11/30/2023

NATO Holds Cyber Defense Exercise as Wartime Hacking Threats Rise

U.S., Partners Target North Korea (and Kimsuky) With Sanctions Following Satellite Launch

North Korean Hackers Amass $3bn in Cryptocurrency Heists

Bad Password May Have Led to Pennsylvania Water System Hack

Google Unveils RETVec – Gmail’s New Defense Against Spam and Malicious Emails

WhatsApp’s New Secret Code feature Hides Your Locked Chats

8 Tips on Leveraging AI Tools Without Compromising Security

Fewer Cybersecurity Professionals Losing Their Jobs in Breach ‘Blame’ Game

Law Firms & Legal Departments Singled Out for Cyberattacks
Capital Health Hospitals Hit by Cyberattack Causing IT Outages

Staples Confirms Cyberattack Behind Service Outages, Delivery Issues

Booking.com Hackers Increase Attacks on Customers

Forward Bank (WI) Notifies 46,019 Customers of Recent Data Breach

FjordPhantom Android Malware Targets Banks With Virtualization

CACTUS Ransomware Exploits Cloud Analytics Qlik Sense Vulnerabilities in Targeted Attacks

RedLine Stealer Malware Deployed Via ScrubCrypt Evasion Tool

Zyxel Warns of Multiple Critical Vulnerabilities in NAS Devices

Google Fixes a Seventh Zero-Day Flaw in Chrome—Update Now

Apple Fixes Two New iOS Zero-Days in Emergency Updates

11/29/2023

Hackers Breach U.S. Water Facility via Exposed Unitronics PLCs

Cybersecurity Agency Warns That Water Utilities Are Vulnerable to Hackers After Pennsylvania Attack

U.S. Dept of Treasury Seizes Sinbad Cryptocurrency Mixer Used by North Korean Lazarus Hackers

Google Researchers’ Attack Prompts ChatGPT to Reveal Its Training Data

How to Find Your Forgotten Gmail Accounts

Keeping Children Safe in a Rapidly Changing Digital Landscape

SIM Swapper Gets 8 Years in Prison for Account Hacks, Crypto Theft

How a Teenage Saudi Hacker Went From Lockpicking to Ransomware
Krebs: Okta Breach Affected All Customer Support Users

Okta Hack Update Shows Challenges in Rapid Cyber Disclosures

Japanese Space Agency JAXA Hacked in Summer Cyberattack

Dollar Tree Hit by Third Party Data Breach at Zeroed-In Technologies Impacting 2 Million People

Hendersonville (NC) Targeted in Cyber Attack, Employee Data Potentially Compromised

Black Basta Ransomware Made Over $100 Million From Extortion

DJVU Ransomware’s Latest Variant ‘Xaro’ Disguised as Cracked Software

GoTitan Botnet and PrCtrl RAT Exploit Apache Vulnerability

11/28/2023

Ransomware Hackers ‘Wreaking Havoc’ Arrested in Ukraine

‘Kingpin Arrests’

N. Korean Hackers ‘Mixing’ macOS Malware Tactics to Evade Detection

Americans Receive Two Billion Spam Calls Per Month

How Hackers Phish for Your Users’ Credentials and Sell Them

AI Tools Such as ChatGPT Are Generating a Mammoth Increase in Malicious Phishing Emails

Cybercriminals Hesitant About Using Generative AI

Deepfake Digital Identity Fraud Surges Tenfold, Sumsub Report Finds

Krebs: ID Theft Service Resold Access to USInfoSearch Data

Reminder: Google Is About to Start Purging Inactive Accounts

The Hundred-Year Battle for India’s Radio Airwaves

India’s CERT Given Exemption From Right to Information Requests

Splunk Beats Quarterly Revenue Estimates on Robust Cybersecurity Demand

Former Uber CISO Speaks Out, After 6 Years, on Data Breach, SolarWinds
Municipal Water Authority of Aliquippa (PA) Victim of Cyberattack

Federal Officials Investigating Pro-Iran Group

Undetected Android Trojan Expands Attack on Iranian Banks

DP World Confirms Data Stolen in Cyberattack, No Ransomware Used

Qilin Ransomware Claims Attack on Automotive Giant Yanfeng

Egyptian E-Payment Vendor Fawry Recovering From LockBit Ransomware Attack

Proliance Surgeons (WA) Announces Cyber Attack Resulting in Data Breach

Gloucester City Council Spent £1.1 Million Recovering From Ransomware Attack

New BLUFFS Attack Lets Attackers Hijack Bluetooth Connections

Hackers Start Exploiting Critical ownCloud Flaw, Patch Now

Design Flaw in Google Workspace Could Let Attackers Gain Unauthorized Access

Google Chrome Emergency Update Fixes 6th Zero-Day Exploited in 2023

11/27/2023

Hackers Targeting Israeli Businesses Say They Will Pause as Fighting Stops

Ukraine Says It Hacked Russian Aviation Agency, Leaks Data

Leader of Pro-Russia DDoS Crew Killnet ‘Unmasked’ by Russian State Media

Beijing Fosters Foreign Influencers to Spread Its Propaganda

General Electric, DARPA Hack Claims Raise National Security Concerns

A Controversial U.S. Surveillance Program May Get Slipped Into a ‘Must-Pass’ Defense Bill

U.S., Britain, Other Countries Ink Agreement to Make AI ‘Secure by Design’

AI Threat Demands New Approach to Security Designs -U.S. Official

OpenAI’s Board Might Have Been Dysfunctional–but They Made the Right Choice; In the Battle Between AI profits and Ethics, It’s No Contest

The Decision to Restore Altman and Appoint a New Board of Directors Is a Victory for Both OpenAI and Microsoft

Cyber Insurers Warn Catastrophic Hacks Will Require Government Help

What a Failed Attack Against ColdFusion Revealed About Ransomware Tools and Tactics
Ardent Hospital ERs Disrupted in 6 States After Ransomware Attack

Meow Ransomware hits Vanderbilt University Medical Center

Healthcare Giant Henry Schein Hit Twice by BlackCat Ransomware

Slovenia’s Largest Power Provider HSE Hit by Ransomware Attack

Clear Spring Life and Annuity Company (IN) Announces Data Breach Following Ransomware Attack

Ransomware ‘Catastrophe’ at Fidelity National Financial Causes Panic With Homeowners and Buyers

Ransomware Attack on Indie Game Maker Gellyberry Studios Wiped All ‘Ethyrial: Echoes of Yore’ MMORPG Player Accounts

British Library Hack: Customer Data Offered for Sale on Dark Web

Some Lee County (FL) Student Laptops Reportedly Hacked

‘Prank’

Microsoft Deprecates Defender Application Guard for Office

The Power of Storytelling in Cybersecurity Training

11/24-26/2023

Hamas-Linked Cyberattacks Using Rust-Powered SysJoker Backdoor Against Israel

New ‘HrServ.dll’ Web Shell Detected in APT Attack Targeting Afghan Government

East Texas Hospital Network Can’t Receive Ambulances Because of Potential Cybersecurity Incident

Cybercriminals Using Telekopye Telegram Bot to Craft Phishing Scams on a Grand Scale

Gmail Hackers Leave Vital Clues Behind—Check These 3 Things Now

Facebook vs. The Free Press
CTS Cyber-Attack Disrupts UK Property Deals

General Electric Investigates Claims of Cyber Attack, Data Theft

Gulf Air Exposed to Data Breach, ‘Vital Operations Not Affected’

Kubernetes Secrets of Fortune 500 Companies Exposed in Configuration Upload to Public Repositories

Critical Bug in ownCloud File Sharing App Exposes Admin Passwords

OpenCart Owner Turns Air Blue After Researcher Discloses Serious Vuln

11/23/2023

EU Mulls Wider Scope for Cybersecurity Certification Scheme

Industry Piles in on North Korea for Sustained Rampage on Software Supply Chains

Rug Pull Schemes: Crypto Investor Losses Near $1M

OpenAI Researchers Warned Board of AI Breakthrough Ahead of CEO Ouster

Nvidia Sued After Video Call Mistake Showed ‘Stolen’ Data

Cyber Security Professionals Are Exhausted, and It’s Putting Firms at Greater Risk of Attack
$115 Million Stolen From Two Crypto Firms Linked to Justin Sun After Hack

BlackCat Claims It Is Behind Fidelity National Financial Ransomware Shakedown

New Relic Warns Customers It’s Experienced a Cyber … Something

Nassau Bay (TX) Attacked by Akira Ransomware Gang

Alert: New WailingCrab Malware Loader Spreading via Shipping-Themed Emails

InfectedSlurs Botnet Resurrects Mirai With Zero-Days

11/22/2023

Australia Beefs up Cyber Defences After Major Breaches

Microsoft: Lazarus Hackers Breach CyberLink in Supply Chain Attack

New Flaws in Fingerprint Sensors Let Attackers Bypass Windows Hello Login

Scattered Spider Hops Nimbly From Cloud to On-Prem in Complex Attack

OpenAI Says Sam Altman to Return as CEO

Behind the Scenes of Sam Altman’s Showdown at OpenAI

Ilya Sutskever: The OpenAI Genius Who Told Sam Altman He Was Fired

3 Ways to Stop Unauthorized Code From Running in Your Network

U.S. Cybercops Take On ‘Pig Butchering’ Org, Return $9M in Scammed Crypto
Open-Source Blender Project Battling DDoS Attacks Since Saturday

Welltok Data Breach Exposes Data of 8.5 Million U.S. Patients

Cyberattackers Leaked Data of 27,000 NYC Bar Association Members

Kansas Courts Confirm Data Theft, Ransom Demand After Cyberattack

HTX Exchange Loses $13.6m in Hot Wallet Hack

Retool Data Breach Affects MG Stover and Multiple Investment Funds

ClearFake Campaign Expands to Target Mac Systems with Atomic Stealer

New Botnet Malware Exploits Two Zero-Days to Infect NVRs and Routers

11/21/2023

U.S. Cybersecurity Lab Suffers Major Data Breach

SiegedSec

Bahrain Government Websites Briefly Inaccessible After Cyberattack Over Israel-Hamas War

Mustang Panda Hackers Targets Philippines Government Amid South China Sea Tensions

Konni Campaign Deploys Advanced RAT With UAC Bypass Capabilities

North Koreans Use Fake Names, Scripts to Land Remote IT Work for Cash

Majority in New Survey Worried About Being Tricked by Scammer

How Multi-Stage Phishing Attacks Exploit QRs, CAPTCHAs, and Steganography

DOJ Charges Binance With Vast Money-Laundering Scheme and Sanctions Violations

Ex-CEO of NSO Group Raises $33.6 Million for Israeli Cyber Startup

Tor Project Removes Relays Because of For-Profit, Risky Activity
Sumo Logic Wrestles With Security Breach, Pins Down Customer Data

Auto Parts Giant AutoZone Warns of MOVEit Data Breach

Owens Group Hit by Ransomware Cyber Attack

Prestige Care Data Breach Affects an Unknown Number of Residents and Employees

New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks

Lumma Malware Can Allegedly Restore Expired Google Auth Cookies

Play Ransomware Goes Commercial – Now Offered as a Service to Cybercriminals

Citrix Warns Admins to Kill NetScaler User Sessions to Block Hackers

CISA Orders Federal Agencies to Patch Looney Tunables Linux Bug

Microsoft Launches Defender Bounty Program With $20,000 Rewards

11/20/2023

Indian Hack-for-Hire Group Targeted U.S., China, and More for Over 10 Years

Gamaredon’s LittleDrifter USB malware spreads beyond Ukraine

Secretive White House Surveillance Program Gives Cops Access to Trillions of U.S. Phone Records

CISA Unveils Healthcare Cybersecurity Guide

NHS Secretary Fined For Accessing Scores of Patient Records

Canadian Government Discloses Data Breach After Contractor Hacks

Cybersecurity Firm Executive Pleads Guilty to Hacking Hospitals

Sam Altman to Join Microsoft Following OpenAI Ouster

More Than 700 of 770 OpenAI Employees Employees Threaten to Quit Unless Board Resigns

Ukraine Sacks Top Cybersecurity Officials in Corruption Probe Involving Software Purchases
MOVEit Victim Count Latest: 2.6K+ Orgs Hit, 77M+ People’s Data Stolen

Greater Paris Wastewater Agency Dealing With Cyberattack

Rhysida Ransomware Gang Claims British Library Cyberattack

NetSupport RAT Infections on the Rise – Targeting Government and Business Sectors

DarkGate and PikaBot Malware Resurrect QakBot’s Tactics in New Phishing Attacks

Infostealer Lumma Evolves With New Anti-Sandbox Method

VX-Underground Malware Collective Framed by Phobos Ransomware

Kinsing Malware Exploits Apache ActiveMQ RCE to Plant Rootkits

How the Evolving Role of the CISO Impacts Cybersecurity Startups

11/17-19/2023

Black Friday: Scammers Exploit Luxury Brands to Lure Victims

FCC Adopts New Rules to Protect Consumers From SIM-Swapping Attacks

FCC Proposes 3-Year Cybersecurity Pilot for Schools, Libraries

Russian Cyber Espionage Group Deploys LitterDrifter USB Worm in Targeted Attacks

Russian Hackers Use Ngrok Feature and WinRAR Exploit to Attack Embassies

Google: Hackers Exploited Zimbra Zero-Day in Attacks on Gov’t Orgs

A Spy Agency Leaked People’s Data Online—Then the Data Was Stolen

LockBit Gang Says ICBC Paid Ransom Over Hack That Disrupted U.S. Treasury Market

How a Hack Shook Wall Street’s Multitrillion-Dollar Foundations

Ransomware Targets Will Pay One Way or Another

Companies Are Building Their Defenses Against AI Hackers, Says TrustedSec’s David Kennedy

OpenAI Ousted CEO Sam Altman, but Is Reportedly Reconsidering the Move

How an Indian Startup Hacked the World

The Cybersecurity Lawsuit That Boards Are Talking About
Multiple Colleges, K-12 Schools Facing Outages After Cyberattacks

‘Sex Life Data’ Stolen From UK Government Among Record Number of Ransomware Attacks

Yamaha Motor Confirms Ransomware Attack on Philippines Subsidiary

British Library: Ongoing Outage Caused by Ransomware Attack

Stanley Steemer Hack Breached Data of Almost 67K Customers

Mt. Graham Regional Medical Center (AZ) Confirms Data Breach from Ransomware Attack

Bloomberg Crypto X Account Snafu Leads to Discord Phishing Attack

8Base Group Deploying New Phobos Ransomware Variant via SmokeLoader

Beware: Malicious Google Ads Trick WinSCP Users into Installing Malware

Exploit for CrushFTP RCE Chain Released, Patch Now

CISA Warns of Actively Exploited Windows, Sophos, and Oracle Bugs

Researchers Extract RSA Keys From SSH Server Signing Errors

Hands Off the Security Budget! Find Efficiencies to Reduce Risk

Cybersecurity: It’s Not A Job—It’s A Mission

11/16/2023

Russian Hackers Linked to ‘Largest Ever Cyber Attack’ on Danish Critical Infrastructure

FBI Warns on Scattered Spider Hackers, Urges Victims to Come Forward

U.S. Congress Report Calls for Privacy Reforms After FBI Surveillance ‘Abuses’

Krebs: Alleged Extortioner of Psychotherapy Patients Faces Trial

Cyber-Criminals Exploit Gaza Crisis With Fake Charity

Most Overused Passwords in the World — Make Sure Yours Isn’t on the List

3 Ways Behavioral Economics Obstructs Cybersecurity

How to Opt Out of Facebook’s Latest Two-Factor Authentication Change

Running Signal Will Soon Cost $50 Million a Year

AI Risks Force Corporate Privacy Officers to Expand Oversight

European Police Take Down $9m Vishing Gang

BlackCat Ransomware Group Reports Victim to SEC

MeridianLink Confirms Cyberattack
Toyota Confirms Breach After Medusa Ransomware Threatens to Leak Data

Long Beach, California Turns off IT Systems After Cyberattack

St. Lucie County (FL) Tax Collector Hacked by Ransomware Attacker ‘Dark Cat’

Rivers Casino (IL) Customers, Employees Targeted by Data Breach

MySQL Servers Targeted by ‘Ddostf’ DDoS-as-a-Service Botnet

Experts Uncover DarkCasino: New Emerging APT Threat Exploiting WinRAR Flaw

Hackers Could Exploit Google Workspace and Cloud Platform for Ransomware Attacks

Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups

Fortinet Warns of Critical Command Injection Bug in FortiSIEM

Consumer Software Security Assessment: Should We Follow NHTSA’s Lead?

CSA Launches First Zero Trust Certification

Almost Half of Ransomware Groups Operating in 2023 Are New

11/15/2023

Australia Says Hacks Surging, State-Sponsored Groups Targeting Critical Infrastructure

European Firms Urge China to Give More Clarity on Data Transfer Laws

U.S. Cloud Providers Create Special Localized Security Services for Europe

U.S. Government Unveils First AI Roadmap For Cybersecurity

Cyber Experts Worry AI Could Create a World of Haves and Have-Nots

Social Media Sleuths, Armed With AI, Are Identifying Dead Bodies

Google’s New Titan Security Keys Are Ready for a World Without Passwords

Microsoft Debuts New Unified Security Solution With Security Copilot

FBI Director: FISA Section 702 Warrant Requirement a ‘De Facto Ban’
Samsung Hit by New Data Breach Impacting UK Store Customers

Perry Johnson & Associates (PJ&A) Says Cyberattack Exposed Data of Nearly 9 Million Patients

Toronto Public Library Confirms Data Stolen in Ransomware Attack

Major Canadian Fintech Moneris Claimed by Medusa Ransomware

BlackCat Ransomware Gang Targets Businesses Via Google Ads

FBI and CISA Warn of Opportunistic Rhysida Ransomware Attacks

Fraudsters Make $50,000 a Day by Spoofing Crypto Researchers

New PoC Exploit for Apache ActiveMQ Flaw Could Let Attackers Fly Under the Radar

Krebs: Microsoft Patch Tuesday, November 2023 Edition

Teenager Who Allegedly Bragged ‘Fraud Is Fun’ Pleads Guilty To Sports Betting Hack

11/14/2023

Biden Meets With Indonesia President Ahead of Xi Summit

The Top U.S. Cybersecurity Agency Has a New Plan for Weaponized AI

FBI Struggled to Disrupt Dangerous Casino Hacking Gang, Cyber Responders Say

Ransomware Royale: U.S. Confirms Royal, BlackSuit Are Linked

Here’s the Proof There’s No Government Alien Conspiracy Around Roswell

Russia Man Arrested in Florida Pleads Guilty to Building Now-Dismantled IPStorm Proxy Botnet

Teens With “Digital Bazookas” Are Winning the Ransomware War, Researcher Laments

LockBit Ransomware Exploits Citrix Bleed in Attacks, 10K Servers Exposed

Did LockBit Ransomware Mess up by Attacking U.S. Arm of China’s Biggest Bank?
New Campaign Targets Middle East Governments with IronWind Malware

Vietnamese Ducktail Hackers Using New Delphi-Powered Malware to Target Indian Marketers

B2B Pharmacy Provider Truepill Reports Data Breach Impacting 2.3 Million Customers

Cyberattack on Bladen County (NC) Allowed Hackers to Access Data

WP Fastest Cache Plugin Bug Exposes 600K WordPress Sites to Attacks

VMware Discloses Critical VCD Appliance Auth Bypass with No Patch

CacheWarp Attack: New Vulnerability in AMD SEV Exposes Encrypted VMs

Intel Out-Of-Band Patch Addresses Privilege Escalation Flaw

Microsoft Fixes Critical Azure CLI Flaw That Leaked Credentials in Logs

11/13/2023

EU Formalizes Cybersecurity Support For Ukraine

LockBit Gang Says ICBC Paid Ransom Over Hack That Disrupted U.S. Treasury Market

Chinese Hackers Launch Covert Espionage Attacks on 24 Cambodian Organizations

China Proposes Cybersecurity Check for Auditors if National Security Involved

Zelle Banks Have Been Paying Back Scam Victims After Government Pressure

In a First, Cryptographic Keys Protecting SSH Connections Stolen in New Attack

Inside Denmark’s Hell Week as Critical Infrastructure Orgs Faced Cyberattacks

U.S. Privacy Groups Urge Senate Not to Ram Through NSA Spying Powers

New York Plans Cyber Rules for Hospitals
New BiBi-Windows Wiper Targets Windows Systems in Pro-Hamas Attacks

Australia Ports Operator Back Online After Cyber Incident

Canadian Banking Tech Giant Moneris Says It Prevented Ransomware Attack

Automotive Supplier Yanfeng Hit by Cyberattack, Disrupting Stellantis Production

Huber Heights (OH) Hit by Ransomware Cyber Attack

Python Malware Poses DDoS Threat Via Docker API Misconfiguration

FBI: Royal Ransomware Asked 350 Victims to Pay $275 Million

Ethereum Feature Abused to Steal $60 Million From 99K Victims

CISA Warns of Actively Exploited Juniper Pre-Auth RCE Exploit Chain

Introducing the Tech That Keeps the Lights On

11/10-12/2023

Australia Ports Operator DP World Australia Suffers ‘Cybersecurity Incident’, Suspends Operations

Australia Says Ports Operator Cyber Incident ‘Serious’

ICBC Puts Capital Into U.S. Unit, Seeks Cyber Review After Hack

The NSA Seems Pretty Stressed About the Threat of Chinese Hackers in U.S. Critical Infrastructure

Senate Leaders Plan to Prolong NSA Surveillance Using a Must-Pass Bill

Microsoft Warns of Sapphire Sleet’s Fake Skills Assessment Portals Targeting IT Job Seekers

Microsoft: BlueNoroff Hackers Plan New Crypto-Theft Attacks

Krebs: It’s Still Easy for Anyone to Become You at Experian

Strangely Enough, No One Wants to Buy a Ransomware Group That Has Cops’ Attention

Police Takes Down BulletProftLink Large-Scale Phishing Provider
Iran-Linked Imperial Kitten Cyber Group Targeting Middle East’s Tech Sectors

Impatient LockBit Says It’s Leaked 50GB of Stolen Boeing Files After Ransom Fails to Land

Poloniex Crypto-Exchange Offers 5% Cut to Thieves if They Return That $120M They Nicked

McLaren Health Care Says Data Breach Impacted 2.2 Million People

Millions of Northwell Health Patients Potentially Caught in Perry Johnson & Associates Data Breach

York Region School Board (ON) Dealing With a Cyber Attack

Hackers Breach Healthcare Orgs via ScreenConnect Remote Access

Alert: ‘Effluence’ Backdoor Persists Despite Patching Atlassian Confluence Servers

Microsoft Extends Windows Server 2012 ESUs to October 2026

Navigating Tech Risks in Modern M&A Waters

11/9/2023

Ransomware Attack on China’s ICBC Disrupts Treasury Market Trades

LockBit

MuddyC2Go: New C2 Framework Iranian Hackers Using Against Israel

Sandworm Hackers Caused Another Blackout in Ukraine—During a Missile Strike

Signature Techniques of Asian APT Groups Revealed

Generative AI Will Level up Cyber Attacks, According to New Google Report

OpenAI Reveals ChatGPT Is Being DDoS-ed

Signal Tests Usernames So You Can Avoid Sharing Your Phone Number

Omegle Is Shutting Down Notorious Video Chat Service as Scrutiny Grows

SolarWinds Denies SEC Charges Over Cyber Disclosures

Downfall Fallout: Intel Knew AVX Chips Were Insecure and Did Nothing, Lawsuit Claims
Kyocera AVX Says Ransomware Attack Impacted 39,000 Individuals

Mr. Cooper Says Customer Data Exposed During Cyberattack

Maine Government Says MOVEit Data Breach Affects 1.3 Million Residents

Law Firm Allen & Overy Hit by ‘Data Incident’

Suspected Ransomware Attack Hits Scottish Council

Tri-City Medical Center in Oceanside (CA) Hit by Cybersecurity Attack

Harris County (TX) Public Mental Health Provider Recovering From Apparent Cyber Attack

New Kamran Spyware Targets Urdu-Speaking Users in Pakistan

New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers

CISA Alerts: High-Severity SLP Vulnerability Now Under Active Exploitation

Zero-Day Alert: Lace Tempest Exploits SysAid IT Support Software Vulnerability

11/8/2023

Microsoft Warns of Election Threats in 2024

Meta Says It Will Label Political Ads That Use AI-Generated Imagery

U.S. Urges Critical Infrastructure Firms to Get “Shields Ready”

FBI Warns of Emerging Ransomware Initial Access Techniques

Predator AI ChatGPT Integration Poses Risk to Cloud Services

WhatsApp Can Now Hide Your IP Address During Calls for Added Security

Fortinet, Rivals Fall on Concerns Around Cybersecurity Spending

Microsoft Drops SMB1 Firewall Rules in New Windows 11 Build
Russian State-Owned Sberbank Hit by 1 Million RPS DDoS Attack

Popular Lego Marketplace BrickLink Went Offline After a ‘Ransom’ Demand

Sumo Logic Discloses Security Breach, Advises API Key Resets

AvidXchange Reports Data Breach After Unauthorized Access

Researchers Uncover Undetectable Crypto Mining Technique on Azure Automation

Ransomware Mastermind Uncovered After Oversharing on Dark Web

Threat Actor Farnetwork Linked to Five Ransomware Schemes

Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPI

11/7/2023

North Korea’s New BlueNoroff Malware Variant Targets Cryptocurrency Exchanges

SideCopy Exploiting WinRAR Flaw in Attacks Targeting Indian Government Entities

A New U.S. Privacy Bill Seeks to End Warrantless Police and FBI Spying

Data Broker’s “Staggering” Sale of Sensitive Info Exposed in Unsealed FTC Filing

Google, Meta, Discord, and More Team Up to Fight Child Abuse Online

Woman Jailed After rentahitman.com Assassin Turned Out to Be – Surprise – FBI

Bradford Ethical Hacker Honoured With Record-Breaking Work

Microsoft Authenticator Now Blocks Suspicious MFA Alerts by Default
Japan Aviation Electronics (JAE) Breached By ALPHV

Cook County (IL) Health: Data Breach Potentially Affected up to 1.2 Million Patients

Data Breach at Singapore’s Marina Bay Sands Affects 665,000 Customers

TransForm Says Ransomware Data Breach Affects 267,000 Patients

Dakota Eye Institute Files Notice of Data Breach Affecting More Than 107k

Pulaski County (VA) Public Schools Investigating Cyber Attack

Fake Ledger Live App in Microsoft Store Steals $768,000 in Crypto

GootBot Implant Heightens Risk of Post-Infection Ransomware

11/6/2023

Iranian Hackers Launches Destructive Cyberattacks on Israeli Tech and Education Sectors

U.S. Slaps Sanctions on Accused Fave Go-to Money Launderer of Russia’s Rich and Ryuk Ransomware

U.S., Japan and South Korea Unite to Counter North Korean Cyber Activities

U.S. Law Firms Rethink China Future Amid Economic Woes, Data Crackdown

Siemens, Ericsson Warn EU Cybersecurity Rules May Disrupt Supply Chains

How Will the SEC’s Pursuit of SolarWinds Affect Cyber Chiefs? Readers Weigh In

Google Warns How Hackers Could Abuse Calendar Service as a Covert C2 Channel

Krebs: Who’s Behind the SWAT USA Reshipping Service?

AI Fake Nudes Are Booming. It’s Ruining Real Teens’ Lives.

Meet Your New Cybersecurity Auditor: Your Insurer
DDoS Attack Revealed as Cause of Online Service Outage at Public Healthcare Institutions

Spy Trojan SpyNote Unveiled in Attacks on Gamers

SecuriDropper: New Android Dropper-as-a-Service Bypasses Google’s Defenses

New Jupyter Infostealer Version Emerges with Sophisticated Stealth Tactics

Critical Atlassian Confluence Bug Exploited in Cerber Ransomware Attacks

TellYouThePass Ransomware Joins Apache ActiveMQ RCE Attacks

Hackers Exploit Looney Tunables Linux Bug, Steal Cloud Creds

Veeam Warns of Critical Bugs in Veeam ONE Monitoring Platform

QNAP Releases Patch for 2 Critical Flaws Threatening Your NAS Devices

Microsoft Will Roll Out MFA-Enforcing Policies for Admin Portal Access

11/3-5/2023

Healthcare Data Breaches Impact 88 Million Americans

Discord File Links Will Expire After a Day to Fight Malware

Google Play Store Introduces ‘Independent Security Review’ Badge for Apps

NodeStealer Malware Hijacking Facebook Business Accounts for Malicious Ads

Apple ‘Find My’ Network Can Be Abused to Steal Keylogged Passwords

Flipper Zero: This Tiny Device Is Sending Updated iPhones Into a Never-Ending DoS Loop, Rending Them Useless

Sam Bankman-Fried Is Convicted of Fraud in FTX Collapse

‘Corrupt’ Cop Jailed for Tipping off Pal to EncroChat Dragnet

Dutch Hacker Jailed for Extortion, Selling Stolen Data on RaidForums
American Airlines Pilot Union Hit by Ransomware Attack

Infosys Subsidiary Hit by Cyber Security Attack–Investigation Launched to Identify Overall Impact

Okta’s Recent Customer Support Data Breach Impacted 134 Customers

81K People’s Sensitive Info Feared Stolen From Hilb After Email Inboxes Ransacked

Socks5Systemz Proxy Service Infects 10,000 Systems Worldwide

Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud Environments

New Microsoft Exchange Zero-Days Allow RCE, Data Theft Attacks

Atlassian Warns of Exploit for Confluence Data Wiping Bug, Get Patching

11/2/2023

Krebs: Russian Reshipping Service ‘SWAT USA Drop’ Exposed

Israeli Entities Under Attack By MuddyWater’s Advanced Tactics

Russia’s Wagner Group Plans to Send Air Defenses to Hezbollah, U.S. Says

The UN Hired an AI Company to Untangle the Israeli-Palestinian Crisis

Brave Responds to Bing and ChatGPT With a New ‘Anonymous and Secure’ AI Chatbot

Microsoft Is Overhauling Its Software Security After Major Azure Cloud Attack

What to Know About New Federal and State Cyber Rules

Infosec Pros Can Secure IT, but Have Harder Time Securing Job Satisfaction

Do Government Sanctions Against Ransomware Groups Work?
Cloudflare Dashboard and APIs Down After Data Center Power Outage

Mortgage Giant Mr. Cooper Hit by Cyberattack Impacting IT Systems

Okta Tells 5,000 of Its Own Staff That Their Data Was Accessed in Third-Party Breach

Ace Hardware Says 1,202 Devices Were Hit During Cyberattack

Boeing Acknowledges Cyberattack on Parts and Distribution Biz

Confidential Student Data Exposed in Fairfax County Public Schools Breach

BlackCat Ransomware Claims Breach of Healthcare Giant Henry Schein

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability

Spy Module Discovered in WhatsApp Mods

11/1/2023

North Korean Hackers Target macOS Crypto Engineers With Kandykorn

Palo Alto Reveals New Features in Russian APT Turla’s Kazuar Backdoor

Mysterious Kill Switch Shuts Down Mozi IoT Botnet

FSB Arrests Russian Hackers Working for Ukrainian Cyber Forces

Feds Collar Suspected Sanctions-Busting Russian Smugglers of U.S. Tech

New York Adds Stiffer Requirements to Cybersecurity Rules

Clorox Bets on Strong Inventory to Help Overcome Cyber Attack Hitting Operations

Splunk to Lay Off Nearly 7% Of Its Workforce Amid Economic Woes

Chainguard, an Open-Source Security Firm, Raises $61 Million

3 Ways to Close the Cybersecurity Skills Gap — Now
Hackers Use Citrix Bleed Flaw in Attacks on Gov’t Networks Worldwide

Iranian Cyber Espionage Group Targets Financial and Government Sectors in Middle East

Mexico’s Querétaro Intercontinental Airport Confirms Cyberattack

Toronto Public Library Outages Caused by Black Basta Ransomware Attack

Data Breach Reported at Meals on Wheels Central Texas

Postmeds Data Breach Impacts Hundreds of Thousands of Consumers Nationwide

Authorities Confirm Town of Iowa (LA) Target of Cyberattack

Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability

3,000 Apache ActiveMQ Servers Vulnerable to RCE Attacks Exposed Online

New CVSS 4.0 Vulnerability Severity Rating Standard Released