The US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the National Cyber Security Centres in New Zealand (NZ NCSC) and the United Kingdom (NCSC-UK) have issued joint guidance on the proper configuration and monitoring of PowerShell to eliminate the risk of abuse.
Apple, Android Phones Targeted by Italian Spyware: Google
An Italy-based firm’s hacking tools were used to spy on Apple and Android smartphones in Italy and Kazakhstan, Google said Thursday, casting a light on a “flourishing” spyware industry.
A Year After Death, McAfee’s Corpse Still in Spanish Morgue
The body of software entrepreneur John McAfee remained at a morgue in Spain Thursday a year after his death as a legal case filed by his family, who do not believe he committed suicide, is yet to be resolved.
Biden Signs Two Cybersecurity Bills Into Law
Two bipartisan cybersecurity bills were signed into law on Tuesday, June 21, 2022, by US President Joe Biden: the Federal Rotational Cyber Workforce Program Act of 2021, and the State and Local Government Cybersecurity Act of 2021.
Top Cryptographers Flag ‘Devastating’ Flaws in MEGA Cloud Storage
Cryptographers at Swiss university ETH Zurich have found at least five exploitable security flaws in the privacy-themed MEGA cloud storage service and warned that the issues could lead to “devastating attacks on the confidentiality and integrity of user data in the MEGA cloud.”
Chinese APT ‘Bronze Starlight’ Uses Ransomware to Disguise Cyberespionage
A China-linked state-sponsored hacking group named Bronze Starlight was observed deploying various ransomware families to hide the true intent of its attacks.
ICS Vendors Respond to OT:Icefall Vulnerabilities Impacting Critical Infrastructure
Some of the industrial control system (ICS) vendors impacted by the OT:Icefall vulnerabilities have released advisories to inform customers about the impact of the flaws and to provide mitigations.
Johnson Controls Acquires Tempered Networks to Shield Buildings From Cyberattacks
MCG Health Faces Lawsuit Over Data Breach Impacting 1.1 Million Individuals
Patient care guidelines provider MCG Health faces a proposed class lawsuit over the compromise of patient information during a March 2022 data breach.
A wholly-owned subsidiary of the New York-based Hearst Health network, MCG Health combines artificial intelligence with clinical expertise to help healthcare organizations provide care to their patients.
US Subsidiary of Automotive Hose Maker Nichirin Hit by Ransomware
A US subsidiary of Nichirin, a Japanese company that makes hoses for the automotive industry, was recently hit by ransomware.
The company said on Wednesday in a press release written in Japanese that the attack, aimed at Nichirin-Flex USA, was discovered on June 14. Other Nichirin subsidiaries do not appear to be affected.












