12/30/2024

China Hacked Treasury Dept. in ‘Major’ Breach, U.S. Says

AT&T and Verizon Say Networks Secure After Salt Typhoon Breach

Finland Seizes Suspected Russian Spy Ship and Questions Crew Following Cable Breaks

Germany Charges Three Suspected Russian Spies Accused of Surveilling Military Sites

Telegram Blocks Russian State Media Channels in Several EU Countries

Italian Websites Subjected to Pro-Russian DDoS Attack Campaign
U.S. Treasury Says Chinese Hackers Stole Documents in ‘Major Incident’

U.S. Treasury Department Breached Through Remote Support Platform

Atos Says Space Bears Ransomware Group Claims It Compromised a Database

In-Home Attendant Services (TX) Files Official Notice of Data Breach

Ransomware Is 35 Years Old and Now a Billion-Dollar Problem. Here’s How It Could Evolve

Happy 15th Anniversary, KrebsOnSecurity!

12/27-29/2024

White House: Salt Typhoon Hacks Possible Because Telecoms Lacked Basic Security Measures

U.S. Adds 9th Telcom to List of Companies Hacked by Chinese-Backed Salt Typhoon Cyberespionage

The U.S. Proposes Rules to Make Healthcare Data More Secure

Biden Administration Finalizes Rule to Block Sale of Americans’ Bulk Data to Adversaries

The Paper Passport Is Dying

CISA’s 2024 Review Highlights Major Efforts in Cybersecurity Industry Collaboration

Record-Breaking Ransoms and Breaches: A Timeline of Ransomware in 2024

How Cops Taking Down LockBit, ALPHV Led to RansomHub’s Meteoric Rise

It’s Only a Matter of Time Before LLMs Jump Start Supply-Chain Attacks
Hackers Steal ZAGG Customers’ Credit Cards in Third-Party Breach

Customer Data From 800,000 Electric Cars and Owners Exposed Online

Blue Yonder Says November Ransomware Attack Not Connected to Cleo Vulnerability

Hackers Hijacked Legitimate Chrome Extensions to Try to Steal Data

Cloud Atlas Deploys VBCloud Malware: Over 80% of Targets Found in Russia

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials

Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately

Too Much ‘Trust,’ Not Enough ‘Verify’

12/26/2024

Cyberattack on Ukraine’s State Registers Disrupts Marriage Registration, Real Estate Deals

A Weird Windows 11 Bug Won’t Let Some People Install Any Security Updates

The Worst Hacks of 2024

Brazilian Hacker Charged for Extorting $3.2M in Bitcoin After Breaching 300,000 Accounts

UN General Assembly Approves Cybercrime Treaty Despite Industry Backlash
Japan Airlines Systems Back to Normal After Cyberattack Delayed Flight

Nearly Half a Million People Had Data Stolen After Cyberattack on American Addiction Centers

New ‘OtterCookie’ Malware Used to Backdoor Devs in Fake Job Offers

Infostealers Dominate as Lumma Stealer Detections Soar by Almost 400%

Apache Warns of Critical Flaws in MINA, HugeGraph, Traffic Control

12/24-25/2024

U.S. and Japan Blame North Korea for $308m DMM Bitcoin Crypto Heist

Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware

European Space Agency’s Official Store Hacked to Steal Payment Cards

American Airlines Resumes Flights After Brief Grounding Ahead of Busy Christmas Travel

Former NSA Cyberspy’s Not-So-Secret Hobby: Hacking Christmas Lights

You Need to Create a Secret Password With Your Family

Major Biometric Data Farming Operation Uncovered

Inside Operation Destabilise: How a Ransomware Investigation Linked Russian Money Laundering and Street-Level Drug Dealing
Ruijie Networks’ Cloud Platform Flaws Could Expose 50,000 Devices to Remote Attacks

Pittsburgh Regional Transit Attributes Recent Service Disruptions to Ransomware Attack

Colonial Surety Company (NJ) Announces Data Breach Stemming from May Cybersecurity Incident

Clop Ransomware Is Now Extorting 66 Cleo Data-Theft Victims

How Androxgh0st Rose From Mozi’s Ashes to Become ‘Most Prevalent Malware’

New Botnet Exploits Vulnerabilities in NVRs, TP-Link Routers

CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation

Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now

12/23/2024

Inside The Invisible Russia-Ukraine Battlefield

France Extends Olympics Security Measures to Christmas Market

Interpol Identifies Over 140 Human Traffickers in New Innovative Initiative

AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case

MFA: Shun This Basic Cybersecurity Tactic and Become a Target for Hackers

FTC Orders Marriott and Starwood to Implement Strict Data Security
Classified Fighter Jet Specs Leaked on War Thunder – Again

Alta Resources Corporation (WI) Provides Notice of Data Breach Affecting Over 37k People

Critical Vulns Found in WordPress Plugins WPLMS and VibeBP

Adobe Warns of Critical ColdFusion Bug with PoC Exploit Code

Apache Fixes Remote Code Execution Bypass in Tomcat Web Server

Non-Human Identities Gain Momentum, Requires Both Management & Security

12/20-22/2024

FAA Banning Drone Flights Over New Jersey, New York Sites

Ukraine’s State Registers Hit with One of Russia’s Largest Cyberattacks, Officials Say

Russia Security Threat Is Far Reaching, Italy’s Prime Minister Warns

Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware

North Korean Hackers Stole $1.3 Billion Worth of Crypto This Year

Italy’s Data Protection Watchdog Issues €15m Fine to OpenAI Over ChatGPT Probe

Pegasus Spyware Maker NSO Group Is Liable for Attacks on 1,400 WhatsApp Users

Ransomware Attackers Target Industries with Low Downtime Tolerance

U.S. Unseals Complaint Against Russian-Israeli Accused of Working for LockBit

Romanian Netwalker Ransomware Affiliate Sentenced to 20 Years in Prison

Massive Live Sports Piracy Ring With 812 Million Yearly Visits Taken Offline

Three of the Biggest U.S. Banks Are Facing a Lawsuit for ‘Widespread Fraud’ on Zelle: Bank of America, JPMorgan Chase, and Wells Fargo

What Google’s Quantum Computing Breakthrough Willow Means for the Future of Bitcoin and Other Cryptos
Ascension: Health Data of 5.6 Million Stolen in Ransomware Attack

Duke Energy Reports Data Breach Potentially Impacting Over 8 Million Customers

PS Logistics Announces Data Breach Stemming from February 2024 Cyberattack

SRP Federal Credit Union (SC) Data Breach—240,000 Members Exposed in Attacked Claimed by Nitrogen Ransomware Group

Wood County (OH) Agencies Continue Investigating Ransomware Attack

Krispy Kreme Breach, Data Theft Claimed by Play Ransomware Gang

LockBit Admins Tease a New Ransomware Version: LockBit 4.0

New FlowerStorm Microsoft Phishing Service Fills Void Left by Rockstar2FA

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation

How Not To Become A Botnet Victim: A Practical Guide For Everyone

Infosec Experts Divided on Ai’s Potential to Assist Red Teams

12/19/2024

UAC-0125 Abuses Cloudflare Workers to Distribute Malware Disguised as Army+ App

Krebs: Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm

This VPN Lets Anyone Use Your Internet Connection. What Could Go Wrong?

Lumen Technologies Launches Sale of Consumer Fiber Unit

U.S. Organizations Still Using Kaspersky Products Despite Ban

Four Smart Questions for Boards Overseeing Cybersecurity

U.S. Seeks Extradition of Alleged LockBit Ransomware Developer From Israel
Bugs in a Major McDonald’s India Delivery System Exposed Sensitive Customer Data

New Malware Can Kill Engineering Processes in ICS Environments

BadBox Malware Botnet Infects 192,000 Android Devices Despite Disruption

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools

Juniper Warns of Mirai Botnet Targeting SSR Devices with Default Passwords

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits

12/18/2024

U.S. Targets TP-Link With a Potential Ban on the Chinese Routers

U.S. Government Tells Officials, Politicians to Ditch Regular Calls and Texts

Chinese National Cyber Centre Says U.S. Hacks Stole Trade Secrets From Tech Firms

Congress Again Fails to Limit Scope of Spy Powers in New Defense Bill

Krebs: How to Lose a Crypto Fortune with Just One Bad Click

Phishing Attacks Double in 2024

Nigeria Cracks Down on Cryptocurrency Investment Fraud and Romance Scams

Raccoon Stealer Malware Operator Gets 5 Years in Prison After Guilty Plea

Dutch Regulator Fines Netflix $5 Million for Data Privacy Violations

Quantum AI Startup SandboxAQ Valued at $5.3 Bln After $300 Mln Fundraising
APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP

‘Bitter’ Cyberspies Target Defense Orgs With New MiyaRAT Malware

HubPhish Exploits HubSpot Tools to Target 20,000 European Users for Credential Theft

Brighton Jones Files Official Notice of Data Breach Following Email Phishing Attack

New Fake Ledger Data Breach Emails Try to Steal Crypto Wallets

A Lightweight App Comes With Some Heavy Consequences, Researchers Say

New Attacks Exploit VSCode Extensions and npm Packages

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products

Microsoft Won’t Let Customers Opt out of Passkey Push

Recorded Future CEO Applauds “Undesirable” Designation by Russia

12/17/2024

Intel Officials Warned Police That U.S. Cities Aren’t Ready for Hostile Drones

U.S. Unveils New National Cyber Incident Response Plan

Sophisticated TA397 Malware Targets Turkish Defense Sector

The Mask APT Resurfaces with Sophisticated Multi-Platform Malware Arsenal

Stop Calling Online Scams ‘Pig Butchering,’ Interpol Warns

Drug Dealers Have Moved on to Social Media

Facebook Owner Meta Hit with 251 Million Euros in Fines for 2018 Data Breach

Coder Wrote a Bug So Bad Security Guards Wanted a Word When He Arrived at Work
Positive Behavior Supports Corporation Reports Data Breach Affecting Sensitive Client Information

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware

Cybercriminals Exploit Google Calendar to Spread Malicious Links

Over 25,000 SonicWall VPN Firewalls Exposed to Critical Flaws

Critical Security Hole in Apache Struts Under Exploit

CISA Orders Federal Agencies to Secure Microsoft 365 Tenants

12/16/2024

Trump Administration Wants to Go on Cyber Offensive Against China

Federal Money Is Helping States Overhaul Cybersecurity. What Happens if It Dries Up?

Russia Recruits Ukrainian Kids for Sabotage and Reconnaissance

Serbian Authorities Are Reportedly Hacking and Installing Spyware on Activists’ Phones: NoviSpy

YouTube Creators Targeted in Global Phishing Campaign

New Investment Scam Leverages AI, Social Media Ads to Target Victims Worldwide

The Education Industry: Why Its Data Must Be Protected

Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets

Israeli Spyware Firm Paragon Acquired by U.S. Investment Group

BlackBerry Offloads Cylance for a Fraction of What It Paid in 2019

Kali Linux 2024.4 Released With 14 New Tools, Deprecates Some Features
Texas Tech University System Data Breach Impacts 1.4 Million Patients

ConnectOnCall Breach Exposes Health Data of Over 910,000 Patients

Hackers Orchestrate Cyberattack Against PIH Health, Claiming Massive Data Breach

Rhode Island Confirms Data Breach After Brain Cipher Ransomware Attack

Cicada3301 Ransomware Claims Attack on French Peugeot Dealership

Namibia’s State Telecom Provider Says Hackers Leaked Data After It Refused to Pay Ransom

FBI Spots HiatusRAT Malware Attacks Targeting Web Cameras, DVRs

DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages

New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP

Windows Kernel Bug Now Exploited in Attacks to Gain SYSTEM Privileges

12/13-15/2024

Winnti Hackers Target Other Threat Actors With New Glutton PHP Backdoor

Thai Officials Targeted in Yokai Backdoor Campaign Using DLL Side-Loading Techniques

Ukraine Uncovers Russian Spy Network Recruiting Teens for Espionage

“Hazardous Drone Operation” Leads to Two Arrests in Boston

Game-Like ‘Task Scams’ Stole More Than $220 Million in Six Months

The Simple Math Behind Public Key Cryptography

Major Cloud Providers Could Get Key Role in AI Chip Access Outside the U.S., Sources Say

Peak Design Denies Snitching on Luigi Mangione

UnitedHealth’s Optum Left an AI Chatbot, Used by Employees to Ask Questions About Claims, Exposed to the Internet

UK Shoppers Frustrated as Bots Snap Up Popular Christmas Gifts

Germany Disrupts BADBOX Malware on 30,000 Devices Using Sinkhole Action

Russia Blocks Viber in Latest Attempt to Censor Communications
Rhode Island’s Online Benefits System Shuts Down After Cyberattack

SRP Federal Credit Union (SC) Says 240,000 Impacted by Recent Cyberattack

Auto Parts Giant LKQ Says Cyberattack Disrupted Canadian Business Unit

Japanese Game and Anime Publisher Kadokawa Reportedly Pays $3 Million Ransom to Russia-Linked Hackers

Young Life Announces Data Breach Affecting Employees and Volunteers

390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits

CISA Confirms Critical Cleo Bug Exploitation in Ransomware Attacks

Clop Ransomware Claims Responsibility for Cleo Data Theft Attacks

Akira and RansomHub Surge as Ransomware Claims Reach All-Time High

Citrix Shares Mitigations for Ongoing Netscaler Password Spray Attacks

CISA Warns Water Facilities to Secure HMI Systems Exposed Online

12/12/2024

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States

North Korea’s Fake IT Worker Scam Hauled in at Least $88 Million Over Six Years

U.S. Offers $5 Million for Info on North Korean IT Worker Farms

Telecoms Haven’t Notified Most Victims of Chinese Phone Data Hacking Campaign, Sources Say

Google Says Its Breakthrough Quantum Chip Can’t Break Modern Cryptography

Police Refer Westminster ‘Honeytrap’ to Prosecutors

Spain Busts Voice Phishing Ring for Defrauding 10,000 Bank Customers

Police Shuts Down Rydox Cybercrime Market, Arrests 3 Admins

Insurance Worker Sentenced After Illegally Accessing Claimants’ Data
Bitcoin ATM Firm Byte Federal Hacked via GitLab Flaw, 58K Users Exposed

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online

Remcos RAT Malware Evolves with New Techniques

New Stealthy Pumakit Linux Rootkit Malware Spotted in the Wild

New IOCONTROL Malware Used in Critical Infrastructure Attacks

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins

Security Flaws in WordPress Woffice Theme Prompts Urgent Update

Cleo Patches Critical Zero-Day Exploited in Data Theft Attacks

12/11/2024

Researchers Uncover Espionage Tactics of China-Based APT Groups in Southeast Asia

Chinese EagleMsgSpy Spyware Found Exploiting Mobile Devices Since 2017

Secret Blizzard Targets Ukrainian Military with Custom Malware Kazuar Backdoor

The ‘Ghost Gun’ Linked to Luigi Mangione Shows Just How Far 3D-Printed Weapons Have Come

Snowflake Pledges to Make MFA Mandatory

Krebs: How Cryptocurrency Turns to Cash in Russian Banks

U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls

South Korea Takes Down Fraudulent Online Trading Network Used to Extort $6.3M

Operation PowerOFF Takes Down DDoS Boosters
Krispy Kreme Security Hole Leads to Cyberattack, Frosting Orders

Lynx Ransomware Behind Electrica Energy Supplier Cyberattack

Sabre (TX) Sends Data Breach Letter to Employees Announcing Leaked SSNs and More

Sophisticated Scam Targets UAE Residents with Fake Police Fines

ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms

New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools

Microsoft Azure MFA Flaw Allowed Easy Access Bypass

Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts

Krebs: Patch Tuesday, December 2024 Edition

12/10/2024

Wyden Proposes Bill to Secure U.S. Telecoms After Salt Typhoon Hacks

U.S. Sanctions Chinese Firm Sichuan Silence Information Technology Company Over Potentially Deadly Ransomware Attack

Nvidia Probed in China Over Possible Antimonopoly Violations

Chinese Hackers Use Visual Studio Code Tunnels for Remote Access

Poker Cheaters Allegedly Use Tiny Hidden Cameras to Spot Dealt Cards

New Jersey Mayors Pen Letter Demanding Action on Mysterious Drone Sightings

AI Safety Is Hard to Steer With Science in Flux, U.S. Official Says

Avast Antivirus Owner Gen Digital Acquires MoneyLion in $1 Bln Deal

FTC Distributes $72 Million in Fortnite Refunds From Epic Games

Next Congress Likely to Tussle Over Cyber Oversight
Nemesis and ShinyHunters Hackers Exploit AWS Misconfigurations in Massive Data Breach

Highgate Hotels Sends Out Data Breach Letters Following Cyberattack

Fake Recruiters Distribute Banking Trojan via Malicious Apps in Phishing Scam

New AppLite Malware Targets Banking Apps in Phishing Campaign

Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged

BadRAM: $10 Security Flaw in Amd Could Allow Hackers to Access Cloud Computing Secrets

WPForms Bug Allows Stripe Refunds on Millions of WordPress Sites

Ivanti Warns of Maximum Severity CSA Auth Bypass Vulnerability

Microsoft December 2024 Patch Tuesday Fixes 1 Exploited Zero-Day, 71 Flaws

12/9/2024

China’s Salt Typhoon Recorded Top American Officials’ Calls, Says White House

U.S. Agencies to Brief House on Chinese Salt Typhoon Telecom Hacking

Phishing Scam Targets Ukrainian Defense Companies

Radiant Links $50 Million Crypto Heist to North Korean Hackers

Police Arrest UHC CEO Shooting Suspect, App Developer Luigi Mangione

Cybercrime Gang Arrested After Turning Airbnbs Into Fraud Centers

Federal Appeals Court Upholds Law Threatening U.S. TikTok Ban

Proposal for Cyber Force Study Is Watered down in Final Defense Bill

The Case For and Against Creating a Military Cyber Force

Russia Disrupts Internet Access in Multiple Regions to Test ‘Sovereign Internet’
Romanian Energy Supplier Electrica Hit by Ransomware Attack

U.S. Subsidiaries of Japanese Water Treatment Company, Green Tea Maker Kurita Water Industries Hit with Ransomware

Ransomware Attack Hits Leading Heart Surgery Device Maker ​Artivion

Amergis Healthcare Staffing (MD) Reports Data Breach Stemming from Compromised Email Accounts

Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering

Socks5Systemz Botnet Powers Illegal Proxy Service with 85,000+ Hacked Devices

OpenWrt Sysupgrade Flaw Let Hackers Push Malicious Firmware Images

Researchers Uncover Prompt Injection Vulnerabilities in DeepSeek and Claude AI

Large-Scale Incidents & the Art of Vulnerability Prioritization

12/6-8/2024

FCC Chair Proposes Cybersecurity Rules in Response to China’s Salt Typhoon Telecom Hack

How Chinese Insiders Are Stealing Data Scooped up by President XI’s National Surveillance System

Romania Exposes TikTok Propaganda Campaign Supporting Pro-Russian Candidate

Romania Cancels Presidential Election Results After Alleged Russian Meddling on TikTok

UK Cybersecurity Agency Unconcerned About Changes to Cisa Under Trump

Hackers Using Fake Video Conferencing Apps to Steal Web3 Professionals’ Data

QR Codes Bypass Browser Isolation for Malicious C2 Communication

The Weight-Loss Drug Boom Has Become One of the Internet’s Biggest Scams

Why SOC Roles Need to Evolve to Attract a New Generation
Pirated Corporate Software Infects Russian Businesses With Info-Stealing Malware

Deloitte Denies Breach, Claims Cyber-Attack Targeted Single Client

Anna Jaques Hospital (MA) Ransomware Breach Exposed Data of 300K Patients

Blue Yonder SaaS Giant Breached by Termite Ransomware Gang

Cardano Foundation X Account Hacked, Scam Links Posted, Then Removed

Ultralytics AI Model Hijacked to Infect Thousands With Cryptominer

More_eggs MaaS Expands Operations with RevC2 Backdoor and Venom Loader

Researchers Uncover Flaws in Popular Open-Source Machine Learning Frameworks

New Windows Zero-Day Exposes NTLM Credentials, Gets Unofficial Patch

12/5/2024

U.S. Phone Companies Could Face Fines for Weak Security Under a Proposed New Rule

Researchers Uncover 4-Month Cyberattack on U.S. Firm Linked to Chinese Hackers

Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor

New Android Spyware Found on Phone Seized by Russian FSB

U.S. Arrests Scattered Spider Suspect Linked to Telecom Hacks

Nebraska Man Pleads Guilty to Dumb Cryptojacking Operation

Europol Shuts Down Manson Market Fraud Marketplace, Seizes 50 Servers

Texas Accuses Four Companies of Sharing Sensitive User Data Without Proper Notice and Consent

She Escaped an Abusive Marriage—Now She Helps Women Battle Cyber Harassment
Romania’s Election Systems Targeted in Over 85,000 Cyberattacks

Ransomware Hackers Target NHS Hospitals With New Cyberattacks

Major USAID Contractor Chemonics Says 263,000 Affected by 2023 Data Breach

Hoboken Government Recovering From Ransomware Attack as Conti-Linked Gang Takes Credit

PointClickCare Data Breach Affects Residents of Multiple Long-Term Care Facilities

ANEL and NOOPDOOR Backdoors Weaponized in New MirrorFace Campaign Against Japan

Pro-Russian Hacktivist Group ‘Noname’ Claims 6600 Attacks Targeting Europe

Mitel MiCollab Zero-Day Flaw Gets Proof-of-Concept Exploit

Vulnerability Management Challenges in IoT & OT Environments

12/4/2024

U.S. Officials Recommend Encrypted Messaging to Evade Hackers in Telecom Networks

‘Large Number’ of Americans’ Metadata Stolen by Chinese Hackers, Senior Official Says

Senators Warn the Pentagon: Get a Handle on China’s Telecom Hacking

White House: Salt Typhoon Hacked Telcos in Dozens of Countries

Trump’s FBI Pick Kash Patel Targeted in Iranian Cyberattack

A New Phone Scanner That Detects Spyware Has Already Found 7 Pegasus Infections

She Was a Russian Socialite and Influencer. Cops Say She’s a Crypto Laundering Kingpin

UK Disrupts Russian Money Laundering Networks Used by Ransomware

Krebs: U.S. Offered $10M for Hacker ‘Wazawaka’ Just Arrested by Russia

Ransomware Costs Manufacturing Sector $17bn in Downtime
Russia-Linked Turla Exploits Pakistani Hackers’ Servers to Target Afghan and Indian Entities

BT Unit Took Servers Offline After Black Basta Ransomware Breach

Liverpool Children’s Hospital Confirms Cyber-Attack

Wirral Hospital Recovery Continues One Week After Cyber Incident

ESHA (NJ) Notifies Over 76k People of Recent Data Breach

New DroidBot Android Malware Targets 77 Banking, Crypto Apps

Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library

Japan Warns of IO-Data Zero-Day Router Flaws Exploited in Attacks

Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access

Navigating the Changing Landscape of Cybersecurity Regulations

FBI Shares Tips on How to Tackle AI-Powered Fraud Schemes

12/3/2024

U.S. Official Fighting Chinese Telecom Intrusions Urges More Encryption

U.S. Shares Tips to Block Hackers Behind Recent Telecom Breaches

French Mobile Operators Join Forces to Tackle Rising Fraud

Finland Says Latest Fiber-Optic Cable Break Was an Accident, Not Sabotage

Kimsuky Group Adopts New Phishing Tactics to Target Victims

Krebs: Why Phishers Love New TLDs Like .shop, .top and .xyz

Police Shut Down Matrix Encrypted Criminal Hub

Police Seizes Largest German Online Crime Marketplace ‘Crimenetwork’ & Arrests Admin

Data Brokers May Be Banned From Selling Your Social Security Number

Two Data Brokers Banned From Selling ‘Sensitive’ Location Data by the FTC

Cyberattack and Financial Troubles Force Stoli’s U.S. Arm to File for Bankruptcy
Data on 760K Workers From Xerox, Nokia, BofA, Morgan Stanley and More Dumped Online

Ransomware Attack Disrupts Operations at U.S. Contractor ENGlobal

Indian Online ID Verification Firm Signzy Confirms Security Incident

Arthur Center Community Health (MO) Files Notice of Data Breach with Federal Government

Horns&Hooves Campaign Delivers RATs via Fake Emails and JavaScript Payloads

Cloudflare’s Developer Domains Increasingly Abused by Threat Actors

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise

Exploit Released for Critical WhatsUp Gold RCE Flaw, Patch Now

Veeam Warns of Critical RCE Bug in Service Provider Console

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

12/2/2024

France Accuses Azerbaijan of Online Manipulation Campaigns

German Intelligence Launches Task Force to Combat Foreign Election Interference

Chinese Lidar Sensors Pose Hacking Risk to U.S. Defense Equipment, Report Says

The Pressure Is on for Big Tech to Regulate the Broken Digital Advertising Industry

Malicious Ads in Search Results Are Driving New Generations of Scams

INTERPOL Arrests 5,500 in Global Cybercrime Crackdown, Seizes Over $400 Million

Korea Arrests CEO for Adding DDoS Feature to Satellite Receivers

Russia Sentences Hydra Dark Web Market Leader to Life in Prison

SEC Settles With an Industrial and Commercial Bank of China Unit Over Ransomware Attack, Imposes No Fine

Are You Being Tracked by an Airtag? Here’s How to Check
Costa Rica State Energy Company Calls in U.S. Experts to Help With Ransomware Attack

Retail Outages Drag Into Second Week After Blue Yonder Ransomware Attack

$300M Bitcoin Hack Forces Japanese Crypto Exchange DMM Bitcoin to Cease Operations

Clipper DEX Says Recent $450K Hack Wasn’t Caused by Private Key Leak

Crypto.com Launches Massive $2m Bug Bounty Program

Zane Benefits (UT) Sends Data Breach Letters Confirming Leaked SSNs

SmokeLoader Malware Campaign Targets Companies in Taiwan

AWS Launches an Incident Response Service to Combat Cybersecurity Threats

Incident Response Playbooks: Are You Prepared?

Apple Patents System for Identifying People When Facial Scans Aren’t Enough

11/29-12/1/2024

Cyber-Attacks Could Impact Romanian Presidential Race, Officials Claim

AI-Powered Fake News Campaign Targets Western Support for Ukraine and U.S. Elections

UN, International Orgs Create Advisory Body for Submarine Cables After Incidents

In the New Space Race, Hackers Are Hitching a Ride Into Orbit

In New Bitcoin Bull Market, It’s Time to Beware of the Same Old Crypto Scams

Met Police Apologises to Honeytrap Victims Over Email

UK Justice System Failing Cybercrime Victims, Cyber Helpline Finds

Wanted Russian Hacker ‘Wazawaka’ Linked to Hive and LockBit Ransomware Arrested

U.S. Citizen Florida Man Sentenced for Spying on Behalf of China’s Intelligence Agency
Uganda Confirms Cyberattack on Central Bank but Minimizes Extent of Breach

INC Ransom Claims Cyber-Attack on UK Children’s Hospital

RansomHub Claims to Net Data Hat-Trick Against Bologna FC

Phishing-as-a-Service “Rockstar 2FA” Targets Microsoft 365 Users with AiTM Attacks

Novel Phising Campaign Uses Corrupted Word Documents to Evade Security

SpyLoan Android Malware on Google Play Installed 8 Million Times

New Windows Server 2012 Zero-Day Gets Free, Unofficial Patches

Tor Needs 200 New Webtunnel Bridges to Fight Censorship

Bulgarians Plead Guilty to Spying for Russia Using ‘Advanced Technology’