3/30/2021

Officials Say Executive Order With ‘a Dozen’ Actions Forthcoming After SolarWinds, Microsoft Breaches

Younger Ransomware Victims More Likely to Pay Up

‘We Have Your Porn Collection’: The Rise of Extortionware

Browser Tracking Protections Won’t Stop Tracking, Warns DuckDuckGo

Intel Sued Under Wiretapping Laws for Tracking User Activity on its Website

Epic Games Submits Apple Complaint to UK Watchdog

U.S. Gov’t Warns That Buying Fake COVID-19 Vaccine Cards Is a Crime
MobiKwik Suffers Major Breach — KYC Data of 3.5 Million Users Exposed

100 Million Records

MobiKwik Denies

Whistleblower: Ubiquiti Breach “Catastrophic” (Krebs)

Scammers Target Universities in Ongoing IRS Phishing Attacks

Microsoft Exchange Attacks Increase While WannaCry Gets a Restart

VMware Fixes Bug Allowing Attackers to Steal Admin Credentials

3/29/2021

SolarWinds Hack Got Emails of Top DHS Officials

White House Weighs ‘Seen and Unseen’ Responses to Major Hack

Cybersecurity Needs a New Alert System

Former Google Executive Launches Left-Leaning Tech Coalition

Flaws in Ovarro TBox RTUs Could Open Industrial Systems to Remote Attacks

Manufacturing Firms Learn Cybersecurity the Hard Way

Staff Unable to Access Patient Files After Eastern Health Cyber Attack

Ziggy Ransomware Admin Is Refunding Victims Their Ransom Payments

Pair of Apex Legends Players Banned for DDoS Server Attacks

U.S. Imprisons BEC Scammer
Harris Federation School Cyber-Attack Affects 40,000 Pupils’ Email

Oil Giant Shell Workers’ Visas Dumped Online in Clop Ransomware Extortion Attempt

FatFace Pays $2 Million Ransom to Conti Gang

Wake Forest Baptist Hospital Patients’ Records Exposed in Healthgrades Data Breach

DeKalb Schools (GA) Address Data Breach From Vendor PCS Revenue Control Systems

Austin, TXPolk County, FL

PHP Infiltrated with Backdoor Malware

Docker Hub Images Downloaded 20M Times Come With Cryptominers

Hades Ransomware Gang Exhibits Connections to Hafnium

New Bugs Could Let Hackers Bypass Spectre Attack Mitigations On Linux Systems

Poland’s CD Projekt Releases Patch for Cyberpunk 2077

3/26-28/2021

Russian Hackers Target German Parliament Again

UK ‘Must Be Clear-Eyed’ on China Tech Ambitions

NSA Chief Says Recent Hacks Expose Limits of U.S. Cyber Protections

‘Time Is Not on Our Side’ — Biden Navigates Cyber Attacks Without a Cyber Czar

Krebs: No, I Did Not Hack Your MS Exchange Server

Burned Out Employees Put Corporate Security at Risk

Ransomware Gang Urges Victims’ Customers to Demand a Ransom Payment

Warner Presses Zuckerberg to Tackle Vaccine Misinformation on Facebook, Instagram

Parler Says It Alerted FBI to Threats Before Capitol Riot

Trump in Talks With Upstart Apps About New Social Network

Phished Healthcare Provider Takes Legal Action Against Amazon
Channel Nine Cyber-Attack Disrupts Live Broadcasts in Australia

Possible Cyber Attack Targets U.S. Virgin Islands Government

Calviva Health Warns Members of Data Breach

Town of Didsbury Victimized by Ransomware Attack

Bedfordshire: Cyber-Attack Destroys School Pupils’ Coursework

CompuCom MSP Expects Over $20m in Losses After Ransomware Attack

FBI Issues Mamba Alert

Watch Out! That Android System Update May Contain A Powerful Spyware

Critical Netmask Networking Bug Impacts Thousands of Applications

Apple Releases Emergency Update for iPhones, iPads, and Apple Watch

SolarWinds Patches Critical Code Execution Bug in Orion Platform

3/25/2021

Cyber Command Chief Says Dozens of Cyber Operations Carried Out to Defend 2020 Elections

Software Vendors Would Have to Disclose Breaches to U.S. Government Users under New Order Draft

Trust No One Becomes Mantra After Massive Cyber-Attacks

In Secure Silicon We Trust

Manufacturing’s Cloud Migration Opens Door to Major Cyber-Risk

Fleeceware Apps Bank $400M in Revenue

Engineer Reports Data Leak to Nonprofit, Hears From the Police

BackBlaze Mistakenly Shared Backup Metadata With Facebook

Microsoft Offers Up To $30K For Teams Bugs
Day Before Election: Hacked Details of Millions of Israeli Voters Exposed Online

Insurance Giant CNA Hit by New Phoenix CryptoLocker Ransomware

Mobile Anesthesiologists (IL) Tech Misstep Exposes 65,000 Patient Files

QNAP Warns of Ongoing Brute-Force Attacks Against NAS Devices

Evil Corp Switches to Hades Ransomware to Evade Sanctions

Severe Vulnerabilities Patched in Facebook for WordPress Plugin

OpenSSL Shuts Down Two High-Severity Bugs: Flaws Enable Cert Shenanigans, Denial-of-Service Attacks

Cloudflare Launches Page Shield to Thwart Magecart Card Skimming Attacks

3/24/2021

Chinese Hackers Used Facebook to Target Uighurs Abroad, Company Says

ProtonVPN CEO Blasts Apple for ‘Aiding Tyrants’ in Myanmar

Facebook’s Zuckerberg Proposes Conditional Section 230 Reforms

Popular Privacy Extension ClearURLs Removed From Chrome Web Store

Google Chrome Will Use HTTPS as Default Navigation Protocol

COVID-Related Fraud Has Cost Americans $382 Million

Ransomware Incidents Continue to Dominate Threat Landscape

Resentful Employee Deletes 1,200 Microsoft Office 365 Accounts, Gets Prison
Forex Broker Leaks Billions of Customer Records Online

FatFace: We’ve Been Hacked. Please Don’t Tell Anyone

City of Frankfort (KY) Has IT Network Hacked

Student Data May Be Part of Polk County (FL) Cyber Hack

SalusCare (FL) Experiences Cyber Attack on Patient, Employee Data

Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws

SaltStack Revises Partial Patch for Command Injection, Privilege Escalation Vulnerability

Microsoft Fixes Windows PSExec Privilege Elevation Vulnerability

Cisco Addresses Critical Bug in Windows, macOS Jabber Clients

3/23/2021

DHS Cyber Chief Says Hacks Slowed Progress on Public-Private Collaboration

Dark Web Bursting With COVID-19 Vaccines, Vaccine Passports

Microsoft Warns of Phishing Attacks Bypassing Email Gateways

Microsoft: 92% of Exchange Servers Safe From ProxyLogon Attacks

Ransomware Operators Are Piling on Already Hacked Exchange Servers

Prince Harry Is Taking on a New Job Title: Chief Impact Officer at BetterUp

Security Analysis Clears TikTok of Censorship, Privacy Accusations 

Parler Co-Founder Sues Company Over His Firing

Office 365 Cyberattack Lands Disgruntled IT Contractor in Jail
CNA Insurance Firm Hit by a Cyberattack, Operations Impacted

High-Availability Server Maker Stratus Hit by Ransomware

Ransomware Attack Shuts Down Sierra Wireless IoT Maker

Krebs: Phish Leads to Breach at Calif. State Controller

Hackers Claim Attack on Oklahoma Company, State Agency

Two Large Government Conference Organizers Suffer Data Breach

University of Northampton Hit by Cyber-Attack

Ransomware Gang Leaks Data Stolen From University of Colorado, University of Miami

Purple Fox Malware Worms Its Way Into Exposed Windows Systems

3/22/2021

Cyberterrorism Tops List of 11 Potential Threats to U.S.

CISA Warns of Security Flaws in GE Power Management Devices

UK Gov’t Department Loses 306 Mobiles and Laptops in Two Years

New Coalition Launches Against ‘Surveillance Advertising’

Top 3 Cybersecurity Lessons Learned From the Pandemic

The Cybersecurity Problem We Should Really Worry About

Krebs: RedTorch Formed from Ashes of Norse Corp.

Delhi Police Bust Call Center Scammers Duping Americans, Canadians, and Brits

Fraudsters Impersonating Tesco In New Phone Scam

Russia’s Darknet Criminals Have Novel Crypto Cash-Out System: ‘Buried Treasure’
Hobby Lobby Exposed 138GB of Data

28,000+ Mendelson Kornblum Orthopedic and Spine (MI) Patients’ Info Exposed

Ransomware’d Flagstar Bank (MI) Tells Customers It Lost Their SSNs

MangaDex Manga Site Temporarily Shut Down After Cyberattack

Classes Canceled Monday for All Park Hill (MO) Students Due to Malware Attack

Microsoft Exchange Servers Now Targeted by Black Kingdom Ransomware

Critical RCE Vulnerability Found in Apache OFBiz ERP Software

Critical Security Bugs Fixed in Netop Vision Pro Virtual Learning Software

Adobe Fixes Critical ColdFusion Flaw in Emergency Update

3/19-21/2021

Biden Under Growing Pressure to Nominate Cyber Czar

Putin Challenges Biden to Debate After President Calls Him a ‘Killer’

Chinese Military Reportedly Restricts Use of Tesla Cars Among Personnel

Elon Musk Denies Cars Were Used to Spy in China: Tesla Would Be ‘Shut Down

Elon Musk Says Tesla Won’t Share Data From Its Cars With China or U.S.

NHS Boss Helen Bevan’s Twitter Accounts Hacked by PS5 Scammers

Twitter Says Marjorie Taylor Greene’s Account Suspended in Error

Office 365 Phishing Attack Targets Financial Execs

FBI Warns of BEC Attacks Increasingly Targeting U.S. Gov’t Orgs

UK Police Warn Students to Avoid ‘Science Website’

Russian Pleads Guilty to Tesla Ransomware Plot

Justice Department Indicts Hacker Connected to Massive Surveillance Camera Breach
Computer Giant Acer Hit by $50 Million Ransomware Attack

Maricopa Community Colleges (AZ) Investigating Possible Cyber Attack After Network Outage

23 South Gloucestershire Schools Hit by Ransomware Attack

Ottawa Warns of Possible Ransomware Attack on Firm That Provides Services Nationally and Worldwide

Bogus Android Clubhouse App Drops Credential-Swiping BlackRock Malware

DDoS Booters Now Abuse DTLS Servers to Amplify Attacks

REvil Ransomware Has a New ‘Windows Safe Mode’ Encryption Mode

Hacking Group Used 11 Zero-Days to Attack Windows, iOS, Android Users

Critical F5 BIG-IP Flaw Now Under Active Attack

Microsoft Defender Adds Automatic Exchange ProxyLogon Mitigation

3/18/2021

China Regulators Held Talks With Alibaba, Tencent, Nine Others on ‘Deepfake’ Tech

Chinese Nation State Hackers Linked to Finnish Parliament Hack

CISA Releases New SolarWinds Malicious Activity Detection Tool

U.S. Grid at Rising Risk to Cyberattack, Says GAO

New Alert Warns of Tax Season Cyberscam

Facebook Rolls Out Physical Keys to Guard Against Hacking Mobile Accounts

Google Reveals What Personal Data Chrome and Its Apps Collect On You

Italy’s Leonardo Eyes More Cyber Security Deals With EU Institutions After Parliament Contract

Pindrop Security Buys Device-Verification Firm

Mom Charged in Deepfake Cheerleading Plot
Zoom Screen-Sharing Glitch ‘Briefly’ Leaks Sensitive Data

Data Breach Reported at Atascadero State Hospital (CA)

PII of a ‘Handful’ Compromised in Millersville University (PA) Cyber Attack

Trojanized Xcode Project Slips MacOS Malware to Apple Developers

New CopperStealer Malware Steals Google, Apple, Facebook Accounts

Tutor LMS for WordPress Open to Info-Stealing Security Holes

Critical RCE Flaw Reported in MyBB Forum Software—Patch Your Sites

3/17/2021

China Plans to Ask U.S. to Roll Back Trump Policies in Alaska Meeting

U.S. Subpoenas Multiple Chinese Communications Providers in Security Review

Microsoft Breach Ramps up Pressure on Biden to Tackle Cyber Vulnerabilities

White House Forms Public-Private Task Force to Tackle Microsoft Exchange Hack

Biden Vows Russia’s Putin Will ‘Pay a Price’ for Election Meddling

Kremlin: ”Baseless”

$4,000 COVID-19 ‘Relief Checks’ Cloak Dridex Malware

Scammers Are Promising to Get Your Student Loans Forgiven

Krebs: Fintech Giant Fiserv Used Unclaimed Domain

Dropbox to Make Password Manager Feature Free for All Users

Florida Mom & Daughter Duo Hack Homecoming Crown
South and City College Birmingham (UK) to Shift Teaching Online After Ransomware Attack

Elective Surgeries Postponed at Melbourne’s Eastern Health After Suspected Cyber Attack

Tri County Sheriff Dispatch (NY) Hit With Ransomware Attack

Japan Line Users’ Data Exposed to China Affiliate

Cyber-Attack Hits Shell’s Data Transfer System

Cybercriminals Say Georgetown County (SC) Employees’ Info Stolen in Ransomware Attack

Chile’s Bank Regulator Shares IOCs After Microsoft Exchange Hack

Twitter Images Can Be Abused to Hide ZIP, MP3 Files

Microsoft’s Azure SDK Site Tricked Into Listing Fake Package

Cisco Plugs Security Hole in Small Business Routers

Apple May Start Delivering Security Patches Separately From Other OS Updates

3/16/2021

Russia’s Putin Likely Directed 2020 Election Meddling, U.S. Finds

U.S. Expected to Sanction Russia Over Alleged Election Meddling

Microsoft Could Reap More Than $150 Million in New U.S. Cyber Spending, Upsetting Some Lawmakers

Exchange Cyberattacks Escalate as Microsoft Rolls One-Click Fix

Advocates Press Facebook to Combat Spanish-Language Disinformation

Encrypted Messaging App Signal Appears to Be Blocked in China

FBI Warns of Escalating Pysa Ransomware Attacks on Education Orgs

Hackers Are Targeting Telecoms Companies to Steal 5G Secrets

401(k) Investors Vulnerable to Cyber Hacks, Watchdog Warns

Krebs: Can We Stop Pretending SMS Is Secure Now?

Companies Turn to Fusion Centers to Deal With Cyber Intelligence Overload

Teen Responsible for Major Twitter Hack to Serve Three Years in Prison
China Suspected of Cyber Attack on Western Australia’s Parliament During State Election

Ukraine Accuses Russian Hackers of New Cyber Attack

Mimecast: SolarWinds Hackers Stole Some of Our Source Code

UK Ministry of Defence Information Exposed Through Personal Email Accounts

$5.7M Stolen in Roll Crypto Heist After Hot Wallet Hacked

Colorado Retina Associates Phishing Incident Exposes Personal Info of 26,000

Ransomware Attack Knocks Newberry County Memorial Hospital (SC) Computer Systems Offline

Leon County Schools (FL) Confirm Website Hack

Magecart Attackers Save Stolen Credit-Card Data in .JPG File

Latest Mirai Variant Targets SonicWall, D-Link and IoT Devices

New Botnet Targets Network Security Devices With Critical Exploits

DuckDuckGo Browser Extension Vulnerability Leaves Edge Users Open to Potential Cyber-Snooping

3/15/2021

Biden Admin Reveals Probe Into Gov’t Security Has Found Holes: Need More Private Sector Collaboration

Cyberattacks See Fundamental Changes, A Year into COVID-19

Facebook to Label All Posts That Discuss Coronavirus Vaccines

Twitter Now Supports Multiple 2FA Security Keys on Mobile and Web

Cybersecurity Bug-Hunting Sparks Enterprise Confidence

Wave of Legal Appeals Challenges How European Regulators Enforce Privacy Rules

I’m Planning to Retire Early — and Rich — Thanks to NFTs
Krebs: WeLeakInfo Leaked Customer Payment Info

Blender Website in Maintenance Mode After Hacking Attempt

Vulnerable Australian Kids Impacted by Data Breach

Hackers Steal Health Data of 50,000 Patients From PeakTPA

Wisconsin Health Department Accidentally Exposes Email Addresses of 907 COVID-19 Vaccine Registrants

Phishing Sites Now Detect Virtual Machines to Bypass Detection

Florida International Claims Breakthrough in ‘Cryptojacking’ Detection

3/12-14/2021

Microsoft Probes Whether Leak Played Role in Suspected Chinese Hack

Warns of New ‘DearCry’ Ransomware Threat to ‘Unpatched’ Networks

Cryptomining Malware

New PoC for Microsoft Exchange Bugs Puts Attacks in Reach of Anyone

UK Urges Organisations to Install Microsoft Updates Urgently

China Blasts Biden Administration Over New Restrictions on Huawei

U.S. Federal Judge Issues Injunction to Temporarily Remove Xiaomi Ban

Ant Group CEO Simon Hu Resigns Amid Heightened Scrutiny Over the Chinese Financial-Technology Behemoth

FBI Alert Warns of Russian, Chinese Use of Deepfake Content

Australia, India, Japan, and USA Create Joint Critical Tech Working Group

Google Slams Microsoft for ‘Naked Corporate Opportunism’

Apple Sues Employee for Stealing Trade Secrets

Europol Credits Sweeping Arrests to Cracked Sky ECC Comms 

Encrypted Comms Firm Denies Police Cracked User Messages

CEO of Sky Global Encrypted Chat Platform Indicted by U.S.

A Hacker Who Exposed Verkada’s Surveillance Camera Snafu Has Been Raided

Netflix Introduces Measures to Prevent Password Sharing
Utah Company Premier Diagnostics Stored Passport Scans on Unsecured Server

Broward School District (FL) Conducting Cybersecurity Investigation Into What Caused Online Learning Outage

Buffalo Public Schools (NY) Hit With Ransomware Attack on Friday

Total Life Healthcare (AR) Data Breached in ‘Ransomware Attack’

REvil Group Claims Slew of Ransomware Attacks

Scammers Promote Fake Cryptocurrency Giveaways via Twitter Ads

OVH Data Center Fire Likely Caused by Faulty UPS Power Supply

Researchers Hacked Indian Gov’t Sites via Exposed Git and Env Files

Metamorfo Banking Trojan Abuses AutoHotKey to Avoid Detection

New ZHtrap Botnet Malware Deploys Honeypots to Find More Targets

Critical Security Hole Can Knock Smart Meters Offline

Another Google Chrome 0-Day Bug Found Actively Exploited In-the-Wild

Google Fixes Second Actively Exploited Chrome Zero-Day This Month

Google Emits Data-Leaking Proof-of-Concept Spectre Exploit for Intel CPUs

15-Year-Old Linux Kernel Bugs Let Attackers Gain Root Privileges

A New Critical Vulnerability Has Been Discovered in Apple M1

3/11/2021

Microsoft Exchange Servers Face APT Attack Tsunami

Microsoft Exchange Email Hack: Hundreds of UK Firms Compromised

CISA: No Federal Civilian Agency Hacked in Exchange Attacks, So Far

ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber Attacks

Lawmakers Roll Out Bill to Protect Critical Infrastructure After Florida Water Hack

China Lays Plans to Tame Tech Giant Alibaba

TrickBot Takes Over, After Cops Kneecap Emotet

Schools Have Become the Leading Targets of Ransomware Attacks
Cyberattack Takes Down Systems at Molson Coors

Thousands of Irish Shoppers Personal Data Stolen in Fastway Couriers Breach

Covington (LA) Police, Fire and City Employees Locked Out of Computer Systems After Hack

34,000 Affected in New London Hospital (NH) Data Breach

Two-Hundred Affected by Petersburg Medical Center (AK) Data Breach

Linux Systems Under Attack By New Chinese RedXOR Malware

NimzaLoader Was Written in an Unusual Programming Language to Stop It From Being Detected

NanoCore RAT Scurries Past Email Defenses with .ZIPX Tactic

Smart Sex Toys Come With Bluetooth and Remote Access Weaknesses

3/10/2021

Norway’s Parliament Hit by New Hack Attack

Federal Agencies Warn Microsoft Vulnerabilities Pose ‘Serious Risk’ to Government, Private Sector

At Least 10 Hacking Groups Using Microsoft Software Flaw: Researchers

Up to 60,000 Computer Systems Exposed in Germany to Microsoft Flaw

Researchers Unveil New Linux Malware Linked to Chinese Hackers

Top U.S., China Officials to Meet Next Week in Alaska on Range of Issues

Solving Data-Transfer Impasse May Require Diplomatic Agreements on Espionage

Superstar K-Pop Band’s TikTok Hacked

OVH Data Center Burns Down Knocking Major Sites Offline

COVID: White Hat Bounty Hackers Become Millionaires

Linux Foundation Unveils Sigstore — a Let’s Encrypt for Code Signing

Europol ‘Unlocks’ Encrypted Sky ECC Chat Service to Make Arrests

Facebook Files to Dismiss Antitrust Lawsuits
Cyberattack Impacts 200,000 People Connected to Multicare Health Systems

University of Central Lancashire Among Three Hit by Cyber-Attacks

Hospital in Southwest France Hit by Cyber-Attack Demanding $50,000 Ransom

Apple’s Device Location-Tracking System Could Expose User Identities

iPhone Call Recorder Bug Gave Access to Other People’s Conversations

FIN8 Hackers Return With More Powerful Version of BADHATCH PoS Malware

Nim-Based Malware Loader Spreads Via Spear-Phishing Emails

Fake Ad Blocker Delivers Hybrid Cryptominer/Ransomware Infection

Cyberattackers Exploiting Critical WordPress Plugin Bug

F5 Urges Customers to Patch Critical BIG-IP Pre-Auth RCE Bug

SAP Stomps Out Critical RCE Flaw in Manufacturing Software

Krebs: Microsoft Patch Tuesday, March 2021 Edition

3/9/2021

Krebs: Warning the World of a Ticking Time Bomb

Microsoft Releases ProxyLogon Updates for Unsupported Exchange Servers

Kremlin Calls NYT Report on Planned U.S. Cyberstrikes on Russia ‘Alarming’

Biden Appoints Clare Martorana as Federal CIO

U.S. Seizes More Domains Used in COVID-19 Vaccine Phishing Attacks

Security Bug Hunters Focus on Misconfigured Services, Earn Big Rewards

Dark Web Markets for Stolen Data See Banner Sales

GandCrab Ransomware Affiliate Arrested for Phishing Attacks

Surveillance Concerns Could Hold Up European-U.S. Data Agreement for Years

Gab, a Haven for Pro-Trump Conspiracy Theories, Has Been Hacked Again

Arkansas Bill Addresses “Unfair” Social Media Censorship

Twitter Sues Texas AG, Alleging Retaliation for Banning Trump
West Ham Supporters’ Personal Details Leaked on Club Website

Hackers Access Surveillance Cameras at Tesla, Cloudflare, Banks, More

Spanish Labor Agency Suffers Ransomware Attack, Union Says

Google Play Harbors Malware-Laced Apps Delivering Spy Trojans

zoMiner Botnet Hunts for Unpatched ElasticSearch, Jenkins Servers

Adobe Critical Code-Execution Flaws Plague Windows Users

Adobe Fixes Critical Creative Cloud, Adobe Connect Vulnerabilities

GitHub Fixes Bug Causing Users to Log Into Other Accounts

Microsoft Shares Detection, Mitigation Advice for Azure LoLBins

Apple Plugs Severe WebKit Remote Code-Execution Hole

Microsoft Patch Tuesday Updates Fix 14 Critical Bugs

3/8/2021

Krebs: A Basic Timeline of the Exchange Mass-Hack

Microsoft Email Server Hacks Put Biden in a Bind

European Banking Authority Hit by Microsoft Exchange Hack

U.S. Reportedly Prepares Action against Russia after Major Cyberattack

Hackers Hiding Supernova Malware in SolarWinds Orion Linked to China

Iranian Hackers Using Remote Utilities Software to Spy On Its Targets

New Sarbloh Ransomware Supports Indian Farmers’ Protest

CISA Takes Over .GOV Top-Level Domain (TLD) Administration

PayPal Is Acquiring Crypto Security Company Curv, for Less Than $200 Million

McAfee to Offload Enterprise Business for $4bn, Focus on Consumer Security

Virginia Passes New Data Protection Law
Flagstar Bank Hit by Data Breach Exposing Customer, Employee Data

Data Breach at Healthcare Provider Elara Caring Exposes 100,000 Patients’ Information

Cosco Shipping Hacked Again

Hackers Target University of Texas at El Paso (UTEP)

University of the Highlands and Islands Shuts Down During ‘Ongoing Cyber Incident’

Melton School Responds to Serious Cyber Attack

Fake Google reCAPTCHA Phishing Attack Swipes Office 365 Passwords

Crypto-Miner Campaign Targets Unpatched QNAP NAS Devices

Newest Intel Side-Channel Attack Sniffs Out Sensitive Data

Google Chrome to Block Port 554 to Stop NAT Slipstreaming Attacks

3/5-7/2021

Krebs: At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email Software

FireEye Finds Evidence Chinese Hackers Exploited Microsoft Email App Flaw Since January

White House Cites ‘Active Threat,’ Urges Action Despite Microsoft Patch

New Microsoft Tool Checks Exchange Servers for ProxyLogon Hacks

Microsoft’s MSERT Tool Now Finds Web Shells From Exchange Server Attacks

Microsoft: Exchange Updates Can Install Without Fixing Vulnerabilities

In Battle with U.S., China to Focus on 7 ‘Frontier’ Technologies from Chips to Brain-Computer Fusion

Spending on Research and Development to Rise 7% per Year in Push for Major Tech Breakthroughs

U.S. DoD Weapons Programs Lack ‘Key’ Cybersecurity Measures

Russian, Chinese Hackers Targeted Europe Drug Regulator

Russian Disinformation Campaign Aims to Undermine Confidence in Pfizer, Other Covid-19 Vaccines, U.S. Officials Say

Virus Tech Draws Scrutiny From European Privacy Advocates

New iPhone Feature Reveals if Someone Is Stalking Your Exact Movements

Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories

Critics Blast Google’s Aim to Replace Browser Cookie with ‘FLoC’

‘Impossible to Trace’ Tech Savvy Dad May Be Holding Daughter Captive in WA, Cops Say

U.S. Indicts John McAfee for Cryptocurrency Fraud, Money Laundering

Effective Cybersecurity Needs Quantum Communication

Companies Are Doing a Terrible Job of Reporting Cybersecurity Risks to Investors
Queen’s University in Belfast Takes ‘Precautions’ After Cyber-Attack Attempt

Czech Capital Prague, Labour Ministry Face Cyber Attacks

Saint Agnes Medical Center (CA) Data Breach Exposed Personal Info

Sandhills Medical (SC) Foundation Patient Info Accessed in Cyber Attack

Humana Notifying 65,000 Health Plan Members Information Was Exposed

Two Medical Practices in the Richmond Region Report Cybersecurity Incidents

SITA: Airline IT Provider Confirms Passenger Data Leaked After Major ‘Cyber-Attack’

Docker Hub and Bitbucket Resources Hijacked for Crypto-Mining

Ongoing Phishing Attacks Target U.S. Brokers With Fake FINRA Audits

Nottinghamshire Schools Suspend Online Learning Following Cyber Attack

D-Link, IoT Devices Under Attack By Tor-Based Gafgyt Variant

WordPress Injection Anchors Widespread Malware Campaign

REvil Ransomware Gang Plans to Call Victim’s Business Partners About Attacks

New ‘Hog’ Ransomware Only Decrypts Victims Who Join Their Discord Server

Two Unusual Versions of Ransomware Tell Us a Lot About How Attacks Are Evolving

Supermicro, Pulse Secure Release Fixes for ‘TrickBoot’ Attacks

Samsung Fixes Critical Android Bugs in March 2021 Updates

Microsoft Office 365 Gets Protection Against Malicious XLM Macros

3/4/2021

Krebs: Three Top Russian Cybercrime Forums Hacked

Microsoft, FireEye Unmask More Malware Linked to SolarWinds Attackers

CISA Issues Emergency Directive on In-the-Wild Microsoft Exchange Flaws

Senate Includes Nearly $2 Billion in Cyber, Tech Funds to COVID-19 Bill

Researcher Bitsquats Microsoft’s windows.com to Steal Traffic

Thousands of Android and iOS Apps Leak Data From the Cloud

National Surveillance Camera Rollout Roils Privacy Activists

Samsung and Mastercard to Pilot Biometric Payments Card in South Korea

Cryptocurrency Fraudster Steals $16m
Singapore Airlines Frequent Flyer Members Hit in Third-Party SITA Data Security Breach

Indian State Government Website Exposed COVID-19 Lab Test Results

Ransomware Attack on Cochise Eye and Laser (AZ)

8-Day Cyber Attack: Hackers Demanded Millions From Allergy Partners (NC)

34,000 Affected in AllyAlign Health (VA) Data Breach

Hacked SendGrid Accounts Used in Phishing Attacks to Steal Logins

CompuCom MSP Hit by DarkSide Ransomware Cyberattack

Windows DNS SIGRed Bug Gets First Public RCE PoC Exploit

VMware Releases Fix for Severe View Planner RCE Vulnerability

3/3/2021

Workers at Canadian Spy and Cyber Agency Threaten to Strike

State-Sponsored Hackers Rush to Exploit Unpatched Microsoft Exchange Servers

Why Some Governments Are Getting Cyber Crime Gangs to Do Their Hacking for Them

High Alert as New QAnon Date Approaches Thursday

Google to Stop Selling Ads Based on Your Specific Web Browsing

Parler Drops Federal Lawsuit Against Amazon, Files in State Court

BEC Scammers Are Targeting Investors for Massive Payouts

U.S. Government Warns of Social Security Scams Using Fake Federal IDs

Home-Office Photos: A Ripe Cyberattack Vector

Hackers Share Methods to Bypass 3D Secure for Payment Cards
Qualys Hit With Ransomware: Customer Invoices Leaked on Extortionists’ Tor Blog

Navajo Nation Hospital Targeted by Large-Scale Ransomware Hack

University of Memphis Hit with Second Cyber Attack In Six Months

Hollywood’s Elite Private Schools Hacked 

CompuCom MSP Confirms Ongoing Outage Following Malware Incident

Cyber Attack Affecting Hanover Area School District and Others (PA)

Telemarketing Biz CallX Exposes 114,000 in Cloud Config Error

Cash App Phishing Kit Deployed in the Wild, Courtesy of 16Shop

GRUB2 Boot Loader Reveals Multiple High Severity Vulnerabilities

Unpatched Bug in WiFi Mouse App Opens PCs to Attack

3/2/2021

Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails (Krebs)

Chinese Cyber Attack: U.S. Congressman Urges Biden to Stand by India

SolarWinds Reports $3.5 Million in Expenses From Supply-Chain Attack

Wray Hints at Federal Response to SolarWinds Hack

Microsoft Warns of Chinese Hackers ‘Hafnium’ Targeting Email Product

Microsoft Shares More on What’s Coming in Windows Server 2022

Microsoft Teams Adds End-to-End Encryption (E2EE) to One-on-One Calls

Microsoft 365 Defender Threat Analytics Enters Public Preview

Gamer Sues Microsoft Over Cyberbullying

Google Teams up With Allianz, Munich Re to Insure Its Cloud Users

Jailbreak Tool Works on iPhones Up to iOS 14.3

Medal of Honor Holders’ Identities Stolen

‘Fake Accounts Used My Pictures to Sell Sex’

Satanic Temple Loses Cyber-squatting Lawsuit

Alarming Cybersecurity Stats: What You Need To Know For 2021
Krebs: Payroll/HR Giant PrismHR Hit by Ransomware?

Malaysia Airlines Discloses a Nine-Year-Long Data Breach

Asian Food Distribution Giant JFC International Hit by Ransomware

Zee5 Once Again Caught In Data Breach; Info Of 9 Mn Users Exposed

CSX Probes ‘Security Incident’ as Hackers Leak Data

Oxfam Australia Confirms Data Breach After Stolen Info Sold Online

Millersville University (PA) Says Network Outage Was the Result of an ‘External Attack’

Ransomware Attack Shuts Down Altona Clinic (MB)

Rookie Coding Mistake Prior to Gab Hack Came From Site’s CTO

Researchers Unearth Links Between SunCrypt and QNAPCrypt Ransomware

Malicious NPM Packages Target Amazon, Slack With New Dependency Attacks

Compromised Website Images Camouflage ObliqueRAT Malware

Microsoft Fixes Actively Exploited Exchange Zero-Day Bugs, Patch Now

Google Fixes Second Actively Exploited Chrome Zero-Day Bug This Year

3/1/2021

Chinese Hackers Targeted India’s Power Grid Amid Geopolitical Tensions

Chinese Businessman Plotted With GE Insider to Steal Transistor Secrets, Say Feds

U.S. ‘Unprepared’ to Defend against New AI Threats, Report Finds

New York Group Urges Action on Cyber Coordination

Free Cybersecurity Tool Aims to Help Smaller Businesses Stay Safer Online

Scientists Have Built This Ultrafast Laser-Powered Random Number Generator

Krebs: Is Your Browser Extension a Botnet Backdoor?

Cybercrime ‘Help Wanted’: Job Hunting on the Dark Web

Universal Health Services Lost $67 Million Due to Ryuk Ransomware Attack

Tether Cryptocurrency Firm Says Docs in $24 Million Ransom Are ‘Forged’

We Are ‘Not Paying’

Facebook Photo-tagging Lawsuit Settled for $650m

Florida Police Arrest 12 Alleged Online Predators
Passwords, Private Posts Exposed in Hack of Gab Social Network

Hurtigruten Reports Passenger Data Exposed in Cyberattack

European E-Ticketing Platform Ticketcounter Extorted in Data Breach

World’s Leading Dairy Group Lactalis Hit by Cyberattack

Kaman Hit by Ransomware Attack, Biden Foreign Policy Change

New South Wales Transport Agency Extorted by Ransomware Gang After Accellion Attack

Cyber Attack on the Ministry of Finance of Kosovo

City of Kingman (AZ) Government Computer System Hit by Cyberattack

Malware Loader Abuses Google SEO to Expand Payload Delivery

Working Windows and Linux Spectre Exploits Found on VirusTotal

Critical Vulnerability Found in Snow Software’s Inventory Agent

Firewall Vendor Genua Patches Critical Auth Bypass Flaw

2/26-28/2021

Congress Has New Appetite for Breach Law Following SolarWinds Hack: Lawmaker

SolarWinds Officials Throw Intern Under the Bus for ‘solarwinds123’ Password Fail

Lawmakers Blame SolarWinds Hack on ‘Collective Failure’ to Prioritize Cybersecurity

Huawei Backs Supply Chain Security Standards in Wake of SolarWinds Breach

NSA, Microsoft Promote a Zero Trust Approach to Cybersecurity

Pits Microsoft Against Dell, IBM Over How Companies Store Data

U.S. Energy Department Floats Solution to Illicit Crypto Mining Malware

Foreign Perpetrators Among Fraudsters Shamming State’s Unemployment Systems

Cyberattacks Cost Hospitals Millions During Covid-19

Amazon Dismisses Claims Alexa ‘Skills’ Can Bypass Security Vetting Process

What Are These Suspicious Google GVT1.Com URLs?
T-Mobile Discloses Data Breach After Sim Swapping Attacks

Ransomware Gang Hits Ecuador’s Largest Private Bank Banco Pichincha, Ministry of Finance

UK’s Npower Shuts Down Mobile App Following Data Breach

Some San Diegans’ Personal Information Provided to Jewish Family Service Exposed Online

Beware: AOL Phishing Email States Your Account Will Be Closed

Stalkerware Volumes Remain Concerningly High, Despite Bans

Yeezy Fans Face Sneaker-Bot Armies for Boost ‘Sun’ Release

Ryuk Ransomware Now Self-Spreads to Other Windows LAN Devices

Google Shares PoC Exploit for Critical Windows 10 Graphics RCE Bug

Microsoft Fixes Windows 10 Drive Corruption Bug — What You Need to Know

German Prosecutors Are Building AI In-House

Cybersecurity Firm Axonius Raises $100 Million at $1.2 Billion Valuation