11/28/2024

Undersea Cable Cuts in the Baltic Sea Are Stoking Geopolitical Tensions — Here’s What’s Going On

Cloned Customer Voice Beats Bank Security Checks

The Only Thing Worse Than Being Fired Is Scammers Fooling You Into Thinking You’re Fired

TfL Faces Independent Investigation Over Cyber-Attack Response

Albanian Drug Smugglers Busted After Cops Decrypt Comms
UK Hospital Network Postpones Procedures After Cyberattack

Crypto Exchange XT.com Suspends Withdrawals After Suspected $1.7M Hack

XMLRPC npm Library Turns Malicious, Steals Data, Deploys Crypto Miner

Critical Vulnerabilities Discovered in Industrial Wireless Access Point

How Learning to Fly Made Me a Better Cybersecurity CEO

11/27/2024

T-Mobile Says Salt Typhoon Cyber Attackers Had No Access to Customer Data

Salt Typhoon Chinese Hackers Breached T-Mobile’s Routers to Scope Out Network

Salt Typhoon’s Surge Extends Far Beyond U.S. Telcos

British Government Demands Chinese-Owned Company Appoint a Security Chief With UK Clearances

Krebs: Hacker in Snowflake Extortions May Be a U.S. Soldier

Police Bust Pirate Streaming Service Making €250 Million per Month

Appeals Court Overturns Treasury Sanctions Against Crypto Mixer Tornado Cash

Exxon Lobbyist Investigated Over Hack-And-Leak of Environmentalist Emails, Sources Say

Microsoft Is Being Investigated by the FTC Over Antitrust Concerns

FTC Changes Its Telemarketing Rules to Cover Growing ‘Tech Support Scam’ Calls

Akamai Technologies: Bankruptcy Court Approves Bid for Edgio Assets

UK Nuclear Decommissioning Authority Opens Sellafield Cyber Center
BIC, Starbucks, Morrisons Continue Recovery After Blue Yonder Ransomware Attack

Hoboken (NJ) Hit with Ransomware Cyberattack, Officials Say

Data Broker SL Data Services Leaves 600K+ Sensitive Files Exposed Online

Cloudflare Says It Lost 55% of Logs Pushed to Customers for 3.5 Hours

Zello Asks Users to Reset Passwords After Security Incident

Contemporary Information Corp (CA) Provides Notice of Data Breach Following Incident at BackChecked, LLC

Attack Group APT-C-60 Targets Japan Using Trusted Platforms

Hackers Abuse Popular Godot Game Engine to Infect Thousands of PCs

New Bootkit “Bootkitty” Targets Linux Systems via UEFI

Matrix Botnet Exploits IoT Devices in Widespread DDoS Botnet Campaign

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers

Microsoft Re-Releases Exchange Updates After Fixing Mail Delivery

11/26/2024

Aggressive Chinese APT Group Earth Estries Targets Governments with New Backdoors

Russian RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks

‘CyberVolk’ Hacktivists Use Ransomware in Support of Russian Interests

Darknet Services Fuel Holiday Scams and E-Commerce Exploits

Emergency Vehicle Lights Can Screw up a Car’s Automated Driving System

My Car Knows My Secrets, and I’m (Mostly) OK With That

CrowdStrike Raises Annual Forecast on Steady Cybersecurity Demand

Over 1,000 Arrested in Massive ‘Serengeti’ Anti-cybercrime Operation
RansomHub Gang Says It Broke Into Networks of Texas City, Minneapolis Agency

NHS Trust Declares Major Incident for “Cybersecurity Reasons”

Canadian Privacy Regulators Publish Details of Medical Testing Company LifeLabs Data Breach

Radiologic Medical Services (IA) Announces Data Breach After Unauthorized Access to Employee Email Account

New DDoS Campaign by ‘Matrix’ Exploits IoT Devices and Server Misconfigurations

New NachoVPN Attack Uses Rogue VPN Servers to Install Malicious Updates

Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks

CISA Urges Agencies to Patch Critical “Array Networks” Flaw Amid Active Attacks

11/25/2024

China Has Utterly Pwned ‘Thousands and Thousands’ of Devices at U.S. Telcos

Salt Typhoon Hackers Backdoor Telcos With New GhostSpider Malware

Former Verizon Employee Gets Four-Year Sentence for Sharing Cyber Secrets With Chinese Government

UK Minister Criticized Over ‘Hyperbolic’ Speech on Russia’s Cyber Capabilities

America’s Rivals Have a New Favorite Weapon: Criminal Gangs

DOJ: Man Hacked Networks to Pitch Cybersecurity Services

Cyberattacks Cost British Businesses $55 Billion in Past Five Years, Broker Says

New York State Fines Geico and Travelers $11.3 Million for Data Breaches
Starbucks, Others Faces Disruptions Following Ransomware Attack on Software Supplier Blue Yonder

Spring EQ (PA) Notifies Consumers of Data Breach Stemming from Compromised Employee Email Account

PyPI Python Library “aiocpa” Found Exfiltrating Crypto Keys via Telegram Bot

BlackBasta Ransomware Brand Picks up Where Conti Left Off

Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks

Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections

QNAP Addresses Critical Flaws Across NAS, Router Software

Going Way Beyond Secure by Demand

11/22-24/2024

Russia’s Ballistic Missile Attack on Ukraine Is an Alarming First

Russia Ready to Wage Cyber War on UK, Minister to Say

Chinese Hackers Preparing for Conflict, U.S. Cyber Official Says

White House Officials Meet with Telecoms Execs on Suspected China Hack

Microsoft President Asks Trump to “Push Harder” Against Russian Hacks

Trump Taps Border Hawk to Head DHS. Will Noem’s ‘Enthusiasm’ Extend to Digital Domain?

The Pentagon’s Battle Inside the U.S. For Control of a New Cyber Force

The U.S. Is Calling Out Foreign Influence Campaigns Faster Than Ever

Google Exposes GLASSBRIDGE: A Pro-China Influence Network of Fake News Sites

Three-Quarters of Black Friday Spam Emails Identified as Scams

Bangkok Busts SMS Blaster Sending 1 Million Scam Texts From a Van

Meta Removes Over 2 Million Accounts Pushing Pig Butchering Scams

Supreme Court Tosses Facebook Appeal in Shareholder Lawsuit Arising From Cambridge Analytica Data Breach

DeliveryHero Subsidiary Fined $5.2 Million for Tracking Drivers’ Geolocation
Andrew Tate’s Site ‘Real World’ Ransacked, Subscriber Data Stolen

Software Company Blue Yonder Providing Services to U.S. and UK Grocery Stores Says It Was Hit by Ransomware Attack

Members Trust Company (FL) Data Breach Following Compromised Email Accounts Affects 11,854 Consumers

Russian Fancy Bear Hackers Breach U.S. Firm Over Wi-Fi From Russia in ‘Nearest Neighbor Attack’

Russian Cyber Spies TAG-110 Target Organizations with HatVibe and CherrySpy Malware

China-Linked TAG-112 Targets Tibetan Media with Cobalt Strike Espionage Campaign

APT-K-47 (aka Mysterious Elephant) Uses Hajj-Themed Lures to Deliver Advanced Asyncshell Malware

North Korean Hackers Sapphire Sleet Steal $10M with AI-Driven Scams and Malware on LinkedIn

PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries

Hackers Abuse Avast Anti-Rootkit Driver to Disable Defenses

Microsoft Rolls Out Recall to Windows Insiders With Copilot+ PCs

Microsoft Testing Windows 11 Support for Third-Party Passkeys

Senators Call for Audit of TSA’s Facial Recognition Tech as Use Expands in Airports

11/21/2024

Potential Trump Cyber Picks Coalesce — But Insiders Say There Could Be Surprises

China’s Surveillance State Is Selling Citizen Data as a Side Hustle

Chinese Ship Casts Shadow Over Baltic Subsea Cable Snipfest

North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs

The AI Effect: Amazon Sees Nearly 1 Billion Cyber Threats a Day

Google’s AI-Powered OSS-Fuzz Tool Finds 26 Vulnerabilities in Open-Source Projects

Microsoft Disrupts ONNX Phishing-as-a-Service Infrastructure

Fortinet VPN Design Flaw Hides Successful Brute-Force Attacks

A New ‘Ultra-Secure’ Phone Carrier Says It Can Make You Harder to Track

Meta Finally Breaks Its Silence on Pig Butchering

U.S. Seizes PopeyeTools Cybercrime Marketplace, Charges Administrators

Krebs: Feds Charge Five Men in ‘Scattered Spider’ Roundup
Dozens of Central Asian Targets Hit in Recent Russia-Linked Cyber-Espionage Campaign

Cyberattack at French Hospital Exposes Health Data of 750,000 Patients

Stop & Shop Races to Restock Shelves After ‘Cybersecurity Issue’

Gambling and Lottery Giant International Game Technology Disrupted by Cyberattack, Working to Bring Systems Back Online

Over 145,000 Industrial Control Systems Across 175 Countries Found Exposed Online

Now BlueSky Hit with Crypto Scams as It Crosses 20 Million Users

Rockford Gastroenterology Associates (IL) Notifies 147,253 of 2023 Data Breach

Linux Malware WolfsBane and FireWood Linked to Gelsemium APT

Vietnam’s Infostealer Crackdown Reveals VietCredCare and DuckTail

NodeStealer Malware Targets Facebook Ad Accounts, Harvesting Credit Card Data

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

11/20/2024

Chinese APT Group Targets Telecom Firms Linked to Belt and Road Initiative

Inside the Booming ‘AI Pimping’ Industry

Amazon and Audible Flooded With ‘Forex Trading’ and Warez Listings

60% of Emails with QR Codes Classified as Spam or Malicious

U.S. Charges Five in ‘Scattered Spider’ Hacking Scheme

Two Brothers Indicted for Operating Illegal Sports Streaming Service That Netted $7 Million

MITRE Shares 2024’s Top 25 Most Dangerous Software Weaknesses
Krebs: Fintech Giant Finastra Investigating Data Breach

Norfolk Sheriff’s Office (VA) Says They Were the ‘Victim of a Cybersecurity Event’

Wexford County (MI) Computer Systems Returning After Cyberattack Forced Shutdown

FBI Says BianLian Based in Russia, Moving From Ransomware Attacks to Extortion

Ghost Tap: Hackers Exploiting NFCGate to Steal Funds via Mobile Payments

Five Privilege Escalation Flaws Found in Ubuntu Needrestart

11/19/2024

Data Privacy Experts Predict Some Wins Under Trump 2.0

Hacker Is Said to Have Gained Access to File With Damaging Testimony About Matt Gaetz

Ransomware Gangs on Recruitment Drive for Pen Testers

Leaked Documents Show What Phones Secretive Tech ‘Graykey’ Can Unlock

Microsoft Shares More Details on Windows 11 Admin Protection

Microsoft Announces Its Own Black Hat-Like Hacking Event With Big Rewards for AI Security

Auto Sector Scrambles to Retool Workforce for Electric and Automated Future

TSA Cyber Disclosure Requirements Worry Natural Gas Companies

TSA Not Monitoring Transportation Sector Efforts to Stop Ransomware, Watchdog Says

D-Link Urges Users to Retire VPN Routers Impacted by Unfixed RCE Flaw
Healthcare Org Equinox Notifies 21K Patients and Staff of Data Theft

Aspen Healthcare Services (TX) Announces Data Breach Following Ransomware Attack

AdventHealth (FL) Files Official Notice of Data Breach

Hackers Hijack Unsecured Jupyter Notebooks to Stream Illegal Sports Broadcasts

Spotify Abused to Promote Pirated Software and Game Cheats

Helldown Ransomware Expands to Target VMware and Linux Systems

Ngioweb Botnet Fuels NSOCKS Residential Proxy Network Exploiting IoT Devices

CISA Tags Progress Kemp Loadmaster Flaw as Exploited in Attacks

Apple Fixes Two Zero-Days Used in Attacks on Intel-Based Macs

Oracle Warns of Agile PLM File Disclosure Flaw Exploited in Attacks

11/18/2024

Sweden’s ‘Doomsday Prep for Dummies’ Guide Hits Mailboxes Today

North Korean IT Worker Network Tied to BeaverTail Phishing Campaign

Surge in DocuSign Phishing Attacks Target U.S. State Contractors

Many U.S. Water Systems Exposed to ‘High-Risk’ Vulnerabilities, Watchdog Finds

Bipartisan Effort to Clean up Cyber Regulations Gets a Boost in House, but Calendar Is Tight

Fake Donald Trump Assassination Story Used in Phishing Scam

Microsoft 365 Admin Portal Abused to Send Sextortion Emails

Heather ‘Razzlekhan’ Morgan Sentenced to 18 Months in Prison, Ending Bitfinex Saga

U.S. Charges Phobos Ransomware Admin After South Korea Extradition

Cybersecurity At A Crossroads As Global Threats Hit Record Highs

Why the Demand for Cybersecurity Innovation Is Surging

Brave on iOS Adds New “Shred” Button to Wipe Site-Specific Data

Gmail’s New Shielded Email Feature Lets Users Create Aliases for Email Privacy

Apple Still Blocking Access to News Apps and Podcasts at Moscow’s Request
U.S. Space Tech Giant Maxar Discloses Employee Data Breach

British Software Company Microlise Confirms Hackers Compromised Corporate Data

Rockport Mortgage Notifies Individuals of Recent Data Breach Leaking Their Personal Information

Great Plains Regional Medical Center (OK) Notifies Patients of Data Breach Following Ransomware Attack

AI Company iLearningEngines Tells SEC That $250,000 Stolen in Cyberattack

Ford ‘Actively Investigating’ After Employee Data Allegedly Parked on Leak Site

Akira Ransomware Racks Up 30+ Victims in a Single Day

‘ClickFix’ Cyber-Attacks for Malware Deployment on the Rise

Fake Bitwarden Ads on Facebook Push Info-Stealing Chrome Extension

Fake Discount Sites Exploit Black Friday to Hijack Shopper Information

New Stealthy BabbleLoader Malware Spotted Delivering WhiteSnake and Meduza Stealers

Critical 9.8-Rated VMware vCenter RCE Bug Exploited After Patch Fumble

Palo Alto Networks Patches Two Firewall Zero-Days Used in Attacks

11/15-17/2024

Library of Congress Email Systems Hacked Earlier This Year by ‘Foreign Adversary’

Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations

Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia

Chinese ‘SilkSpecter’ Fraud Network Uses 4,700 Fake Shopping Sites to Steal Credit Cards

T-Mobile Confirms It Was Hacked in Recent Wave of Telecom Breaches

New Apple Security Feature Reboots iPhones After 3 Days, Researchers Confirm

NSO Group Used Another WhatsApp Zero-Day After Being Sued, Court Docs Say

Cyber Schemes Among Projects Getting £20M Windfall

Bitfinex Hacker Ilya Lichtenstein Sentenced to 5 Years, Guilty of Laundering $10.5 Billion in Bitcoin

Ohio Man Behind Helix Cryptocurrency Mixer Gets 3-Year Sentence

Krebs: An Interview With the Target & Home Depot Hacker

Will Passkeys Ever Replace Passwords? Can They?

FTC Reports 50% Drop In Unwanted Call Complaints Since 2021
Otsego Public Schools (MI) Hacked; Personal Info Exposed

Fake AI Video Generators Infect Windows, macOS With Infostealers

Phishing Emails Increasingly Use SVG Attachments to Evade Detection

Ransomware Groups Use Cloud Services For Data Exfiltration

Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform

Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN Credentials

PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released

Botnet Exploits GeoVision Zero-Day to Install Mirai Malware

watchTowr Finds New Zero-Day Vulnerability in Fortinet Products

High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables

Security Plugin Flaw in Millions of WordPress Sites Gives Admin Access

Microsoft Pulls Exchange Security Updates Over Mail Delivery Issues

The Vendor’s Role in Combating Alert Fatigue

Top Ukrainian Cyber Official Resigns a Year After Taking Office

11/14/2024

Trump’s Second Term Is Expected to Bring Big Change to Top U.S. Cyber Agency

More Spyware, Fewer Rules: What Trump’s Return Means for U.S. Cybersecurity

Washington’s Cybersecurity Storm of Complacency

Sitting Ducks DNS Attacks Put Global Domains at Risk

Google Warns of Rising Cloaking Scams, AI-Driven Fraud, and Crypto Schemes

Bank of England U-turns on Vulnerability Disclosure Rules

Cybercriminal Devoid of Boundaries Gets 10-Year Prison Sentence

Teen Behind Hundreds of Swatting Attacks Pleads Guilty to Federal Charges

Malware Being Delivered by Mail, Warns Swiss Cyber Agency
Hungary Confirms Hack of Defense Procurement Agency

Kids’ Shoemaker Start-Rite Trips Over Security Again, Spilling Customer Card Info

Microsoft Power Pages Misconfiguration Leads to Data Exposure

New Glove Infostealer Malware Bypasses Chrome’s Cookie Encryption

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails

New RustyAttr Malware Targets macOS Through Extended Attribute Abuse

CISA Warns of More Palo Alto Networks Bugs Exploited in Attacks

ChatGPT Allows Access to Underlying Sandbox OS, “Playbook” Data

11/13/2024

China-Linked Hackers Stole Surveillance Data From Telecom Companies, U.S. Says

Hamas-Affiliated WIRTE Employs SameCoin Wiper in Disruptive Attacks Against Israel

Trump’s Second Term Is Expected to Bring Big Change to Top U.S. Cyber Agency

Top White House Cyber Official Urges Trump to Focus on Ransomware, China

These Are the Passwords You Definitely Shouldn’t Be Using

Leaked Info of 122 Million Linked to B2B Data Aggregator Breach

Data Broker Amasses 100M+ Records on People – Then Someone Snatches, Sells It

These Guys Hacked AirPods to Give Their Grandmas Hearing Aids

Amazon MOVEit Leaker Claims to Be Ethical Hacker

Chinese National Faces 20 Years in U.S. Prison for Laundering Pig-Butchering Proceeds
China-Linked Group Hacked Tibetan Media and University Sites to Distribute Cobalt Strike Payload

Embargo Ransomware Fiends Boast They’ve Stolen 1.4TB From U.S. Pharmacy Network

Wisconsin City of Sheboygan Says Ransom Demanded After Cyberattack

ASM Global (CA) Notifies Affected Individuals of Recent Data Breach

Hive0145 Targets Europe with Advanced Strela Stealer Campaigns

New ShrinkLocker Ransomware Decryptor Recovers Bitlocker Password

Critical Bug in EoL D-Link NAS Devices Now Exploited in Attacks

Krebs: Microsoft Patch Tuesday, November 2024 Edition

NIST Says Exploited Vulnerability Backlog Cleared but End-Of-Year Goal for Full List Unlikely

New Google Pixel AI Feature Analyzes Phone Conversations for Scams

11/12/2024

German Interior Minister Warns of Cyber Threat Ahead of Elections

Volt Typhoon Rebuilds Malware Botnet Following FBI Disruption

Surge in Exploits of Zero-Day Vulnerabilities Is ‘New Normal’ Warns Five Eyes Alliance

FBI, CISA, and NSA Reveal Most Exploited Vulnerabilities of 2023

Microsoft November 2024 Patch Tuesday Fixes 4 Zero-Days, 91 Flaws

Two Zero-Day Bugs in Microsoft’s Nov. Update Under Active Exploit

Windows 10 KB5046613 Update Released with Fixes For Printer Bugs

CISOs Turn to Indemnity Insurance as Breach Pressure Mounts

Signal Introduces Convenient “Call Links” for Private Group Chats

Pentagon Leaker Sentenced to 15 Years in Jail After Sharing Military Secrets Online
Dutch Company Behind Hannaford, Stop & Shop Says Cyber Issue Affecting U.S. Network

Delta, Amazon Confirm Vendor Breach as Dark Web Posts Revive MOVEit Leak Concerns

BBS Financial (MA) Confirms Data Breach Following January 2024 Ransomware Attack

North Korean Hackers Target macOS Using Flutter-Embedded Malware

TA455’s Iranian Dream Job Campaign Targets Aerospace with Malware

Phishing Tool GoIssue Targets Developers on GitHub

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

D-Link Won’t Fix Critical Bug in 60,000 Exposed EoL Modems

How Italy Became an Unexpected Spyware Hub

11/11/2024

Credit Cards Readers Across Israeli Stores, Gas Stations Crash in Cyberattack

FBI Issues Warning as Crooks Ramp up Emergency Data Request Scams

WEF Introduces Framework to Strengthen Anti-Cybercrime Partnerships

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation

The AI Machine Gun of the Future Is Already Here

Halliburton Reports $35 Million Loss After Ransomware Attack

Open Source Security Incidents Aren’t Going Away
Amazon Confirms Employee Data Breach, but Says It’s Limited to Contact Info

HIBP Notifies 57 Million People of Hot Topic Data Breach

Food Lion Acknowledges They Were Hit by Cyberattack

Set Forth, Inc. (IL) Sends Data Breach Letters to 1.5 Million Consumers

English Construction Company (VA) Targeted in Ransomware Attack, Leading to Data Breach Affecting Former Employees

New Remcos RAT Variant Targets Windows Users Via Phishing

New Ymir Ransomware Partners With RustyStealer in Attacks

11/8-10/2024

Pro-Russian Hacktivists Target South Korea as North Korea Joins Ukraine War

Authorities Work to Find the Source of Racist Texts Sent to Black People Nationwide After the Election

TSA Wants to Expand Cyber Rules for Pipelines and Railroads

Scattered Spider, BlackCat Claw Their Way Back From Criminal Underground

Scammers Target UK Senior Citizens With Winter Fuel Payment Texts

Google’s Mysterious ‘search.app’ Links Leave Android Users Concerned

A New iOS 18 Security Feature Makes It Harder for Police to Unlock iPhones

FBI: Spike in Hacked Police Emails, Fake Subpoenas (Krebs)

Bitcoin Fog Founder Sentenced to 12 Years for Cryptocurrency Money Laundering
IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools

Malicious NPM Packages Target Roblox Users with Data-Stealing Malware

Malicious PyPI Package with 37,000 Downloads Steals AWS Keys

Hackers Now Use Zip File Concatenation to Evade Detection

Critical Veeam RCE Bug Now Used in Frag Ransomware Attacks

Unpatched Mazda Connect Bugs Let Hackers Install Persistent Malware

Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat Concerns

D-Link Won’t Fix Critical Flaw Affecting 60,000 Older NAS Devices

How the Creator of Zero Trust Developed Today’s Most Robust Cybersecurity Strategy

Russia’s Internet Watchdog Blocks Thousands of Websites That Use Cloudflare’s Privacy Service

11/7/2024

U.S. Agency Warns Employees About Phone Use Amid Ongoing China Hack

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

China-Linked Hackers Tasked With Japanese Targets Pursue Them Through Europe

Canada Orders Shutdown of Local TikTok Branch Over Security Concerns

764 Terror Network Member Richard Densmore Sentenced to 30 Years in Prison

Akamai Forecasts Fourth-Quarter Revenue Below Estimates on Weak Client Spending

Cloudflare’s Q4 Revenue Forecast Falls Short as Cybersec Competition Intensifies

Fortinet’s Quarterly Revenue Forecast Disappoints, Shares Fall

Datadog Raises Annual Forecast Betting on AI-Driven Cybersecurity Demand

Defenders Outpace Attackers in AI Adoption
Nokia Says Hackers Leaked Third-Party App Source Code

Texas-Based Oilfield Supplier Newpark Resources Faces Disruptions Following Ransomware Attack

OrthopedicsNY Files Official Notice of 2023 Data Breach Affecting Patient Information

North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS

Don’t Open That ‘Copyright Infringement’ Email Attachment – It’s an Infostealer

Androxgh0st Botnet Adopts Mozi Payloads, Expands IoT Reach

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

CISA Warns of Critical Palo Alto Networks Bug Exploited in Attacks

HPE Warns of Critical Rce Flaws in Aruba Networking Access Points

The Power of Process in Creating a Successful Security Posture

11/6/2024

Top U.S. Cyber Official Says ‘No Evidence of Malicious Activity’ Impacting Election

Fact Check: Georgia Voter Fraud Video Labeled Russian Disinformation Uses False Personal Data

IRISSCON: Organizations Still Falling Victim to Predictable Cyber-Attacks

Cybercrooks Are Targeting Bengal Cat Lovers in Australia for Some Reason

People Urged to Update Some Internet Routers

Germany Drafts Law to Protect Researchers Who Find Security Flaws

Major Ukrainian University Bans Telegram to Reduce Cyberthreats

UK Orders Chinese Owners to Relinquish Control of Scottish Semiconductor Business

Massive Nigerian Cybercrime Bust Sees 130 Arrested
Washington Courts’ Systems Offline Following Weekend Cyberattack

Cyber-Attack on Microlise Disrupts DHL and Serco Tracking Services

Cyberattack Disables Tracking Systems and Panic Alarms on British Prison Vans

SelectBlinds Says 200,000 Customers Impacted After Hackers Embed Malware on Site

Nokia: No Evidence So Far That Hackers Breached Company Data

Winos4.0 Malware Found in Game Apps, Targets Windows Users

New SteelFox Malware Hijacks Windows PCs Using Vulnerable Driver

VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware

Cisco Bug Lets Hackers Run Commands as Root on UWRB Access Points

11/5/2024

The FBI Says Russian Emails Are Sending Fake Bomb Threats to Polling Stations

Russia Is Going All Out on Election Day Interference

U.S. Warns of Last-Minute Iranian and Russian Election Influence Ops

Officials Warn Against Fake U.S. Election Videos, but See Little Disruption

ClickFix Exploits Users with Fake Errors and Malicious Code

Interpol Disrupts Cybercrime Activity on 22,000 IP Addresses, Arrests 41

Krebs: Canadian Man Arrested in Snowflake Data Extortions

A Kansas Pig Butchering: CEO Who Defrauded Bank, Church, Friends Gets 24 Years

FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions

Meta Found to Have Exposed Info on North Korean Defectors to Advertisers

Ukraine Accuses Google of Revealing Locations of Its Military Systems
Georgia Hospital Unable to Access Record System After Ransomware Attack

Schneider Electric Ransomware Crew Demands $125K Paid in Baguettes

Chinese Group Accused of Hacking Singtel in Telecom Attacks

Chinese Air Fryers May Be Spying on Consumers, Which? Warns

ToxicPanda Malware Targets Banking Apps on Android Devices

Pakistani Hackers Targeted High-Profile Indian Entities using Custom ElizaRAT

Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages

Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices

Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System

Google Cloud to Make MFA Mandatory by the End of 2025

How to Win at Cyber by Influencing People

11/4/2024

U.S. Cybersecurity Chief Says Disinformation Surge Hasn’t Impacted Election

In Final Check-in Before Election Day, CISA Cites Low-Level Threats, and Not Much Else

Nakasone Says All the News About Influence Campaigns Ahead of Election Day Is Actually ‘A Sign of Success’

Rep. Yvette Clarke on AI-Fueled Disinformation: ‘We Have Not Protected Ourselves in Time for This Election Cycle’

U.S. Says Russia Behind Fake Haitian Voters Video

Moldova Elects Pro-West President Maia Sandu Despite Russian Interference

Custom “Pygmy Goat” Malware Used in Sophos Firewall Hack on Gov’t Network

Inside the Massive Crime Industry That’s Hacking Billion-Dollar Companies

Northern Minnesota Man Cost Former Employer $45K in Cryptojacking Scheme, Charges Say

Nigerian Handed 26-Year Sentence for Real Estate Phishing Scam

Google Researchers Claim First Vulnerability Found Using AI
Schneider Electric Confirms Dev Platform Breach After Hacker Steals Data

Nokia Investigates Breach After Hacker Claims to Steal Source Code

Cisco Says DevHub Site Leak Won’t Enable Future Breaches

Columbus (OH) Ransomware Attack Exposes Data of 500,000 Residents

Middlesbrough Council Targeted in Second Cyber Attack in a Week

Houston Housing Authority Was Victim of a Ransomware Attack, Agency Says

Kemlon Products & Development Group (TX) Files Official Notice of Data Breach

Meet Interlock — The New Ransomware Targeting FreeBSD Servers

Windows Infected With Backdoored Linux VMs in New Phishing Attacks

Cybercriminals Exploit DocuSign APIs to Send Fake Invoices

Supply Chain Attack Uses Smart Contracts for C2 Ops

Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning

11/1-3/2024

Georgia Says U.S., Election Disinformation Likely Coming From Russian Troll Farms

U.S. Blames Russia Over Video Falsely Alleging Fraudulent Voting in State of Georgia

China’s Typhoon Hacks Ahead of U.S. Election Spurred by Elite Competition

Cyber Threats and the Election: What You Need to Know

Sophos Warns Chinese Hackers Are Becoming Stealthier

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft

U.S. and Israel Warn of Iranian Threat Actor’s New Tradecraft

Krebs: Booking.com Phishers May Leave You With Reservations

They’re Giving Scammers All Their Money. The Kids Can’t Stop Them.

6 IT Contractors Arrested for Defrauding Uncle Sam Out of Millions

DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany

Florida Man Accused of Hacking Disney World Menus, Changing Font to Wingdings

Hack Nintendo’s Alarm Clock to Show Cat Pics? Let’s-A-Go!

ChatGPT-4o Can Be Used for Autonomous Voice-Based Scams

OpenAI’s New ChatGPT Search Chrome Extension Feels Like a Search Hijacker
LA Housing Authority Confirms Breach Claimed by Cactus Ransomware

San Joaquin County Superior Court (CA) Suffering From Tech Outages After Cyberattack

Ransomware Attack Hits German Pharmaceutical Wholesaler AEP, Disrupts Medicine Supplies

Young People’s Data Feared Stolen in Cyberattack on French Government Contractor

Saint Xavier University Notifies Over 200k People of Recent Data Breach

Middlesbrough Council Website Restored After Online Attack

A Devon School ‘Blackmailed’ by Hackers in Cyber-Attack

LastPass Warns of Fake Support Centers Trying to Steal Customer Data

An Okta Login Bug Bypassed Checking Passwords on Some Long Usernames

Microsoft SharePoint RCE Bug Exploited to Breach Corporate Network

Zero-Click Flaw Exposes Potentially Millions of Popular Storage Devices to Attack

CISA Warns of Critical Software Vulnerabilities in Industrial Devices

Microsoft Delays Windows Copilot+ Recall Release Over Privacy Concerns

Federal Agency Investigating How Meta Uses Consumer Financial Data for Advertising