cybersecurity firm Rapid7. Tracked as MuddyWater, the hackers gathered Microsoft Teams login credentials and bypassed multifactor authentication to access organizations in the U.S. and abroad, the firm said. (CybersecurityDive)
|
|
|
|
|
|
PHOTO: KEVIN LAMARQUE/REUTERS
|
|
|
|
|
The Pentagon plans to require service members to complete cybersecurity training every three years, revising a recent shift to a five-year requirement, according to DefenseScoop. In September, Defense Secretary Pete Hegseth directed military officials to limit mandatory training courses, including cybersecurity, saying it distracted troops from their core mission. (DefenseScoop)
|
|
|
|
The National Institute of Standards and Technology said it will conduct “pre-deployment evaluations” of frontier AI models from Google, Microsoft and xAI to assess cybersecurity risks. To date, NIST's Center for AI Standards and Innovation has completed more than 40 evaluations, "including on state-of-the-art models that remain unreleased," the agency said. (NIST)
|
|
|
Healthcare software maker Networking Technology is notifying customers of a breach in March that exposed data on some patients, including names, dates of birth, contact information and patient IDs, according to a notification letter reviewed by HIPAA Journal. The company, which does business as RXNT, said it brought in third-party cybersecurity experts to determine the nature and scope of breach. (HIPAA Journal)
|
|
|
A cybercrime suspect arrested in January by Romanian police was extradited to the U.S. last month over his alleged role in a bank-fraud scheme carried out 17 years ago, the Justice Department said. Gavril Sandu, a 53-year-old Romanian national, is accused of hacking into small-business VoIP systems to obtain login credientials, payment card numbers and PINs, the DOJ said. (Security Week).
|
|
|
|
|
|
|
|
|
|
|
|