6/28-30/2024

TeamViewer Links Corporate Cyberattack to Russian State Hackers

Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data

Google Thwarts Over 10,000 Attempts by Chinese Influence Operator

Fake Information on TikTok is Rampant

Fake IT Support Sites Push Malicious PowerShell Scripts as Windows Fixes

Dev Rejects CVE Severity, Makes His GitHub Repo Read-Only

Dark Reading Confidential: Meet the Ransomware Negotiators

‘I Don’t See It Happening’: CISA Chief Dismisses Ban on Ransomware Payments

The U.S. Wants to Integrate the Commercial Space Industry With Its Military to Prevent Cyber Attacks

Google Is Piloting Face Recognition for Office Security

Google to Block Entrust Certificates in Chrome Starting November 2024

Insurers Warn Standardizing Cyber Policies Could Limit Future Coverage

Former Geisinger IT Employee Accessed Data of Over 1 Million U.S. Patients

Nearly 4,000 Arrested in Global Police Crackdown on Online Scam Networks

Polish Parliament Strips Official of Immunity, Clearing Path for Prosecution in Spyware Scandal
HubSpot Investigating Customer Account Hacks

Dairy Giant Agropur Says Data Breach Exposed Customer Info

Infosys McCamish Says LockBit Stole Data of 6 Million People

Lurie Children’s Hospital of Chicago Says Nearly 800,000 Affected by January Ransomware Attack

BlackSuit Ransomware Gang Claims Attack on KADOKAWA Corporation

Now Targeting: Meet Brain Cipher — The New Ransomware Behind Indonesia’s Data Center Attack

Ticketmaster Sends Notifications About Recent Massive Data Breach

Polyfill.io, BootCDN, Bootcss, Staticfile Attack Traced to 1 Operator

New Unfurling Hemlock Threat Actor Floods Systems With Malware

New SnailLoad Attack Exploits Network Latency to Spy on Users’ Web Activities

8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining

Hackers Exploit Critical D-Link DIR-859 Router Flaw to Steal Passwords

Researchers Warn of Flaws in Widely Used Industrial Gas Analysis Equipment

GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others

Juniper Releases Out-Of-Cycle Fix for Max Severity Auth Bypass Flaw

6/27/2024

TeamViewer’s Corporate Network Was Breached in Alleged APT29 Hack

Crimea Warns of Internet Disruptions Following DDoS Attacks on Local Telecom Operators

Chinese Cyberspies Employ Ransomware in Attacks for Diversion

China-Sponsored Attackers Target 40K Corporate Users in 90 Days

U.S. Lawmakers Wave Red Flags Over Chinese Drone Dominance

CISOs Reveal Firms Prioritize Savings Over Long-Term Security

Operation First Light Seizes $257m in Global Scam Bust

As Backlash Mounts, Data Privacy Bill Markup Is Canceled Moments Before It Was to Start
Cloudflare: We Never Authorized polyfill.io to Use Our Name

Polyfill Claims It Has Been ‘Defamed’, Returns After Domain Shut Down

Startups Scramble to Assess Fallout From Evolve Bank Data Breach

Rust-Based P2PInfect Botnet Evolves with Miner and Ransomware Payloads

Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

Critical GitLab Bug Lets Attackers Run Pipelines as Any User

Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application

6/26/2024

U.S., Japan, South Korea Vow Strategic Cooperation to Boost Security, Economies

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware

‘ChamelGang’ APT

America’s Drinking Water Is Facing Attack, With Links Back to China, Russia and Iran

Why Things Can’t Go Back To Normal After The Change Healthcare Attack

War Crime Prosecutions Enter a New Digital Age

Julian Assange Lands in Australia a Free Man

How Wikileaks Changed the Internet, From Clinton’s Emails to the Iraq War

U.S. Convicts Crypto-Robbing Gang Leader Who Kidnapped Victims Before Draining Their Account

Feds Put $5M Bounty on ‘CryptoQueen’ Ruja Ignatova

WhisperGate Suspect Indicted as U.S. Offers a $10M Bounty for His Capture

U.S. Supreme Court Will Not Curb Biden Administration Social Media Contacts

Russia to Ban 81 Foreign Media Outlets in Response to Europe’s Sanctions
IRS Apologizes for Data Breach That Leaked Taxpayer Information

LockBit Lied: Stolen Data Is From a Bank, Not U.S. Federal Reserve

Arkansas-Based Evolve Bank Confirms Cyber Attack and Data Breach

CDK Expects Car Dealership System Outage to Last Until at Least June 30

Texas Retina Associates Notifies Nearly 300k People of Recent Data Breach

Novel Banking Malware ‘Snowblind’ Targets Customers in Southeast Asia

New Credit Card ‘Caesar Cipher Skimmer’ Targets WordPress, Magento, and OpenCart Sites

Exploit for Critical Fortra FileCatalyst Workflow SQLi Flaw Released

Progress Discloses Two New Vulnerabilities in MOVEit Products

Apple Patches AirPods Bluetooth Vulnerability That Could Allow Eavesdropping

Google Will Address Android’s Find My Device Network Issues ‘Over the Coming Weeks’

CISA: Most Critical Open Source Projects Not Using Memory Safe Code

6/25/2024

Cloud Breaches Impact Nearly Half of Organizations

FBI Warns of Fake Law Firms Targeting Crypto Scam Victims

U.K. and U.S. Cops Band Together to Tackle Qilin’s Ransomware Shakedowns

Indonesia Refuses to Pay $8M Ransom After Cyberattack

The Mystery of AI Gunshot-Detection Accuracy Is Finally Unraveling

Deepfake Creators Are Revictimizing GirlsDoPorn Sex Trafficking Survivors

Financial Sextortion Schemes Mostly Target Teenage Boys, Largely Through Instagram

French Police Shut down Chat Website ‘Coco’ Reviled as ‘Den of Predators’

Wikileaks’ Julian Assange Released from U.K. Prison, Heads to Australia
South Africa’s National Health Lab Hit with Ransomware Attack Amid Mpox Outbreak

Neiman Marcus Confirms Data Breach After Snowflake Account Hack

Geisinger Provides Notice of Data Breach for More Than One Million Patients

New Medusa Trojan Variant Emerges with Enhanced Stealth Features

If You’re Using polyfill.io Code on Your Site – Like 100,000+ Are – Remove It Immediately

New Attack Technique Exploits Microsoft Management Console Files

P2PInfect Botnet Targets REdis Servers with New Ransomware Module

Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

6/24/2024

Thwarting Cyberattacks From China Is DHS’s Top Infrastructure Security Priority

China-Based RedJuliett Targets Taiwan in Cyber Espionage Campaign

LockBit Claims Hack of the U.S. Federal Reserve

Red Tape Is Making Hospital Ransomware Attacks Worse

Google Introduces New Framework Called ‘Project Naptime’ for Improved AI-Powered Vulnerability Research

Russian Hackers Sanctioned by European Council for Attacks on EU and Ukraine

Four FIN9 Hackers Indicted for Cyberattacks Causing $71M in Losses

Sellafield Pleads Guilty to Historic Cybersecurity Offenses

Julian Assange to Plead Guilty in U.S. Case

Allowing Him to Go Free
Cyber Attack Compromised Indonesia Data Centre, Ransom Sought

Levi’s and More Affected in Pants-Dropping Week of Data Breaches

Car Dealerships in North America Revert to Pens and Paper After Cyberattacks on CDK Global

Multiple Car Dealers Report Disruptions to SEC

Heart South Cardiovascular Group (AL) Files Official Notice of Data Breach

Modular Malware Boolka’s BMANAGER Trojan Exposed

Android Users Warned of Rising Malware Threat From Rafel RAT

New Attack Uses MSC Files and Windows XSS Flaw to Breach Networks

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

6/21-23/2024

Since Joining NATO, Sweden Claims Russia Has Been Borking Nordic Satellites

Japan’s Space Agency Hit by Series of Cyberattacks Since Last Year, Official Says

U.S. Imposes Sanctions on Russia’s AO Kaspersky Lab Executives Over Cyber Risks

But Not Eugene Kaspersky

Kaspersky’s U.S. Customers Face Tight Deadline Following Gov’t Ban

Polish Investigators Seize Pegasus Spyware Systems as Part of Probe Into Alleged Abuse

Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign

Risk of Getting Malicious Extension From Chrome Store Way Worse Than Google’s Letting On, Study Suggests

Facebook PrestaShop Module Exploited to Steal Credit Cards

Wired: Perplexity Plagiarized Our Story About How Perplexity Is a Bullshit Machine

Five Men Convicted for Operating Illegal Streaming Site Jetflicks

Tor Browser 13.5 Brings Android Enhancements, Better Bridge Management

Multifactor Authentication Is Not Enough to Protect Cloud Data

CISO Corner: Critical Infrastructure Misinformation; France’s Atos Bid
CDK Global Begins to Restore Systems After Cyber Hack Hits Thousands of Retailers

CDK Warns: Threat Actors Are Calling Customers, Posing as Support

CDK Global Outage Caused by BlackSuit Ransomware Attack

Synnovis Attackers Publish NHS Patient Data Online

Almost 200 Cancer Operations Postponed

Change Healthcare Lists the Medical Data Stolen in Ransomware Attack

Chemical Security Assessment Tool (CSAT) Warned of Possible Data Exfiltration Following CISA Breach

Los Angeles Unified Confirms Student Data Stolen in Snowflake Account Hack

Jollibee Investigates Alleged Data Breach Affecting Millions

ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor

Military-Themed Email Scam Spreads Malware to Infect Pakistani Users

Oyster Backdoor Spreading via Trojanized Popular Software Downloads

Ratel RAT Targets Outdated Android Phones in Ransomware Attacks

SolarWinds Serv-U Vulnerability Under Active Attack – Patch Immediately

6/20/2024

U.S. Bans Kaspersky Software

Later This Year

“Security Concerns”

“Threat of Influence Operation”

Kaspersky Denies Threat Accusations

UN Security Council to Debate Cybersecurity Threats, Despite Russian Veto

French Diplomatic Entities Targeted by Russian-Aligned Nobelium

Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

Experts Uncover New Evasive SquidLoader Malware Targeting Chinese Organizations

Krebs: KrebsOnSecurity Threatened with Defamation Lawsuit Over Fake Radaris CEO

Apax Discussing With Possible Advisers IT Services Firm Lutech’s Sale, Sources Say

How Cybersecurity Can Steer Organizations Toward Sustainability
Threat Actor ‘IntelBroker’ Claims AMD and Apple Breaches

CDK Global Hacked Again While Recovering From First Cyberattack

T-Mobile Denies It Was Hacked, Links Leaked Data to Vendor Breach

Crooks Get Their Hands on 500K+ Consulting Radiologists Patient Records in Cyber-Attack

More Than 400,000 Have Data Leaked in Cyberattack on Texas Education Organization

Change Healthcare Starts Notifying Data-Breach Victims

Linux Version of RansomHub Ransomware Targets VMware ESXi VMs

New Rust-Based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

SolarWinds Serv-U Path Traversal Flaw Actively Exploited in Attacks

CosmicSting Flaw Impacts 75% of Adobe Commerce, Magento Sites

Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

6/19/2024

This Is What Would Happen if China Invaded Taiwan

UNC3886 Uses Fortinet, VMware 0-Days and Stealth Tactics in Long-Term Spying

Cyberattack Led to Harrowing Lapses at Ascension Hospitals, Clinicians Say

Don’t Blame Us for People Suffering – London Hospital Hackers

Road to Redemption: GhostSec’s Hacktivists Went to the Dark Side. Now They Want Back.

Perplexity Is a B*!!$4!t Machine

France Seeks to Protect National Interests With Bid for Atos Cybersec

Leonardo Nears Deals to Grow in Cybersecurity, Space and Drone Industries, CEO Says

Cybersecurity Burnout Costing Firms $700m+ Annually

CIISec Urges Employers to Target Young Talent in Gaming Centers

Hamster Kombat Is Dangerous, Agree Officials in Russia, Ukraine and Beyond
New Threat Actor ‘Void Arachne’ Targets Chinese Users with Malicious VPN Installers

Quishing Campaign Targets Chinese Citizens via Fake Official Documents

CDK Global Cyberattack Impacts Thousands of U.S. Car Dealerships

Advance Auto Parts Confirms Data Breach Exposed Employee Information

Crown Equipment Confirms a Cyberattack Disrupted Manufacturing

U.S. Meat Company Carl Buddig Suffers Data Security Breach

Scout Energy Partners (TX) Notifies Consumers of Early 2024 Data Breach

Kraken Crypto Exchange Hit by $3 Million Theft Exploiting Zero-Day Flaw

Mailcow Mail Server Flaws Expose Servers to Remote Code Execution

Update Your Windows PC to Avoid a Serious Wi-Fi Vulnerability

6/18/2024

G7 Countries Vow to Establish Collective Cybersecurity Framework for Operational Tech

U.S. Secret Service, CISA Host Cybersecurity Training for Critical-Infrastructure Directors

Quarter of Firms Suffer an API-Related Breach

92% of Organizations Hit by Credential Compromise from Social Engineering Attacks

Scathing Report on Medibank Cyberattack Highlights Unenforced MFA

New AI Deepfake Porn Bill Would Require Big Tech to Police and Remove Images

Two Men Guilty of Breaching Law Enforcement Portal in Blackmail Scheme

Cybersecurity Startup Huntress Valued at Over $1.5 Bln After Latest Funding

Signal Foundation Warns Against EU’s Plan to Scan Private Messages for CSAM

FTC Files Complaint Against TikTok for Alleged Data Privacy Practices
Dark-Web Kingpin Puts ‘Stolen’ Internal AMD databases, Source Code up for Sale

AMD Investigating

Hackers Derail Amtrak Guest Rewards Accounts in Breach

LendingTree Says It’s Probing Potential Snowflake-Related Data Breach

Highland Health Systems (AL) Notifies Patients of July 2023 Data Breach

ONNX Phishing Service Targets Microsoft 365 Accounts at Financial Firms

Fake Meeting Software ‘Vortax’ Spreads macOS Infostealer

Cybercriminals Exploit Free Software Lures to Deploy Hijack Loader and Vidar Stealer

New Malware Targets Exposed Docker APIs for Cryptocurrency Mining

VMware Discloses Critical Vulnerabilities, Urges Immediate Remediation

6/17/2024

China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 Devices

China Attempted Covert Military Drone Tie-Up With UK University – Report

ShinyHunters Hacker Details How They Allegedly Stole Ticketmaster Data From Snowflake

Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers

EU Cybersecurity Label Should Not Discriminate Against Big Tech, European Groups Say

Academics Develop Testing Benchmark for LLMs in Cyber Threat Intelligence

Empire Market Owners Charged for Enabling $430M in Dark Web Transactions
Panera Bread Likely Paid a Ransom in March Ransomware Attack

Cleveland Confirms Ransomware Attack as City Hall Remains Closed

All Households in Scottish Region to Get Alert About Hackers Publishing Stolen Medical Data

U.S. to Stop Advance Payments for Medicare Providers Hit by Change Hack

NiceRAT Malware Targets South Korean Users via Cracked Software

Fake Google Chrome Errors Trick You Into Running Malicious Powershell Scripts

Hackers Exploit Legitimate Websites to Deliver BadSpace Windows Backdoor

Space: The Final Frontier for Cyberattacks

6/14-16/2024

ICC Probes Cyberattacks in Ukraine as Possible War Crimes, Sources Say

Ukraine Busts SIM Farms Targeting Soldiers With Spyware

Taiwan Must Prepare for Cyber, Financial Attacks by China

Microsoft to Delay Launch of AI Recall Tool Due to Security Concerns

Apple’s AI for iPhone Just Showed Google How It’s Done

Meta Pauses Plans to Train AI Using European Users’ Data, Bowing to Regulatory Pressure

It’s Time for the FTC to Act on ChatGPT

Google Loses Bid to End U.S. Antitrust Case Over Digital Advertising

French State Bidding for Piece of Atos, Offers €700M

Krebs: Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested

Scattered Spider Hackers Switch Focus to Cloud Apps for Data Theft

Former IT Employee Gets 2.5 Years for Wiping 180 Virtual Servers

Nigerian Faces up to 102 Years in the Slammer for $1.5m Phishing Scam

How to Spot a Business Email Compromise Scam

A Guide to RCS, Why Apple’s Adopting It, and How It Makes Texting Better

Stanford Internet Observatory Wilts Under Legal Pressure During Election Year
Pakistani Hackers Use DISGOMOJI Malware in Indian Government Cyber Attacks

Controlled Through Emojis Sent From Discord

North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics

Grandoreiro Banking Trojan Hits Brazil as Smishing Scams Surge in Pakistan

London Hospital Hack Delayed More Than 800 Operations

Keytronic Confirms Data Breach After Ransomware Gang Leaks Stolen Files

Truist Bank Says Breach of Customer Data Is Unrelated to Snowflake

Kulicke and Soffa Admit Data Breach From LockBit Attack

Phishing Attack Hits L.A. County Public Health, Jeopardizing 200,000+ Residents’ Info

Insurance Giant Globe Life Investigating Web Portal Breach

CISA Warns of Windows Bug Exploited in Ransomware Attacks

New ARM ‘TIKTAG’ Attack Impacts Google Chrome, Linux Systems

ASUS Warns of Critical Remote Authentication Bypass on 7 Routers

Mozilla Firefox Can Now Secure Access to Passwords With Device Credentials

Microsoft: New Outlook Security Changes Coming to Personal Accounts

6/13/2024

Arid Viper Hackers Spy in Egypt and Palestine Using Android Spyware

Pakistan-Linked Malware Campaign ‘Operation Celestial Force’ Evolves to Target Windows, Android, and macOS

U.S. Lawmakers Grill Microsoft President Over China Ties, Hacks

Microsoft in Damage-Control Mode, Says It Will Prioritize Security Over AI

Majority of Voters Concerned With Microsoft Ties to Government After Breaches: Poll

New Attack Technique ‘Sleepy Pickle’ Targets Machine Learning Models

U.S. Space Force Wanted $77M to Reinforce Gps – And Congress Shot It Down

New Apple iPhone App Proves Just How Hard It Is to Kill the Online Password

Cyber Insurance Claims Hit Record High in North America

Cyber and Data Privacy Insurance Trends in an Era of Increased Regulation
Traverse City (MI) & Newburgh (NY) City Governments Face Shutdowns After Ransomware Attacks

Ascension: Hackers Stole Some Patient Data but Didn’t Breach Electronic Health Record System

Ascension Attack Caused by Employee Downloading Malicious File

Truist Bank Confirms Breach After Stolen Data Shows up on Hacking Forum

Panera Warns of Employee Data Breach After March Ransomware Attack

New York Times Warns Freelancers of GitHub Repo Data Breach

Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware

Phishing Emails Abuse Windows Search Protocol to Push Malicious Scripts

Exploit for Veeam Recovery Orchestrator Auth Bypass Available, Patch Now

PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager

6/12/2024

China’s Dominant Drone Industry Is a Step Ahead of Congress

Chinese Hackers Leveraging ‘Noodle RAT’ Backdoor

Medical-Targeted Ransomware Is Breaking Records After Change Healthcare’s $22M Payout

Scattered Spider Now Affiliated with RansomHub Following BlackCat Exit

U.S. Federal Authorities Say UnitedHealth Can Notify Victims of Massive Data Breach

CISA Warns of Criminals Impersonating Its Employees in Phone Calls

AWS Adds Passkeys Support, Warns Root Users Must Enable MFA

U.S. Business Owners Seek Higher Insurance Coverage as AI, Election Risks Loom, Survey Shows

Microsoft Deprecates Windows DirectAccess, Recommends Always On VPN

Police Arrest Conti and LockBit Ransomware Crypter Specialist
White House Report Dishes Deets on All 11 Major Government Breaches From 2023

Life360 Confirms a Hacker Stole Tile Tracker IDs and Customer Info

Toronto School Board Reports Ransomware Attack on Test Environment

Epic Games Database Leak Hints at a Trove of Unannounced Games

Cryptojacking Campaign Targets Misconfigured Kubernetes Clusters

New Phishing Toolkit Uses PWAs to Steal Login Credentials

WithSecure Reveals Mass Exploitation of Edge Software and Infrastructure Appliances

Google Warns of Actively Exploited Pixel Firmware Zero-Day

Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw

Krebs: Patch Tuesday, June 2024 “Recall” Edition

6/11/2024

Chinese Actor SecShow Conducts Massive DNS Probing on Global Scale

China-Linked ValleyRAT Malware Resurfaces with Advanced Data Theft Tactics

Chinese Hackers Breached 20,000 FortiGate Systems Worldwide

Phishing Attacks Targeting U.S. and European Organizations Double According to Reports from Abnormal Security

U.S. Leaders Dodge Questions About Israel’s Influence Campaign

Apple Launches Private Cloud Compute for Privacy-Centric AI Processing

I Asked an AI Chatbot to Tell Me About Myself. It Was Wrong in an Uncanny Way.

The Evolving Role Of Cybersecurity Operations In A Rapidly Changing World
Ticketmaster’s Snowflake Data Breach Was Just One of 165

Trionfo Solutions Announces Data Breach Affecting BCBS of Texas, Illinois, Montana, Oklahoma and New Mexico

New Warmcookie Windows Backdoor Pushed via Fake Job Offers

Pure Storage Pwned, Claims Data Plundered by Crims Who Broke Into Snowflake Workspace

TellYouThePass Ransomware Exploits Recent PHP RCE Flaw to Breach Servers

JetBrains Warns of IntelliJ IDE Bug Exposing GitHub Access Tokens

Kaspersky Finds Critical Vulnerabilities in ZKTeco Biometric Access Control Terminal

Microsoft June 2024 Patch Tuesday Fixes 51 Flaws, 18 RCEs

6/10/2024

Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus

Google Takes Down Influence Campaigns Tied to China, Indonesia, and Russia

IoT Vulnerabilities Skyrocket, Becoming Key Entry Point for Attackers

A Look at the Riskiest Connected Devices of 2024

Apple’s Standalone Passwords App Syncs Across iOS, iPad, Mac, and Windows

Apple’s AI Promise: “Your Data Is Never Stored or Made Accessible to Apple”

Everything Apple Announced at WWDC 2024

America’s Rural Hospitals Keep Getting Attacked by Cybercriminals. Microsoft and Google Are Working to Fix That

Deepfakes, Fraudsters and Hackers Are Coming for Cybersecurity Jobs

16 DevSecOps Trends Shaping The Future Of Software And Cybersecurity

23andMe Data Breach Under Investigation in UK and Canada

Two Arrested in UK Over ‘Fake Cell Tower-Powered’ Smishing Campaign
London Hospitals Face Blood Shortage After Synnovis Ransomware Attack

Cyber Incident Forces Cleveland to Shut down City Hall

Vietnam’s State Postal Service Claims to Restore Its Systems After Cyberattack

Snowflake Tells Customers to Enable MFA as Investigations Continue

Cylance Confirms Data Breach Linked to ‘Third-Party’ Platform

Lykke Crypto Exchange Acknowledges Hack After Halting Withdrawals

Diversified Global Graphics Group Announces Data Breach Affecting an Unknown Number of Consumer SSNs

More_eggs Malware Disguised as Resumes Targets Recruiters in Phishing Attack

Gitloker Attacks Abuse GitHub Notifications to Push Malicious oAuth Apps

Exploit for Critical Veeam Auth Bypass Available, Patch Now

Arm Warns of Actively Exploited Flaw in Mali GPU Kernel Drivers

Netgear WNR614 Flaws Allow Device Takeover, No Fix Available

6/7-9/2024

SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign

DDoS Attacks Target EU Political Parties as Elections Begin

Dead in 6 Hours: How Nigerian Sextortion Scammers Targeted My Son

Feds Seize Domains Linked to Crypto Investment Scam Preying on New York’s Russian Diaspora

Apple Might Reveal a New ‘Passwords’ App This Week

Microsoft Will Switch Off Recall by Default After Security Backlash

Amazon, Best Buy, Google May Soon Sell Home Smart Devices With ‘Hacker-Safe’ Label

CrowdStrike, KKR, GoDaddy to Join Benchmark S&P 500

LastPass Says 12-Hour Outage Caused by Bad Chrome Extension Update

EmailGPT Exposed to Prompt Injection Attacks
Sapphire Werewolf Hackers Spy on Russian Education, Defense and Aerospace Industries

Trainees Urged to Help Hospitals After Cyber-Attack

‘New York Times Source Code’ Leaks Online via 4chan

Japan Video-Sharing Site Niconico Hit by Cyberattack

Frontier Warns 750,000 of a Data Breach After Extortion Threats

Christie’s Starts Notifying Clients of RansomHub Data Breach

What Snowflake Isn’t Saying About Its Customer Data Breaches

Malicious VSCode Extensions with Millions of Installs Discovered

Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances

New PHP Vulnerability Exposes Windows Servers to Remote Code Execution

Security Flaws Found in Popular WooCommerce Plugin

6/6/2024

Ukraine Says Hackers Abuse SyncThing Data Sync Tool to Steal Data

The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever

Microsoft’s Recall Feature Is Even More Hackable Than You Thought

SEC Cyber Disclosures Delayed Several Times Since December

‘Significant Work’ Remains to Harmonize Cybersecurity Rules: Watchdog

FCC Launches $200 Million Program to Bolster Cybersecurity for Schools and Libraries

FBI Encourages LockBit Victims to Step Right up for Free Encryption Keys

Google Maps Timeline Data to be Stored Locally on Your Device for Privacy

Greylock Leads $36 Million Financing for Cybersecurity Startup Seven AI

Technology, Regulations Can’t Save Orgs From Deepfake Harm

Narrowing the Stubborn Cybersecurity Worker Gap

Why Your Organization Should Focus More On OT Cybersecurity
Los Angeles Unified School District Investigates Data Theft Claims

PandaBuy Pays Ransom to Hacker Only to Get Extorted Again

Nearly 400,000 Affected by Data Breach at Panorama Eyecare

Brockton Area Multi-Services Files Notice of Data Breach Involving Client SSNs

PruittHealth Notifies Patients of November 2023 Data Breach Following Ransomware Attack

Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS Attacks

Hackers Exploit Legitimate Packer Software to Spread Malware Undetected

Hackers Target Python Developers with Fake “Crytic-Compilers” Package on PyPI

New Gitloker Attacks Wipe GitHub Repos in Extortion Scheme

Linux Version of TargetCompany Ransomware Focuses on VMware ESXi

POC Exploit Code Published for 9.8-Rated Apache HugeGraph RCE Flaw

Hackers Exploit 2018 ThinkPHP Flaws to Install ‘Dama’ Web Shells

6/5/2024

Russian Hackers Claim Cyberattack on Spanish Defence Company

Chinese State-Backed Cyber Espionage ‘Crimson Palace’ Targets Southeast Asian Government

Trump, Biden Battle for Youth Vote on TikTok

A U.S. Company Enabled a North Korean Scam That Raised Money for WMDs

Ariane Systems Check-in Terminals Used by Thousands of Hotels Leak Guest Info

The Age of the Drone Police Is Here

Alarming Cybersecurity Stats: What You Need To Know In 2024

Apple Refused to Pay Bug Bounty to Russian Cybersecurity Firm Kaspersky Lab
Peak Design Accidentally Leaked 10 Years of Client Data and Records

Club Penguin Fans Breached Disney Confluence Server, Stole 2.5gb of Data

Advance Auto Parts Stolen Data for Sale After Snowflake Attack

Qilin Ransomware Gang Linked to Attack on London Hospitals

WD & Associates (RI) Data Breach Affects an Unknown Number of Consumers

Rebranded Knight Ransomware Targeting Healthcare and Businesses Worldwide

Kali Linux 2024.2 Released With 18 New Tools, Y2038 Changes

6/4/2024

London Hospitals Cancel Operations Following Ransomware Incident

TikTok Fixes Zero-Day Bug Used to Hijack High-Profile Accounts

Account Takeovers Outpace Ransomware as Top Security Concern

This Hacker Tool Extracts All the Data Collected by Windows’ New Recall AI

AI Is Your Coworker Now. Can You Trust It?

FBI Warns of Fake Remote Work Ads Used for Cryptocurrency Fraud

Chinese Spies Are Targeting Disgruntled U.S. Corporate Workers, Warns National Counterintelligence Head Michael Casey

Biden: ‘All the Bad Guys Are Rooting for Trump’ on Foreign Election Meddling

Things the Guys Who Stole My Phone Have Texted Me to Try to Get Me to Unlock It

Command Senior Chief Busted for Secretly Setting up Wi-Fi on U.S. Navy Combat Ship

Pentagon ‘Doubling Down’ on Microsoft Despite ‘Massive Hack,’ Senators Complain

Microsoft Accused of Tracking Kids With Education Software

Microsoft Deprecates Windows NTLM Authentication Protocol

Crowdstrike Forecasts Upbeat Second-Quarter Revenue on Robust Demand for Cybersecurity Solutions

Netskope Crosses $500 Million in Subscription Revenue, in No Rush to Go Public
Russian Power Companies, IT Firms, and Gov’t Agencies Hit by Decoy Dog Trojan

New Multi-Stage Malware Targets Windows Users in Ukraine

Snowflake Warns: Targeted Credential Theft Campaign Hits Cloud Customers

ARRL Says It Was Hacked by an “International Cyber Group”

Christie’s Stolen Data Sold to Highest Bidder Rather Than Leaked, RansomHub Claims

Children’s Names, Addresses, and Medical Information Leaked From Billericay School in Essex After Cyber-Attack

Australian Mining Company Northern Minerals Discloses Breach After BianLian Leaks Data

Thriving Mind South Florida Notifies Patients of August 2023 Data Breach

New v3B Phishing Kit Targets Customers of 54 European Banks

‘Fog’ Ransomware Rolls in to Target Education, Recreation Sectors

DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber Attacks

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

Zyxel Issues Emergency RCE Patch for End-Of-Life NAS Devices

6/3/2024

Andariel Hackers Target South Korean Institutes with New Dora RAT Malware

Russia Aims Cyber Operations at Summer Olympics

Microsoft India’s X Account Hijacked in Roaring Kitty Crypto Scam

Azure Service Tags Tagged as Security Risk, Microsoft Disagrees

Snowflake Says There’s No Evidence Attackers Breached Its Platform to Hack Ticketmaster

Ransomware Rises Despite Law Enforcement Takedowns

Authorities Ramp Up Efforts to Capture the Mastermind Behind Emotet

Data Firm Execs Convicted for Helping Fraudsters Target the Elderly

NIST Turns to IT Consultants to Clear National Vulnerability Database Backlog
361 Million Stolen Accounts Leaked on Telegram Added to HIBP

Collection Agency FBCS UPS Data Breach Tally to 3.2 Million People

Crooks Threaten to Leak 3B Personal Records ‘Stolen From Background Check Firm’

Illinois Secretary of State Warning of a Data Breach Originating From Lake County

Cyberattack on Telecom Giant Frontier Claimed by RansomHub

Beware: Fake Browser Updates Deliver BitRAT and Lumma Stealer Malware

Researchers Uncover RAT-Dropping npm Package Targeting Gulp Users

Exploit for Critical Progress Telerik Auth Bypass Released, Patch Now

Researcher Uncovers Flaws in Cox Modems, Potentially Impacting Millions

5/31-6/2/2024

OpenAI, Meta, and TikTok Crack Down on Covert Influence Campaigns, Some AI-Powered

Lobbyists for AI-Related Issues Surged in 2023

Live Nation Took 11 Days to Confirm the Massive Ticketmaster Data Breach

Massive Ticketmaster, Santander Data Breaches Linked to Snowflake Cloud Storage

The Ticketmaster Data Breach May Be Just the Beginning

Warren Buffett Is Worried About Potential for ‘Huge Losses’ in Booming, but Still Tiny Cyber Insurance Market

Trend Micro Taps Nvidia Software Tools for AI Cybersecurity Offering

Microsoft Warns of Surge in Cyber Attacks Targeting Internet-Exposed OT Devices

Europol Identifies 8 Cybercriminals Tied to Malware Loader Botnets

Police Dismantle Pirated TV Streaming Network That Made $5.7 Million
Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting

Germany’s Christian Democratic Party Hit by ‘Serious’ Cyberattack

Polish News Agency Probably Hit by Russian Cyberattack, Minister Says

AI Company Hugging Face Detects Unauthorized Access to Its Spaces Platform

The Billericay School in Essex Facing ‘Critical Incident’ After Cyber Attack

ShinyHunters Claims Santander Breach, Selling Data for 30M Customers

Japanese Crypto Exchange DMM Bitcoin Warns That Hackers Stole $308 Million in Bitcoin (BTC)

Kaspersky Releases Free Tool That Scans Linux for Known Threats

Google Chrome Change That Weakens Ad Blockers Begins June 3rd