12/30/2021 December 31, 2021December 31, 2021 ~ The Cyber Beat ~ Leave a comment 2021: Tech’s Big YearAn Amazon Lawsuit Encounters a Big Snag: A Judge With a Conflict of InterestConfusing Data Breach in Rhode Island Leads to AG InvestigationIn the Fight Against Cybercrime, Takedowns Are Only TemporaryTwitter Account of FBI’s Fake Chat App, ANOM Seen Trolling TodayHave I Been Pwned Adds 441k Accounts Stolen by Redline MalwareKyoto University Loses 77TB of Research Data Due to Backup ErrorCyberattack Cripples Norway’s AmediaSega Narrowly Avoids Huge Data Breach, Thanks to Security FirmPick N Pay Denies Customer Data Was Exposed Online Despite ‘Glitch’New iLOBleed Rootkit Targeting HP Enterprise Servers with Data Wiping AttacksFirmware Attack Can Drop Persistent Malware in Hidden SSD Area
12/29/2021 December 30, 2021December 30, 2021 ~ The Cyber Beat ~ Leave a comment Cyber Agency Warns of Increased Threats to Manufacturing Groups During PandemicHackers Are Getting Better and Better at Defeating Your 2FA SecurityOne in Five Aged Domains Is Malicious, Risky, or UnsafeRansomware Gang AvosLocker Coughs up Decryptor After Realizing They Hit the Police5 Cybersecurity Trends to Watch in 20226 Things in Cybersecurity We Didn’t Know Last YearHappy 12th Birthday, KrebsOnSecurity.com!China-Based ‘Aquatic Panda’ Infiltrated Academic Institution Through Log4j VulnFintech Firm ONUS Hit by Log4j Hack Refuses to Pay $5 Million RansomMicrosoft Defender Log4j Scanner Triggers False Positive AlertsLastPass Says No Passwords Were Compromised Following Breach ScareCryptomining Attack Exploits Docker API Misconfiguration Since 2019Polygon Justifies Its Quiet Hard-Fork Citing ‘Critical Vulnerability’
12/28/2021 December 28, 2021December 28, 2021 ~ The Cyber Beat ~ Leave a comment Log4j 2.17.1 Out Now, Fixes New Remote Code Execution BugBiden Signs NDAA Relying on Voluntary Private-Sector Cybersecurity CollaborationCongress Zooms in on Cybersecurity After Banner Year of AttacksWashington Grapples With How to Expand Crypto OversightIn 2022, Cybersecurity Will Be Linux and Other Open-Source Developers Real Job Number OneA Year in Microsoft Bugs: The Most Critical, Overlooked & Hard to PatchRedLine Malware Shows Why Passwords Shouldn’t Be Saved in BrowsersLastPass Users Warned Their Master Passwords Are CompromisedT-Mobile Reportedly Suffers Another, Smaller Data BreachMon Health (WV) Reports Email Phishing Incident, Potential Data BreachSecurity Breach at Duneland School Corp (IN)Most of CompuGroup Medical’s Systems Back Online After Ransomware AttackNew Info States Pro Wrestling Tees Data Breach Occurred In April, Affected 31,000 PeopleNew Flagpro Malware Linked to Chinese State-Backed Hackers ‘BlackTech’ APTExperts Detail Logging Tool of DanderSpritz Framework Used by Equation Group HackersRiskware Android Streaming Apps Found on Samsung’s Galaxy Store
12/27/2021 December 27, 2021December 27, 2021 ~ The Cyber Beat ~ Leave a comment European Privacy and Antitrust Regulators Join Forces on Corporate DataJapan, U.S. to Team Up Against RansomwareData Assessment, User Consent Key to Compliance With China LawShutterfly Hit by Conti Ransomware Attack, Impacting Multiple BusinessesQNAP NAS Devices Hit in Surge of ech0raix Ransomware AttacksTop 5 Stories of 2021
12/24-26/2021 December 26, 2021December 26, 2021 ~ The Cyber Beat ~ Leave a comment Multiple Log4j Scanners Released by CISA, CrowdStrikeFaking a COVID-19 Vaccine Card in New York Can Now Get You a Year in JailDridex Omicron Phishing Taunts With Funeral Helpline NumberFrom Airport WiFi to ‘Juice Jacking’: 7 Ways to Protect Your Data When TravelingRussia Fines Google $100m Over “Illegal” ContentHow to Avoid Falling Into China’s ‘Data Trap’Global IT Services Provider Inetum Hit by Ransomware AttackAndroid Banking Trojan Targeting Brazil’s Itaú Unibanco Spreads via Fake Google Play Store PageRook Ransomware Is Yet Another Spawn of the Leaked Babuk CodeJackson Public Schools (MS) Ups Cybersecurity After 2020 Hacker AttackWorst Hacks of 2021BlackMagic Fixes Critical DaVinci Resolve Code Execution Flaws
12/23/2021 December 23, 2021December 23, 2021 ~ The Cyber Beat ~ Leave a comment White House National Security Adviser Asks Software Companies to Discuss CybersecurityConsumers Warned of Surging Delivery Text Scams Ahead of Christmas‘Spider-Man: No Way Home’ Download Installs CryptominerPhishing Victim Can’t Claim $5 Million Loss for Money It Never ‘Held’Texas Man Convicted for BEC Scam on Idaho School DistrictRussian Hacker’s $1.7M Restitution Order OverturnedRussian Social Media Platform VK Introduces 2FA and Plans to Make It Mandatory in 20227 of the Most Impactful Cybersecurity Incidents of 2021Albanian Prime Minister Apologizes Over Database LeakTelegram Abused to Steal Crypto-Wallet CredentialsPhishing Campaign Targets CoinSpot Cryptoexchange 2FA CodeStealthy BLISTER Malware Slips in Unnoticed on Windows SystemsAvosLocker Ransomware Reboots in Safe Mode to Bypass Security ToolsFisher Price’s Bluetooth Reboot of Pre-school Play Phone Has Adult Privacy FlawApple Fixes macOS Security Flaw Behind Gatekeeper Bypass
12/22/2021 December 23, 2021December 23, 2021 ~ The Cyber Beat ~ Leave a comment VP Harris Calls for ‘Cyber Doctrine’ to Address Increasing AttacksFive Eyes Nations Warn of Cyber Threats From Apache Log4j VulnerabilityNVIDIA Discloses Applications Impacted by Log4j VulnerabilityLog4j Flaw: Attackers Are ‘Actively Scanning Networks’ Warns New CISA GuidanceLog4j Reveals Cybersecurity’s Dirty Little SecretChina Suspends Cloud Deal With Alibaba for Not Sharing Log4j 0-Day First With the GovernmentUK Cybercrime Cops Arrest NHS WorkersRideshare Account Hacker Faces up to 22 Years in PrisonHoneypot Experiment Reveals What Hackers Want From IoT DevicesBEC Attack on Monongalia Health (WV) SystemUbisoft Reveals Player Data Breach Came from User ErrorNJ Volunteer EMS Agency Says Patient Data Was BreachedDridex Malware Trolls Employees With Fake Job Termination EmailsMicrosoft Azure App Service Flaw Exposed Customer Source CodeMicrosoft Teams Bug Allowing Phishing Unpatched Since MarchOpera Browser Working on Clipboard Anti-hijacking Feature
12/21/2021 December 22, 2021December 22, 2021 ~ The Cyber Beat ~ Leave a comment A UAE Agency Put Pegasus Spyware on Phone of Jamal Khashoggi’s Wife Months Before His Murder, New Forensics ShowPolish Opposition Duo Roman Giertych and Ewa Wrzosek Hacked With NSO Group Pegasus SpywareDHS Expands Bug Bounty Program to Encourage Hunting Down Apache Log4j VulnerabilityJava Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to LookWe’re Starting to See a National Response to Ransomware, Says Mandiant CEOThis Security Researcher Fooled an At-Home COVID-19 Test Using a Bluetooth HackThreat Actors Steal $80 Million per Month With Fake Giveaways, SurveysU.S. Returns $154 Million in Bitcoins Stolen by Sony Employee2Easy Now a Significant Dark Web Marketplace for Stolen DataProminent Harvard Professor Charles Lieber Found Guilty of Lying About China TiesCity of Denver Hit By Cyber Attack Targeting KronosSaskatoon Airport Computer System Hit by a Cyber AttackGhana NSS Allegedly Hit by Data Breach as 700,000 People’s Documents Leak OnlineScammers Steal $150k Worth of Crypto From NFT Project Fractal With Discord HackPYSA Ransomware Behind Most Double Extortion Attacks in November800k WordPress Sites Still Impacted by Critical SEO Plugin FlawSecret Backdoors Found in German-made Auerswald VoIP SystemGarrett Walk-Through Metal Detectors Can Be Remotely ManipulatedWindows 10 21H2 Adds Ransomware Protection to Security Baseline
12/20/2021 December 21, 2021December 21, 2021 ~ The Cyber Beat ~ Leave a comment Belgian Defense Ministry Hacked by Attackers Exploiting Apache Log4j VulnerabilityLog4j Vulnerability Now Used to Install Dridex Banking Malware2021: The Year Hackers Went Wild and Changed EverythingPhishing Attacks Impersonate Pfizer in Fake Requests for QuotationUK Donates 225 Million Stolen Passwords to Hack-Checking Site Have I Been Pwned Robocalls More Than Doubled in 2021, Cost Victims $30BGoogle & Meta to Protect Data on Undersea CableMeta Sues People Behind Facebook and Instagram PhishingJustice Department Indicts Russian Hacker for Allegedly Participating in Trading SchemeCyber-Attack Impacts Aussie CompaniesClop Ransomware Gang Publish Confidential UK Police Data on the Dark Web…Police National Computer Not Pwned by Clop Ransomware Crims, Insists Home OfficeTexas Ear, Nose and Throat Specialists (Texas ENT) Alerts 535,000 Patients to Data BreachCapital Region Medical Center (MO) Reports System-Wide Network OutageIndustrial Construction Company Basil Read Hit by Ransomware AttackFBI: State Hackers Exploiting New Zoho Zero-Day Since OctoberNew Mobile Network Vulnerabilities Affect All Cellular Generations Since 2GMicrosoft Warns of Easy Windows Domain Takeover via Active Directory Bugs
12/17-19/2021 December 20, 2021December 20, 2021 ~ The Cyber Beat ~ Leave a comment Federal Agencies Ordered to Immediately Patch Systems Against Apache VulnerabilityApache Issues 3rd Patch to Fix New High-Severity Log4j VulnerabilityBuckle Up for More Log4j MadnessSecurity Firm Blumira Discovers Major New Log4j Attack VectorTellYouThePass Ransomware Revived in Linux, Windows Log4j AttacksConti Ransomware Uses Log4j Bug to Hack VMware vCenter ServersCISA Urges VMware Admins to Patch Critical Flaw in Workspace ONE UEMU.S. Distrust of Huawei Linked in Part to Malicious Software Update in 2012Backdoor Gives Hackers Complete Control Over Unnamed Federal Agency NetworkNeuberger: Change Your Passwords NowWestern Digital Warns Customers to Update Their My Cloud DevicesGrim Finance Targeted by ‘Advanced’ Hack; Losses of Over $30 MillionCredit Card Info of 1.8 Million People Stolen From Sports Gear SitesPro Wrestling Tees Owner Confirms Data Breach, Provides Details in Press ReleaseCyberattack on Payroll Provider Kronos Sets Off Scramble Ahead of HolidaysLogistics Giant Hellmann Worldwide Warns of BEC Emails Following Ransomware AttackMeta Says 50,000 Facebook Users May Have Been Spied on by Private Surveillance FirmsSpider-Man Movie Release Frenzy Bites Fans with Credit-Card HarvestingMalicious Joker App Scores Half-Million Downloads on Google Play
12/16/2021 December 17, 2021December 17, 2021 ~ The Cyber Beat ~ Leave a comment Log4j Flaw: This New Threat Is Going to Affect Cybersecurity for a Long TimeOfficials Point to Apache Vulnerability in Urging Passage of Cyber Incident Reporting BillU.S. Concerns Grow Over Potential Russian Cyber Targeting of Ukraine Amid Troop Buildup on BorderRussia Proposes Holding Collective Cybersecurity Talks With EUProminent Egyptian Opposition Activist’s Phone Hacked – WatchdogGoogle Calendar Now Lets You Block Invitation Phishing AttemptsHive Ransomware Enters Big League With Hundreds Breached in Four MonthsMeta Bans Surveillance-For-Hire Firms for Targeting FB UsersJapan Draws a LINE: Web Giants Must Reveal Where They Store User DataFrance Orders Clearview AI to Delete DataKrebs: NY Man Pleads Guilty in $20 Million SIM Swap TheftFirefox Users Can’t Reach Microsoft.com — Here’s What to DoLog4j Attackers Switch to Injecting Monero Miners via RMIMicrosoft: Khonsari Ransomware Hits Self-Hosted Minecraft ServersMcMenamins Breweries Hit by a Conti Ransomware AttackGumtree Classifieds Site Leaked Personal Info via the F12 KeySennheiser Exposed 28,000 Customers’ Data Online ‘Tropic Trooper’ Reemerges as ‘Earth Centaur’ to Target Transportation Outfits‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K SystemsPhorpiex Botnet Returns With New Tricks Making It Harder to Disrupt‘DarkWatchman’ RAT Shows Evolution in Fileless MalwareResearchers Uncover New Coexistence Attacks On Wi-Fi and Bluetooth ChipsLenovo Laptops Vulnerable to Bug Allowing Admin Privileges
12/15/2021 December 16, 2021December 16, 2021 ~ The Cyber Beat ~ Leave a comment Google Warns That NSO Hacking Is On Par With Elite Nation-State SpiesCISA Warns Critical Infrastructure to Stay Vigilant for Ongoing ThreatsInside the UK Government’s Secret Data RoomZoom Joins Counterterrorism Tech GroupFacebook to Pay Hackers for Reporting Data Scraping Bugs & Scraped DatasetsLarge-Scale Phishing Study Shows Who Bites the Bait More OftenCoinMarketCap Suffers a Seeming Hack, Falsely Driving Crypto Prices to Tens of BillionsHackers Backed by China Seen Exploiting Log4J Security Flaw in Internet SoftwareIran Also Among Those Exploiting Apache Cyber Vulnerability, Researchers SayGlobal Fight Against Log4j Vulnerability Relies on Apache VolunteersApache’s Fix for Log4Shell Can Lead to DoS AttacksState-Sponsored Hackers Abuse Slack API to Steal Airline DataEmotet Starts Dropping Cobalt Strike Again for Faster AttacksSites Hacked With Credit Card Stealers Undetected for Months
12/14/2021 December 15, 2021December 15, 2021 ~ The Cyber Beat ~ Leave a comment DHS Announces Bug Bounty Program to Hunt Down Cyber VulnerabilitiesUSPS Secretly Built & Tested Mobile Voting System Before 2020Hackers Launch Over 840,000 Attacks Through Log4J FlawHackers Exploit Log4j Vulnerability to Infect Computers with Khonsari RansomwareSecond Log4j Vulnerability Discovered, Patch Already ReleasedLog4j: List of Vulnerable Products and Vendor AdvisoriesCISA Orders Federal Agencies to Patch Log4Shell by December 24th‘Seedworm’ Attackers Target Telcos in Asia, Middle EastMicrosoft Rolls Out End-To-End Encryption for Teams CallsPopular Password Manager LastPass to be Spun Out From LogMeInKrebs: Inside Ireland’s Public Healthcare Ransomware ScareHackers Steal $140 Million From Users of Crypto Gaming Company VulcanForgeCyberattack on BHG Opioid Treatment Network Disrupts Patient CareGeorge Washington University Cyberattack During Finals Upends Law Students’ Study PlansSuperior Plus Hit by Ransomware AttackHonolulu Board of Water Supply, Emergency Medical Services Report Attacks on Employee DataAfter Cyber Attack, Maryland Department of Health Website Still Missing COVID Metrics400 Banks’ Customers Targeted with Anubis TrojanNew PS4 Homebrew Exploit Points to Similar PS5 Hacks to ComeHackers Steal Microsoft Exchange Credentials Using IIS ModuleApple iOS Update Fixes Cringey iPhone 13 Jailbreak ExploitMicrosoft Fixes Windows AppX Installer Zero-Day Used by EmotetKrebs: Microsoft Patch Tuesday, December 2021 Edition
12/13/2021 December 14, 2021December 14, 2021 ~ The Cyber Beat ~ Leave a comment Hackers Start Pushing Malware in Worldwide Log4Shell AttacksLog4Shell Flaw Prompts 100 Hack Attacks a Minute, Check Point SaysLog4Shell Is Spawning Even Nastier MutationsLog4j Software Vulnerability Expected to Persist, Possibly for MonthsBugs in Billions of WiFi, Bluetooth Chips Allow Password, Data TheftHackers Target India’s Prime Minister Twitter Account with Fake Bitcoin MessageRomanian Ransomware Suspect Arrested Over Attacks on ‘High-Profile’ OrganisationsEx-NFL Player Joshua Bellamy Gets Three Years for #COVID19 FraudUkraine Arrests 51 for Selling Data of 300 Million People in U.S., EUCSAM Found on LSU Professor’s ComputerThe State of U.S. Cybersecurity a Year After the SolarWinds HackKronos Ransomware Outage Drives Widespread Payroll ChaosTimekeeping Biz Kronos Hit by Ransomware and Warns Customers to Engage Biz Continuity PlansVirginia Assembly IT Agency Hit With Ransomware AttackTinyNuke Info-Stealing Malware Is Again Attacking French UsersPhishing Campaign Uses PowerPoint Macros to Drop Agent TeslaMalicious PyPI Code Packages Rack Up Thousands of DownloadsAttackers Can Get Root by Crashing Ubuntu’s AccountsServiceTelehealth Platform Doxy.me Fixing Issue That Exposed Patient DataGoogle Pushes Emergency Chrome Update to Fix Zero-Day Used in AttacksDell Driver Fix Still Allows Windows Kernel-Level Attacks
12/10-12/2021 December 12, 2021December 12, 2021 ~ The Cyber Beat ~ Leave a comment Officials, Experts Sound the Alarm About Critical Cyber Vulnerability…Press for Actionable Recommendations From New Cyber Advisory Committee‘Karakurt’ Extortion Threat Emerges, But Says No to Ransomware‘Appalling’ Riot Games Job Fraud Takes Aim at WalletsPhishing Attacks Use QR Codes to Steal Banking CredentialsFTC: Americans lost $148 million to gift card scams this yearAustralian Gov’t Raises Alarm Over Conti Ransomware AttacksIrish Health Cyber-Attack Could Have Been Even Worse, Report Says…Happened After One Staffer Opened Malware-Ridden EmailC-Suite’s Biggest Ransomware Fear: Post-attack Regulatory SanctionsBitcoin Mining Has Totally Recovered From Chinese BanUK Court Paves Way for Julian Assange’s Extradition to the U.S.Volvo Hit by Cyber-thieves, R&D StolenBrazilian Ministry of Health Suffers Cyberattack and COVID-19 Vaccination Data VanishesCrypto Exchange AscendEX Suspends Services After $77 Million HackData Breach Impacts 80,000 South Australian Gov’t EmployeesSprawling Active Attack Aims to Take Over 1.6M WordPress SitesZero Day in Ubiquitous Apache Log4j Tool Under Active Attack…‘Enterprise Nightmare’Minecraft Rushes Out Patch for Critical Log4j VulnerabilityResearchers Release ‘Vaccine’ for Critical Log4Shell VulnerabilityMicrosoft: These are the building blocks of QBot malware attacksMozilla Rolls Out GPC for All Firefox Users, but Enforcement Limited to Two StatesEarlier Schreiber Cyber Attack Causes Cream Cheese Shortage as Christmas Nears
12/9/2021 December 9, 2021December 9, 2021 ~ The Cyber Beat ~ Leave a comment U.S. to Tighten Restrictions on Exports of Malicious Cyber ToolsDARPA Announces SMOKE ProgramFueled by Pandemic Realities, Grinchbots Aggressively Surge in ActivityALPHV Blackcat – This Year’s Most Sophisticated RansomwareFujitsu Pins Japanese Gov’t Data Breach on Stolen ProjectWEB AccountsAmazon Fined $1.3 Billion in Italian Antitrust CaseA Third of You Slackers Out There Still Aren’t Using HTTPS by DefaultMicrosoft Previews New Endpoint Security Solution for SMBsKali Linux 2021.4 Released With 9 New Tools, Further Apple M1 SupportCox Communications Discloses Data Breach After Hacker Impersonates Support AgentHellmann Worldwide Logistics Hit by Cyber AttackSuspected Cyberattack Kicks Honolulu City Bus, Handi-Van Systems OfflineButler County Community College (PA) Cooperating With FBI After Ransomware AttackBay Village High School (OH) Staff Member Retiring After Private Records Released for Entire Senior ClassDark Mirai Botnet Targeting RCE on Popular TP-Link RouterMalicious Notepad++ Installers Push StrongPity MalwareHow MikroTik Routers Became a Cybercriminal TargetMicrosoft, Google OAuth Flaws Can Be Abused in Phishing AttacksSanDisk SecureAccess Bug Allows Brute Forcing Vault PasswordsWindows ‘InstallerFileTakeOver’ Zero-Day Bug Gets Free Micropatch
12/8/2021 December 8, 2021December 8, 2021 ~ The Cyber Beat ~ Leave a comment Beijing Reins In China’s Central BankTor’s Main Site Blocked in Russia as Censorship WidensVietnamese ‘XE Group’ Exposed for Eight Years of Hacking, Credit Card TheftOver 40 Million People Had Health Information Leaked This YearCybersecurity Can Pose a Risk in More Than One Way for Financial AdvisorsCoinbase Customers Demand Refunds Over GYEN Stablecoin GlitchKrebs: Canada Charges Its “Most Prolific Cybercriminal”Amazon Is Shutting Down Web Ranking Site Alexa.comMicrosoft: Secured-Core Servers Help Prevent Ransomware AttacksIsrael’s National Insurance Institute Hacked in Dos AttackTwo Data Breaches at Sound Generations (WA) Senior Care Nonprofit Impact 103KEmotet Now Drops Cobalt Strike, Fast Forwards Ransomware AttacksHackers Infect Random WordPress Plugins to Steal Credit CardsMoobot Botnet Chews Up Hikvision Surveillance SystemsMalicious npm Code Packages Built for Hijacking Discord ServersCritical SonicWall VPN Bugs Allow Complete Appliance TakeoverGraphQL API Authorization Flaw Found in Major B2B Financial Platform
12/7/2021 December 7, 2021December 7, 2021 ~ The Cyber Beat ~ Leave a comment Language Requiring Companies to Report Cyberattacks Left Out of Defense BillWhy Voluntary Approaches To Federal Cybersecurity Mandates Threaten ComplianceGoogle Sues Alleged Russian Cyber Criminals Behind GluptebaStop Ransomware Vaccine Released to Block EncryptionTwitter Bots Pose as Support Staff to Steal Your CryptocurrencyCryptominers Aren’t Just a Headache – They’re a Big Neon Sign That Bad Things Are on Your NetworkHackers Using Omicron, COVID-19 Phishing Emails to Target UniversitiesWhy Companies Shouldn’t Shame Employees Who Fall for Hacking ScamsBosses Are Reluctant to Spend Money on Cybersecurity: Then They Get HackedWhen Scammers Get Scammed, They Take It to Cybercrime CourtCanadian Man Arrested for Alleged Ransomware Healthcare Attacks5G Brings Promise – And Risk: Why Security Is Critical as We Build Out the Mobile Networks of the FutureDisney+, Netflix, Slack Among Services Affected by Amazon Web Services OutageCS Energy Hit by Chinese Cyberattack That Almost Cost 3M Homes PowerNordic Choice Hotels Hit by Conti Ransomware, No Ransom Demand YetLINE Pay Leaks Around 133,000 Users’ Data to Github, of All PlacesPellissippi State (TN) Computer Network Brought Down After Suspected Ransomware AttackEldon Schools (MO) Closed After Cyber-Attack on District ComputersNew Cerber Ransomware Targets Confluence and GitLab ServersQNAP Warns Users of Bitcoin Miner Targeting Their NAS DevicesVulnerabilities Found in GOautodialEltima SDK Contain Multiple Vulnerabilities Affecting Several Cloud Service ProvidesWindows 10 Drive-By RCE Triggered by Default URI HandlerGrafana Fixes Zero-Day Vulnerability After Exploits Spread Over Twitter
12/6/2021 December 6, 2021December 6, 2021 ~ The Cyber Beat ~ Leave a comment U.S. Military Has Acted Against Ransomware Groups, General AcknowledgesMicrosoft Disrupts Chinese Hacking Group ‘Nickel’ (aka APT15) Targeting Organizations in Dozens of CountriesIsrael Tightening Cyber Exports After ScandalsCriminal Hackers Are Now Going After Phone Lines, TooSolarWinds Hackers Have a Whole Bag of New Tricks for Mass Compromise Attacks…France Warns of Nobelium Cyberspies Attacking French Orgs…Russian Hacking Group Uses New Stealthy Ceeloader MalwareRomance Fraudster Targeted 670 Women OnlineCyber-attack Closes UK SPAR Convenience StoresMaryland Health Department Says There’s No Evidence of Data Lost After CyberattackIranians Accused of Hacking St. Charles (MO) Computers to Mine CryptocurrencyGravatar Profile Add-on Leaks Data on Millions of UsersApache Kafka Cloud Clusters Expose Sensitive Data for Large CompaniesWhatsApp Adds Default Disappearing Messages for New Chats
12/3-5/2021 December 5, 2021December 5, 2021 ~ The Cyber Beat ~ Leave a comment U.S. State Department Phones Were Hacked With NSO Group Pegasus SpywareFederal Watchdog Warns Security of U.S. Infrastructure ‘In Jeopardy’ Without ActionDidi Hunts for Way to Delist in New York, Rocking Other Chinese ADRsResearchers Detail How Pakistani Hackers Targeting Indian and Afghan GovernmentsFBI: Cuba Ransomware Group Hit 49 Critical Infrastructure OrganizationsPlanned Parenthood Breach Opens Patients to Follow-On AttacksCO Utility Delta-Montrose Electric Loses Billing Ability and 2 Decades of Records After AttackKrebs: Who Is the Network Access Broker ‘Babam’?USB Devices the Common Denominator in All Attacks on Air-Gapped SystemsConvincing Microsoft Phishing Uses Fake Office 365 Spam AlertsNew Twitter Phishing Campaign Targets Verified AccountsCrypto Exchange Bitmart Hacked With Losses Estimated at $196MCelsius Network Confirms It Lost Money in the BadgerDAO DeFi HackPolish T-Mobile Unit Faces Cyber Attack, Systems Not CompromisedRiverhead School District (NY) Targeted in Cyber AttackFake Support Agents Call Victims to Install Android Banking MalwareMalicious KMSPico Installers Steal Your Cryptocurrency WalletsResearchers Discover 14 New Data-Stealing Web Browser AttacksMalicious Excel XLL Add-Ins Push Redline Password-Stealing MalwareZoho: Patch New ManageEngine Bug Exploited in Attacks ASAPUK Government Fined Over Honors List Data Breach
12/2/2021 December 2, 2021December 2, 2021 ~ The Cyber Beat ~ Leave a comment U.S. to Lead Global Effort to Curb Authoritarians’ Access to Surveillance ToolsTSA Issues Directives to Rail Sector to Strengthen CybersecurityNew UK Product Security Law Won’t Be Undercut by Rogue Traders Upping and Vanishing, Gov’t BoastsRussian Internet Watchdog Announces Ban of Six More VPN Products‘Double-Extortion’ Ransomware Damage Skyrockets 935%Phishing Actors Start Exploiting the Omicron COVID-19 VariantPhishing Scam Targets Military FamiliesFacebook Taking Steps to Secure Accounts of Activists, Journalists, OfficialsTwitter Removes 3,400 Accounts Used in Gov’t Propaganda CampaignsAT&T Takes Steps to Mitigate Botnet Found Inside Its NetworkRansomware Attack Hits French-Public School Board (ON)New NginRAT Malware Hides as Legit Nginx Process on E-commerce ServersHackers Use In-House Zoho ServiceDesk Exploit to Drop WebshellsResearches Detail 17 Malicious Frameworks Used to Attack Air-Gapped NetworksNine WiFi Routers Used by Millions Were Vulnerable to 226 FlawsNavigating Cybersecurity Risks in International TradeKrebs: Ubiquiti Developer Charged With Extortion, Causing 2020 “Breach”
12/1/2021 December 2, 2021December 2, 2021 ~ The Cyber Beat ~ Leave a comment House Passes Bipartisan Bills to Strengthen Networks Security, Cyber LiteracyPatchy Cyber Data Makes U.S. Policy Success Difficult to GaugeCISA Names Big Tech, Financial Execs and Others to Cybersecurity Advisory CommitteeCrowdStrike Chosen by CISA for Government Endpoint Security InitiativeAustralia Set to Gain Ability to Sanction Cyber Attackers Under ‘Magnitsky-Style’ LawState-Backed Hackers Increasingly Use RTF Injection for PhishingFacebook, Instagram Remove Accounts Linked to Chinese COVID-19 Disinformation EffortsTwitter Bans Users From Posting ‘Private Media’ Without a Person’s ConsentWidespread ‘Smishing’ Campaign Defrauds Iranian Android UsersRacy Affair Saga Between Jeff Bezos and Enquirer Reaches Final ChapterFormer Ubiquiti Dev Charged for Trying to Extort His EmployerBulletproof Hosting Founder Imprisoned for Helping Cybercrime GangsEuropol: 18k Money Mules Caught Laundering Money From Online FraudPlanned Parenthood Los Angeles Says Hack Breached About 400,000 Patients’ InformationDen Hartog Industries (IA) Victim of Cyber Attack, 5315 Employees CompromisedRansomware Attack Exposed Personal Info of John Hancock (IL) Unit OwnersGale Healthcare Solutions (FL) Info Leak Exposes 170k RecordsTriValley Primary Care (PA) Victim of RansomwareWaikato DHB (NZ) Cyber Attack: Cancer Hub Out of Action in Chaotic AftermathBroward County Public Schools (FL) Reveal What Information Was Stolen in Earlier Breach80K Retail WooCommerce Sites Exposed by Plugin XSS BugMalicious Android App Steals Malaysian Bank Credentials, MFA CodesEmotet Now Spreads via Fake Adobe Windows App Installer PackagesMicrosoft Exchange Servers Hacked to Deploy BlackByte RansomwareMozilla Fixes Critical Bug in Cross-Platform Cryptography LibraryVirusTotal Collections Feature Helps Keep Neat IoC Lists