1/31/2024

U.S. Officials Deliver Warning That Chinese Hackers Are Targeting Infrastructure

Chinese Cyber Attacks Are Intended to ‘Induce Societal Panic’ Across America, Security Directors Tell Congress

CISA: Vendors Must Secure Soho Routers Against Volt Typhoon Attacks

Pawn Storm’s Stealthy Net-NTLMv2 Assault Revealed

U.S. Sanctions Egyptian IT Experts Aiding ISIS in Cybersecurity

EU Launches First Cybersecurity Certification for Digital Products

CISA Warns of Patched iPhone Kernel Bug Now Exploited in Attacks

Exploit Released for Android Local Elevation Flaw Impacting 7 OEMs

Krebs: Florida Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

Police Seize Record 50,000 Bitcoin From Now-Defunct Piracy Site

Uber Fined Almost $11 Million by Dutch Privacy Watchdog
UNC4990: Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware Since 2020

Telegram Marketplaces Fuel Phishing Attacks with Easy-to-Use Kits and Malware

December Cyberattack on Chicago Community Hospital Claimed by LockBit Gang

Johnson Controls Says Ransomware Attack Cost $27 Million, Data Stolen

Hackers Steal $112 Million of XRP Ripple Cryptocurrency

Europcar Denies Data Breach of 50 Million Users, Says Data Is Fake

Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation

Nearly 4-Year-Old Cisco Vuln Linked to Recent Akira Ransomware Attacks

RunC Flaws Enable Container Escapes, Granting Attackers Host Access

Apple and Google Just Patched Their First Zero-Day Flaws of the Year

1/30/2024

U.S. Disabled Chinese Hacking Network Targeting Critical Infrastructure

What Is Volt Typhoon, the Alleged China-Backed Hacking Group?

Robots Are Fighting Robots in Russia’s War in Ukraine

Alpha Ransomware Group Launches Data Leak Site on the Dark Web

Online Ransomware Decryptor Helps Recover Partially Encrypted Files

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

Vastaamo Hacker Traced via ‘Untraceable’ Monero Transactions, Police Says

Citibank Sued Over Failure to Defend Customers Against Hacks, Fraud

U.S. Charges Two More Suspects With DraftKing Account Hacks

How to Stop Location Tracking on Your Android Phone (Mostly)

UK House of Lords Calls For Legislation on Facial Recognition Tech
China-Linked Hackers Target Myanmar’s Top Ministries with Backdoor Blitz

Orange España Breach: Dark Web Flooded With Operator Credentials

Schneider Electric Confirms Ransomware Attack on Sustainability Division

Authorities Investigating Massive Security Breach at Global Affairs Canada

New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility

Rust Payloads Exploiting Ivanti Zero-Days Linked to Sophisticated Sliver Toolkit

Microsoft Teams Phishing Pushes DarkGate Malware via Group Chats

New Linux Glibc Flaw Lets Attackers Get Root on Major Distros

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws

7 Hacking Tools That Look Harmless but Can Do Real Damage

Growing Threats Outpace Cybersecurity Workforce

1/29/2024

Ukraine’s Prisoners of War Agency Hit by Cyberattack

U.S., UK Impose Sanctions on Network That Targeted Iran Dissidents for Assassination

U.S. Lawmakers Tell DOJ to Quit Blindly Funding ‘Predictive’ Police Tools

FBI: Tech Support Scams Now Use Couriers to Collect Victims’ Money

Ransomware Payments Drop to Record Low as Victims Refuse to Pay

Nigerian ‘Yahoo Boys’ Behind Social Media Sextortion Surge in the U.S.

Dark Web Drugs Vendor Forfeits $150m After Guilty Plea

DHS Employees Jailed for Stealing Data of 200K U.S. Gov’t Workers

SolarWinds Slams SEC Lawsuit Against It as ‘Unprecedented’ Victim Blaming

Apple’s New Stolen Device Protection Has a Big Vulnerability: Here’s How to Fix It
Energy Giant Schneider Electric Hit by Cactus Ransomware Attack

Fulton County (GA) Hit With a Cyberattack

Freehold Township School District (NJ) Shut Down by Cyberattack

Keenan Warns 1.5 Million People of Data Breach After Summer Cyberattack

750 Million Indian Mobile Subscribers’ Info for Sale on Dark Web

Phobos Ransomware Family Expands With New FAUST Variant

Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords

45K Jenkins Servers Exposed to RCE Attacks Using Public Exploits

Top 3 Data Breaches of 2023; What’s Ahead in 2024

1/26-28/2024

Microsoft Warns of Widening APT29 Espionage Attacks Targeting Global Orgs

Microsoft Reveals How Hackers Breached Its Exchange Online Accounts

Ukraine: Hack Wiped 2 Petabytes of Data From Russian Research Center

U.S. National Security Agency Buys Web Browsing Data Without Warrant, Letter Shows

The Pentagon Tried to Hide That It Bought Americans’ Data Without a Warrant

Krebs: Who is Alleged Medibank Hacker Aleksandr Ermakov?

Ukraine Arrests Hacker for Assisting Russian Missile Strikes

Police Arrest California Teen Said to Be Linked to Hundreds of Swatting Attacks Nationwide

Apple Faces ‘Strong Action’ if App Store Changes Fall Short, EU’s Breton Says

Cyber Management Details Emerge Under SEC Rules

The SEC Can’t Protect Its Own Data. Should It Be Trusted to Protect Yours?
New Leaks Expose Web of Iranian Intelligence and Cyber Companies

23andMe Failed to Detect Account Intrusions for Months

Akira Ransomware Gang Says It Stole Passport Scans From Lush in 110 GB Data Heist

Data Theft Plaguing K-12 Schools After Holiday Season Attacks

How a Mistakenly Published Password Exposed Mercedes-Benz Source Code

Malicious Ads on Google Target Chinese Users with Fake Messaging Apps

AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks

Exploits Released for Critical Jenkins RCE Flaw, Patch Now

Pwn2Own Automotive: $1.3M for 49 Zero-Days, Tesla Hacked Twice

Wait, Security Courses Aren’t a Requirement to Graduate With a Computer Science Degree?

CISO Corner: Deep Dive Into SecOps, Insurance, & CISOs’ Evolving Role

1/25/2024

Ukraine Energy Firm, Postal Service Among State Agencies Hit by Apparent Cyberattack

China-Aligned APT Group Blackwood Unleashes NSPX30 Implant

Big-Name Targets Push Midnight Blizzard Hacking Spree Back Into the Limelight

How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar

Fake Robocalls in New Hampshire Stoke Election Misinformation Fears

Krebs: Using Google Search to Find Software Can Be Risky

Apple to Allow Downloads Outside App Store in EU, With New Fees

iPhone Apps Abuse iOS Push Notifications to Collect User Data

Russian TrickBot Malware Dev Sentenced to 64 Months in Prison

Help Wanted From Convicted Cybercriminals
Over 198GB of BuyGoods.com Data Exposed By Misconfigured Database

23andMe Data Breach: Hackers Stole Raw Genotype Data, Health Reports

New CherryLoader Malware Mimics CherryTree to Deploy PrivEsc Exploits

SystemBC Malware’s C2 Server Analysis Exposes Payload Delivery Tricks

LODEINFO Fileless Malware Evolves with Anti-Analysis and Remote Code Tricks

Hackers Target WordPress Database Plugin Active on 1 Million Sites

Critical Jenkins Vulnerability Exposes Servers to RCE Attacks – Patch ASAP!

Cisco Warns of Critical RCE Flaw in Communications Software

Tesla Hacked Again, 24 More Zero-Days Exploited at Pwn2Own Tokyo

1/24/2024

Notorious Spyware Maker NSO Group Is Quietly Plotting a Comeback

U.S. Judge Rejects Spyware Developer NSO’s Attempt to Bin Apple’s Spyware Lawsuit

Ring Steps Back From Sharing Video With Police — Mostly

ChatGPT Cybercrime Surge Revealed in 3000 Dark Web Posts

UK Says AI Will Empower Ransomware Over the Next Two Years

Why Bulletproof Hosting is Key to Cybercrime-as-a-Service

Italy Government Proposes Tougher Jail Terms for Cybercriminals

U.S., UK, Australia Sanction Russian REvil Hacker Behind Medibank Breach
Wall Street Fintech EquiLend Offline After Cyberattack

Hewlett Packard Enterprise Suffered Cyber Breach Over Months Last Year

Major IT Outage at Europe’s Largest Caravan and RV Club Makes for Not-So-Happy Campers

Kansas City Area Transportation Authority Hit With Cybersecurity Attack

Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters

Over 5,300 GitLab Servers Exposed to Zero-Click Account Takeover Attacks

Tesla Hacked, 24 Zero-Days Demoed at Pwn2Own Automotive 2024

Who Pays, and Why: A Researcher Examines the Ransomware Victim’s Mindset

1/23/2024

Missouri Secretary of State Accused of Withholding Cybersecurity Reviews of Election Authorities

UK Water Giant Southern Water Admits Attackers Broke Into System as Gang Holds It to Ransom

Water Services Giant Veolia North America Hit by Ransomware Attack

Microsoft Balances SEC Disclosure Rules After Email Hack

HP CEO Says They Brick Printers That Use Third-Party Ink Because of … Hackers

French Watchdog Slams Amazon with €32m Fine for Spying on Workers

CISA Boss Swatted: ‘While My Own Experience Was Certainly Harrowing, It Was Unfortunately Not Unique’

Accused PII Seller Faces Jail for Running Underground Fraud Op

X Adds Passkeys Support for iOS Users in the United States

AI Will Make Scam Emails Look Genuine, UK Cybersecurity Agency Warns

AI Program Poised to Advance Cybersecurity in Abu Dhabi
Mega-Breach Database Exposes 26 Billion Records

Trello API Abused to Link Email Addresses to 15 Million Accounts

Jason’s Deli Says Online Platform Customer Data Exposed in Credential Stuffing Attack from December

Douglas County (CO) Libraries Hacked by Overseas Criminal Group

First Financial Security (GA) Notifies Consumers of Breach Following October Ransomware Attack

Bucks County (PA) Emergency Dispatch System Down for Days Due to Cyberattack

VexTrio: The Uber of Cybercrime – Brokering Malware for 60+ Affiliates

Kasseika Ransomware Uses Antivirus Driver to Kill Other Antiviruses

Malicious npm Packages Used to Target GitHub Developer SSH Keys

Fortra Warns of New Critical GoAnywhere MFT Auth Bypass, Patch Now

Exploit Released for Fortra GoAnywhere MFT Auth Bypass Bug

1/22/2024

Microsoft Russian Hack Leaves Too Much Unanswered

Tietoevry Ransomware Attack Causes Outages for Swedish Firms, Cities

North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor

A SIM-Swapping Attack Was Behind the Sec’s Fake Bitcoin Post

Malicious Web Redirect Scripts Stealth up to Hide on Hacked Sites

Cracked macOS Apps Drain Wallets Using Scripts Fetched From DNS Records

You Need to Turn on Apple’s New Stolen iPhone Tool

Cops Used DNA to Predict a Suspect’s Face—and Tried to Run Facial Recognition on It

Medibank Hack: Russian Sanctioned Over Australia’s Worst Data Breach

Thai Court Blocks 9near.org to Avoid Exposure of 55M Citizens

FTC Orders Intuit to Stop Pushing “Free” Software That Isn’t Really Free
AerCap Discloses Cybersecurity Incident

LoanDepot Data Breach Hits 16.6 Customers

Trezor Support Site Breach Exposes Personal Data of 66,000 Customers

Dawson James Securities (FL) Reports Data Breach After Unauthorized Access to Network

Subway’s Data Torpedoed by LockBit, Ransomware Gang Claims

NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers

Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks

Hackers Start Exploiting Critical Atlassian Confluence RCE Flaw

MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries

Ivanti: VPN Appliances Vulnerable if Pushing Configs After Mitigation

Apple Issues Patch for Critical Zero-Day in iPhones, Macs – Update Now

1/19-21/2024

Microsoft ‘Senior Leadership’ Emails Accessed by Russian SolarWinds Hackers 

Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years

VMware Confirms Critical vCenter Flaw Now Exploited in Attacks

ABB’s China Operations Under Investigation by U.S. Congress

Fashion Giant Faces New IPO Hitch: China’s Cybersecurity Police

The Verge: The Verge Is Not Interested in Interviewing You About Crypto — But Scammers Are

Krebs: Canadian Man Stuck in Triangle of E-Commerce Fraud

Fujitsu Bugs That Sent Innocent People to Prison Were Known ‘From the Start’

IT Consultant Fined for Daring to Expose Shoddy Security

Five Ripped off IT Giant With Bogus Work Expenses, Prosecutors Claim

BreachForums Hacking Forum Admin Sentenced to 20 Years Supervised Release

FTC Bans One More Data Broker From Selling Your Location Info
U.S. Agencies Warn Made-In-China Drones Might Help Beijing Snoop on the World

VF Cyberattack Compromised Data for 35 Million Customers

Payoneer Accounts in Argentina Hacked in 2FA Bypass Attacks

Carnegie Mellon University Hit by Cyber Attack Last August

Money Message Ransomware Gang Claims Responsibility for Christmas Hospital Attack

Researchers Link 3AM Ransomware to Conti, Royal Cybercrime Gangs

Watch Out for “I Can’t Believe He Is Gone” Facebook Phishing Posts

Meta Won’t Remove Fake Instagram Profiles That Are Clearly Catfishing

Npm Trojan Bypasses UAC, Installs AnyDesk with “Oscompatible” Package

CISA Issues Emergency Directive to Federal Agencies on Ivanti Zero-Day Exploits

Brave to End ‘Strict’ Fingerprinting Protection as It Breaks Websites

Missing the Cybersecurity Mark With the Essential Eight

1/18/2024

Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware Written in Rust

Google: Russian FSB Hackers Deploy New Spica Backdoor Malware

CISA: Critical Ivanti Auth Bypass Bug Now Actively Exploited

‘Stablecoins’ Enabled $40 Billion in Crypto Crime Since 2022

Haier Hits Home Assistant Plugin Dev With Takedown Notice

JPMorgan Exec Claims Bank Repels ’45 Billion Cyberattack Attempts per Day’

U.S. Gov’t Wants BreachForums Admin Sentenced to 15 Years in Prison
Bangladeshi Elections Come Into DDoS Crosshairs

Cyber Attacks on Kent Councils Disrupt Online Services

Hampton-Newport News Community Services Board Ransomware Attack Leads to Breach

TA866 Resurfaces in Targeted OneDrive Campaign

TeamViewer Abused to Breach Networks in New Ransomware Attacks

New Malware Campaign Exploits 9hits in Docker Assault

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

1/17/2024

Microsoft: Iranian Hackers Target Researchers With New MediaPl Malware

Krebs: E-Crime Rapper ‘Punchmade Dev’ Debuts Card Shop

Experts Ponder Effectiveness of Official Warnings of Cyber Scams

How a 27-Year-Old Codebreaker Busted the Myth of Bitcoin’s Anonymity

The Next iOS Update Will Make It Harder to Break Into Your iPhone

iShutdown Scripts Can Help Detect iOS Spyware on Your iPhone

OpenAI Announces Plans to Combat Misinformation Amid 2024 Elections

Mastercard Aims to Limit AI Bias, Cyber Risk

Philippines to Propose ASEAN AI Regulatory Framework, House Speaker Says

AI, Gaming, FinTech Named Major Cybersecurity Threats For Kids
Taiwanese Semiconductor Company Foxsemicon Hit by Ransomware Attack

Ameriprise Financial Notifies Consumers of Recent Data Breach

Burr & Forman Discloses October Data Breach

Toronto Zoo Employees’ Personal Information Stolen in Ransomware Attack

Kansas State University Systems Impacted by Cybersecurity Threat

Have I Been Pwned Adds 71 Million Emails From Naz.API Stolen Account List

Cheap .Cloud Domains and Fake Shark Tank News Fuel Unhealthy Wellness Scams

Bigpanzi Botnet Infects 170,000 Android TV Boxes With Malware

PAX PoS Terminal Flaw Could Allow Attackers to Tamper with Transactions

CISA Pushes Federal Agencies to Patch Citrix RCE Within a Week

1/16/2024

Ivanti Connect Secure Zero-Days Now Under Mass Exploitation

FBI: Androxgh0st Malware Botnet Steals AWS, Microsoft Credentials

A Flaw in Millions of Apple, AMD, and Qualcomm GPUs Could Expose AI Data

MacOS Info-Stealers Quickly Evolve to Evade XProtect Detection

New Tool Identifies Pegasus and Other iOS Spyware

GitHub Rotates Keys to Mitigate Impact of Credential-Exposing Flaw

The Sad Truth of the FTC’s ‘Historic’ Privacy Win

Pentagon Using ChatGPT? Oh Sure, for Cyber-Things and Veterans, Says OpenAI

Africa, Middle East Lead Peers in Cybersecurity, but Lag Globally

Cybersecurity Giant Palo Alto Networks to Record High After Record High
Majorca City Calvià Extorted for $11M in Ransomware Attack

Singing River Health System (MS) Notifies 252K Patients of Recent Data Breach

Data Breach at Dallas-Based Cooper Aerobics Exposes 90,000 Customer Accounts

Leaked COVID Tests Expose Sensitive Patient Data

Remcos RAT Spreading Through Adult Games in New Attack Wave

Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+

Citrix Warns of New Netscaler Zero-Days Exploited in Attacks

Google Fixes First Actively Exploited Chrome Zero-Day of 2024

PixieFail Flaws Impact PXE Network Boot in Enterprise Systems

Patch Now: Critical VMware, Atlassian Flaws Found

1/15/2024

Anonymous Sudan Claims London Internet Exchange Attack Over Yemen Strikes

Environmental Websites Hit by DDoS Surge in COP28 Crossfire

Latest Adblock Update Causes Massive YouTube Performance Hit

U.S. Court Docs Expose Fake Antivirus Renewal Phishing Tactics
British Library Starts Restoring Services Online After Hack

Windows SmartScreen Flaw Exploited to Drop Phemedrone Malware

Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows

Over 178K SonicWall Firewalls Vulnerable to DoS, Potential RCE Attacks

1/12-14/2024

New Findings Challenge Attribution in Denmark’s Energy Sector Cyberattacks

Hyundai MEA X Account Hacked, Followed by Crypto Promotion

U.S. SEC Says Breach of X Account Did Not Lead To Breach of Its Broader Systems

CISA Urges Critical Infrastructure to Patch Urgent ICS Vulnerabilities

Waiting for Your Pay Raise? Cofense Warns Against HR-Related Scams

29-Year-Old Ukrainian Cryptojacking Kingpin Arrested for Exploiting Cloud Services

GrapheneOS: Frequent Android Auto-Reboots Block Firmware Exploits

Cybersecurity Measures For Remote Hiring: Ensuring Confidentiality And Data Protection

A Guide to Getting the Right Cyber Insurance
British Cosmetics Firm Lush Confirms Cyberattack

2023 Ransomware Attack on U.S. Navy Shipbuilder Fincantieri Leaked Info of Nearly 17K People

Medusa Ransomware Gang Targets Nonprofit Water for People

Medusa Ransomware on the Rise: From Data Leaks to Multi-Extortion

Number of Orgs Compromised via Ivanti VPN Zero-Days Grows as Mandiant Weighs In

Exploit for Under-Siege Sharepoint Vuln Reportedly in Hands of Ransomware Crew

Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches

GitLab Warns of Critical Zero-Click Account Hijacking Vulnerability

1/11/2024

Finland Warns of Akira Ransomware Wiping NAS and Tape Backup Devices

Anonymous Sudan Launches Cyberattack on Chad Telco

U.S. School Shooter Emergency Plans Exposed in a Highly Sensitive Database Leak

Fake Recruiters Defraud Facebook Users via Remote-Work Offers

Mandiant’s X Account Was Hacked in Brute-Force Password Attack

Crypto Drainer-As-A-Service Gang

SEC Twitter Hack: Here’s How to Protect Your Own Account on X

Child Abusers Are Getting Better at Using Crypto to Cover Their Tracks

Threat Actors Increasingly Abusing GitHub for Malicious Purposes

eBay to Cough up $3M After Cyber-Stalking Couple Who Dared Criticize the Souk

Bitwarden Adds Passkey Support to Log Into Web Password Vaults
Framework Discloses Data Breach After Accountant Gets Phished

Halara Probes Breach After Hacker Leaks Data for 950,000 People

Fallon Ambulance announces data breach affecting over 900,000 patients

Oregon Pacific Bank Files Official Notice of Data Breach

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms

New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems

Atomic Stealer Gets an Upgrade – Targeting Mac Users with Encrypted Payload

New Balada Injector Campaign Infects 6,700 WordPress Sites

Over 150K WordPress Sites at Takeover Risk via Vulnerable Plugin

Microsoft Shares Script to Update Windows 10 WinRE With BitLocker Fixes

1/10/2024

AI Helps U.S. Intelligence Track Hackers Targeting Critical Infrastructure

Krebs: Here’s Some Bitcoin, Oh, and You’ve Been Served!

Cybercrooks Play Dress-up as ‘Helpful’ Researchers in Latest Ransomware Ruse

Malware Takedowns Show Progress, But Fight Against Cybercrime Not Over

Lawmakers Are Out for Blood After a Hack of the SEC’s X Account Causes Bitcoin Chaos

SEC Approves Bitcoin ETFs for Everyday Investors

Uncle Sam Tells Hospitals: Meet Security Standards or No Federal Dollars for You

Fake 401K Year-End Statements Used to Steal Corporate Credentials

ShinyHunters Chief Phisherman Gets 3 Years, Must Cough up $5M
Attack on UK Defense Contractor Ultra I&C Leaks Military Details

Texas-Based Care Provider HMG Healthcare Says Hackers Stole Unencrypted Patient Data

ConsensioHealth (WI) Data Breach Affects Patients of Four Healthcare Providers

India’s Shopping Giant Infiniti Mall Cyberattack: 280,000 Records Potentially Exposed

Attacker Targets Hadoop YARN, Flint Servers in Stealthy Campaign

NoaBot: Latest Mirai-Based Botnet Targeting SSH Servers for Crypto Mining

Ivanti Warns of Connect Secure Zero-Days Exploited in Attacks

Cisco Says Critical Unity Connection Bug Lets Attackers Get Root

Windows 10 KB5034441 Security Update Fails With 0x80070643 Errors

1/9/2024

Hackers Hit Moscow Internet Provider in Response to Kyivstar Cyber Attack

The SEC’s X Account Was Hijacked to Post a Fake Approval of Bitcoin ETFs

FTC Bans Data Broker From Selling Americans’ Location Data

CISA Warns Agencies of Fourth Flaw Used in Triangulation Spyware Attacks on Apple, Adobe, Apache, D-Link, and Joomla Products

China Claims It Cracked Apple’s Airdrop to Find Numbers, Email Addresses

Ransomware Victims Targeted by Fake Hack-Back Offers

New Decryption Key Available for Babuk Tortilla Ransomware Victims

Krebs: Meet Ika & Sal, The Bulletproof Hosting Duo from Hell

Cybersecurity Deals Boom as Investment Dips, Pinpoint Reports

82% of Companies Struggle to Manage Security Exposure

New York State Plans to Give Some Cities Free Cyber Tools

Amazon Is Going ‘Super Aggressive’ on Generative AI

Nigerian Gets 10 Years For Laundering Scam Funds

Google Search Bug Shows Blank Page in Firefox for Android
Paraguay Warns of Black Hunt Ransomware Attacks After Tigo Business Breach

Australian Travel Agency Inspiring Vacations Hit by Data Breach, Leaking Passport and Travel Details of Thousands of Customers

Entire Population of Brazil Possibly Exposed in Massive Data Leak

ProSmile Notifies Patients of July 2022 Data Breach

Hackers Can Infect Network-Connected Wrenches to Install Ransomware

Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware

Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer

Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager

Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe

Flaw in AI Plugin Exposes 50,000 WordPress Sites to Remote Attack

Path Traversal Bug Besets Popular Kyocera Office Printers

New Year, New Bugs in Windows, Adobe, Android, More to Be Fixed

Microsoft January 2024 Patch Tuesday Fixes 49 Flaws, 12 RCE Bugs

1/8/2024

Netgear, Hyundai Latest X Accounts Hacked to Push Crypto Drainers

North Korean Hackers Stole $600m in Crypto in 2023

Merck Settles With Insurers Over $700m NotPetya Claim

NIST Warns of Security and Privacy Risks from Rapid AI System Deployment

Facebook, Instagram Now Mine Web Links You Visit to Fuel Targeted Ads

Twilio Will Ditch Its Authy Desktop 2FA Application in August of This Yeah , Goes Mobile Only

Can Hackers Get Into Your Google Account Without a Password?
Toronto Zoo: Ransomware Attack Had No Impact on Animal Wellbeing

Anti-Hezbollah Groups Hack Beirut Airport Screens

Iranian Crypto Exchange Leaks User Passports and IDs

Capital Health Attack Claimed by LockBit Ransomware, Risk of Data Leak

Rhysida Ransomware Gang Takes Credit for Christmas Attack on Global Lutheran Organization

U.S. Mortgage Lender loanDepot Confirms Ransomware Attack

New Research: Tackling .NET Malware With Harmony Library

1/5-7/2024

Stealthy AsyncRAT Malware Attacks Target U.S. Infrastructure for 11 Months

Web3 Security Firm CertiK’s X Account Hacked to Push Crypto Drainer

X Users Fed up With Constant Stream of Malicious Crypto Ads

Crypto Wallet Founder Loses $125,000 to Fake Airdrop Website

How to Be More Anonymous Online

BreachForums Boss Busted for Bond Blunders – Including Using a VPN

19 xDedic Cybercrime Market Users and Admins Face Prison

Google: Malware abusing API is standard token theft, not an API issue

KyberSlash Attacks Put Quantum Encryption Projects at Risk
Pro-Iranian Hacker Group Targeting Albania with No-Justice Wiper Malware

Syrian Threat Group Peddles Destructive SilverRAT

SpectralBlur: New macOS Backdoor Threat from North Korean Hackers

Sea Turtle Cyber Espionage Campaign Targets Dutch IT and Telecom Companies

Memorial University Recovers From Cyberattack, Delays Semester Start

Mortgage Firm loanDepot Cyberattack Impacts IT Systems, Payment Portal

Beckley (WV) Latest Municipality Hit With Cyberattack

CompleteCare Health Network (NJ) Reports Data Breach From Ransomware Attack

Hackers Target Apache RocketMQ Servers Vulnerable to RCE Attacks

1/4/2024

Russian Sandworm Hackers Were Inside Ukraine Telecoms Giant Kyivstar for Months

To Beat Russia, Ukraine Needs a Major Tech Breakthrough

Hackers Hijack Gov’t and Business Accounts on X for Crypto Scams

Mandiant’s Twitter Account Restored After Six-Hour Crypto Scam Hack

Fun New Deepfake Consequence: More Convincing Crypto Scam

Cyber Leaders With Tight Budgets Still Must Secure AI, Cloud

FTC Offers $25,000 Prize for Detecting AI-Enabled Voice Cloning
Law Firm Orrick, Herrington & Sutcliffe That Handles Data Breaches Was Hit by Data Breach

Navvis & Company Reports Data Breach Affecting Patients of Certain Healthcare Providers

UAC-0050 Group Using New Phishing Tactics to Distribute Remcos RAT

3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners

‘Everything’ Blocks Devs From Removing Their Own Npm Packages

Ivanti Warns Critical EPM Bug Lets Hackers Hijack Enrolled Devices

Zeppelin Ransomware Source Code Sold for $500 on Hacking Forum

1/3/2024

Russia Spies on Kyiv Defenses via Hacked Cameras Before Missile Strikes

23andMe Tells Victims It’s Their Fault That Their Data Was Breached

LastPass Will Finally Enforce a 12-Character Minimum Master Password

A New Year’s Resolution for Tech Companies: Knock It off With the CAPTCHAs

For Cyber Companies, Economic Turbulence in 2023 Sets Up Uncertain 2024

Alleged Crunchbase Data Breach Exposes Millions to Potential Threats

Formal Ban on Ransomware Payments? Asking Orgs Nicely to Not Cough up Ain’t Working

Over 100 European Banks Face Cyber Resilience Test

VoIP Firm XCast Agrees to Settle $10m Illegal Robocall Case

Nigerian Hacker Arrested for Stealing $7.5m From Charities
Data Breach at Healthcare Tech Firm HealthEC Impacts 4.5 Million Patients

Nearly 1 Million Affected by Ambulance Service Transformative Healthcare Data Breach

Network180 (MI) Data Breach Impacts as Many as 59,000 People

Freight Giant Estes Refuses to Deliver Ransom, Says Personal Data Opened and Stolen

Hacker Hijacks Orange Spain RIPE Account to Cause BGP Havoc

‘Large-Scale’ Cyberattack Hits French Township, All Local Services Down

Fake and Stolen X Gold Accounts Flood Dark Web

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset

Nearly 11 Million SSH Servers Vulnerable to New Terrapin Attacks

CISA Warns of Actively Exploited Bugs in Chrome and Excel Parsing Library

1/2/2024

States and Congress Wrestle With Cybersecurity After Iran Attacks Small Town Water Utilities

Israel Battles Spike in Wartime Hacktivist, OT Cyberattacks

What It’s Like to Use Apple’s Lockdown Mode

Passkeys: All the News and Updates Around Passwordless Sign-on

Google Password Resets Not Enough to Stop These Info-Stealing Malware Strains

Teen Found Alive After “Cyber-Kidnapping” Incident

Google Settles $5 Billion Privacy Lawsuit Over Tracking Users in ‘Incognito Mode’

Google Groups Is Ending Support for Usenet to Combat Spam
Online Museum Collections Down After Cyberattack on Service Provider

Xerox Says Subsidiary XBS U.S. Breached After Ransomware Gang Leaks Data

Swedish Grocery Chain Coop Targeted by Cactus Ransomware Gang

Iranian Food Delivery Giant Snappfood Cyber Attack: 3TB of Data Stolen

Bunker Hill Community College (MA) Announces Data Breach

Akumin (FL) Data Breach Impacts Consumers’ SSNs Following Ransomware Attack

Steam Drops Support for Windows 7 and 8.1 to Boost Security

12/29/2023-1/1/2024

The Biggest Cybersecurity and Cyberattack Stories of 2023

The Worst Hacks of 2023

Here We Go Again: 2023’s Badly Handled Data Breaches

Happy 14th Birthday, KrebsOnSecurity!

CEO Arranged His Own Cybersecurity, With Predictable Results

2023 Showed Cybersecurity Isn’t Immune From Brutal Layoffs

New Black Basta Decryptor Exploits Ransomware Flaw to Recover Files

Beware: Scam-as-a-Service Aiding Cybercriminals in Crypto Wallet-Draining Attacks

Hospitals Ask Courts to Force Cloud Storage Firm to Return Stolen Data

The Law Enforcement Operations Targeting Cybercrime in 2023

Chinese Authorities Arrest Four in Ransomware Case Involving ChatGPT
Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks

Pro-Palestinian Operation Claims Dozens of Data Breaches Against Israeli Firms

Russian Hackers Believed to Be Behind Cyber Attack on Victoria’s Court System

Albanian Parliament and One Albania Telecom Hit by Cyber Attacks

Cyberattack on Anna Jaques Hospital (MA) Disrupted Records System, Emergency Services

Orbit Chain Confirms Hack, Warns of Scam Repayment Offers

Android Game Dev’s Google Drive Misconfig Highlights Cloud Security Risks

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

Malware Abuses Google OAuth Endpoint to ‘Revive’ Cookies, Hijack Accounts

Google Fixes Nearly 100 Android Security Issues