5/30/2024

FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine

macOS Version of Elusive ‘LightSpy’ Spyware Tool Discovered

Healthcare Sector Maps Cyber Risk Posed by ‘Single Points of Failure’

Mystery Attacker Remotely Bricked 600,000 SOHO Routers With Malicious Firmware Update

U.S. Treasury Says NFTs ‘Highly Susceptible’ to Fraud, but Ignored by High-Tier Criminals

Krebs: ‘Operation Endgame’ Hits Malware Delivery Platforms

U.S. Dismantles World’s Largest 911 S5 Botnet with 19 Million Infected Devices

The Unusual Espionage Act Case Against a Drone Photographer

These Internet Browsers Promise Privacy. What Does That Actually Mean?
Cybercriminals Raid BBC Pension Database, Steal Records of Over 25,000 People

Patients’ Personal Information Possibly Exposed in Data Breach at UChicago Medicine

Everbridge Warns of Corporate Systems Breach Exposing Business Data

Cooler Master Confirms Customer Info Stolen in Data Breach

Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package

Pirated Microsoft Office Delivers Malware Cocktail on Systems

RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall Vulnerability

Researchers Uncover Active Exploitation of WordPress Plugin Vulnerabilities

CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

5/29/2024

Meta Says It Removed Six ‘Inauthentic’ Influence Campaigns Including Those From Israel and China

Advance Fee Fraud Targets Colleges With Free Piano Offers

Over 90 Malicious Android Apps With 5.5M Installs Found on Google Play

Krebs: Treasury Sanctions Creators of 911 S5 Proxy Botnet (Update)

Stole $5.9 Billion in COVID Relief Funds

More Krebs: Is Your Computer Part of ‘The Largest Botnet Ever?’

New Head of FBI Pittsburgh Office Is Cyber Security Expert

NIST Expects to Clear Backlog in Vulnerabilities Database by End of Fiscal Year
Internet Archive Disrupted by Sustained and “Mean” DDoS Attack

Hackers Claim Ticketmaster Data Breach: 560M Users’ Info for Sale at $500K

Cooler Master Hit by Data Breach Exposing Customer Information

First American December Data Breach Impacts 44,000 People

New PyPI Malware “Pytoileur” Steals Crypto and Evades Detection

Okta Warns of Credential Stuffing Attacks Targeting Its CORS Feature

Check Point Releases Emergency Fix for VPN Zero-Day Exploited in Attacks for Remote Access

Check Point VPN Zero-Day Exploited in Attacks Since April 30

5/28/2024

Microsoft Links North Korean Hackers to New FakePenny Ransomware

Deepfake Scams Have Robbed Companies of Millions. Experts Warn It Could Get Worse

OpenAI Sets up Safety Committee as It Starts Training New Model

How Researchers Cracked an 11-Year-Old Password to a $3 Million Crypto Wallet

SpiderOak One Customers Threaten to Jump Ship Following Datacenter Upgrade

BreachForums Returns, Just Weeks After FBI-Led Takedown

U.S. Gov’t Sanctions Cybercrime Gang Behind Massive 911 S5 Botnet

Russian Indicted for Selling Access to U.S. Corporate Networks
Ransomware Group RansomHub Claims Responsibility for Christie’s Hack

Auction House Christie’s Confirms Criminals Stole Some Client Data

Spyware Maker pcTattletale Shutters After Data Breach

Seattle Public Library Goes Offline After Ransomware Event

TeaBot Banking Trojan Activity on the Rise, Zscaler Observes

Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique

Exploit Released for Maximum Severity Fortinet RCE Bug, Patch Now

XSS Vulnerabilities Found in WordPress Plugin Slider Revolution

5/27/2024

Pakistan-Linked Hackers ‘Transparent Tribe’ Deploy Python, Golang, and Rust Malware on Indian Targets

Moroccan Cybercrime Group Steals Up to $100K Daily Through Gift Card Fraud

New Tricks in the Phishing Playbook: Cloudflare Workers, HTML Smuggling, GenAI

Generative AI May Be Creating More Work Than It Saves
Bayer and 12 Other Major Drug Companies Caught up in Wholesaler Cencora Data Loss

Sav-Rx Discloses Data Breach Impacting 2.8 Million Americans

Hackers Target Check Point VPNs to Breach Enterprise Networks

TP-Link Fixes Critical RCE Bug in Popular C5400X Gaming Router

5/24-26/2024

North Korea Rejects U.S. Accusation, Says It Is Not Linked to Any Cyber Attacks

Fake Pegasus Spyware Strains Populate Clear and Dark Web

Hacker Defaces Spyware App Site pcTattletale, Dumps Database and Source Code

Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack

Beware: These Fake Antivirus Sites Spreading Android and Windows Malware

Best Buy and Geek Squad Were Most Impersonated Orgs by Scammers in 2023

Here’s Why Deleted iPhone Photos Returned to Some iOS Devices

Experts Find Flaw in Replicate AI Service Exposing Customers’ Models and Data

Indian Man Stole $37 Million in Crypto Using Fake Coinbase Pro Site

Man Behind Deepfake Biden Robocall Indicted on Felony Charges, Faces $6M Fine

Wargames Director Jackie Schneider on Why Cyber Is One of ‘The Most Interesting Scholarly Puzzles’
Stealthy BLOODALCHEMY Malware Targeting ASEAN Government Networks

Cencora Notifies Individuals About Data Stolen Earlier This Year

Health Information Published Online After MediSecure Ransomware Attack

Suspected Cyber Attack Continues to Hobble Operations at Palomar Health Medical Group (CA)

Walmart 401(K) Data Breach Leaks Names, Social Security Numbers of Plan Participants

Albany County (NY) Investigating ‘Cybersecurity Breach’ Ahead of Holiday Weekend

Hackers Phish Finance Orgs Using Trojanized Minesweeper Clone

New ShrinkLocker Ransomware Uses BitLocker to Encrypt Your Files

Arc Browser’s Windows Launch Targeted by Google Ads Malvertising

Google Fixes Eighth Actively Exploited Chrome Zero-Day This Year

Three-Year-Old Apache Flink Flaw Under Active Attack

ICQ Messenger Shuts Down After Almost 28 Years

5/23/2024

Inside Operation Diplomatic Specter: Chinese APT Group’s Stealthy Tactics Exposed

A Leak of Biometric Police Data Is a Sign of Things to Come

Absolutely Wild: How the FBI Built and Ran Its Own Smartphone Company to Hack the Criminal Underworld

He Trained Cops to Fight Crypto Crime—and Allegedly Ran a $100M Dark-Web Drug Market

Krebs: Stark Industries Solutions: An Iron Hammer in the Cloud

Cybercriminals Exploit Cloud Storage For SMS Phishing Scams

Microsoft Spots Gift Card Thieves Using Cyber-Espionage Tactics

Casino Cyberattacks Put a Bullseye on Scattered Spider – And the FBI Is Closing In

You Can Now Share Passwords Within Your Google Family Group

Apple Wasn’t Storing Deleted iOS Photos in iCloud After All
Fallout From Cyberattack at Ascension Hospitals Persists, Causing Delays in Patient Care

National Records of Scotland Data Breached in NHS Cyber-Attack

JAVS Courtroom Recording Software Backdoored in Supply Chain Attack

A Closer Look at What Wyandotte County (KS) Leaders Spend on Cybersecurity Amid ‘Network Incident’

Lash Group (SC) Announces Data Breach Affecting Bayer Corp. Customers

Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern

High-Severity GitLab Flaw Lets Attackers Take Over Accounts

Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager

NVD Leaves Exploited Vulnerabilities Unchecked

5/22/2024

Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries: ‘Unfading Sea Haze’

Chinese Hackers Rely on Covert Proxy Networks to Evade Detection

‘People Are Just Not Worried About Being Scammed’

Spyware Found on U.S. Hotel Check-In Computers

Teslas Can Still Be Stolen With a Cheap Radio Hack—Despite New Keyless Tech

Mastercard Doubles Speed of Fraud Detection with Generative AI

SEC’s $10 Million Fine of NYSE Owner Shows Focus on Cyber Disclosures

U.S. Unveils $50M Program to Help Hospitals Patch Cybersecurity Gaps

Preparing Your Organization for Upcoming Cybersecurity Deadlines
Conservative Cell Carrier Patriot Mobile Hit by Data Breach

Norman Public Schools (OK) Facing Ransomware Attack

Accounting Firm Dohman, Akerlund & Eddy (NE) Notifies Consumers of February 2024 Data Breach

MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted Attacks

UserPro Plugin Vulnerability Allows Account Takeover

QNAP Patches New Flaws in QTS and QuTS hero Impacting NAS Appliances

Microsoft to Start Killing Off VBScript in Second Half of 2024

Microsoft’s New Windows 11 Recall Is a Privacy Nightmare

LastPass Is Now Encrypting URLs in Password Vaults for Better Security

5/21/2024

Russia’s Turla APT Abuses MSBuild to Deliver TinyTurla Backdoor

Russia’s DoppelGänger Campaign Manipulates Social Media

Russia Is Expanding Its Cyberwar Against the West

Billionaire Urges Russian Firms to Build Alternative to SAP Software

Hacktivists Turn to Ransomware in Attacks on Philippines Government

Family Offices Become Prime Targets for Cyber Hacks and Ransomware

With Ransomware Whales Becoming So Dominant, Would-Be Challengers Ask ‘What’s the Point?’

UK to Propose Mandatory Reporting for Ransomware Attacks and Licensing Regime for All Payments

Rockwell Automation Warns Admins to Take ICS Devices Offline

Krebs: Why Your Wi-Fi Router Doubles as an Apple AirTag

YouTube Becomes Latest Battlefront for Phishing, Deepfakes

Zoom Adds ‘Post-Quantum’ Encryption for Video Nattering

Ransomware and AI-Powered Hacks Drive Cyber Investment

Eventbrite Promoted Illegal Opioid Sales to People Searching for Addiction Recovery Help

Can Cybersecurity Be a Unifying Factor in Digital Trade Negotiations?
Western Sydney University Data Breach Exposed Student Data

LockBit Says They Stole Data in London Drugs Ransomware Attack

Trego County Hospital (KS) Targeted by Ransomware Attack

CentroMed (TX) Confirms Data Breach Affecting an Estimated 400k

GhostEngine Mining Attacks Kill EDR Security Using Vulnerable Drivers

SolarMarker Malware Evolves to Resist Takedown Attempts with Multi-Tiered Infrastructure

Malware Delivery via Cloud Services Exploits Unicode Trick to Deceive Users

Bitbucket Artifact Files Can Leak Plaintext Authentication Secrets

Critical GitHub Enterprise Server Flaw Allows Authentication Bypass

Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by Firefox

“Linguistic Lumberjack” Vulnerability Discovered in Popular Logging Utility Fluent Bit

NextGen Healthcare Mirth Connect Under Attack – CISA Issues Urgent Warning

Veeam Warns of Critical Backup Enterprise Manager Auth Bypass Bug

5/20/2024

Iranian President Ebrahim Raisi, Hardline Ally of Khamenei, Killed in Helicopter Crash

Iran-Linked Void Manticore Intensifies Cyber-Attacks on Israel: ‘BiBi Wiper’

EPA Says It Will Step up Enforcement to Address ‘Critical’ Vulnerabilities Within Water Sector

HHS Offering $50 Million for Proposals to Improve Hospital Cybersecurity

Election Officials Are Role-Playing AI Threats to Protect Democracy

AI Chatbots Highly Vulnerable to Jailbreaks, UK Researchers Find

Windows 11 Recall AI Feature Will Record Everything You Do on Your PC

Google Thinks the Public Sector Can Do Better Than Microsoft’s ‘Security Failures’

How to Remove Your Personal Info From Google’s Search Results

Can I Phone a Friend? How Cops Circumvent Face Recognition Bans
OmniVision Discloses Data Breach After 2023 Ransomware Attack

Interactive Brokers (CT) Announces Data Breach Due to Compromised Employee Email Account

Latrodectus Malware Loader Emerges as IcedID’s Successor in Phishing Campaigns

Cyber Criminals Exploit GitHub and FileZilla to Deliver Malware Cocktail

QNAP QTS Zero-Day in Share Feature Gets Public RCE Exploit

Critical Fluent Bit Flaw Impacts All Major Cloud Providers

Data Breach Response Provider, CyEx, Acquires Settlement Administrator, Simpluris Inc.

Cyber Firm CyberArk Inks $1.54 Billion Deal to Acquire Venafi

Owner of Incognito Dark Web Drugs Market Arrested in New York

WikiLeaks’ Julian Assange Can Appeal His Extradition to the US, British Court Says

5/17-19/2024

China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT

Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks

Cyber Official Speaks Out, Reveals Mobile Network Attacks in U.S.

Two Santa Cruz Students Uncover Security Bug That Could Let Millions Do Their Laundry for Free

An Attorney Says She Saw Her Library Reading Habits Reflected in Mobile Ads. That’s Not Supposed to Happen

Frustration Grows Over Google’s AI Overviews Feature, How to Disable

Microsoft to Start Enforcing Azure Multi-Factor Authentication in July

Chinese Nationals Arrested for Laundering $73 Million in Pig Butchering Crypto Scam
UK Councils Warn of Data Breach After Attack on Medical Supplier Nottingham Rehab Supplies Healthcare

WebTPA Data Breach Impacts 2.4 Million Insurance Policyholders

American Radio Relay League Cyberattack Takes Logbook of the World Offline

Kinsing Hacker Group Exploits More Flaws to Expand Botnet for Cryptojacking

Ransomware Gang Targets Windows Admins via PuTTy, WinSCP Malvertising

New Android Banking Trojan ‘Antidot’ Mimics Google Play Update App

Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide

CISA Warns of Actively Exploited D-Link Router Vulnerabilities – Patch Now

5/16/2024

Congressional Leaders Concerned by NYPD’s Use of Chinese-Made Drones

Stifling Beijing in Cyberspace Is Now British Intelligence’s Number-One Mission

UK Lags Europe on Exploited Vulnerability Remediation

EU Probes Meta Over Its Provisions for Protecting Children

Researchers: New Wi-Fi Vulnerability Enables Network Eavesdropping via Downgrade Attacks

Norway Recommends Replacing SSL VPN to Prevent Breaches

Five Charged for Cyber Schemes to Benefit North Korea’s Weapons Program

Meet Hackbat: An Open-Source, More Powerful Flipper Zero Alternative
North Korean Kimsuky Hackers Exploit Facebook Messenger in Targeted Malware Campaign

Asian Threat Actors Use New Techniques to Attack Familiar Targets

MediSecure E-script Firm Hit by ‘Large-Scale’ Ransomware Data Breach

SugarGh0st RAT Variant Used in Targeted AI Industry Attacks

GE Ultrasound Gear Riddled With Bugs, Open to Ransomware & Data Theft

Addressing the Cybersecurity Vendor Ecosystem Disconnect

Ashley Madison Netflix Doc: All the Celebrities Revealed in Cheating Hack

SEC to Require Financial Firms to Have Data Breach Incident Plans

5/15/2024

Turla Group Deploys LunarWeb and LunarMail Backdoors Against Unnamed Diplomatic Missions

NCSC Expands Election Cybersecurity to Safeguard Candidates and Officials

Google Unveils New Android 15 Security Updates

Android Will Be Able to Detect if Your Phone Has Been Snatched

Apple Blocked $7 Billion in Fraudulent App Store Purchases in 4 Years

Current Market Forces Disincentivizing Cybersecurity, Says NCSC CTO

Brothers Arrested for $25 Million Theft in Ethereum Blockchain Attack

FBI Seizes BreachForums Again, Urges Users to Report Criminal Activity
Nissan North America Data Breach Impacts Over 53,000 Employees

Rockford Public Schools (MI) Turns off Phones, Computer Network to Stop Spread of Ransomware

A Cyberattack Took Down Washington’s Metro Website for Two Hours

Law Enforcement Data Stolen in Wichita Ransomware Attack

FEI Systems (MD) Files Official Notice of Data Breach Affecting Consumers’ SSNs

PDF Exploitation Targets Foxit Reader Users

Windows Quick Assist Abused in Black Basta Ransomware Attacks

Google Patches Third Exploited Chrome Zero-Day in a Week

Krebs: Patch Tuesday, May 2024 Edition

5/14/2024

China Presents Defining Challenge to Global Cybersecurity, Says GCHQ

Russian Actors Weaponize Legitimate Services in Multi-Malware Attack

Secrecy Concerns Mount Over Spy Powers Targeting U.S. Data Centers

Telegram CEO Calls Out Rival Signal, Claiming It Has Ties to U.S. Government

Data Breaches in U.S. Schools Exposed 37.6M Records

Android Is Getting an AI-Powered Scam Call Detection Feature

VC Firm Accel Raises $650 Mln to Invest in AI, Cybersecurity Startups

Amazon-Backed Anthropic Launches Its Claude AI Chatbot Across Europe

First AI Talks Begin Between Chinese and U.S. Envoys

Nigeria Suspends Cybersecurity Levy Amid Cost of Living Crisis

MITRE Unveils EMB3D: A Threat-Modeling Framework for Embedded Devices

Cybersec Chiefs Team up With Insurers to Say ‘No’ to Ransomware Bullies

44% of Cybersecurity Professionals Struggle with Regulatory Compliance

Apple and Google Add Alerts for Unknown Bluetooth Trackers to iOS, Android
Santander Reports Customer, Employee Data Breach in Spain, Chile, Uruguay

Singing River Health System: Data of 895,000 Stolen in Ransomware Attack

The Art Market is Down. A Cyberattack at Christie’s May Make Things Worse.

Ebury Botnet Operators Diversify with Financial and Crypto Theft

Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

PoC Exploit Released for RCE Zero-Day in D-Link EXO AX4800 Routers

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

VMware Patches Severe Security Flaws in Workstation and Fusion Products

Apple Fixes Safari WebKit Zero-Day Flaw Exploited at Pwn2Own

Apple Backports Fix for Zero-Day Exploited in Attacks to Older iPhones

Microsoft Fixes Windows Zero-Day Exploited in QakBot Malware Attacks

Microsoft May 2024 Patch Tuesday Fixes 3 Zero-Days, 61 Flaws

5/13/2024

Hack of Provincial Canadian Government Suspected to Be ‘State-Sponsored’

Hack of France Sports Minister’s X Account Highlights Olympics Cyberthreats

Welcome to the Laser Wars!

INC Ransomware Source Code Selling on Hacking Forums for $300,000

Krebs: How Did Authorities Identify the Alleged LockBit Boss?

The $2.3 Billion Tornado Cash Case Is a Pivotal Moment for Crypto Privacy

Internal Emails Show How a Controversial Gun-Detection AI System Found Its Way to NYC

Tile Owner Life360 Picks Satellites Over Partnering With Apple or Google

FCC Reveals Royal Tiger, Its First Tagged Robocall Threat Actor
Helsinki Suffers Data Breach After Hackers Exploit Unpatched Flaw

WebTPA Employer Services Data Breach Affects an Unknown Number of Consumers

Palomar Health Medical Group (CA) Cyber Attack Raises Patient Concerns of Possible Breach

Aussie Software Firm Iress Flags Data Breach at Third-Party Platform

Botnet Sent Millions of Emails in LockBit Black Ransomware Campaign

‘The Mask’ Espionage Group Resurfaces After 10-Year Hiatus

Hackers Use DNS Tunneling for Network Scanning, Tracking Victims

Mallox Ransomware Deployed Via MS-SQL Honeypot Attack

Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo

5/10-12/2024

Europol Confirms Web Portal Breach, Says No Operational Data Stolen

Microsoft Launches Generative AI Model Designed Exclusively for U.S. Intelligence Services

House Committee Asks Microsoft’s Brad Smith to Attend Hearing on Security Lapses

UK’s AI Safety Institute Unveils Platform to Accelerate Safe AI Development

UK Hit by More Ransomware and Cyberattacks Last Year Than Ever Before

Pupils Miss Classes as School Cyber Attacks Rise

GhostStripe Attack Haunts Self-Driving Cars by Making Them Ignore Road Signs

Widely Used Telit Cinterion Cellular Modems in Industrial IoT Devices Open to SMS Attack

‘TunnelVision’ Attack Leaves Nearly All VPNs Vulnerable to Spying

Monday.com Removes “Share Update” Feature Abused for Phishing Attacks

Businesses, Government See Progress in Cyber Hiring, With Exceptions
North Korean Hackers Deploy New Golang Malware ‘Durian’ Against Crypto Firms

FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT

Largest Non-Bank Lender in Australia Firstmac Limited Warns of a Data Breach

Christie’s Says $850M Auctions to Go ahead as Planned Despite Cyberattack

The Post Millennial Hack Leaked Data Impacting 26 Million People

Ohio Lottery Ransomware Attack Impacts Over 538,000 Individuals

Ascension Redirects Ambulances After Suspected Ransomware Attack

CISA: Black Basta Ransomware Breached Over 500 Orgs Worldwide

Malicious Android Apps Pose as Google, Instagram, WhatsApp to Steal Credentials

Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability

5/9/2024

Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign

AI-Powered Russian Network Pushes Fake Political News

FBI Warns Hackers’ Use of AI Is Growing. So Is the Bureau’s.

Generative AI’s Disinformation Threat Is ‘Overblown,’ Top Cyber Expert Says

AT&T Delays Microsoft 365 Email Delivery Due to Spam Wave

Mobile Banking Malware Surges 32%

How Government Agencies Can Leverage Grants to Shore Up Cybersecurity

In Interview, LockBItSupp Says Authorities Outed the Wrong Guy

Zscaler Takes “Test Environment” Offline After Rumors of a Breach
Dell Customer Order Database of ‘49M Records’ Stolen, Now up for Sale on Dark Web

Ransomware Attack at Mexico’s Pemex Halts Work, Threatens to Cripple Computers

University System of Georgia: 800K Exposed in 2023 MOVEit Attack

British Columbia Investigating Cyberattacks on Government Networks

Surety HR (OH) Notifies Consumers of January 2024 Data Breach

New ‘LLMjacking’ Attack Exploits Stolen Cloud Credentials

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

Citrix Warns Admins to Manually Mitigate PuTTY SSH Client Bug

5/8/2024

UK Opens Investigation of MoD Payroll Contractor After Confirming Attack

Von Der Leyen’s Campaign Website Hit by Cyberattack

U.S. Confronts China Over Volt Typhoon Cyber Espionage

CISA Boss: Secure Code Is the ‘Only Way to Make Ransomware a Shocking Anomaly’

Microsoft Will Hold Executives Accountable for Cybersecurity

AI Threatens Elections by Capitalizing on Human Foibles, Officials Warn

FBI Warns of Gift Card Fraud Ring Targeting Retail Companies

Top FBI Official Urges Agents to Use Warrantless Wiretaps on U.S. Soil

Six Austrians Arrested in Multi-Million Euro Crypto Scheme
10,000 Customers’ Data Exposed in UK Government Breaches

Nearly 150K Impacted by Kansas Court System Hack

Massive Webshop Fraud Ring Steals Credit Cards From 850,000 People

Ascension Warns of Suspected Cyberattack; Clinical Operations Disrupted

Patient Appointments Imperiled by Cyberattack on French Radiologist

City of Wichita Breach Claimed by LockBit Ransomware Gang

Hijack Loader Malware Employs Process Hollowing, UAC Bypass in Latest Version

New Spectre-Style ‘Pathfinder’ Attack Targets Intel CPU, Leak Encryption Keys and Data

New BIG-IP Next Central Manager Bugs Allow Device Takeover

5/7/2024

UK MoD Data Breach: State Involvement Cannot Be Ruled Out in Armed Forces Hack, Says Grant Shapps

A (Strange) Interview With the Russian-Military-Linked Hackers Targeting US Water Utilities

Krebs: U.S. Charges Russian Man as Boss of LockBit Ransomware Group

$10 Million Reward for His Arrest

U.S. State Dept Broadens Security Vendor List Amid Microsoft Hacking Woes

America’s War on Drugs and Crime Will Be AI Powered, Says Homeland Security Boss

Google’s AI Plans Now Include Cybersecurity

Cyber Startup Wiz Raises $1 Billion on Path to IPO

Nigeria to Charge Levy on Domestic Transfers to Fund Cybersecurity
China-Linked Hackers Used ROOTROT Webshell in MITRE Network Intrusion Dating Back to December

DocGo Discloses Cyberattack After Hackers Steal Patient Health Data

Children’s Mental Health Data Published After NHS Cyber Attack

Brandywine Realty Trust Says Data Stolen in Ransomware Attack

Concord (MA) Schools Hit with Cyber Security Attack

Ransomware Crooks Now SIM Swap Executives’ Kids to Pressure Their Parents

New Attack Leaks VPN Traffic Using Rogue DHCP Servers

Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites

Russian Operator of BTC-e Crypto Exchange Pleads Guilty to Money Laundering

5/6/2024

Germany Recalls Ambassador to Russia in Response to Alleged Cyberattack Targeting Chancellor’s Party

MoD Data Breach: UK Armed Forces’ Personal Details Accessed in Hack

Apple’s iPhone Spyware Problem Is Getting Worse. Here’s What You Should Know

Krebs: Why Your VPN May Not Be As Secure As It Claims

Tech Giants Agree to Build Security Into Software Products

Kretinsky and Layani Face off in Battle for Distressed IT Firm Atos

AT&T Splits Cybersecurity Services Business, Launches LevelBlue
China-Linked Hackers Suspected in ArcaneDoor Cyberattacks Targeting Network Devices

City of Wichita Shuts Down IT Network After Ransomware Attack

MedStar Health Notifies 183,079 Patients of Recent Data Breach

Xiaomi Android Devices Hit by Multiple Flaws Across Apps and System Components

Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution

Mastodon Delays Fix for Link Previews DDoSing Websites

Consultant Charged Over $1.5M Extortion Scheme Against IT Giant

5/3-5/2024

Microsoft Outlook Privilege Escalation Flaw Exploited by Russia’s APT28 to Hack Czech, German Entities

Microsoft Overhaul Treats Security as ‘Top Priority’ After a Series of Failures

Kaspersky Hits Back at Claims Its AI Helped Russia Develop Military Drone Systems

Atos Creditors Reach Deal to Rescue Debt-Laden Group, La Tribune Says

Paris Olympics Cybersecurity at Risk via Attack Surface Gaps

New EU Cyber Rules for Electricity Providers Aim to Prevent Cascading Outages

LockBit’s Seized Darknet Site Resurrected by Police, Teasing New Revelations

From Teenage Cyber-Thug to Europe’s Most Wanted
North Korean Hackers Spoofing Journalist Emails to Spy on Policy Experts

Iranian Hackers Pose as Journalists to Push Backdoor Malware

Finland Warns of Android Malware Attacks Breaching Bank Accounts

Indonesia is a Spyware Haven, Amnesty International Finds

More Than 380,000 Additional NYC Students Had Personal Info Hacked, Bringing Total to Over 1M

LAPD Website Goes Offline; Officials Give No Cause but Say It’s ‘Not Ransomware’

Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications

Android Bug Leaks DNS Queries Even When VPN Kill Switch is Enabled

Google Rolls Back reCaptcha Update to Fix Firefox Issues

5/2/2024

U.S. Intelligence Chief Warns Congress of Rise in Cyberattacks

Think Tank: China’s Tech Giants Refine and Define Beijing’s Propaganda Push

Passkeys: All the News and Updates Around Passwordless Sign-Ins

Bitwarden Launches New MFA Authenticator App for iOS, Android

The Breach of a Face Recognition Firm Reveals a Hidden Danger of Biometrics

REvil Ransomware Affiliate Sentenced to Over 13 Years in Prison

Florida Man Gets 6 Years Behind Bars for Flogging Fake Cisco Kit to U.S. Military

Police Shut Down 12 Fraud Call Centers, Arrests 21 Suspects
Hackers Target New NATO Member Sweden with Surge of DDoS Attacks

Dropbox Reports Cyberattack on Dropbox Sign Product

LockBit Publishes Confidential Data Stolen From Cannes Hospital in France

New “Goldoon” Botnet Targets D-Link Routers With Decade-Old Flaw

Android Flaw Affected Apps With 4 Billion Installs

Microsoft Warns of “Dirty Stream” Attack Impacting Android Apps

4 Critical Bugs in ArubaOS Lead to Remote Code Execution

Three-Quarters of CISOs Admit App Security Incidents

CISA Urges Software Devs to Weed out Path Traversal Vulnerabilities

5/1/2024

U.S. Gov’t Warns of Pro-Russian Hacktivists Targeting Water Facilities

U.S. Government Releases New AI Security Guidelines for Critical Infrastructure

It’s Time to Rethink the National Vulnerabilities Database for the AI Era, Senators Say

The U.S. Government Is Asking Big Tech to Promise Better Cybersecurity

LockBit, Black Basta, Play Dominate Ransomware in Q1 2024

Lawsuits and Company Devaluations Await For Breached Firms

1 in 5 U.S. Ransomware Attacks Triggers Lawsuit

Bitcoin Forensic Analysis Uncovers Money Laundering Clusters and Criminal Proceeds

A Vast New Data Set Could Supercharge the AI Hunt for Crypto Money Laundering

U.S. Charges 16 Over ‘Depraved’ Grandparent Scams

Infosec Biz Boss Accused of BS’ing the World About His Career, Anti-Crime Product, Customers

Ex-NSA Employee Sentenced to 22 Years for Trying to Sell U.S. Secrets to Russia
Senators Slam UnitedHealth’s CEO Over Cyberattack

Cyberattack Was Due to a Lack of Multifactor Authentication, UnitedHealth CEO Says

UnitedHealth CEO Says ‘Maybe a Third’ of U.S. Citizens Were Affected by Recent Hack

UnitedHealth CEO Tells Lawmakers the Company Paid Hackers a $22 Million Ransom

French Hospital CHC-SV Refuses to Pay LockBit Extortion Demand

Panda Restaurants Discloses Data Breach After Corporate Systems Hack

Qantas App Glitch Sees Boarding Passes Fly to Other Accounts

ZLoader Malware Evolves with Anti-Analysis Trick from Zeus Banking Trojan

New Latrodectus Malware Attacks Use Microsoft, Cloudflare Themes

New Cuttlefish Malware Infects Routers to Monitor Traffic for Credentials

CISA Says GitLab Account Takeover Bug Is Actively Exploited in Attacks

Verizon DBIR: Basic Security Gaffes Underpin Bumper Crop of Breaches