1/19/2022

Biden Administration Sets New Requirements for U.S. Secure Networks

Official Beijing 2022 Olympics Mobile App Is Marred by Security Flaws, Researchers Say

UK’s Cyber Security Center Publishes New Guidance to Fight Smishing

Cloned Dept. of Labor Site Hawks Fake Government Contracts

CISA Urges U.S. Orgs to Prepare for Data-Wiping Cyberattacks

Krebs: IRS Will Soon Require Selfies for Online Access

Facebook Messenger: The Battle Over End-To-End Encryption

Europe’s Move Against Google Analytics Is Just the Beginning

Man Charged with Smuggling Tech Exports to Iran

Interpol and Nigerian Police Bust Cybercrime BEC Ring
Red Cross Hit With Cyberattack That Compromised Data of 515,000 ‘Highly Vulnerable People’

Marketing Giant RR Donnelly Confirms Data Theft in Conti Ransomware Attack

Aditya Birla Fashion Says Back After Data Breach; Hackers Say Site Still Vulnerable

Visalia Unified School District (CA) Says ‘Ransomware Attack Failed’

Russian Hackers Heavily Using Malicious Traffic Direction System to Distribute Malware

New BHUNT Malware Targets Your Crypto Wallets and Passwords

Microsoft: SolarWinds Fixes Serv-U bug Exploited for Log4j Attacks

Deloitte Launches New SaaS Cyber Threat Detection and Response Platform

Ukraine: Cyber Warfare — Call It What It Is

1/18/2022

Israel Police Uses NSO’s Pegasus to Spy on Citizens

U.S. Aims Sanctions at Pro-Russian Agents as Blinken Plans Ukraine, Russia Meetings

Poland Raises Cybersecurity Terror Threat After Ukraine Cyber Attack

Gloucester Council Cyber Attack Linked to Russian Hackers

From 6G to Big Data, China Is Looking to Boost Tech’s Share of Its Economy

Beijing 2022 Winter Olympics App Bursting With Privacy Risks

Winter Olympics: Athletes Advised to Use Burner Phones in Beijing

Airlines Warn of ‘Catastrophic’ Crisis When New 5G Service Is Deployed

Drugmaker Gilead Alleges Counterfeiting Ring Sold Its HIV Drugs

Will 2022 Be the Year of the Software Bill of Materials?

Half of Global Cyber Defence Investment Has Been in Israel -PM Bennett

Europol Shuts Down VPNLab, Cybercriminals’ Favourite VPN Service

Democrats Propose Bill to Ban “Surveillance Advertising”
Parasol’s Sister Firms, SJD Accountancy and Nixon Williams, Confirm Cyberattack

Fashion Giant Moncler Confirms Data Breach After Ransomware Attack

Entira Family Clinics (MN) Notifies Patients of Data Breach 1 Year Later

Oscar Health Notifies Members of Data Breach

Crypto.com Acknowledges ‘Unauthorized Activity’ on Servers, Maintains No Funds Lost

Telegram Is a Hotspot for the Sale of Stolen Financial Accounts

Cybercriminals Actively Target VMware vSphere with Cryptominers

‘White Rabbit’ Ransomware May Be FIN8’s Latest Tool

Researchers Bypass SMS-based Multi-Factor Authentication Protecting Box Accounts

‘Zero-Click’ Zoom Vulnerabilities Could Have Exposed Calls Raises Concerns

Microsoft Issues Out-of-Band Update for Patch Tuesday Problems

Organizations Face a ‘Losing Battle’ Against Vulnerabilities

Open Source Developers, Who Work for Free, Are Discovering They Have Power

1/17/2022

Destructive Hacks Against Ukraine Echo Its Last Cyberwar

Cyber Espionage Campaign Targets Renewable Energy Companies

DHL, Microsoft, WhatsApp Top Phishing List of Most Imitated Brands

Nintendo Warns of Spoofed Sites Pushing Fake Switch Discounts

Firefox Relay’s Addition to Disposable Email Blocklist Upsets Users
Umbrella Company Parasol Group Confirms Cyber Attack as ‘Root Cause’ of Prolonged Network Outage

UK – Brookson Legal Hit by Cyber-Attack, Confirms No Data Was Removed

Jackson Hospital (FL) Fends off Recent Ransomware Attack

Microsoft: Edge Will Mitigate ‘Unforeseen Active’ Zero Day Bugs

Zoho Patches New Critical Authentication Bypass in Desktop Central

Chrome Limits Websites’ Direct Access to Private Networks for Security Reasons

1/14-16/2022

Krebs: At Request of U.S., Russia Rounds Up 14 REvil Ransomware Affiliates

Biden Administration Says Russia Arrested Colonial Pipeline Hacker

What Russia’s Arrest of REvil Hackers Means for Ransomware

Ukraine: ‘Massive Cyber Attack’ Shuts Down Government Websites

Hackers Likely Used Software Administration Rights of Third Party to Hit Ukrainian Sites, Kyiv Says

Some Signs That Cyber Attack Linked to Hacker Groups Associated With Russia

Ukraine Suspects Group Linked to Belarus Intelligence Over Cyberattack

Microsoft: Fake Ransomware Targets Ukraine in Data-Wiping Attacks

No Lights, No Heat, No Money – That’s Life in Ukraine During Cyber Warfare

U.S. Offers Support After Ukraine Hit By Massive Cyberattack

U.S. Considers Backing an Insurgency if Russia Invades Ukraine

Researchers Develop CAPTCHA Solver to Aid Dark Web Research

The Race Towards Renewable Energy Is Creating New Cybersecurity Risks

States Push Forward With Facebook Antitrust Case, Reportedly Probe VR Unit

Former DHS Official Charged With Stealing Gov’t Employees’ PII

Prosecutors Recommend Dropping Case Over China Ties Against MIT Scientist
Defense Contractor Hensoldt Confirms Lorenz Ransomware Attack

Goodwill Discloses Data Breach on Its ShopGoodwill Platform

Crawford County (AR) Grappling With Ransomware Attack Aftermath

Multi-Day IT Systems Outage Whacks Umbrella Biz Parasol Group Amid Fears of a Cyber Attack

Google Might’ve Accidentally Approved an Ad for a Target Gift Card Scam

eNom Data Center Migration Mistakenly Knocks Sites Offline

npm Dependency Is Breaking Some React Apps Today — Here’s the Fix

Watch Out, That Microsoft Edge Update Is Actually Ransomware

QLocker Ransomware Returns to Target QNAP NAS Devices Worldwide

Safari 15 Bug Can Leak Your Recent Browsing Activity and Personal Identifiers

Three Plugins With Same Bug Put 84k WordPress Sites at Risk

Critical Cisco Contact Center Bug Threatens Customer-Service Havoc

Flaw Found in IDEMIA Biometric ID Devices

New Intel Chips Won’t Play Blu-Ray Disks Due to SGX Deprecation

The Cybersecurity Measures CTOs Are Actually Implementing

Why Is Data Destruction the Best Way to Impede Data Breach Risks?

If You Use The Same Password Everywhere, This is For You

1/13/2022

Apple, Amazon Executives to Meet With White House to Discuss Software Security

Google Calls for New Government Action to Protect Open-Source Software Projects

FCC Proposes New Data Breach Rules for Phone Companies

NSO Group Spyware Targeted Dozens of Reporters in El Salvador

North Korean Hackers Stole Almost $400M in Cryptocurrency in 2021

BlueNoroff Hackers Steal Crypto Using fake MetaMask Extension

Ukrainian Cops Nab Husband and Wife Suspected to Be Part of $1M Ransomware Operation

Florida Woman Vice Principal Charged with Cyber-Stalking

Carding Site UniCC Retires After Generating $358 Million in Sales

How Cryptojacking Can Raise Your Energy Bills

Cybersecurity Labels for Products?
North Port (FL) Officials Investigate Potential Hack on City Network

New GootLoader Campaign Targets Accounting, Law Firms

Adobe Cloud Abused to Steal Office 365, Gmail Credentials

Researchers Decrypted Qakbot Banking Trojan’s Encrypted Registry Keys

Microsoft Defender Weakness Lets Hackers Bypass Malware Detection

Microsoft Yanks Buggy Windows Server Updates

Windows ‘RemotePotato0’ Zero-day Gets An Unofficial Patch

Android Users Can Now Disable 2G to Block Stingray Attacks

AWS Fixes Security Flaws That Exposed AWS Customer Data

New Vulnerabilities Highlight Risks of Trust in Public Cloud

1/12/2022

U.S. Links MuddyWater Hacking Group to Iranian Intelligence Agency

Hackers Take Over Diplomat’s Email, Target Russian Deputy Minister

Teen Hacker Claims Ability to Control 25 Teslas Worldwide

The Latest Phishing Scam: Fraudulent QR Codes on Parking Meters

Stolen TikTok Videos, Bent on Fraud, Invade YouTube Shorts

Krebs: Who is the Network Access Broker ‘Wazawaka?’

Inside the December Ransomware Hit at Nordic Choice Hotels

EU to Stage Large-Scale Cyberattack Exercise on Supply Chains

The ESA Wants You to Hack Its Satellite for Cybersecurity Reasons

Two Years for UK Man Who Used RATs to Spy on Women and Children
Medical Review Institute of America (MRIoA) Reports Data Breach

FIFA Ultimate Team Account Takeovers Plague EA Gamers

Cyber Attack Causes Albuquerque Public Schools to Cancel Classes Thursday

Ransomware to Blame for Maryland Department of Health Service Delays

OceanLotus Hackers Turn to Web Archive Files to Deploy Backdoors

Magniber Ransomware Using Signed APPX Files to Infect Systems

TellYouThePass Ransomware Returns as a Cross-platform Golang Threat

Amazon, Azure Clouds Host RAT-ty Trio in Infostealing Campaign

Widespread, Easily Exploitable Windows RDP Bug Opens Users to Data Theft

Apple Fixes doorLock Bug That Can Disable iPhones and iPads

1/11/2022

World Economic Forum: Cybersecurity an Increasing Global Threat

CISA Alerts Federal Agencies of Ancient Bugs Still Being Exploited

CISA: Russian State-Sponsored Groups Exploited Vulnerabilities in Microsoft, Cisco, Oracle Tools

New RedLine Malware Version Spread as Fake Omicron Stat Counter

DDoS Attacks That Come Combined With Extortion Demands Are on the Rise

Kaspersky Research Uncovers Cybersecurity Budgets, Insurance, and Vendor Expectations for 2022

Top Jobs in the U.S.: Information Security Analyst, #1

Moxie Marlinspike Leaves Encrypted-Messaging App Signal

Medigate Acquired by Claroty

Pentera Announces $150M Series C at $1 Billion Valuation to Disrupt Legacy Vulnerability Management Market

A Missouri Reporter Is Getting Blamed For the Security Flaw He Exposed
FinalSite: No School Data Stolen in Ransomware Attack Behind Site Outages

Children’s Data Is Showing up More Often on the Dark Web

Bernalillo County (NM) Ransomware Attack Left Jail Offline, Leaving Inmates in Lockdown

‘Fully Undetected’ SysJoker Backdoor Malware Targets Windows, Linux & macOS

Millions of Routers Exposed to RCE by USB Kernel Bug

Four Million Outdated Log4j Downloads Were Served From Apache Maven Central Alone Despite Vuln Publicity Blitz

Critical SonicWall NAC Vulnerability Stems from Apache Mods

State Hackers APT35 Use New PowerShell Backdoor in Log4j Attacks

Night Sky Ransomware Uses Log4j Bug to Hack VMware Horizon Servers

Firefox Focus Now Blocks Cross-Site Tracking on Android Devices

Krebs: ‘Wormable’ Flaw Leads January 2022 Patch Tuesday

1/10/2022

Cyber-Spike 2021: Orgs Suffer 925 Attacks per Week, an All-Time High

CISA Director: ‘We Have Not Seen Significant Intrusions’ From Log4j…. Yet

Extortion DDoS Attacks Grow Stronger and More Common

‘PatchWork’ Cyberspies Infect Themselves With Their Own Malware, Exposing Operations

Why Politically Motivated Cyber-Attacks Are a Threat to Democracy

The End of Car Keys, Passwords and Fumbling With Your Phone at Checkout

Castor, Schakowsky Seek Information on Children’s Online Safety Program

Europol Ordered to Erase Data on Those Not Linked to Crime

UK Jails Forensics Expert Who Kept Murder Snaps on PC
Cyber-Thieves Raid Grass Valley (CA)

Loyola Medical Center (IL) Email Breach Exposes Nearly 17,000 Patients’ Info

Singapore Retailer OG Hit by Data Breach

Ragnar_Locker Claims Successful Hack Of Broomfield (CO) Cybersecurity Firm

Panasonic Says Hackers Accessed Personal Data of Job Candidates During November Attack

Abcbot Botnet Linked to Operators of Xanthe Cryptomining Malware

Linux Version of AvosLocker Ransomware Targets VMware ESXi Servers

URL Parsing Bugs Allow DoS, RCE, Spoofing & More

Microsoft: Powerdir Bug Gives Access to Protected macOS User Data

WordPress 5.8.3 Security Update Fixes SQL Injection, XSS Flaws

1/6-9/2022

Hackers Have Been Sending Malware-Filled USB Sticks to U.S. Companies Disguised as Presents

Trojanized dnSspy App Drops Malware Cocktail on Researchers, Devs

U.S. Counterintelligence Shares Tips to Block Spyware Attacks

China’s Next Regulatory Target — Algorithms, the Secret of Many Tech Giants’ Success

Walmart in China’s Spotlight Again as Regulator Cites Infractions

Monsanto Employee Stole Trade Secret to Sell to China

EoL Systems Stonewalling Log4j Fixes for Fed Agencies

Attackers Exploit Flaw in Google Docs’ Comments Feature

Google Voice Authentication Scam Leaves Victims on the Hook

COVID Test Data Breach at British School

Krebs: Norton 360 Now Comes With a Cryptominer

Krebs: 500M Avira Antivirus Users Introduced to Cryptomining

This Tesla Owner Says He Mines up to $800 a Month in Cryptocurrency With His Car

France Fines Google, Facebook for Privacy Violations

Facebook Launches ‘Privacy Center’ to Educate Users on Data Collection and Privacy Options

Swiss Army Bans All Chat Apps but Locally-Developed Threema

U.S. Arrests Suspect Who Stole Unpublished Books in Phishing Attacks

Victims of $200 Million Hack of BitMart Crypto Exchange Still Waiting to Get Their Money Back

Iranian Immigrant Lost $53,000 in Crypto Hack, Says He Faces Ruin if BitMart Doesn’t Pay Him Back
Thousands of Schools Impacted After IT Provider Finalsite Hit by Ransomware

Cyberattackers Hit Data of 80K Patients at Fertility Centers of Illinois

Ciox Health Data Breach Affects ​​AdventHealth, Northwestern and 30 More Providers

3.7M FlexBooker Records Dumped on Hacker Forum

U.S. Online Pharmacy Ravkoo Links Data Breach to AWS Portal Incident

SonicWall: Y2K22 Bug Hits Email Security, Firewall Products

Night Sky Is the Latest Ransomware Targeting Corporate Networks

FluBot Malware Now Targets Europe Posing as Flash Player App

Dev Corrupts NPM Libs ‘Colors’ and ‘Faker’ Breaking Thousands of Apps

QNAP: Get NAS Devices Off the Internet Now

Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover

NHS Warns of Hackers Exploiting Log4Shell in VMware Horizon

Log4J-Related RCE Flaw in H2 Database Earns Critical Rating

Rapid Window Title Changes Cause ‘White Screen of Death’

Cybersecurity Training Isn’t Working. And Hacking Attacks Are Only Getting Worse

Cybersecurity Moving Forward: Four Big Things to Watch in 2022

1/5/2022

China Says Apps That Could Influence Public Opinion Require a Security Review

U.S. Army Journal’s Top Paper From 2021 Says Taiwan Should Destroy TSMC if China Invades

Progressives Put Pressure on Google

How Ransomware Gangs Went Pro

Defending Against Modern Ransomware Tactics

Putting Ransomware Gangs Out of Business With AI

Why Words Matter In Cybersecurity

‘Bulli Bai’ Three Arrested in India for Online Harassment of Muslim Women

1.1M Compromised Accounts Found at 17 Major Companies: NY AG

70 Investors Lose $50 Million to Fraudsters Posing as Broker-Dealers

Crypto Platform ARBIX Flagged as a Rugpull, Transfers $10 Million
Canadian Heavy Equipment Maker Weldco-Beales Confirms Cyber Attack by Karakurt

Franklin Park Conservatory (OH) Experiences Data Breach; Notifying Affected Patrons

Bernalillo County (NM) Reports Suspected Ransomware Attack

Samoan Meteorology Service (SMS) Website May Have Suffered Cyber Attack

‘Elephant Beetle’ Lurks for Months in Networks

‘Malsmoke’ Exploits Microsoft’s E-Signature Verification Using Zloader

iOS Malware Can Fake iPhone Shut Downs to Snoop on Camera, Microphone

Google Chrome Update Includes 37 Security Fixes

Microsoft Defender for Endpoint Adds Zero-Touch iOS Onboarding

CrowdStrike Incorporates Intel CPU Telemetry Into Falcon Sensor

1/4/2022

FTC Warns Companies to Secure Consumer Data From Log4j Attacks

Fears Mount About Russian Cyberattacks in Ukraine

China to Make Some Firms Undergo a Data Security Review Before Listing Overseas

Coming to a Laptop Near You: A New Type of Security Chip From Microsoft: ‘Pluton’; AMD to Integrate Into Upcoming Ryzen CPUs

Upskilling, Better Training Keys to Increasing Cyber Talent Pool

Opportunity Not Fear: Reframing Cybersecurity to Build a Safer Net for All

Come the Metaverse, Can Privacy Exist?

Bulli Bai: India App That Put Muslim Women up for Sale Is Shut

Google Acquires its First Non-American Cybersecurity Firm Siemplify
Have I Been Pwned Warns of DatPiff Data Breach Impacting Millions

Data Skimmer Hits 100+ Sotheby’s Real Estate Websites

UScellular Discloses Data Breach After Billing System Hack

Cyberattack Hits Quasi-State Agency Illinois Office of the Special Deputy Receiver (OSD) For $6.8 Million

Montreal Tourism Agency Confirms Cyber Attack

Carthage Schools (MO) Confirm Ransomware Attack Caused Outage in December

McMenamins December Data Breach Affects 12 Years of Employee Info

SAILFISH System to Find State-Inconsistency Bugs in Smart Contracts

1/3/2022

Companies Face Stricter Cyber Rules in 2022

Novel Method for Detecting Evasive Malware on IoT Devices Using Electromagnetic Field Emanations

Log4j Highlights Need for Better Handle on Software Dependencies

Don’t Copy-Paste Commands From Webpages — You Can Get Hacked

Microsoft Skype Makes You Solve a Complex CAPTCHA 10 Times to Sign Up

Connecting the Dots on Diversity in Cybersecurity Recruitment

Creating the Next Generation of Secure Developers
UK Defence School Hit by Sick Cyber Attack by ‘Russia or China’ Causing ‘Significant’ Damage in Early 2021

Jerusalem Post Targeted by Pro-Iranian Hackers on Soleimani Assassination Anniversary

Portuguese Media Group Impresa Knocked Offline in Ransomware Attack

Purple Fox Malware Distributed via Malicious Telegram Installers

An Apple HomeKit Bug Can Send iOS Devices Into a Death Spiral

Microsoft Issues Fix for Exchange Y2K22 Bug That Crippled Email Delivery Service

12/31/2021-1/2/2022

Fake Vaccine Card Sales a Booming Business as Omicron Surges

The Biggest Data Breaches, Hacks of 2021

Top Cybersecurity and Tech Stories of 2021

Top 10 Healthcare Breaches in the U.S. Exposed Data of 19 Million

Copycat and Fad Hackers Will Be the Bane of Supply Chain Security in 2022

Tech That Will Change Your Life in 2022

Can Social Media Alter a War?
Cyber Attack Disrupts Gloucestershire Council’s Website

PulseTV Discloses Potential Compromise of 200,000 Credit Cards

Broward Health (FL) Suffers Data Breach, Including Medical Info, Through 3rd Party

Popular Q&A App Curious Cat Loses Domain, Posts Bizarre Tweets

Uber Ignores Vulnerability That Lets You Send Any Email From Uber.com

Netgear Leaves Vulnerabilities Unpatched in Nighthawk Router