8/29/2024

Russian APT29 Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack

North Korean Hackers Launch New Wave of npm Package Attacks

Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

Powerful Spyware Exploits Enable a New String of ‘Watering Hole’ Attacks

Krebs: When Get-Out-The-Vote Efforts Look Like Phishing

Surge in New Scams as Pig Butchering Dominates

Harmful ‘Nudify’ Websites Used Google, Apple, and Discord Sign-On Systems

Dell Attempts to Sell Cybersecurity Firm Secureworks Again, Sources Say

CrowdStrike’s Meltdown Didn’t Dent Its Market Dominance … Yet

Halliburton Cyberattack Linked to RansomHub Ransomware Gang

FBI: RansomHub Ransomware Breached 210 Victims Since February

Brain Cipher Claims Attack on Olympic Venue, Promises 300 GB Data Leak

Irish Wildlife Park Warns Visitors to Cancel Bank Cards After Discovering Cyberattack

USAA Data Breach Affects Over 32k Consumers

Cambodian Scam Giant Handled $49 Billion in Crypto Transactions Since 2021

Fake Palo Alto GlobalProtect Used as Lure to Backdoor Enterprises

How AitM Phishing Attacks Bypass MFA and EDR—and How to Fight Back

How Telecom Vulnerabilities Can Be a Threat to Cybersecurity Posture

8/28/2024

Intel Officials Say They Anticipate More Hacking Attempts as U.S. Election Nears

Notorious Iranian APT33 (aka Peach Sandstorm) Hackers Have Been Targeting the Space Industry With a New Backdoor

Iran’s APT42 (aka Charming Kitten) Operated Fake Human-Resources Firm to Root Out Unfriendly Spies, Researchers Say

Iranian UNC757 (aka Pioneer Kitten) Hackers Work With Ransomware Gangs to Extort Breached Orgs

South Korean Spies Exploit WPS Office Zero-Day

Microsoft Hosts a Security Summit but No Press, Public Allowed

Employee Arrested for Locking Windows Admins Out of 254 Servers in Extortion Plot

Google Increases Chrome Bug Bounty Rewards up to $250,000

U.S. Offers $2.5 Million Reward for Hacker Linked to Angler Exploit Kit

Telegram Founder Pavel Durov Was Wooed and Targeted by Governments

Telegram Repeatedly Refuses to Join Child Protection Schemes

1 in 10 Minors Say Their Friends Use AI to Generate Nudes of Other Kids, Survey Finds

Hundreds of LLM Servers Expose Corporate, Health & Other Online Data

‘Store Now, Decrypt Later’: U.S. Leaders Prep for Quantum Cryptography Concerns

Colorado Contacted Pac-12 About Potential Data Breach Before Loss to Oregon

‘Malfunction’ at Dutch Defense Ministry Datacenter Causing Mass Disruption

Dick’s Sporting Goods Discloses Unauthorized Third-Party Access to Info, Including Some Confidential Data

Seattle-Tacoma Airport Deals With Delays Five Days After Detecting Cyberattack

Play Ransomware Hackers Claim Attack on U.S. Manufacturer Microchip Technology

Norfolk (UK) Poultry Farm Banham Poultry Hit by Cyber-Attack

Essex (UK) Infant School Canvey Island Infant School Hit by Cyber Attack

LummaC2 Infostealer Resurfaces With Obfuscated PowerShell Tactics

PoorTry Windows Driver Evolves Into a Full-Featured EDR Wiper

BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack Wave

Attackers Exploit Critical Atlassian Confluence Flaw for Cryptojacking

CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet

Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code Execution

CISA Flags Critical Apache OFBiz Flaw Amid Active Exploitation Reports

Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability

8/27/2024

Krebs: New Versa Director 0-Day Attacks Linked to China’s ‘Volt Typhoon’

Internet Outages Spread Across Ukraine Following Russian Air Strikes on Critical Infrastructure

U.S. Marshals Service Disputes Hunters International Ransomware Gang’s Breach Claims

A Third of Organizations Suffer SaaS Data Breaches

Threat Group ‘Bling Libra’ Pivots to Extortion for Cloud Attacks

Microsoft Security Tools Questioned for Treating Employees as Threats

Intel’s Software Guard Extensions Broken? Don’t Panic

Patchwork of State Privacy Laws Remains After Latest Failed Bid for Federal Law

Notion Exits Russia and Will Terminate Accounts in September

Windows Downdate Tool Lets You ‘Unpatch’ Windows Systems

Park’N Fly Notifies 1 Million Customers of Data Breach

BlackSuit Ransomware Stole Data of 950,000 From Software Vendor Young Consulting

Malware Infiltrates Pidgin Messenger’s Official Plugin Repository

Trionfo Solutions (IL) Announces Data Breach Affecting Over 76k MetLife Plan Holders

MOVEit Hack Exposed Personal Data of Half Million TDECU Users

Microsoft Sway Abused in Massive QR Code Phishing Campaign

macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users

Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation

Microsoft Fixes ASCII Smuggling Flaw That Enabled Data Theft from Microsoft 365 Copilot

PoC Exploit for Zero-Click Vulnerability Made Available to the Masses

8/26/2024

NSA Releases Guide to Combat Living Off the Land Attacks

In a Kyiv Hangar, Ukraine Launches a Cyber Range for Everyone

Pavel Durov’s Arrest Leaves Telegram Hanging in the Balance

Telegram’s Durov Still Held by French Police, Franceinfo Reports

Telegram Says Arrested CEO Has ‘Nothing to Hide’ as France Reportedly Extends His Detention

Elon Musk Calls for Release of Telegram Founder Pavel Durov as Arrest Sparks Debate Whether X Owner May Be Next

Dutch Regulator Fines Uber €290 Million for GDPR Violations in Data Transfers to U.S.

Microsoft: Exchange Online Mistakenly Tags Emails as Malware

The Future of Cybersecurity: Insights From Theresa Payton, Former White House CIO

Researchers Warn of Text Scams That Send Drivers Fake Bills for Highway Tolls

C-Suite Involvement in Cybersecurity Is Little More Than Lip Service

AMD Internal Data Reportedly Offered for Sale

Seattle’s Airport, Seaport Isolate Systems After Cyberattack

31.5 Million Invoices, Contracts, Patient Consent Forms, Documents, and Much, Much More Exposed to the Internet

Patelco Notifies 726,000 Customers of Ransomware Data Breach

Data of Nearly 1,000 People Leaked in St. Helena Cyberattack, City Says

Keystone Pacific Property Management Notifies Consumers of Recent Data Breach

Researchers Identify Over 20 Supply Chain Vulnerabilities in MLOps Platforms

Critical Flaws in Traccar GPS System Expose Users to Remote Attacks

SonicWall Issues Critical Patch for Firewall Vulnerability Allowing Unauthorized Access

Versa Fixes Director Zero-Day Vulnerability Exploited in Attacks

Google Tags a Tenth Chrome Zero-Day as Exploited This Year

8/22-25/2024

The Iranians Who Hacked Trump’s Campaign Have Deep Expertise

Meta Exposes Iranian Hacker Group Targeting Global Political Figures on WhatsApp

When War Came to Their Country, They Built a Map

Kremlin Blames Widespread Website Disruptions on DDoS Attack; Digital Experts Disagree

Russia Calls for Restrictions on Surveillance Cameras, Dating Apps in Cities Under Attack From Ukraine

Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System Control

Microsoft to Host CrowdStrike and Others to Discuss Windows Security Changes

Krebs: Local Networks Go Global When Domain Names Collide

AI Copilots Are Making Internal Breaches Easier and Costlier to Defend Against

Companies Prepare to Fight Quantum Hackers

U.S. Charges Karakurt Extortion Gang’s “Cold Case” Negotiator

Russian Laundering Millions for Lazarus Hackers Arrested in Argentina

Suspect in $14 Billion Cryptocurrency Pyramid Scheme Extradited to China

Telegram Messaging App CEO Durov Arrested in France

Content Moderation Failures

A Bank Exec Stole $47 Million for a Crypto Scam, and Now He’s Going to Jail

Why Parents May Want to Start Locking a Child’s Credit at a Very Young Age

Company Fined $1m for Fake Joe Biden AI Calls

YouTube Launches AI Tool to Recover Hacked Accounts

Operating as a Legitimate Business, Greasy Opal’s CAPTCHA Solver Still Serving Cybercrime After 16 Years

University of California Santa Cruz Thought It Would Be a Good Idea to Do a Phishing Test With a Fake Ebola Scare

U.S. Oil Giant Halliburton Confirms Cyberattack Behind Systems Shutdown

Port of Seattle Says It Was Hit with Possible Cyberattack; Outage Affects Airport, Phone Systems

American Radio Relay League Confirms $1 Million Ransom Payment

Qilin Caught Red-Handed Stealing Credentials in Google Chrome

New Malware PG_MEM Targets PostgreSQL Databases for Crypto Mining

Cthulhu Stealer Malware Targets macOS With Deceptive Tactics

Hackers Now Use AppDomain Injection to Drop CobaltStrike Beacons

PEAKLIGHT Downloader Deployed in Attacks Targeting Windows with Malicious Movie Downloads

Hackers Steal Banking Creds from iOS, Android Users via PWA Apps

New Linux Malware ‘sedexp’ Hides Credit Card Skimmers Using Udev Rules

Novel Android Malware Steals Card NFC Data For ATM Withdrawals

Backdoor in Mifare Smart Cards Could Open Doors Around the World

Hackers Are Exploiting Critical Bug in LiteSpeed Cache Plugin

Security Flaws in UK Political Party Donation Platforms Exposed

New ‘ALBeast’ Vulnerability Exposes Weakness in AWS Application Load Balancer

Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk

Georgia Tech Sued Over Cybersecurity Violations, DOJ Joins In

Audit Finds Notable Security Gaps in FBI’s Storage Media Management

Hack on North Miami Tests Ransom Payment Bans

8/21/2024

Moscow Detains Scientist Suspected of Carrying out DDoS Attacks on Russia

Russia Tells Citizens to Switch off Home Surveillance Because the Ukrainians Are Coming

Healthcare Hit by a Fifth of Reported Ransomware Incidents

Most Ransomware Attacks Now Happen at Night

FAA Proposes New Cybersecurity Rules for Airplanes

The U.S. Government Wants You—Yes, You—to Hunt down Generative AI Flaws

Australia Calls Off Clearview AI Investigation Despite Lack of Compliance

Critical Thinking AI in Cybersecurity: A Stretch or a Possibility?

Stadiums Are Embracing Face Recognition. Privacy Advocates Say They Should Stick to Sports

How to Freeze Your Credit After a Data Breach

Phrack Hacker Zine Publishes New Edition After Three Years

Financial Services Firm Fined $850K for Violating SEC Cyber Rules

McDonald’s Instagram Page Hacked by Crypto Scammers Who Claim They Stole $700K

110K Domains Targeted in ‘Sophisticated’ AWS Cloud Extortion Campaign

Top U.S. Oilfield Firm Halliburton Hit by Cyberattack, Source Says

Patelco Credit Union Says Personal Info of Customers, Employees Exposed in June Breach

Dental Specialists (MN) Data Breach Affects an Estimated 38,442 People

New MoonPeak RAT Linked to North Korean Threat Group UAT-5394

New macOS Malware TodoSwift Linked to North Korean Hacking Groups

Critical LiteSpeed Cache Plugin Flaw Exposes WordPress Sites

GitHub Enterprise Server Vulnerable to Critical Auth Bypass Flaw

Google Fixes Ninth Chrome Zero-Day Exploited in Attacks This Year

Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data

Microsoft to Roll out Windows Recall to Insiders in October

QNAP Adds NAS Ransomware Protection to Latest QTS Version

8/20/2024

U.S. Warns of Iranian Hackers Escalating Influence Operations

Iranian Group TA453 Launches Phishing Attacks with BlackSmith

An AWS Configuration Issue Could Expose Thousands of Web Apps

Thousands of Oracle NetSuite Sites at Risk of Exposing Customer Information

‘Styx Stealer’ Malware Developer Accidentally Exposes Personal Info to Researchers in ‘Critical Opsec Error’

Novel Phishing Method Used in Android/iOS Financial Fraud Campaigns

Former Congressman Santos Admits Identity Theft and Fraud

Man Who Hacked Hawaii State Registry to Forge His Own Death Certificate Sentenced to 81 Months

Don’t Let Your Cash App Get Hacked. Cybersecurity Expert Tips to Safeguard Your Money

August Windows Updates Break Dual Boot on Some Linux Systems

Jewish Home Lifecare Notifies 100,000 Victims of Ransomware Breach

Microchip Technology Says Certain Operations Disrupted by Cyber Incident by ‘Unauthorized Party’

CannonDesign Confirms Avos Locker Ransomware Data Breach

Enroll Confidently (WA) Notifies Consumers of February 2024 Data Breach

Blind Eagle Hackers Exploit Spear-Phishing to Deploy RATs in Latin America

Czech Mobile Users Targeted in New Banking Credential Theft Scheme

Hackers Exploit PHP Vulnerability to Deploy Stealthy Msupedge Backdoor

New DNS-Based Backdoor Threat Discovered at Taiwanese University

Researchers Uncover TLS Bootstrap Attack on Azure Kubernetes Clusters

8/19/2024

U.S. Intelligence Community Says Iran Responsible for Hack of Trump Campaign

FBI and CISA Assure Public on Election Ransomware Security

Krebs: National Public Data Published Its Own Passwords

National Public Data Insists ‘Only’ 1.3M People Affected by Intrusion

Was Your Social Security Number Leaked to the Dark Web? Use This Tool to Find Out.

Russia-Linked Vermin Hackers Target Ukraine With New Malware Strain

Ukrainian Bank’s Service for Military Donations Targeted by ‘Massive’ DDoS Attack

The Pentagon Is Planning a Drone ‘Hellscape’ to Defend Taiwan

Researchers Uncover New Infrastructure Tied to FIN7 Cybercrime Group

Columbus Officials Warn Victims, Witnesses After Ransomware Leak of Prosecutor Files

Human Nature Is Causing Our Cybersecurity Problem

Toyota Confirms Breach After Stolen Data Leaks on Hacking Forum

FlightAware Configuration Error Leaked User Data for Years

Cybercriminals Siphon Credit Card Numbers From Oregon Zoo Website

Hackers Linked to $14M Holograph Crypto Heist Arrested in Italy

New UULoader Malware Distributes Gh0st RAT and Mimikatz in East Asia

New Tool Xeon Sender Enables Large-Scale SMS Spam Attacks

Cybercriminals Exploit Popular Software Searches to Spread FakeBat Malware

Microsoft Apps for macOS Exposed to Library Injection Attacks

CISA Warns of Jenkins RCE Bug Exploited in Ransomware Attacks

Microsoft Patches Zero-Day Flaw Exploited by North Korea’s Lazarus Group

8/16-18/2024

OpenAI Says Iran Tried to Influence U.S. Elections With ChatGPT

Geopolitical Tensions Drive Explosion in DDoS Attacks

Krebs: NationalPublicData.com Hack Exposes a Nation’s Data

Why Are Organizations Losing the Ransomware Battle?

How the CrowdStrike Tech Outage Reignited a Battle Over the Heart of Microsoft Systems

Chrome Will Redact Credit Cards, Passwords When You Share Android Screen

How Safe Am I Online?—and Other Questions Readers Asked About Cybersecurity

Microsoft Mandates MFA for All Azure Sign-Ins

Azure Domains and Google Abused to Spread Disinformation and Malware

Geofence Warrants Ruled Unconstitutional—but That’s Not the End of It

Unicoin Hints at Potential Data Meddling After G-Suite Compromise

Ransomware Attack on Flint (MI) Affecting City Services as FBI Investigates Incident

North Miami (FL) Works to Restore Services After Cyber Attack

Ransomware Attack on Indian Payment System Traced Back to Jenkins Bug

Russian Hackers Using Fake Brand Sites to Spread DanaBot and StealC Malware

New Mad Liberator Gang Uses Fake Windows Update Screen to Hide Data Theft

New Banshee Stealer Targets 100+ Browser Extensions on Apple macOS Systems

Attackers Exploit Public .env Files to Breach Cloud Accounts in Extortion Campaign

CISA Warns Critical SolarWinds RCE Bug is Exploited in Attacks

8/15/2024

U.S. Lawmakers Urge Probe of WiFi Router Maker TP-Link Over Fears of Chinese Cyber Attacks

Russia’s FSB Behind Massive Phishing Espionage Campaign

New Cyber Threat Targets Azerbaijan and Israel Diplomats, Stealing Sensitive Data

Meta Warns of Troll Networks From Russia, Iran Ahead of U.S. Elections

Inside the $93 Million Wall Street Heist That Stemmed From Russia

Pakistan’s Internet Firewall Could Cost Economy $300 Million, Association Says

Ransomware Gangs Rake in More Than $450 Million in First Half of 2024

T-Mobile Fined $60 Million to Settle Alleged National Security Violations

Hearing about Leaked Social Security Numbers? Don’t Panic

Cyber-Criminals Exploited Paris Olympics With Fake Domains

Fraser Child and Family Center (MN) Notifies 67k of Recent Data Breach

Advanced ValleyRAT Campaign Hits Windows Users in China

RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks

New Gafgyt Botnet Variant Targets Weak SSH Passwords for GPU Crypto Mining

Google Pixel Phones Sold With Security Vulnerability, Report Finds

Microsoft Disables Recent BitLocker Security Fix, Advises Manual Mitigation

Microsoft Removes FAT32 Partition Size Limit in Windows 11

8/14/2024

Russia’s Critics Targeted With Global Hacking Campaign, Rights Group Says

China-Backed Earth Baku Expands Cyber Attacks to Europe, Middle East, and Africa

APT42: A Single Iranian Hacker Group Targeted Both Presidential Campaigns, Google Says

Large-Scale Cyber Attack Cripples Iranian Banks

DDoS Attacks Surge 46% in First Half of 2024, Gcore Report Reveals

NIST Releases First Encryption Tools to Resist Quantum Computing

The Weirdest ‘3 Billion People’ Data Breach Ever

German Cyber Agency Wants Changes in Microsoft, CrowdStrike Products After Tech Outage

Texas Sues GM for Selling Driver Data to Analytics, Insurance Companies

Russian Who Sold 300,000 Stolen Credentials Gets 40 Months in Prison

AutoCanada Discloses Cyberattack Impacting Internal IT Systems

Copiah-Lincoln Community College (MS) Data Breach Affects 53,628 People

Cyber-Attack Spreads Phishing Scam Across Greater Manchester Areas

New Phishing Attack Uses Sophisticated Infostealer Malware

Black Basta-Linked Attackers Target Users with SystemBC Malware

GitHub Actions Artifacts Found Leaking Auth Tokens in Popular Projects

High-End Racing Bikes Are Now Vulnerable to Hacking

Your Gym Locker May Be Hackable

Zero-Click Windows TCP/IP RCE Impacts All Systems with IPv6 Enabled, Patch Now

SolarWinds Fixes Critical RCE Bug Affecting all Web Help Desk Versions

8/13/2024

FBI Probing Alleged Iran Hack Attempts Targeting Trump, Biden Camps

Suspected Iranian Hackers Breached Roger Stone’s Personal Email as Part of Effort to Target Trump Campaign

News Outlets Were Leaked Insider Material From the Trump Campaign. They Chose Not to Print It Yet

Musk Claims X Hit by ‘Massive DDoS Attack’ During Trump Interview

Russia Is Pushing Disinformation About Kursk Operation, Ukrainian Officials Say

What We Learned From the Cyberattack on Change Healthcare

Google Says It’s Focusing on Privacy With Gemini AI on Android

Companies Prepare to Fight Quantum Hackers


X Faces GDPR Complaints for Unauthorized Use of Data for AI Training

Prolific Belarusian Cybercriminal Arrested in Spain

CrowdStrike Tries to Patch Things Up With Cybersecurity Industry
3AM Ransomware Stole Data of 464,000 Kootenai Health Patients

Leading Carbon Black Industrial Supplier Orion Loses $60 Million in Business Email Compromise Scam

Gadsden Independent School District (NM) Hit by Ransomware Attack

Roseland Community Hospital (IL) Provides Notice of June 2024 Data Breach

GhostWrite: New T-Head CPU Bugs Expose Devices to Unrestricted Attacks

Ivanti Warns of Critical vTM Auth Bypass with Public Exploit

Researchers Uncover Vulnerabilities in AI-Powered Azure Health Bot Service

Critical SAP Flaw Allows Remote Attackers to Bypass Authentication

Krebs: Six 0-Days Lead Microsoft’s August 2024 Patch Push

New Windows SmartScreen Bypass Exploited as Zero-Day Since March

8/12/2024

South Korea Says DPRK Hackers Stole Spy Plane Technical Data

Hackers Posing as Ukraine’s Security Service Infect 100 Gov’t PCs

UN Adopts Controversial Cybercrime Treaty
DARPA Awards $14m to Seven Teams in AI Cyber Challenge

CrowdStrike Accepted a ‘Most Epic Fail’ Award at Def Con Hacking Conference

FBI Disrupts the Dispossessor Ransomware Operation, Seizes Servers

Co-Founder of DDoSecrets Was Dark Web Drug Kingpin Thomas White of Silk Road 2.0

Man in Dock Accused of Breaking Hi-Tech Export Controls

As He Retires After Two Decades at Homeland Security, Brandon Wales Reflects on CISA’s Future
Australian Gold Producer Evolution Mining Hit by Ransomware

Swiss Manufacturer Schlatter Group Investigating Ransomware Attack That Shut Down IT Network

Baxter International (IL) Notifies Consumers of June 2024 Data Breach

Attacker Steals Personal Data of 200K+ People With Links to Arizona Tech School

Vulnerability in Windows Driver Leads to System Crashes

Industrial Remote Access Tool Ewon Cosy+ Vulnerable to Root Access Attacks

Researchers Uncover Vulnerabilities in Solarman and Deye Solar Systems

FreeBSD Releases Urgent Patch for High-Severity OpenSSH Vulnerability

Tackling Vulnerabilities & Errors Head-on for Proactive Security

8/9-11/2024

Trump Campaign Says Its Internal Messages Hacked by Iran

Iran Targeting U.S. Elections Using Fake News, Cyberattacks: Microsoft

Chinese Hacking Groups Target Russian Government, IT Firms

Russians Team up With Young, English-Speaking Hackers for Cyberattacks

Russia Blocks Signal for ‘Violating’ Anti-Terrorism Laws

Fake X Content Warnings on Ukraine War, Earthquakes Used as Clickbait

Thousands of Corporate Secrets Were Left Exposed. This Guy Found Them All

Apple Prototypes and Corporate Secrets Are for Sale Online—If You Know Where to Look

The Hacker Who Hunts Video Game Speedrunning Cheaters

GPS Spoofers ‘Hack Time’ on Commercial Airlines, Researchers Say

ATM Software Flaws Left Piles of Cash for Anyone Who Knew to Look

Cyber Companies Report Mixed Results as Security Budgets Prove Challenging

OpenAI Leadership Split Over In-House AI Watermarking Technology

How a Cybersecurity Researcher Befriended, Then Doxed, the Leader of LockBit Ransomware Gang
CSC ServiceWorks Discloses Data Breach After 2023 Cyberattack

Hackers Leak 2.7 Billion Data Records With Social Security Numbers

Ohio School Boards Association Suffers From a Cyber Attack

Local Gov’ts in Texas, Florida Hit with Ransomware as Cyber Leaders Question Best Path Forward

New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions

Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration Tools

Rogue PyPI Library Solana Users, Steals Blockchain Wallet Keys

Sonos Speaker Flaws Could Have Let Remote Hackers Eavesdrop on Users

Experts Uncover Severe AWS Flaws Leading to RCE, Data Theft, and Full-Service Takeovers

Hackers Leak 2.7 Billion Data Records With Social Security Numbers

Microsoft Reveals Four OpenVPN Flaws Leading to Potential RCE and LPE

New AMD SinkClose Flaw Helps Install Nearly Undetectable Malware

Google Researchers Found Nearly a Dozen Flaws in Popular Qualcomm Software for Mobile GPUs

8/8/2024

Russian Spies Hacked UK Government Systems Earlier This Year, Stole Data and Emails

U.S. Elections Have Never Been More Secure, Says CISA Chief

U.S. ‘Laptop Farm’ Man Accused of Outsourcing His IT Jobs to North Korea to Fund Weapons Programs

Tricky Web Timing Attacks Are Getting Easier to Use—and Abuse

Watch How a Hacker’s Infrared Laser Can Spy on Your Laptop’s Keystrokes

Microsoft’s AI Can Be Turned Into an Automated Phishing Machine

Krebs: Cybercrime Rapper Sues Bank over Fraud Investigation

SEC Investigation into Progress MOVEit Hack Ends Without Charges

USPS Text Scammers Duped His Wife, So He Hacked Their Operation

Delta Shrugs Off Criticism, Says Damages Caused by CrowdStrike Outage Total at Least $500 Million

Cybersecurity Firm Trend Micro Explores Sale, Sources Say
ADT Admits Security Breach After Hackers Advertise Stolen Data on the Dark Web

Hackers Return $12 Million Taken During Ronin Network Breach

Russia’s Kursk Region Suffers ‘Massive’ DDoS Attack Amid Ukraine Offensive

North Korea Kimsuky Launch Phishing Attacks on Universities

Phishing Attack Exploits Google, WhatsApp to Steal Data

Cisco Warns of Critical RCE Zero-Days in End of Life IP Phones

Exploit Released For Cisco SSM Bug Allowing Admin Password Changes

CISA Warns of Hackers Abusing Cisco Smart Install Feature

CISA Warns About Actively Exploited Apache OFBiz RCE Flaw

Hackers Have Exploited An 18-Year-Old ‘0.0.0.0-Day’ Loophole In Safari, Chrome And Firefox

8/7/2024

A Flaw in Windows Update Opens the Door to Zombie Exploits

Microsoft 365 Anti-Phishing Feature Can Be Bypassed With CSS

CrowdStrike Blames Test Software for Taking Down 8.5 Million Windows Machines

Delta Passengers Sue Airline for Refusing Refunds After Massive Computer Outage

Ireland’s DPC Takes Twitter to Court Over AI User Data Concerns

The Business World Is Obsessed With AI but Company Leaders Ignore Cybersecurity at Their Peril

UK IT Provider Faces $7.7 Million Fine for 2022 Ransomware Breach

Google Chrome Will Let You Send Money to Your Favourite Website

Knostic Wins 2024 Black Hat Startup Spotlight Competition
Port of Tyne Website Hit by Cyber Attack

McLaren Hospitals Disruption Linked to Inc Ransomware Attack

New CMoon USB Worm Targets Russians in Data Theft Attacks

New Go-based Backdoor GoGra Targets South Asian Media Organization

Royal Ransomware Successor BlackSuit Has Demanded More Than $500 Million

Chameleon Android Banking Trojan Targets Users Through Fake CRM App

Critical Progress WhatsUp RCE Flaw Now Under Active Exploitation

Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords

Apple’s New macOS Sequoia Tightens Gatekeeper Controls to Block Unauthorized Software

8/6/2024

Cyberattack and Tropical Storm Debby Disrupt Blood Supply

A New Plan to Break the Cycle of Destructive Critical Infrastructure Hacks

Microsoft Says Delta Ignored Satya Nadella’s Offer of CrowdStrike Help

Google Violated U.S. Antitrust Laws to Maintain Dominance Over Online Search, Judge Says

How Google’s Huge Defeat in Antitrust Case Could Change How You Search the Internet

What Google’s Antitrust Defeat Means for the Search Giant and Its Partner Apple

A Microsoft Victory and Mozilla Defeat: The Fallout From Google’s Antitrust Saga

Abnormal Security, Valued at $5.1 Billion Amid Email Security Push, Eyes Eventual IPO

Police Recover Over $40m Headed to BEC Scammers
Nearly 40 French Museums Hit By Ransomware Attack

Mobile Guardian Hack Leads to 13,000 Student Devices Wiped in Singapore

Sumter County (FL) Sheriff’s Office Hit by Ransomware Attack

Northwest Arkansas Community College Delays Fall Classes After Ransomware Attack

Ronin Bridge Paused, Restarted After $12M Drained in Whitehat Hack

Krebs: Low-Drama ‘Dark Angels’ Reap Record Ransoms

North Korean Hackers Moonstone Sleet Push Malicious JS Packages to npm Registry

Samsung to Pay $1,000,000 for Rces on Galaxy’s Secure Vault

Proton VPN Adds ‘Discreet Icons’ to Hide App on Android Devices

8/5/2024

North Korean Hackers Exploit VPN Update Flaw to Install Malware

CrowdStrike Is Sued by Fliers After Massive Outage Disrupts Air Travel

CrowdStrike Says It’s Not to Blame for Delta’s Days-Long Outage

CrowdStrike: Delta Air Lines Refused Free Help to Resolve IT Outage

Companies Sue Tech Firms After Outages, but It’s an Uphill Battle

Every Microsoft Employee Is Now Being Judged on Their Security Work

Hacked, Scammed, Exposed: Why You’re One Step Away From A Major Disaster Online

TikTok Withdraws Lite Rewards Program from EU Over Child Safety Fears

China Starts Testing National Cyber-ID Before Consultation on the Idea Closes

Replacement for Action Fraud, Uk’s Cybercrime Reporting Service, Delayed Again Until 2025

Singapore Police Wrest Back $41 Million Stolen From Commodities Firm in Bec Scam
New Android Trojan “BlankBot” Targets Turkish Users’ Financial Data

Kazakh Organizations Targeted by ‘Bloody Wolf’ Cyber Attacks

Keytronic Reports Losses of Over $17 Million After Ransomware Attack

Calibrated Healthcare (CA) Notifies Healthcare Patients of Recent Data Breach

Hunters International Ransomware Targets IT Workers With New SharpRhino Malware

New LianSpy Malware Hides by Blocking Android Security Feature

Sneaky SnakeKeylogger Slithers Into Windows Inboxes to Steal Sensitive Secrets

Researchers Uncover Flaws in Windows Smart App Control and SmartScreen

Critical Flaw in Rockwell Automation Devices Allows Unauthorized Access

Critical Vulnerability in Apache OFBiz Requires Immediate Patching

Google Fixes Android Kernel Zero-Day Exploited in Targeted Attacks

8/2-4/2024

APT28 Targets Diplomats with HeadLace Malware via Car Sale Phishing Lure

Sensitive Illinois Voter Data Exposed by Contractor’s Unsecured Databases

Social Media Firms Fail to Protect Children’s Privacy, Says UK ICO

Krebs: U.S. Trades Cybercriminals to Russia in Prisoner Swap

Who Ya’ Gonna Call? Why IoT Companies Should Embrace Vulnerability Disclosure Programs

Why the Market’s Most-Regulated Companies Need Military-Grade Cybersecurity

U.S. Expected to Propose Barring Chinese Software in Autonomous Vehicles

Five Chinese Nationals Arrested by Feds for ‘Massive’ Elder Fraud Scheme

Cryptonator Seized for Laundering Ransom Payments, Stolen Crypto

DuckDuckGo Blocked in Indonesia Over Porn, Gambling Search Results
Israeli Hacktivist Group ‘WeRedEvils’ Brags It Took Down Iran’s Internet

‘StormBamboo’ Hackers Breach ISP to Poison Software Updates With Malware

Hackers Directly Email Customers of Immigration Firm After Damaging Cyberattack

Fake AI Editor Ads on Facebook Push Password-Stealing Malware

Surge in Magniber Ransomware Attacks Impact Home Users Worldwide

Hackers Exploit Misconfigured Jupyter Notebooks with Repurposed Minecraft DDoS Tool

Mirai Botnet targeting OFBiz Servers Vulnerable to Directory Traversal

New Windows Backdoor BITSLOTH Exploits BITS for Stealthy Communication

Linux Kernel Impacted by New Slubstick Cross-Cache Attack

Legendary Rom Hacking Site RomHacking.net Shutting Down After Almost 20 Years

8/1/2024

U.S. Releases Russian Hackers and Spies as Part of Prisoner Swap That Includes Evan Gershkovich & Paul Whelan 

Putin’s Trader: How Russian Hackers Stole Millions From U.S. Investors

A $500 Open Source Tool Lets Anyone Hack Computer Chips With Lasers

Delta CEO: ‘When Was the Last Time You Heard of a Big Outage at Apple?

CISA Names Lisa Einstein as Its First Chief AI Officer

He Was an FBI Informant—and Inspired a Generation of Violent Extremists

Scam Platform Shut Down by UK Authorities After 1.8 Million Fraudulent Calls

Tech Support Scam Ring Leader Gets 7 Years in Prison, $6M Fine

Australian Companies Will Soon Need to Report Ransom Payments
Taiwan Government-Backed Research Organization Targeted by APT41 Hackers

Cencora Confirms Patient Data Stolen in Cyber-Attack

Rhysida Ransomware Group Takes Credit for Columbus Cyberattack, Auctions Stolen Data

Hennepin County (MN) Sheriff’s Office Is Responding to Data Breach

FBI Warns of Scammers Posing as Crypto Exchange Employees

RansomEXX Group Targets Indian Banking With New Tactics

Hackers Distributing Malicious Python Packages via Popular Developer Q&A Platform Stack Exchange

Hackers Abuse Free TryCloudflare to Deliver Remote Access Malware

Twilio Kills off Authy for Desktop, Forcibly Logs Out All Users