9/30/2024

Watch Out for Hurricane Helene Donation Scams

UK and U.S. Warn of Growing Iranian Spear Phishing Threat

U.S. Sets New Rule That Could Spur AI Chip Shipments to the Middle East

U.S. State CISOs Struggling With Insufficient Cybersecurity Funding

Systems Used by Courts and Governments Across the U.S. Riddled With Vulnerabilities

The Pig Butchering Invasion Has Begun

U.S. Reaches $31.5 Million Settlement With T-Mobile Over Data Breaches

Man Charged for Selling Forged License Keys for Network Switches

Remote ID Verification Tech Is Often Biased, Bungling, and No Good on Its Own

Media Giant AFP Hit by Cyberattack Impacting News Delivery Services

CF Medical Data Breach Stems from Incident at Financial Business and Consumer Solutions

Verizon Outage Impacts 100,000 Plus Users Across U.S.

Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware

Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks

Critical RCE Vulnerabilities Found in Common Unix Printing System

Microsoft Defender Adds Detection of Unsecure Wi-Fi Networks

JPCERT Shares Windows Event Log Tips to Detect Ransomware Attacks

Here’s What to Expect From the Counter Ransomware Initiative Meeting This Week

9/27-29/2024

As Hezbollah Threat Loomed, Israel Built up Its Spy Agencies

Pentagon Gives Thumbs-Down to Cyber Service Proposal in Defense Bills

Tesla’s Cybertruck Goes, Inevitably, to War

Governments Urge Improved Security and Resilience for Undersea Cables

Why It’s Time to Take Warnings About Using Public Wi-Fi, in Places Like Airports, Seriously

Watch: Can BBC Reporter’s AI Clone Fool His Colleagues?

How Pen and Paper Comes to the Rescue in an IT Crisis

The U.S. Government Wants to Cut out Some of Its Weirdest Password Rules

Irish Data Protection Commission Fines Meta $102 Million for Storing Passwords in Plain Text

UK National Hacked Public Companies for Stock Trading Intel, DOJ Says

All Dutch Police Officers’ Contact Details Stolen in Cyberattack

Richmond Community Schools (IN) Suffers Ransomware Attack

Ransomware Attack Continues at UMC Hospital in Lubbock (TX)

Amgen (CA) Announces Third-party Data Breach from Incident at Sirva Relocation

Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks

New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users

Progress Urges Admins to Patch Critical Whatsup Gold Bugs ASAP

Microsoft: Windows Recall Now Can Be Removed, Is More Secure

How Should CISOs Navigate the SEC Cybersecurity and Disclosure Rules?

Red Team Hacker on How She ‘Breaks Into Buildings and Pretends to Be the Bad Guy’

9/26/2024

Hurricane Helene Prompts CISA Fraud Warning

Russia-Backed Gamaredon Still ‘Most Engaged’ Hacker Group in Ukraine

N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks

Cloudflare Warns of India-Linked Hackers Targeting South and East Asian Entities

Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware

Israeli Military Chief Says Troops Are Preparing for Ground War in Lebanon

Amid Air Strikes and Rockets, an SMS From the Enemy

Fears of Weakness in Water Cybersecurity Grow After Kansas Attack

Iranians Indicted in Connection With Trump Campaign Hack

Krebs: U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex

York Mayor Eric Adams Is Indicted After Years-Long Federal Corruption Investigation Into Bribery and Fraud

Told FBI He Forgot His Phone’s Passcode

Don’t Ever Hand Your Phone to the Cops

Over a Third of Employees Secretly Sharing Work Info with AI

NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines

Chicago Stops Using Controversial ShotSpotter Gunshot Detection System

Kuwait Health Ministry Restoring Systems After Cyberattack Takes Down Hospitals, Healthcare App

Data Breach at MC2 Data Leaves 100 Million at Risk of Fraud

58K Patients Have Health Info Possibly Exposed in Michigan Medicine Breach

Ross, Anglim, Angelini & Co. (NJ) Breach Compromises an Unknown Number of Social Security Numbers

Cybercriminals Hack UK Rail Network Wi-Fi

Man Arrested After ‘Islamophobic’ Cyber Attack Hits London Stations Wi-Fi

MoneyGram Services Restored but Questions Remain About Cyber Incident

Richardson (TX) Working With FBI to Address Attempted Ransomware Attack

First Mobile Crypto Drainer ‘WalletConnect’ Found on Google Play

Malicious Ads Hide Infostealer in League of Legends ‘Download’

Automattic Blocks WP Engine’s Access to WordPress Resources

CUPS Flaws Enable Linux Remote Code Execution, but There’s a Catch

Millions of Kia Vehicles Could Be Hacked and Tracked Due to a Simple Website Bug

Patch Now: Critical Nvidia Bug Allows Container Escape, Complete Host Takeover

HPE Patches Three Critical Security Holes in Aruba Papi

Tails OS Merges With Tor Project for Better Privacy, Security

9/25/2024

China-Linked Hackers Breach U.S. Internet Providers in New ‘Salt Typhoon’ Cyberattack

U.S. House Bill Addresses Growing Threat of Chinese Cyber Actors

Biden Meets Vietnam Leader to Counter Hanoi’s Ties With China and Russia

Donald Trump Briefed on Suspected Iranian Assassination Plot

OpenAI Chief Technology Officer Mira Murati Says She’s Leaving Artificial Intelligence Company

OpenAI to Become For-Profit Company

Google Paid $2.7 Billion to Bring Back an AI Genius Who Quit in Frustration

Surging AI Demand Could Cause the World’s Next Chip Shortage, Research Says

How Apple and Microsoft’s Trusted Brands Are Being Used to Scam You Online

82% of Phishing Sites Now Target Mobile Devices

Caroline Ellison, Former FTX Executive, Sentenced to 24 Months in Prison

Krebs: Timeshare Owner? The Mexican Drug Cartels Want You

China Claims Taiwan, Not Civilians, Behind Web Vandalism

RansomHub Genius Tries to Put the Squeeze on Delaware Libraries

Modified LockBit and Conti Ransomware Shows up in DragonForce Gang’s Attacks

Transportation Companies Hit by Cyberattacks Using Lumma Stealer and NetSupport Malware

CISA: Hackers Target Industrial Systems Using “Unsophisticated Methods”

Study Finds Many European Car Resellers Fail to Delete Driver Data

Connecting Your Phone to Rental Car Infotainment System? There Is a Big, Hidden Privacy Risk

Pwn2Own Auto Offers $500K for Tesla Hacks

ChatGPT macOS Flaw Could’ve Enabled Long-Term Spyware via Memory Function

Google’s Shift to Rust Programming Cuts Android Memory Vulnerabilities by 52%

Google Sees 68% Drop in Android Memory Safety Flaws Over 5 Years

Mozilla Faces Privacy Complaint for Enabling Tracking in Firefox Without User Consent

9/24/2024

Sweden Accuses Iran of Hacking Text Messaging Service Last Year After Public Koran Burnings

Trump Campaign’s Suspected Iranian Hack May Still Be Happening

U.S. Capitol Hit by Massive Dark Web Cyber Attack: Reports

State Department Cyber Bureau Preps Funding Blitz Aimed at Boosting Allies’ Defenses

Russia-Backed Media Outlets Are Under Fire in the U.S.—but Still Trusted Worldwide

TikTok Blocks Dozens of Kremlin-Backed Media Accounts

How to Spot a North Korean Agent Before They Get Comfy Inside Payroll

Threat Actors Shift to JavaScript-Based Phishing Attacks

Hackers Deploy AI-Written Malware in Targeted Attacks

CrowdStrike Boss Apologises for Global IT Outage

Cybersecurity Incident Affects Arkansas City Water Treatment Facility

The Centers for Medicare & Medicaid Services Says Data Breach Impacted 3.1 Million People

Twilio Purportedly Breached, Nearly 12K Call Records Compromised

AutoCanada Says Ransomware Attack “May” Impact Employee Data

One Point HR Solutions (OH) Data Breach Affects an Unknown Number of Consumers

RomCom Malware Resurfaces With SnipBot Variant

New Octo2 Malware Variant Threatens Mobile Banking Security

Infostealer Malware Bypasses Chrome’s New Cookie-Theft Defenses

Critical Ivanti vTM Auth Bypass Bug Now Exploited in Attacks

9/23/2024

Dozens of Fortune 100 Companies Have Unwittingly Hired North Korean IT Workers, According to Report

U.S. Intelligence Agencies Confirm Russia Is Pushing Fake Videos of Kamala Harris

Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware

Russian Cyber-Attacks Home in on Ukraine’s Military Infrastructure

U.S. Proposes Ban on Chinese, Russian Connected Car Tech Over Security Fears

Microsoft’s Largest Ever Security Transformation Detailed in New Report

Why ‘Never Expire’ Passwords Can Be a Risky Decision

UPS Supplier’s Password Policy Flip-Flops From Unlimited, to 32, Then 64 Characters

Telegram Will Now Hand Over Your Phone Number and IP if You’re a Criminal Suspect

Kaspersky Deletes Itself, Installs UltraAV Antivirus Without Warning

Israeli Tech Sector Resilient but Faces Funding Uncertainty Amid Ongoing War With Hamas Group

How Apple, Google, and Microsoft Can Save Us From AI Deepfakes

Hezbollah Likely to Launch Retaliatory Cyberattack on Israel, Expert Says

Alaska Airlines Reports IT Outage, Disruption in Seattle

‘Cybersecurity Issue’ Takes MoneyGram Offline for Three Days – And Counting

Tewkesbury Borough Council: Cyber Incident ‘Was an Accident – Not an Attack’

Ransomware Attack on Franklin County (KS) Exposed Sensitive Info of Nearly 30,000 Residents

Kryptina Ransomware Resurfaces in Enterprise Attacks By Mallox

Android Malware ‘Necro’ Infects 11 Million Devices via Google Play

New PondRAT Malware Hidden in Python Packages Targets Software Developers

Move Over, Cobalt Strike. Splinter’s the New Post-Exploit Menace in Town

Vulnerabilities Found in Popular Houzez Theme and Plugin

Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk

Gavin Newsom Vetoes Legislation to Mandate Universal Data Privacy Opt-Outs in California

9/20-22/2024

Ukraine Bans Telegram Use for Government and Military Personnel

Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber Attacks

Court Finds Former German Cyber Chief Was Falsely Accused of Associating With Russian Spies

U.S. Cyberspace Solarium Commission Outlines Ten New Cyber Policy Priorities

Cyber Leaders Struggle to Fill AI Security Jobs

Cybersecurity Skills Gap Leaves Cloud Environments Vulnerable

CISA Boss: Makers of Insecure Software Are the Real Cyber Villains

Companies Face Risk of Huge Fines and Suspensions Under Tough New Cyber Rules in the EU

U.S. Indicts Two, Including One Florida Man, Over Socially Engineered $230M+ Crypto Heist

Clickbaity or Genius? ‘BF Cheated on You’ QR Codes Pop up Across UK

LinkedIn Halts AI Data Processing in UK Amid Privacy Concerns Raised by ICO

Federal Civil Rights Watchdog Sounds Alarm Over DOJ, DHS, and HUD Use of Facial Recognition Technology

Hacker Uses Telegram Chatbots to Leak Data of Top Indian Insurer Star Health

Dell Investigates Data Breach Claims After Hacker Leaks Employee Info

Wells Fargo Clearing Services Notifies Consumers of Recent Data Breach

More Than $44 Million in Cryptocurrency Stolen From Singaporean Platform BingX

Cybercrooks Strut Away With Haute Couture Harvey Nichols Data

Schools Across Lancashire Threatened by Hackers in Cyber Attack

Valencia Ransomware Explodes on the Scene, Claims California City, Fashion Giant, More as Victims

Global ‘Marko Polo’ Infostealer Malware Operation Targets Crypto Users, Gamers

CISA Warns of Actively Exploited Apache HugeGraph-Server Bug

Researcher Reveals ‘Catastrophic’ Security Flaw in the Arc Browser

Windows Server 2025 Previews Security Updates Without Restarts

macOS Sequoia Change Breaks Networking for VPN, Antivirus Software

9/19/2024

First Israel’s Exploding Pagers Maimed and Killed. Now Comes the Paranoia

Your Phone Won’t Be the Next Exploding Pager

Iran Backdoors Planted Across Middle East Telecoms, Government Agencies, Google Says

Long Island County Hack Probe Details History of Cyber Failures

Disney to Stop Using Slack Following Hack That Exposed Company Data

Insecure APIs and Bot Attacks Cost Global Firms $186bn

1 in 10 Orgs Dumping Their Security Vendors After CrowdStrike Outage

Infostealers Cause Surge in Ransomware Attacks, Just One in Three Recover Data

Californians Can Now Add Their Driver’s Licenses to Apple Wallet

No Way? Big Tech’s Endless ‘Lucrative Surveillance’ of Everyone Is Terrible for Privacy, Freedom

Tor Says It’s “Still Safe” Amid Reports of Police Deanonymizing Users

Germany Seizes 47 Crypto Exchanges Used by Ransomware Gangs

Police Dismantles Phone Unlocking Ring Linked to 483,000 Victims

8,000 Claimants Sue Outsourcing Giant Capita Over 2023 Data Breach

Indonesia’s Tax Agency Probes Alleged Personal Data Breach

Altman Plants Notifies Thousands of Data Breach Involving Their SSNs and Medical Information

Elitecare Emergency Room (TX) Notifies Patients of July 2024 Data Breach

Tewkesbury Borough Council in Gloucestershire IT Systems Deemed ‘Safe’ After Cyber Attack

Hackers Exploit Default Credentials in FOUNDATION Software to Breach Construction Firms

Cryptojacking Gang TeamTNT Makes a Comeback

New Brazilian-Linked SambaSpy Malware Targets Italian Users via Phishing Emails

Clever ‘GitHub Scanner’ Campaign Abusing Repos to Push Malware

Krebs: This Windows PowerShell Phish Has Scary Potential

1 PoC Exploit for Critical RCE Flaw, but 2 Patches From Veeam

Ivanti Warns of Another Critical CSA Flaw Exploited in Attacks

Apple’s New macOS Sequoia Update Is Breaking Some Cybersecurity Tools

Google Password Manager Now Automatically Syncs Your Passkeys

Unexplained ‘Noise Storms’ Flood the Internet, Puzzle Experts

9/18/2024

Hezbollah Devices Explode Again in Lebanon, Raising Fears of Wider Israel Conflict

Walkie-Talkies This Time

Solar Panels and Fingerprint Recognition Devices Used by Hezbollah Fighters

Hezbollah Pager Attack Puts Spotlight on Israel’s Cyber Warfare Unit 8200

Supply-Chain Interference

Europol Taskforce Disrupts ‘Ghost’ Global Criminal Network Through Supply Chain Attack

Germany Seizes Leak Site of ‘Vanir’ Ransomware Operation

Flax Typhoon: U.S. FBI Disrupts Second Chinese Hacking Group, Director Says

Did a Chinese University Hacking Competition Target a Real Victim?

U.S. Says Iran Tried to Influence Election With Messages to Biden Camp With Stolen Info From Trump Campaign

Critical Infrastructure at Risk From Email Security Breaches

DOJ, FBI Need Better Metrics for Tracking Ransomware Disruption Efforts, Audit Finds

Russian Security Firm Dr.Web Disconnects All Servers After Breach

Deja Blues… Ransomware Group LockBit Boasts Once Again of Ransoming IRS-Authorized eFile.com

North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Microsoft: Vanilla Tempest Hackers Hit Healthcare With INC Ransomware

X Hacking Spree Fuels “$HACKED” Crypto Token Pump-and-Dump

QR Phishing Scams Gain Motorized Momentum in UK

Krebs: Scam ‘Funeral Streaming’ Groups Thrive on Facebook

Google Street View Images Used For Extortion Scams

GitLab Releases Fix for Critical SAML Authentication Bypass Flaw

Discord Rolls Out End-To-End Encryption for Audio, Video Calls

9/17/2024

Hezbollah Pagers Explode in Apparent Attack Across Lebanon

4,000 Injured, 11 Dead

The Mystery of Hezbollah’s Deadly Exploding Pagers

Hezbollah Vows to Punish Israel After Pager Explosions Across Lebanon

U.S. Looks to Align Security Across Government

CISA Urges Software Devs to Weed out XSS Vulnerabilities

Cyberattacks Plague Health Care. Critics Call the Federal Response ‘Inadequate’

Over Half of Breached UK Firms Pay Ransom

Most Cyber Leaders Fear AI-Generated Code Will Increase Security Risks

AT&T Pays $13 Million FCC Settlement Over 2023 Data Breach

Chinese National Accused by Feds of Spear-Phishing for NASA, Military Source Code

Meta Blocks RT and Other Russian State Media; Kremlin Says It’s ‘Unacceptable’

Pro-Ukraine Hackers Claim Attack on Agency That Certifies Digital Signatures in Russia

Temu Denies Breach After Hacker Claims Theft of 87 Million Data Records

Over 1,000 ServiceNow Instances Found Leaking Corporate KB Data

Construction Firms Breached in Brute Force Attacks on Accounting Software

Aramark myPay Data Breach Affects an Unknown Number of Employees

Binance Warns of Rising Clipper Malware Attacks Targeting Cryptocurrency Users

Marko Polo Cybercrime Gang Targets Cryptocurrency Users, Influencers With Scams

Ransomware Gangs Now Abuse Microsoft Azure Tool for Data Theft

PKfail Secure Boot Bypass Remains a Significant Risk Two Months Later

SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks

VMware Patches Remote Make-Me-Root Holes in vCenter Server, Cloud Foundation

9/16/2024

Cybersecurity & the 2024 U.S. Elections

White House to Tackle AI-Generated Sexual Abuse Images

CISA Warns of Windows Flaw Used in Infostealer Malware Attacks

Cybercriminals Exploit HTTP Headers for Credential Theft via Large-Scale Phishing Attacks

Advanced Phishing Attacks Put X Accounts at Risk

Snowflake Slams ‘More MFA’ Button Again – Months After Ticketmaster, Santander Breaches

Half of UK Firms Lack Basic Cybersecurity Skills

Tech Firm CACI Beefs up Defense Business With $1.28 Bln Azure Summit Deal

Chrome Switching to NIST-Approved ML-KEM Quantum Encryption to Protect Against Quantum TLS Attacks

U.S. Cracks Down on Spyware Vendor Intellexa With More Sanctions

Feds Sentence 12 Crypto Thieves, Including a Florida Man, Behind SIM Swaps, Home Invasions

Pacific Islands Forum Investigating Cyberattack on Networks by Reported China State Actors

Only U.S. Platinum Mine Stillwater Mining Company Confirms Data Breach After Ransomware Claims

Data on Nearly 1 Million NHS Patients Leaked Online Following Ransomware Attack on London Hospitals

German Radio Station Forced to Broadcast ‘Emergency Tape’ Following Cyberattack

The Maids International Notifies Consumers of the January 2024 Data Breach

North Korean Hackers Target Cryptocurrency Users on LinkedIn with RustDoor Malware

Windows Vulnerability Abused Braille “Spaces” in Zero-Day Attacks

Exploit Code Released for Critical Ivanti RCE Flaw, Patch Now

Google Fixes GCP Composer Flaw That Could’ve Led to Remote Code Execution

D-Link Fixes Critical RCE, Hardcoded Password Flaws in WiFi 6 Routers

9/13-15/2024

Malicious Actors Spreading False U.S. Voter Registration Breach Claims

State Dept: Russia’s RT News Agency Has ‘Cyber Operational Capabilities,’ Assists in Military Procurement

How a U.S. Spy Tapped Into Russian Communication Lines

Krebs: The Dark Nexus Between Harm Groups and ‘The Com’

Nightsleeper: Could a Cyber Hack Derail a Train in Real Life?

Hardware Supply Chain Threats Can Undermine Endpoint Infrastructure

Largest Crypto Exchange in Indonesia Indodax Pledges to Reimburse Users After $22 Million Theft

23andMe Agrees to Pay $30 Million to Settle Lawsuit Over Massive Data Breach

Cambodian Senator Sanctioned by U.S. Over Alleged Forced Labor Cyber-Scam Camps

Apple Seeks Dismissal of Its NSO Group Lawsuit, Citing Risk of Exposing ‘Vital Security Information’

Meta to Resume Plans to Harness UK Users’ Social Media Posts for AI Model Training

Feeld Dating App’s Security Too Open-Minded as Private Data Swings Into Public View

Port of Seattle Hit by Rhysida Ransomware in August Attack

RansomHub Claims Kawasaki Cyberattack, Threatens to Leak Stolen Data

Atrium Health Apologizes After Employees Fall For Phishing Attack; Patient Info May Have Been Exposed

Shamrock Trading Corporation Announces May 2024 Data Breach

TfL Requires In-Person Password Resets for 30,000 Employees After Hack

Johnson County Board of Education (TN) Loses $3.4 Million to a Fake Curriculum Vendor

Malware Locks Browser in Kiosk Mode to Steal Google Credentials

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

Ivanti Warns of Active Exploitation of Newly Patched Cloud Appliance Vulnerability

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw

9/12/2024

The U.S. Is Preparing Criminal Charges in Iran Hack Targeting Trump

Chinese-Made Port Cranes in U.S. Included ‘Backdoor’ Modems, House Report Says

Microsoft Is Building New Windows Security Features to Prevent Another CrowdStrike Incident

Apple Vision Pro’s Eye Tracking Exposed What People Type

Hacker Tricks ChatGPT Into Giving Out Detailed Instructions for Making Homemade Bombs

BT Spots 2,000 Potential Attacks on Its Network a Second

Google Chrome Makes It Easier to Opt out of Annoying Notifications on Android

Why Credit Card Fraud Alerts Are Rising, and How Worried You Should Be About Them

Mastercard Bolsters Threat Intelligence Capabilities With $2.65 Billion Deal for Recorded Future

Cyber Intelligence Company Strider Raises $55 Million in Funding

Hospital System to Pay $65 Million for Dark Web Data Leak, Including Images of Nude Cancer Patients

TfL Confirms Customer Data Breach, 17-Year-Old Suspect Arrested

U.S. Sanctions Cambodian Tycoon for Alleged Human Trafficking to Cyber Scam Centers

Fortinet Confirms Data Breach After Hacker Claims to Steal 440GB of Files

I Stole 20GB of Data From Capgemini – And Now I’m Leaking It, Says Cyber-Crook

Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack

Socially Savvy Scattered Spider Traps Cloud Admins in Web

Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking

Beware: New Vo1d Malware Infects 1.3 Million Android TV Boxes Worldwide

New Android Malware ‘Ajina.Banker’ Steals Financial Data and Bypasses 2FA via Telegram

‘Hadooken’ Linux Malware Targets Oracle WebLogic Servers

Hackers Targeting WhatsUp Gold With Public Exploit Since August

Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

Open Source Updates Have 75% Chance of Breaking Apps

Schools Face Million-Dollar Bills as Ransomware Rises

Business Email Compromise Costs $55bn Over a Decade

9/11/2024

Cyberattacks on U.S. Utilities Surged 70% This Year, Says Check Point

UK Designates the Data Center Sector Part of Its ‘Critical National Infrastructure’

Hackers Have Sights Set on Four Microsoft Vulnerabilities, CISA Warns

Operational Technology Leaves Itself Open to Cyber-Attack

WordPress.org to Require 2FA for Plugin Developers by October

Apple Intelligence Promises Better AI Privacy for Personal Information . Here’s How It Actually Works

Poland’s Supreme Court Blocks Pegasus Spyware Probe

Singapore Police Arrest Six Hackers Linked to Global Cybercrime Syndicate

So You Paid a Ransom Demand … and Now the Decryptor Doesn’t Work

How Law Enforcement’s Ransomware Strategies Are Evolving

How $20 and a Lapsed Domain Allowed Security Pros to Undermine Internet Integrity

TD Bank Fined $28 Million for Sharing Inaccurate and Negative Data on Customers

Hunters International Claims Ransom on Chinese Mega-Bank’s London HQ

Japanese Media Giant Kadokawa Investigating Another Reported Data Leak by BlackSuit Hackers

Multiple Popular French Retailers Confirm Hackers Stole Customer Data

NJ Union Reports Cyber Incident May Have Exposed Members’ Private Information

Highline Public Schools Will Reopen Classes — Without Internet — Amid Cyberattack Recovery

Bollinger County (MO) Sheriff Talks About Hack of Facebook Page

Developers Beware: Lazarus Group Uses Fake Coding Tests to Spread Malware

DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe

Major Sales and Ops Overhaul Leads to Much More Activity … For Meow Ransomware Gang

Gallup: Pollster Acts to Close Down Security Threat

Adobe Fixes Acrobat Reader Zero-Day With Public PoC Exploit

Krebs: Bug Left Some Windows PCs Dangerously Unpatched

9/10/2024

Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia

New Portuguese Government to Keep Ban on Chinese 5G Equipment

Thanks, Edward Snowden: You Propelled China to Quantum Networking Leadership

Wix to Block Russian Users Starting September 12

Russia to Spend Over Half a Billion Dollars to Bolster Internet Censorship System

DoJ Distributes 18 and a Half Million Dollars to Western Union Fraud Victims

Crypto Scams Rake in Five and Three-Fifths of a Billion Dollars a Year for Cyberscum Lowlifes, FBI Says

WhatsApp’s ‘View Once’ Could Be ‘View Whenever’ Due To a Flaw

Gallup Poll Bugs Open Door to Election Misinformation

Cyber Staffing Shortages Remain CISOs’ Biggest Challenge

London’s Transit Agency Drops Claim It Has ‘No Evidence’ of Customer Data Theft After Hack

Vista Higher Learning (MA) Data Breach Impacts an Unknown Number of Consumers

CosmicBeetle (aka NoName) Deploys Custom ScRansom Ransomware, Partnering with RansomHub

RansomHub Ransomware Abuses Kaspersky TDSSKiller to Disable EDR Software

New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers

Ivanti Fixes Maximum Severity RCE Bug in Endpoint Management Software

Microsoft September 2024 Patch Tuesday Fixes 4 Zero-Days, 79 Flaws

Microsoft Fixes Windows Smart App Control Zero-Day Exploited Since 2018

Microsoft Fixes Windows Server Performance Issues From August Updates

9/9/2024

Chinese Mustang Panda APT Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

Mustang Panda Use New Data Theft Malware in Gov’t Attacks

TIDRONE Espionage Group Targets Taiwan Drone Makers in Cyber Campaign

German Intelligence Says Russian GRU Group Behind NATO, EU Cyberattacks

Poland Dismantles Cyber Sabotage Group Linked to Russia, Belarus

Russia’s Top-Secret Military Unit Reportedly Plots Undersea Cable ‘Sabotage’

DDoS Attacks Double With Governments Most Targeted

The Bitcoin ATM Has Emerged as One of Cryptocurrency’s Biggest Threats

U.S. Proposes Requiring Reporting for Advanced AI, Cloud Providers

Technology Causes “Digital Entropy” as Firms Struggle With Governance

What You Need to Know about Grok AI and Your Privacy

U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major Attacks

Cyber-Attack on Payment Gateway Slim CD Exposes 1.7 Million Credit Card Details

Data of Nearly 300,000 Exposed in Avis Cyberattack

Highline Public Schools (WA) Closes Schools Following Cyberattack

Ransomware Attack Forces London’s Charles Darwin School to Close and Send Students Home

Kent’s Biggin Hill School Closes Due to Ransomware Attack

Welcome Health (CA) Data Breach Put Confidential Patient Information at Risk

RetailData (VA) Data Breach Affects an Unknown Number of Consumers

Blind Eagle Targets Colombian Insurance Sector with Customized Quasar RAT

Quad7 Botnet Targets More SOHO and VPN Routers, Media Servers

Akira Ransomware Actors Exploit SonicWall Bug for RCE

Meta Fixes Easily Bypassed WhatsApp ‘View Once’ Privacy Feature

Ford Seeks Patent for Tech That Listens to Driver Conversations to Serve Ads

9/6-8/2024

U.S. Financial Markets, Public Companies Are a Growing Target for Russian Hackers

Lawmakers Want U.S. to Address Risks Posed by Chinese Agriculture Drones

Despite Cyberattacks, Water Security Standards Remain a Pipe Dream

Researchers Say a Bug Let Them Add Fake Pilots to Rosters Used for TSA Checks

The NSA Has a Podcast—Here’s How to Decode It

Telegram Changes Its Tone on Moderating Private Chats After CEO’s Arrest

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity

Russian Authorities Able to Identify Train Saboteur Teen From Anonymous Telegram Account

AI, Growing Data Risks Expand the Role of Chief Privacy Officer

Amid AI Boom, Tech Can’t Afford to Neglect Spending in These IT Areas

Spyware Vendors’ Nebulous Ecosystem Helps Them Evade Sanctions

FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals

YouTube Removes Tenet Media Channel Over Alleged Ties to Russian Disinformation Effort

Therapy Sessions Exposed by Mental Health Care Firm Confidant Health’s Unsecured Database

900,000 on Medicare in Wisconsin Warned of Data Breach from MOVEit

Car Rental Giant Avis Discloses Data Breach Impacting Customers

Transport for London (TfL) Still Affected by ‘Ongoing Cyber Incident’

North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

Sextortion Scam Now Use Your “Cheating” Spouse’s Name as a Lure

SpyAgent Android Malware Steals Your Crypto Recovery Phrases from Images

New RAMBO Attack Steals Data Using RAM in Air-Gapped Computers

GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code

SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation

Progress LoadMaster Vulnerable to 10/10 Severity RCE Flaw

Microsoft Office 2024 to Disable ActiveX Controls by Default

Cybersecurity Talent Shortage Prompts White House Action

9/5/2024

WhisperGate: Russian Military Hackers ‘Cadet Blizzard’ Linked to Critical Infrastructure

Russia’s Most Notorious Special Forces Unit Now Has Its Own Cyber Warfare Team

Google Searches Are Becoming a Bigger Target of Cybercriminals With the Rise of ‘Malvertising’

Brazil Says Its Resistance to Elon Musk Is Global Example

With Musk’s X Banned in Brazil, Its Users Carve Out New Digital Homes

Why It’s So Hard to Fully Block X in Brazil

UK Signs Council of Europe AI Convention

Musician Charged With $10M Streaming Royalties Fraud Using AI and Bots

Microsoft Removes Revenge Porn From Bing Search Using New Tool

Cyber Spending Rises Modestly While Hacking Threats Evolve

Services Disrupted as Local Council Near GCHQ’s Headquarters Hit by Cyberattack

Penpie DeFi Platform Files Reports With FBI, Singapore Police After $27 Million Crypto Theft

Dr. Daniel Leeman, MD (TX) Notifies 20k+ Patients of Recent Data Breach

OnlyFans Hackers Targeted With Infostealer Malware

New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm

Chinese-Speaking Hacker Group ‘Tropic Trooper’ Targets Human Rights Studies in Middle East

LiteSpeed Cache Bug Exposes 6 Million WordPress Sites to Takeover Attacks

Apache Fixes Critical OFBiz Remote Code Execution Vulnerability

Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues

9/4/2024

U.S. Cracks Down on Russian Disinformation Before 2024 Election

U.S. Indicts Two RT Employees for Alleged Russian Disinformation Effort

North Korean Hackers Targets Job Seekers with Fake FreeConference App

Red Teaming Tool MacroPack Abused for Malware Deployment

U.S. Government Set Out to Improve Internet Routing Security

The Japanese Robot Controversy Lurking in Israel’s Military Supply Chain

Telegram Apologizes to South Korea and Takes Down Smutty Deepfakes

Reed Smith Is Latest U.S. Law Firm to Shrink China Presence With Beijing Closure

Copilot for Microsoft 365 Might Boost Productivity if You Survive the Compliance Minefield

European Data Privacy Watchdog Closes Case Against X Over Its Grok AI Bot

Planned Parenthood Confirms Cyber-Attack as RansomHub Threatens to Leak Data

Microchip Technology Confirms Data Was Stolen in Cyberattack

Hospital Sisters Health System (IL) Data Breach Affects an Unknown Number of Patients

Cicada Ransomware May Be a BlackCat/ALPHV Rebrand and Upgrade

Hackers Inject Malicious JS in Cisco Store to Steal Credit Cards, Credentials

Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack

YubiKeys Have an Unfixable Security Flaw — But It’s Difficult to Exploit

Cisco Warns of Backdoor Admin Account in Smart Licensing Utility

Cisco Fixes Root Escalation Vulnerability With Public Exploit Code

Android Users Urged to Install Latest Security Updates to Fix Actively Exploited Flaw

9/3/2024

Spamouflage Trolls Pretend to Be American Patriots on X, TikTok Ahead of U.S. Presidential Election

The U.S. Navy Is Going All in on Starlink

How Navy Chiefs Conspired to Get Themselves Illegal Warship Wi-Fi

Indicted Pair of Foreign Nationals Were Behind Swatting Attack on Cisa Director

Civil Rights Groups Call For Spyware Controls

Inside the Deepfake Porn Crisis Engulfing Korean Schools

Krebs: Sextortion Scams Now Include Photos of Your Home

FTC: Over $110 Million Lost to Bitcoin ATM Scams in 2023

Bitcoin ATM Scammers Stole $65 Million in First Half of 2024

Dutch Data Watchdog Fines Clearview AI $33M for ‘Illegal’ Data Collection

Zscaler Forecasts Annual Results Below Estimates on Weak Cybersecurity Spending

Halliburton Says Hackers Removed Data in August Cyberattack

Over 1.4M Users Exposed in Tracelo Breach

Young Consulting and Blue Shield of California Announce Data Breach

FBI Warns Crypto Firms of Aggressive Social Engineering Attacks from North Korea

Rapid Growth of Password Reset Attacks Boosts Fraud and Account Takeovers

Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

Zyxel Warns of Critical OS Command Injection Flaw in Routers

D-Link Says It is Not Fixing Four RCE Flaws in DIR-846W Routers

Google Releases Pixel Update to Get Rid of Surveillance Vulnerability

9/2/2024

U.S. Authorities Issue RansomHub Ransomware Alert

South Korea Police Investigates Telegram Over Deepfake Porn

Telegram CEO Was ‘Too Free’ on Content Moderation, Says Russian Minister

Verkada Facing $3M Penalty to Federal Trade Commission After Hackers Viewed Sensitive Video Footage

Admins of MFA Bypass Service Plead Guilty to Fraud

German Air Traffic Control Agency Confirms Cyberattack, Says Current Operations Remain Unaffected

Transport for London Discloses Ongoing “Cyber Security Incident”

Business Services Giant CBIZ Discloses Customer Data Breach

Malicious npm Packages Mimicking ‘noblox.js’ Compromise Roblox Developers’ Systems

Ransomware Gangs Pummel Southeast Asia

8/30-9/1/2024

Iranian Hackers Set Up New Network to Target U.S. Political Campaigns

CIA Says It Busted Teen Terror Cell Targeting Taylor Swift in Vienna

How the CIA Tries to Recruit Russians to Spy on Their Country

Tired of Airport Security Queues? SQL Inject Yourself Into the Cockpit, Claim Researchers

CrowdStrike Exec Will Testify to Congress About July’s Global IT Meltdown

Companies Grapple With Expanding Cyber Rules

Researcher Sued for Sharing Data Stolen by Ransomware With Media

Docker-OSX Image Used for Security Research Hit by Apple DMCA Takedown

City of Columbus Sues Man After He Discloses The Severity of Recent Ransomware Attack by Rhysida Group

U.S. Indicts Duo Over Alleged Swatting Spree That Targeted Elected Officials

Telegram: ‘The Dark Web in Your Pocket’

Data Breach at Minnesota Human Services Department May Have Compromised Personal Info of 4,000

Durex India’s Security Lapse Reveals Personal Data of Customers

Toronto School Board Confirms Students’ Info Stolen as LockBit Claims Breach

‘Voldemort’: Cyberattackers Exploit Google Sheets for Malware Control in Likely Espionage Campaign

North Korean Hackers Exploit Chrome Zero-Day to Deploy Rootkit

New Cyberattack Targets Chinese-Speaking Businesses with Cobalt Strike Payloads

New Malware Masquerades as Palo Alto VPN Targeting Middle East Users

GitHub Comments Abused to Push Password Stealing Malware Masked as Fixes

Cicada3301 Ransomware’s Linux Encryptor Targets VMware ESXi Systems

Don’t Wait for the Next Big Data Breach to Freeze Your Credit