7/31/2024

Urgent Blood Donation Appeal Issued in U.S. After Critical OneBlood Ransomware Attack

DDoS Attack Triggers New Microsoft Global Outage

‘Error’ in Microsoft’s DDoS Defenses Amplified 8-hour Azure Outage

Swiss Stock Exchange Suffers Hours-Long Outage After Data Glitch

CISA and FBI: DDoS Attacks Won’t Impact U.S. Election Integrity

Krebs: Don’t Let Your Domain Name Become a “Sitting Duck”

Credit Card Users Get Mysterious shopify-charge.com Charges

Can GPT-4o Be Trusted With Your Private Data?

Meta to Pay Texas $1.4bn for Unlawful Biometric Data Capture

CrowdStrike Is Sued by Shareholders Over Huge Software Outage

Russia Legalizes Cryptocurrency Mining as Ongoing Global Sanctions Continue to Disrupt Traditional Finances

Germany Summons Chinese Ambassador Over Cyberattack on Cartography Agency
World Leading Silver Producer Fresnillo Discloses Cyberattack

Ransomware Attack Forces Hundreds of Small Indian Banks Offline, Sources Say

Chinese Hackers Target Japanese Firms with LODEINFO and NOOPDOOR Malware

Fraud Ring Pushes 600+ Fake Web Shops via Facebook Ads

New SMS Stealer Malware Targets Over 600 Global Brands

New PyPI Package Zlibxjson Steals Discord, Browser Data

Cybercriminals Deploy 100K+ Malware Android Apps to Steal OTP Codes

New Android Malware ‘BingoMod’ Wipes Your Device After Draining Bank Accounts

Google Ads Push Fake Google Authenticator Site Installing Malware

DigiCert to Revoke 83,000+ SSL Certificates Due to Domain Validation Oversight

No Really, What Cybersecurity Requirements and Standards Does My Company Need to Follow and Why?

7/30/2024

Russia, Moldova Targeted by Obscure Hacking Group in New XDSpy Cyberespionage Campaign

New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries

U.S. Senate Bill Would Radically Improve Voting Machine Security

UK ICO Slams Electoral Commission for Basic Security Failings

Stolen GenAI Accounts Flood Dark Web With 400 Daily Listings

‘LockBit of Phishing’ EvilProxy Used in More Than a Million Attacks Every Month

Just One in 10 Attacks Flagged By Security Tools

Cybersecurity Firm Tenable Is Exploring a Potential Sale

Delta Hires David Boies to Seek Damages From CrowdStrike, Microsoft After Outage

Malaysia Is Working on an Internet ‘Kill Switch’, Says Minister
Sophisticated Phishing Campaign Targets Microsoft OneDrive Users

Black Basta Ransomware Switches to More Evasive Custom Malware

Dark Angels Ransomware Receives Record-Breaking $75 Million Ransom

Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware

VMware ESXi Flaw Exploited by Ransomware Groups for Admin Access

New Specula Tool Uses Outlook for Remote Code Execution in Windows

Google Chrome Adds App-Bound Encryption to Block Infostealer Malware

DigiCert Mass-Revoking TLS Certificates Due to Domain Validation Bug

‘The Worst Thing You Can Do’ After a Data Breach, According to a Cybersecurity Expert

7/29/2024

Saboteurs Cut Internet Cables in Latest Disruption During Paris Olympics

Quad Foreign Ministers Decry Dangerous South China Sea Actions

Another European Parliament Member Says He’s Been Targeted With Commercial Spyware

Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails

Krebs: Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services

How Infostealers Pillaged the World’s Passwords

Meta’s AI Safety System Defeated by the Space Bar

Apple iOS 18.1 Beta Previews Apple Intelligence For the First Time

Former Avaya Employee Gets 4 Years for $88M License Piracy Scheme
Pro-Ukrainian Hackers Claim Attack on Russian Cyber Company

Intruders at HealthEquity Rifled Through Storage, Stole 4.3M People’s Data

HairClub for Men Notifies Consumers of October 2023 Data Breach

Town of Summerville (SC) Says Sensitive Data May Have Been Stolen During Recent Cyberattack

Gh0st RAT Trojan Targets Chinese Windows Users via Fake Chrome Site

Mandrake Spyware Infects 32,000 Devices Via Google Play Apps

Walmart Discovers New PowerShell Backdoor Linked to Zloader Malware

Hotjar, Business Insider Vulnerabilities Expose OAuth Data Risks

7/26-28/2024

Attack on Train System Highlights Broad Array of Security Threats to Paris Olympics

ECB’s Cyber Security Test Shows ‘Room for Improvement’ for Banks

CrowdStrike Says Over 97% of Windows Sensors Back Online

Hacktivists Claim Leak of CrowdStrike Threat Intelligence

CrowdStrike Warns of New Phishing Scam Targeting German Customers

Microsoft Calls for Windows Changes and Resilience After CrowdStrike Outage

Secure Boot Is Completely Broken on 200+ Models From 5 Big Device Makers

Why You Should Avoid Use of One-Time Passwords Sent by Text

The Personal Cybersecurity Concierge Is a New Perk, and Need, Among the Wealthy

Despite Bans, AI Code Tools Widespread in Organizations

X Begins Training Grok AI With Your Posts, Here’s How to Disable
Russian Ransomware Gangs Account for 69% of All Ransom Proceeds

FBCS Data Breach Impact Now Reaches 4.2 Million People

Private Health Information of More Than 1,600 UAB Patients Exposed on Postcards

Allcare Medical Management (CA) Data Breach Affects Patients of FPA Women’s Health

Synnovis Restores Systems After Cyber-Attack, But Blood Shortages Remain

Casper Network Halts Operations Following Security Breach

Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining

Crypto Exchange Gemini Discloses Third-Party Data Breach

Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials

WhatsApp for Windows Lets Python, PHP Scripts Execute With No Warning

Acronis Warns of Cyber Infrastructure Default Password Abused in Attacks

7/25/2024

North Korean APT45 Hackers Stealing Military Secrets, Say U.S. and Allies

At the Olympics, AI Is Watching You

Las Vegas Transit System Is Nation’s First to Plan Full Deployment of AI Surveillance System for Weapons

CrowdStrike Offers a $10 Apology Uber Eats Gift Card to Say Sorry for Outage

Insurers Brace for Claims From Global Tech Outage

‘Innovative’ £9.27m Shared Workspace Opens in Town

Kaspersky Says Uncle Sam Snubbed Proposal to Open up Its Code for Third-Party Review

Uncle Sam Accuses Florida Man Telco IT Pro of Decade-Long Spying Campaign for China

U.S. Offers $10M for Tips on DPRK Hacker Linked to Maui Ransomware Attacks

French Police Push PlugX Malware Self-Destruct Payload to Clean PCs
Belarus-Linked Hackers Target Ukrainian Orgs With PicassoLoader Malware

Pro-Palestinian Actor Levels 6-Day DDoS Attack on UAE Bank

Columbus (OH) Reports Cyber Incident as Multiple Cities Recover From Ransomware Attacks

Futurity First Insurance (CT) Provides Notice of November 2033 Data Breach

Researchers Reveal ConfusedFunction Vulnerability in Google Cloud Platform

Progress Warns of Critical RCE Bug in Telerik Report Server

Critical ServiceNow RCE Flaws Actively Exploited to Steal Credentials

PKfail Secure Boot Bypass Lets Attackers Install UEFI Malware

CISA Warns of Exploitable Vulnerabilities in Popular BIND 9 DNS Software

7/24/2024

North Korean Hackers Targeted Cybersecurity Firm KnowBe4 with Fake IT Worker

Major Russian Banks Hit with DDoS Attacks as Ukraine Claims Responsibility

CrowdStrike Blames Test Software for Taking Down 8.5 Million Windows Machines

No Sign Microsoft Plans to Limit CrowdStrike Access to Windows After Outage, Source Says

This Machine Exposes Privacy Violations

Chrome Adds New Warnings and Cloud Scanning for Suspicious Downloads

Google Criticized for Abandoning Cookie Phase-Out

Google Chrome Now Warns About Risky Password-Protected Archives

School Gets an F for Using Facial Recognition on Kids in Canteen

BreachForums v1 Database Leak is an OPSEC Test for Hackers

Encrypted Apps Still a Challenge as FBI Probes Trump Shooter’s Devices, Wray Says
Data Pilfered From Pentagon IT Supplier Leidos

Crypto Exchange MonoSwap Has Been Hacked, Warns Users Not to Deposit Funds

Hamster Kombat’s 250 Million Players Targeted in Malware Attacks

Brookfield Zoo (IL) Confirms Data Breach; Employee Information Accessed

Jefferson County (KY) Clerk’s Offices to Remain Closed on Thursday Amid Cyberattack

A Hacker ‘Ghost’ Network Is Quietly Spreading Malware on GitHub

Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers

Docker Fixes Critical 5-Year Old Authentication Bypass Flaw

CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities List

Meta Bans 63,000 Accounts Belonging to Nigeria’s Sextortionist Yahoo Boy

7/23/2024

CrowdStrike CEO to Testify About Massive Outage That Halted Flights and Hospitals and More

Inside the 78 Minutes That Took Down Millions of Windows Machines

CrowdStrike’s Botched Tech Update Wasn’t Unique. Are Lessons Ever Learned?

DOT Investigating Delta Over IT Outage Chaos

Fake CrowdStrike Repair Manual Pushes New Infostealer Malware

Russia Shifts Cyber Focus to Battlefield Intelligence in Ukraine

How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep Winter

‘FrostyGoop’

Possible APT28-Linked Hackers Target Ukraine’s Scientific Institutions

Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware

Chinese Hackers Target Taiwan and U.S. NGO with MgBot Malware

Chinese Espionage Group Upgrades Malware Arsenal to Target All Major OS
Greece’s Land Registry Agency Breached in Wave of 400 Cyberattacks

BreachForums v1 Hacking Forum Data Leak Exposes Members’ Info

DeFi Exchange dYdX v3 Website Hacked in DNS Hijack Attack

Red Art Games Hit with Major Cyber Attack

Employer Flexible (TX) Confirms Data Breach Related to myHR Platform

Magento Sites Targeted with Sneaky Credit Card Skimmer via Swap Files

Google Abandons Plan to Phase Out Third-Party Cookies in Chrome

FTC Launches Probe Into How Companies Use Data to Tailor What Each Customer Pays

Verizon to Pay $16 Million in TracFone Data Breach Settlement

Wiz Rejects Google’s $23 Billion Takeover in Favor of IPO

Krebs: Phish-Friendly Domain Registry “.top” Put on Notice

7/22/2024

CrowdStrike Update That Caused Global Outage Likely Skipped Checks, Experts Say

‘Significant Number’ of Devices Fixed – CrowdStrike

Microsoft Releases a CrowdStrike Recovery Tool – Here’s How It Works

The Pentagon Wants to Spend $141 Billion on a Doomsday Machine

Ransomware Groups Fragment Amid Rising Cybercrime Threats

Cybercrooks Crafting Solo Careers in Wake of Recent Ransomware Takedowns & Disruptions

Police Infiltrates, Takes Down DigitalStress DDoS-For-Hire Service

Spain Arrests Three for Using DDoSia Hacktivist Platform
Los Angeles County Court System Slated to Reopen Tuesday After Ransomware Attack

56K Michigan Medicine Patients’ Information Potentially Exposed in May Cyberattacks

Experts Uncover Chinese Cybercrime Network Behind Gambling and Human Trafficking

Play Ransomware Expands to Target VMWare ESXi Environments

PINEAPPLE and FLUXROOT Hacker Groups Abuse Google Cloud for Credential Phishing

SocGholish Malware Exploits BOINC Project for Covert Cyberattacks

Telegram Zero-Day Allowed Sending Malicious Android APKs as Videos

7/19-21/2024

Major Tech Outage Grounds Flights, Hits Banks and Businesses Worldwide

Krebs: Global Microsoft Meltdown Tied to Bad CrowdStrike Update

IT Teams Scramble to Recover From CrowdStrike Incident as Officials Warn of ‘Risks of Consolidation

CrowdStrike IT Outage Affected 8.5 Million Windows Devices, Microsoft Says

The CrowdStrike Outage and Global Software’s Single-Point Failure Problem

Fast and Automated: Global Tech Outage Shows Hazards of Cloud Software Updates

CrowdStrike Has a New Guidance Hub for Dealing with the Windows Outage

Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware

Don’t Fall for CrowdStrike Outage Scams

More U.S. Flights Cancelled in Wake of Global Cyber Outage

IT Outage Exposes Fragility of Tech Infrastructure
IDF Has Rebuffed 3 Billion Cyberattacks Since Oct. 7, Colonel Claims

Hackers Are Using Fake Drone Contracts to Infect Ukrainian Defense Enterprises

APT41 Infiltrates Networks in Italy, Spain, Taiwan, Turkey, and the UK

Pro-Houthi Group Targets Yemen Aid Organizations with Android Spyware

Ransomware Attack Shuts Down Los Angeles Superior Court Systems

The Feds Say These Are the Russian Hackers Who Attacked U.S. Water Utilities

Two Russian Nationals Plead Guilty in LockBit Ransomware Attacks

17-Year-Old Linked to Scattered Spider Cybercrime Syndicate, Including MGM Hack, Arrested in UK

DHS Watchdog Rebukes CISA and Law Enforcement Training Center for Failing to Protect Data

DHS Inspector General: Coast Guard Shortcomings Hinder Us Maritime Security

7/18/2024

Von Der Leyen Pledges to Tackle Ransomware Attacks Against EU Hospitals

Chainalysis Launches Public-Private Plans to Crack Down on Crypto Scams

Firms Skip Security Reviews of Major App Updates About Half the Time

SolarWinds Beats Most of U.S. SEC Lawsuit Over Russia-Linked Cyberattack

SolarWinds Fixes 8 Critical Bugs in Access Rights Audit Software

Kaspersky Challenges U.S. Government to Put Up or Shut up About Kremlin Ties

Meta Halts AI Use in Brazil Following Data Protection Authority’s Ban

Alleged ‘Maniac Murder Cult’ Leader ‘Commander Butcher’ Indicted Over Plot to Murder Jews

Hacker Jailed After Jobcentre Suffers Cyber Attacks
UK National Blood Stocks in ‘Very Fragile’ State Following Ransomware Attack

Nearly 13 Million Australians Affected by MediSecure Attack

SAP AI Core Flaws Expose Sensitive Customer Data and Keys

Liverpool Suspend Ticket Sales After Cyber Attack

Indian Crypto Platform WazirX Confirms $230 Million Stolen During Cyberattack

Revolver Rabbit Gang Registers 500,000 Domains for Malware Campaigns

TAG-100: New Threat Actor Uses Open-Source Tools for Widespread World-Wide Attacks

HotPage Malware Hijacks Browsers With Signed Microsoft Driver

Critical Cisco Bug Lets Hackers Add Root Users on SEG Devices

7/17/2024

Paris 2024 Olympics Face Escalating Cyber-Threats

‘Ghostemperor’ Returns: Mysterious Chinese Hacking Group Spotted for First Time in Two Years

China-Linked APT17 Targets Italian Companies with 9002 RAT Malware

North Korean Hackers Update BeaverTail Malware to Target MacOS Users

The U.S. Supreme Court Kneecapped U.S. Cyber Strategy, Now Up to U.S. Congress

Kaspersky Gives U.S. Customers Six Months of Free Updates as a Parting Gift

Data Breaches Highlight Lack of Basic Cyber Controls

Google-Backed Software Developer Gitlab Explores Sale, Sources Say

Craig Wright Admits He Isn’t the Inventor of Bitcoin After High Court Judgment in UK

Training at Black Hat to Focus on Equipping Cybersecurity Leaders With Soft Skills

Global Police Swoop on Black Axe Cybercrime Syndicate
Over 400,000 Life360 User Phone Numbers Leaked via Unsecured API

Yacht Giant MarineMax Data Breach Impacts Over 123,000 People

Hackney Council in London Reprimanded for Failing to Prevent Ransomware Attack

Furniture Giant Bassett Shuts Down Manufacturing Facilities After Ransomware Attack

Shadowroot Ransomware Lures Turkish Victims via Phishing Attacks

Qilin Ransomware’s Sophisticated Tactics Unveiled By Experts

FIN7 Group Advertises Security-Bypassing Tool on Dark Web Forums

Iraq-Based Cybercriminals Deploy Malicious Python Packages to Steal Data

Cisco SSM On-Prem Bug Lets Hackers Change Any User’s Password

Critical Apache HugeGraph Vulnerability Under Attack – Patch ASAP

Exchange Online Adds Inbound DANE with DNSSEC For Security Boost

7/16/2024

CyberDragon & Cyber Army of Russia: Hacktivist Groups Target Romania Amid Geopolitical Tensions

MHTML Exploited By APT Group Void Banshee

Senators Press AT&T, Snowflake for Answers on Wide-Ranging Data Breach

AT&T Ransom Laundered Through Mixers, Gambling Services

CISA Warns Critical Geoserver GeoTools RCE Flaw is Exploited in Attacks

Two-Fifths of Senior Citizens Suffer Frequent Fraud Attempts

FCC Chair Proposes New Tactics to Crack Down on AI-Generated Robocalls

Hacked, Leaked, Exposed: Why You Should Never Use Stalkerware Apps
Rite Aid Says June Data Breach Impacts 2.2 Million People

Email Addresses of 15 Million Trello Users Leaked on Hacking Forum

Philippine Department of Migrant Workers Hit by Ransomware Attack; Online Systems Down

Family Dynamics Counseling Services (WA) Discloses May 2024 Data Breach

Cyber-Crime Super-Crew Scattered Spider Falls Madly in Love With RansomHub and Qilin

‘Konfety’ Ad Fraud Uses 250+ Google Play Decoy Apps to Hide Malicious Twins

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

Microsoft Finally Fixes Outlook Alerts Bug Caused by December Updates

7/15/2024

The FBI Says It Has ‘Gained Access’ to the Trump Rally Shooter’s Phone

U.S. Senators Secretly Work to Block Safeguards Against Surveillance Abuse

North Korean Hackers Sent Stolen Crypto to Wallet Used by Asian Payment Firm

Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks (Krebs)

Attackers Exploit URL Protections to Disguise Phishing Links

CRYSTALRAY Cyber-Attacks Grow Tenfold Using OSS Tools

Kaspersky Lab Closing U.S. Division; Laying Off Workers

UK Cyber-Boss Slams China’s Bug-Hoarding Laws

Patagonia Invaded Privacy by Using AI to Analyze Customer Service Interactions, Lawsuit Alleges
Hackers Claim to Have Leaked 1.1 TB of Disney Slack Messages

AT&T Breach May Also Impact Millions of Boost, Cricket, H2O Customers

‘Trial’ DDoS Attacks on French Sites Portend Greater Olympics Threats

New BugSleep Malware Implant Deployed in MuddyWater Attacks

Facebook Ads for Windows Desktop Themes Push Info-Stealing Malware

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection

SEXi Ransomware Rebrands to APT INC, Continues VMware ESXi Attacks

WP Time Capsule Plugin Update Urged After Critical Security Flaw

GitHub Token Leak Exposes Python’s Core Repositories to Potential Attacks

7/12-14/2024

Former President Donald Trump Injured in Assassination Attempt at Campaign Rally

NATO Set to Build New Cyber Defense Center

White House Urged by GOP to Double Check Microsoft Isn’t Funneling AI to China via Recent G42 Deal

CISA Broke Into a U.S. Federal Agency, and No One Noticed for a Full 5 Months

Iran’s Illusion of Reform Masks the Crumbling of Khamenei’s Regime

Australian Defence Force Private and Husband Charged with Espionage for Russia

The Rabbit R1 Has Been Logging Users’ Chats — With No Way to Wipe Them

Google Parent in Talks to Buy Cybersecurity Startup Wiz for $23 Billion

Banks in Singapore to Phase Out One-Time Passwords in 3 Months

Hackers Use PoC Exploits in Attacks 22 Minutes After Release
Krebs: Crooks Steal Phone, SMS Records for Nearly All AT&T Customers

AT&T’s Massive Data Breach Deepens Crisis for Snowflake Seven Weeks After Hack Was Disclosed

AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records

One Tech Tip: What to Do if Your Personal Info Has Been Exposed in a Data Breach

Car Dealer Software Slinger CDK Global Said to Have Paid $25M Ransom After Cyberattack

Rite Aid Confirms Data Breach After June Ransomware Attack

DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign

DNS Hijacks Target Crypto Platforms Registered With Squarespace

Netgear warns users to patch auth bypass, XSS router flaws

EU Threatens Musk’s X With a Fine of up to 6% of Global Turnover

7/11/2024

Macau Government Websites Hit with Cyberattack by Suspected Foreign Hackers

Why Indo-Pacific Countries Are Joining the NATO Summit

Germany to Phase Out Huawei, ZTE Components From its 5G Core Network

U.S. Lawmakers Raise Worries About China in Microsoft Deal with Emirati AI Firm

Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk

Companies Sharply Criticize Draft U.S. Cyber Reporting Rules

Akira Ransomware: Lightning-Fast Data Exfiltration in 2-Ish Hours

Pressure Grows in Congress to Treat Crypto Investigator Tigran Gambaryan, Jailed in Nigeria, as a Hostage

Notorious Hacker Kingpin ‘Tank’ Is Finally Going to Prison

Privacy Expert Put away for 9 Years After ‘Grotesque’ Cyberstalking Campaign

Data Breach Exposes Millions of mSpy Spyware Customers

Google Increases Bug Bounty Rewards Five Times, up to $151K
Advance Auto Parts Data Breach Impacts 2.3 Million People

Dallas County: Data of 200,000 Exposed in 2023 Ransomware Attack

ARRL Finally Confirms Ransomware Gang Stole Data in Cyberattack

Signal Downplays Encryption Key Flaw, Fixes It After X Drama

Heritage Foundation Insists It Was Not Hacked by ‘Gay Furries’ Hacktivist Collective SiegedSec

Sibanye Stillwater Hit by Ransomware Attack

CRYSTALRAY Hacker Expands to 1,500 Breached Systems Using SSH-Snake Tool

60 New Malicious Packages Uncovered in NuGet Supply Chain Attack

Exim Vulnerability Affecting 1.5 Million Servers Lets Attackers Attach Malicious Files

PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks

Palo Alto Networks Patches Critical Flaw in Expedition Migration Tool

7/10/2024

Election Deepfakes Could Undermine Institutional Credibility, Moody’s Warns

NATO Funds Startups Aiming to Solve Cyber Problems in Infrastructure

Japan Warns of Attacks Linked to North Korean Kimsuky Hackers

Beijing Accused of Misusing Western Research to Claim Volt Typhoon Is a Ransomware Group

Krebs: The Stark Truth Behind the Resurgence of Russia’s Fin7

Ransomware Groups Prioritize Defense Evasion for Data Exfiltration

Huione: The $11 Billion Marketplace Enabling the Crypto Scam Economy

You Can Now Protect Your High-Risk Google Account With Just Your Phone

Snowflake Lets Admins Make MFA Mandatory Across All User Accounts

Most Security Pros Admit Shadow SaaS and AI Use

CISA Urges Devs to Weed Out OS Command Injection Vulnerabilities

Microsoft Emails That Warned Customers of Russian Hacks Criticized for Looking Like Spam and Phishing
Ticket Heist Fraud Gang Uses 700 Domains to Sell Fake Olympics Tickets

Hacktivists Release Two Gigabytes of Heritage Foundation Data

Kovack Financial (FL) Provides Notice of Third-Party Data Breach That Leaked Consumer SSNs

Clay County (IN) Courthouse Remains Closed After Ransomware Attack

Smishing Triad Targets India with Fraud Surge

ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks

Poco RAT Burrows Deep Into Mining Sector

New Ransomware Group Exploiting Veeam Backup Software Vulnerability

New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk

GitLab: Critical Bug Lets Attackers Run Pipelines as Other Users

Krebs: Microsoft Patch Tuesday, July 2024 Edition

Microsoft Outlook Faced Critical Zero-Click RCE Vulnerability

7/9/2024

U.S., Allies Issue Rare Warning on Chinese Hacking Group: APT40

Chinese State Actor APT40 Exploits N-Day Vulnerabilities “Within Hours”

Chinese APT40 Hackers Hijack SOHO Routers to Launch Attacks

Houthi ‘GuardZoo’ Malware Targets Over 450 Middle Eastern Military Personnel

U.S. Disrupts AI-Powered Bot Farm Pushing Russian Propaganda on X

Just a Fifth of Manufacturers Have Strongest Anti-Phishing Protection

Scammers Double-Scam Victims by Offering to Help Recover From Scams

Google’s Dark Web Monitoring Service Will Soon Be Free for All Users

Microsoft China Staff Can’t Log on With an Android, so Redmond Buys Them iThings
Cyber-Attack on Evolve Bank Exposed Data of 7.6 Million Customers

Financial Business and Consumer Solutions (FBCS) Data Breach Affects 4 Million People

City of Philadelphia Says Over 35,000 Hit in May 2023 Breach

Monroe County (IN) Victim of Intrusion by Ransomware Group BlackSuit

Fujitsu Confirms Customer Data Exposed in March Cyberattack

Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories

Hackers Target WordPress Calendar Plugin Used by 150,000 Sites

Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks

RADIUS Protocol Vulnerability Exposes Networks to MitM Attacks

7/8/2024

New APT CloudSorcerer Malware Hits Russian Targets

Fix NHS Gaps or Face More Attacks – Ex Cyber Chief

Avast Secretly Gave DoNex Ransomware Decryptors to Victims Before Crims Vanished

Russia Blocks VPN Services in Information Crackdown

10 Billion Passwords Leaked on Hacking Forum

Crypto Thefts Double to $1.4 Billion, TRM Labs Finds

Scalpers Work With Hackers to Liberate Ticketmaster’s ‘Non-Transferable’ Tickets

Selfie-Based Authentication Raises Eyebrows Among Infosec Experts

Apple Geolocation API Exposes Wi-Fi Access Points Worldwide

Microsoft Forgets About SwiftKey’s Support Site
Roblox Vendor Data Breach Exposes Dev Conference Attendee Info

Computer Maker Zotac Exposed Customers’ RMA Info on Google Search

Neiman Marcus Data Breach: 31 Million Email Addresses Found Exposed

‘Serious Hacker Attack’ Forces Frankfurt University to Shut down IT Systems

Florida Health Department Data Exposed by RansomHub

Cyber Incident Impacts Systems at Southwest Tennessee Community College

Mekotio Trojan Targets Latin American Banking Credentials

RCE Bug in Widely Used Ghostscript Library Now Exploited in Attacks

Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service

7/5-7/2024

The U.S. Must Secure Its Supremacy Against China in AI and Cloud Computing

There’s a New Government in the UK. What Can We Expect From It on Cyber?

Devs Claim Apple Is Banning VPNs in Russia ‘More Effectively’ Than Putin

Europol Says Home Routing Mobile Encryption Feature Aids Criminals

Euro 2024 Becomes Latest Sporting Event to Attract Cyberattacks

Hackers Leak Alleged Taylor Swift Ticket Data to Extort Ticketmaster

Ticketmaster Discredits Dark Web Claims of Stolen Barcodes for Taylor Swift Concerts

Mt. Gox Begins Repaying Bitcoin to Creditors a Decade After Exchange’s Collapse
Shopify Denies It Was Hacked, Links Stolen Data to Third-Party App

Louisiana Special School District Hit by Akira Cyber Attack

New Eldorado Ransomware Targets Windows, VMware ESXi VMs

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

OVHcloud Hit with Record 840 Million PPS DDoS Attack Using MikroTik Routers

Cloudflare Blames Recent Outage on BGP Hijacking Incident

New Golang-Based Zergeca Botnet Capable of Powerful DDoS Attacks

Polyfill[.]io Attack Impacts Over 380,000 Hosts, Including Major Companies

7/3-4/2024

Microsoft’s Midnight Blizzard Source Code Breach Also Impacted Federal Agencies

Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks

Senate Leader Demands Answers From CISA on Ivanti-Enabled Hack of Sensitive Systems

Half of Employees Fear Punishment for Reporting Security Mistakes

Meta Faces Suspension of AI Data Training in Brazil

How Apple Intelligence’s Privacy Stacks Up Against Android’s ‘Hybrid AI’

OpenAI’s ChatGPT Mac App Was Storing Conversations in Plain Text 

A Hacker Stole OpenAI Secrets, Raising Fears That China Could, Too

Krebs: The Not-So-Secret Network Access Broker x999xx

Romance Scams Cost Consumers $1.14 Billion Last Year. It’s a ‘More Insidious’ Fraud, Expert Says

Europol Warns of Home Routing Challenges For Lawful Interception

APP Fraud Singled Out as Biggest Financial Crime Threat

Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt Strike

Proton Is Launching Encrypted Documents to Take On Google Docs

Auto Industry Warns of Supply-Chain Upsets, Higher Costs From Cybersecurity Rules

Is Our Food Supply Chain at Risk?
Twilio Alerts Authy Two-Factor App Users That ‘Threat Actors’ Have Their Phone Numbers

Formula 1 Governing Body Discloses Data Breach After Email Hacks

Alabama Dept. Of Education Announces Data Breach, Attempted Cyber Attack

Gamers’ Data Exposed in RPG Platform Roll20 Breach

Ethereum Mailing List Breach Exposes 35,000 to Crypto Draining Attack

Hackers Attack HFS Servers to Drop Malware and Monero Miners

HealthEquity Data Breach Exposes Protected Health Information

South Africa National Healthcare Lab Still Reeling From Ransomware Attack

Ransomware Scum Who Hit Indonesian Government Apologizes, Hands Over Encryption Key

New Ransomware Group ‘Volcano Demon’ Phones Execs to Extort Payment

FakeBat Loader Malware Spreads Widely Through Drive-by Download Attacks

OVHcloud Blames Record-Breaking DDoS Attack on MikroTik Botnet

Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool

WordPress Plugins at Risk From Polyfill Library Compromise

Microsoft Uncovers Major Flaws in Rockwell PanelView Plus

7/2/2024

UN Urges Russia to ‘Immediately’ Cease Interference in European Satellites

The Tech Crash Course That Trains U.S. Diplomats to Spot Threats

What Cybersecurity Defense Looks Like for School Districts

Health Tech Execs Get Jail Time For $1bn Fraud Scheme

Stolen Credentials Could Unmask Thousands of Darknet Child Abuse Website Users
LockBit Claims Cyberattack on Croatia’s Largest Hospital

Patelco Shuts Down Banking Systems Following Ransomware Attack

Affirm Fears Customer Info Pilfered During Ransomware Raid at Evolve Bank

Baddies Hijack Korean ERP Vendor’s Update Systems to Spew Malware

Google Now Pays $250,000 for KVM Zero-Day Vulnerabilities

7/1/2024

Transparent Tribe’s CapraRAT Spyware Disguised as Popular Apps Threatens Android Users

TeamViewer: Hackers Copied Employee Directory and Encrypted Passwords

The Problem the U.S. TikTok Crackdown and Kaspersky Ban Have in Common

CISA Director: U.S. Is ‘Not Afraid’ to Shout About Big Tech’s Security Failings

Google Chrome to Let Isolated Web App Access Sensitive USB Devices

Meta’s ‘Pay or Consent’ Data Model Breaches EU Law

Indonesian Government Didn’t Have Backups of Ransomwared Data, Because DR Was Only an Option

Poland to Probe Russia-Linked Cyberattack on State News Agency

Australian Police Arrest Suspect in Fake Wi-Fi Scam Targeting Airport Passengers

Unfounded Fears: AI Extinction-Level Threats & the AI Arms Race
Indian Software Firm Conceptworld’s Products Hacked to Spread Data-Stealing Malware

Router Maker’s Support Portal Hacked, Replies With MetaMask Phishing

CDK Global Says All Dealers Will Be Back Online by Thursday

Fintech Company Wise Says Some Customers Affected by Evolve Bank Data Breach

Prudential Financial Now Says 2.5 Million Impacted by Data Breach

Japanese Anime and Gaming Giant Kadokawa Admits Data Leak Following Ransomware Attack

Cisco Warns of NX-OS Zero-Day Exploited to Deploy Custom Malware

Critical regreSSHion OpenSSH Flaw Enables Full System Compromise

Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks

Latest Intel CPUs Impacted by New Indirector Side-Channel Attack