Logo

Cyber Insights • January 2025

Dreamlab Technologies presents to you our brand new ‘Cyber Insights’ newsletter – an expert analysis of the latest developments in the cyber domain across the globe. The cyber world is a world full of opportunities but unfortunately faces new and emerging threats every day. This newsletter contains insights and trends in cyber security and emerging technologies that will help you stay informed regarding the threats and challenges in today's rapidly evolving digital world. It also comes with a brief analysis of the cyber security events from a geo-political perspective. In the evolving geo-political dynamics today, cyber security is increasingly being prioritised by countries worldwide. Stronger cyber defence capabilities, higher investments in cyber security budgets and facilitating cyber policy dialogues are some of the new trends observed in the global geo-politics. The concise content in this paper provides a glimpse into this global scenario concerning the cyberspace. It is easy to read and can help promote awareness regarding best cyber security practices and safeguard our digital lives. 

Inside this issue:

  • CISA warns of Cleo Zero-Day vulnerability being exploited in ransomware attacks

  • EU imposes first-ever sanctions over Russian hybrid threats and destabilising actions abroad

  • Australia passes law banning social media for children under 16

  • Interpol’s ‘Think Twice’ warns of cybercrime; ‘Operation Serengeti’ disrupts networks across Africa

  • Apple to pay $95 million to settle lawsuit accusing Siri of secretly eavesdropping

In this edition, we dive into the critical warning issued by the Cybersecurity and Infrastructure Security Agency (CISA) on an actively exploited vulnerability linked to ransomware attacks, urging organisations to take immediate action on patching it to prevent cyberattacks. The vulnerability ‘CVE-2024-50623’, affected file-sharing products from Cleo, a software company, allowing attackers to launch malware and potentially execute remote codes. According to researchers, the exploitation of the vulnerability led to several businesses across industries getting affected. The issue highlights an increase in the targeting of file transfer tools in data theft campaigns, which calls for proactive monitoring and urgent patching of potential vulnerabilities in one’s cyberspace.

Spanning Europe, we come across EU’s first-ever sanctions in response to Russia’s destabilising activities across EU and allies. The sanctions targeting 16 individuals and three entities, were imposed under a framework introduced earlier by the EU to target Russia’s increasing hybrid activities including malicious cyber activities, assassinations, espionage, disinformation campaigns, etc., aimed at destabilising the EU. We take a look at the how the EU continues to condemn this increasing use of hybrid tactics against its member states and partners.

Across Oceania, we delve into the recent Online Safety Amendment (Social Media Minimum Age) Act 2024 passed by the Australian Parliament that restricts children under 16 to access social media. We look into some of its provisions and implementation challenges, and how the Australian government plans to overcome these challenges by balancing protection of the youth and their digital rights like online exploration and privacy. The law will be reviewed after two years to assess its outcomes after consultation with young people, parents, carers, and educators, and gathering evidence on its impact.

In the global arena, we study the Interpol’s ‘Think Twice’ campaign that was recently organised to counter cyber and financial crimes by encouraging vigilance through educational content on emerging online threats like ransomware attacks, malware, phishing, generative AI scams, and romance baiting, and help individuals and organisations avoid falling prey to such crimes. Earlier in 2024, under ‘Operation Serengeti’, jointly led by the Interpol and Afripol, over 134,000 malicious networks involving cybercriminals were disrupted across Africa. We also look at this Interpol operation to know more about the tactics and techniques used by cybercriminals and how initiatives like ‘Think Twice’ can promote proactive cyber security to help create a safer digital world for everyone in the future.

And in Big Tech, we learn about Apple’s decision to pay $95 million to settle a five-year-old lawsuit accusing Siri of secretly eavesdropping on users without their consent and sharing recorded conversations with third parties like advertisers. Apple, however, maintained its commitment to privacy by denying any wrongdoing, but settling could avoid further legal costs and reputational damage. The incident encourages users to exercise caution through regular reviews of device’s privacy settings, app permissions, disabling unnecessary permissions and getting familiar with company privacy policies.

Discover more and explore the captivating stories, by downloading a copy of ‘Cyber Insights’ below.

 

 

Cyber Insights • January 2025

All blog posts