1/19/2022

Biden Administration Sets New Requirements for U.S. Secure Networks

Official Beijing 2022 Olympics Mobile App Is Marred by Security Flaws, Researchers Say

UK’s Cyber Security Center Publishes New Guidance to Fight Smishing

Cloned Dept. of Labor Site Hawks Fake Government Contracts

CISA Urges U.S. Orgs to Prepare for Data-Wiping Cyberattacks

Krebs: IRS Will Soon Require Selfies for Online Access

Facebook Messenger: The Battle Over End-To-End Encryption

Europe’s Move Against Google Analytics Is Just the Beginning

Man Charged with Smuggling Tech Exports to Iran

Interpol and Nigerian Police Bust Cybercrime BEC Ring
Red Cross Hit With Cyberattack That Compromised Data of 515,000 ‘Highly Vulnerable People’

Marketing Giant RR Donnelly Confirms Data Theft in Conti Ransomware Attack

Aditya Birla Fashion Says Back After Data Breach; Hackers Say Site Still Vulnerable

Visalia Unified School District (CA) Says ‘Ransomware Attack Failed’

Russian Hackers Heavily Using Malicious Traffic Direction System to Distribute Malware

New BHUNT Malware Targets Your Crypto Wallets and Passwords

Microsoft: SolarWinds Fixes Serv-U bug Exploited for Log4j Attacks

Deloitte Launches New SaaS Cyber Threat Detection and Response Platform

Ukraine: Cyber Warfare — Call It What It Is

1/18/2022

Israel Police Uses NSO’s Pegasus to Spy on Citizens

U.S. Aims Sanctions at Pro-Russian Agents as Blinken Plans Ukraine, Russia Meetings

Poland Raises Cybersecurity Terror Threat After Ukraine Cyber Attack

Gloucester Council Cyber Attack Linked to Russian Hackers

From 6G to Big Data, China Is Looking to Boost Tech’s Share of Its Economy

Beijing 2022 Winter Olympics App Bursting With Privacy Risks

Winter Olympics: Athletes Advised to Use Burner Phones in Beijing

Airlines Warn of ‘Catastrophic’ Crisis When New 5G Service Is Deployed

Drugmaker Gilead Alleges Counterfeiting Ring Sold Its HIV Drugs

Will 2022 Be the Year of the Software Bill of Materials?

Half of Global Cyber Defence Investment Has Been in Israel -PM Bennett

Europol Shuts Down VPNLab, Cybercriminals’ Favourite VPN Service

Democrats Propose Bill to Ban “Surveillance Advertising”
Parasol’s Sister Firms, SJD Accountancy and Nixon Williams, Confirm Cyberattack

Fashion Giant Moncler Confirms Data Breach After Ransomware Attack

Entira Family Clinics (MN) Notifies Patients of Data Breach 1 Year Later

Oscar Health Notifies Members of Data Breach

Crypto.com Acknowledges ‘Unauthorized Activity’ on Servers, Maintains No Funds Lost

Telegram Is a Hotspot for the Sale of Stolen Financial Accounts

Cybercriminals Actively Target VMware vSphere with Cryptominers

‘White Rabbit’ Ransomware May Be FIN8’s Latest Tool

Researchers Bypass SMS-based Multi-Factor Authentication Protecting Box Accounts

‘Zero-Click’ Zoom Vulnerabilities Could Have Exposed Calls Raises Concerns

Microsoft Issues Out-of-Band Update for Patch Tuesday Problems

Organizations Face a ‘Losing Battle’ Against Vulnerabilities

Open Source Developers, Who Work for Free, Are Discovering They Have Power

1/17/2022

Destructive Hacks Against Ukraine Echo Its Last Cyberwar

Cyber Espionage Campaign Targets Renewable Energy Companies

DHL, Microsoft, WhatsApp Top Phishing List of Most Imitated Brands

Nintendo Warns of Spoofed Sites Pushing Fake Switch Discounts

Firefox Relay’s Addition to Disposable Email Blocklist Upsets Users
Umbrella Company Parasol Group Confirms Cyber Attack as ‘Root Cause’ of Prolonged Network Outage

UK – Brookson Legal Hit by Cyber-Attack, Confirms No Data Was Removed

Jackson Hospital (FL) Fends off Recent Ransomware Attack

Microsoft: Edge Will Mitigate ‘Unforeseen Active’ Zero Day Bugs

Zoho Patches New Critical Authentication Bypass in Desktop Central

Chrome Limits Websites’ Direct Access to Private Networks for Security Reasons

1/14-16/2022

Krebs: At Request of U.S., Russia Rounds Up 14 REvil Ransomware Affiliates

Biden Administration Says Russia Arrested Colonial Pipeline Hacker

What Russia’s Arrest of REvil Hackers Means for Ransomware

Ukraine: ‘Massive Cyber Attack’ Shuts Down Government Websites

Hackers Likely Used Software Administration Rights of Third Party to Hit Ukrainian Sites, Kyiv Says

Some Signs That Cyber Attack Linked to Hacker Groups Associated With Russia

Ukraine Suspects Group Linked to Belarus Intelligence Over Cyberattack

Microsoft: Fake Ransomware Targets Ukraine in Data-Wiping Attacks

No Lights, No Heat, No Money – That’s Life in Ukraine During Cyber Warfare

U.S. Offers Support After Ukraine Hit By Massive Cyberattack

U.S. Considers Backing an Insurgency if Russia Invades Ukraine

Researchers Develop CAPTCHA Solver to Aid Dark Web Research

The Race Towards Renewable Energy Is Creating New Cybersecurity Risks

States Push Forward With Facebook Antitrust Case, Reportedly Probe VR Unit

Former DHS Official Charged With Stealing Gov’t Employees’ PII

Prosecutors Recommend Dropping Case Over China Ties Against MIT Scientist
Defense Contractor Hensoldt Confirms Lorenz Ransomware Attack

Goodwill Discloses Data Breach on Its ShopGoodwill Platform

Crawford County (AR) Grappling With Ransomware Attack Aftermath

Multi-Day IT Systems Outage Whacks Umbrella Biz Parasol Group Amid Fears of a Cyber Attack

Google Might’ve Accidentally Approved an Ad for a Target Gift Card Scam

eNom Data Center Migration Mistakenly Knocks Sites Offline

npm Dependency Is Breaking Some React Apps Today — Here’s the Fix

Watch Out, That Microsoft Edge Update Is Actually Ransomware

QLocker Ransomware Returns to Target QNAP NAS Devices Worldwide

Safari 15 Bug Can Leak Your Recent Browsing Activity and Personal Identifiers

Three Plugins With Same Bug Put 84k WordPress Sites at Risk

Critical Cisco Contact Center Bug Threatens Customer-Service Havoc

Flaw Found in IDEMIA Biometric ID Devices

New Intel Chips Won’t Play Blu-Ray Disks Due to SGX Deprecation

The Cybersecurity Measures CTOs Are Actually Implementing

Why Is Data Destruction the Best Way to Impede Data Breach Risks?

If You Use The Same Password Everywhere, This is For You

1/13/2022

Apple, Amazon Executives to Meet With White House to Discuss Software Security

Google Calls for New Government Action to Protect Open-Source Software Projects

FCC Proposes New Data Breach Rules for Phone Companies

NSO Group Spyware Targeted Dozens of Reporters in El Salvador

North Korean Hackers Stole Almost $400M in Cryptocurrency in 2021

BlueNoroff Hackers Steal Crypto Using fake MetaMask Extension

Ukrainian Cops Nab Husband and Wife Suspected to Be Part of $1M Ransomware Operation

Florida Woman Vice Principal Charged with Cyber-Stalking

Carding Site UniCC Retires After Generating $358 Million in Sales

How Cryptojacking Can Raise Your Energy Bills

Cybersecurity Labels for Products?
North Port (FL) Officials Investigate Potential Hack on City Network

New GootLoader Campaign Targets Accounting, Law Firms

Adobe Cloud Abused to Steal Office 365, Gmail Credentials

Researchers Decrypted Qakbot Banking Trojan’s Encrypted Registry Keys

Microsoft Defender Weakness Lets Hackers Bypass Malware Detection

Microsoft Yanks Buggy Windows Server Updates

Windows ‘RemotePotato0’ Zero-day Gets An Unofficial Patch

Android Users Can Now Disable 2G to Block Stingray Attacks

AWS Fixes Security Flaws That Exposed AWS Customer Data

New Vulnerabilities Highlight Risks of Trust in Public Cloud

1/12/2022

U.S. Links MuddyWater Hacking Group to Iranian Intelligence Agency

Hackers Take Over Diplomat’s Email, Target Russian Deputy Minister

Teen Hacker Claims Ability to Control 25 Teslas Worldwide

The Latest Phishing Scam: Fraudulent QR Codes on Parking Meters

Stolen TikTok Videos, Bent on Fraud, Invade YouTube Shorts

Krebs: Who is the Network Access Broker ‘Wazawaka?’

Inside the December Ransomware Hit at Nordic Choice Hotels

EU to Stage Large-Scale Cyberattack Exercise on Supply Chains

The ESA Wants You to Hack Its Satellite for Cybersecurity Reasons

Two Years for UK Man Who Used RATs to Spy on Women and Children
Medical Review Institute of America (MRIoA) Reports Data Breach

FIFA Ultimate Team Account Takeovers Plague EA Gamers

Cyber Attack Causes Albuquerque Public Schools to Cancel Classes Thursday

Ransomware to Blame for Maryland Department of Health Service Delays

OceanLotus Hackers Turn to Web Archive Files to Deploy Backdoors

Magniber Ransomware Using Signed APPX Files to Infect Systems

TellYouThePass Ransomware Returns as a Cross-platform Golang Threat

Amazon, Azure Clouds Host RAT-ty Trio in Infostealing Campaign

Widespread, Easily Exploitable Windows RDP Bug Opens Users to Data Theft

Apple Fixes doorLock Bug That Can Disable iPhones and iPads

1/11/2022

World Economic Forum: Cybersecurity an Increasing Global Threat

CISA Alerts Federal Agencies of Ancient Bugs Still Being Exploited

CISA: Russian State-Sponsored Groups Exploited Vulnerabilities in Microsoft, Cisco, Oracle Tools

New RedLine Malware Version Spread as Fake Omicron Stat Counter

DDoS Attacks That Come Combined With Extortion Demands Are on the Rise

Kaspersky Research Uncovers Cybersecurity Budgets, Insurance, and Vendor Expectations for 2022

Top Jobs in the U.S.: Information Security Analyst, #1

Moxie Marlinspike Leaves Encrypted-Messaging App Signal

Medigate Acquired by Claroty

Pentera Announces $150M Series C at $1 Billion Valuation to Disrupt Legacy Vulnerability Management Market

A Missouri Reporter Is Getting Blamed For the Security Flaw He Exposed
FinalSite: No School Data Stolen in Ransomware Attack Behind Site Outages

Children’s Data Is Showing up More Often on the Dark Web

Bernalillo County (NM) Ransomware Attack Left Jail Offline, Leaving Inmates in Lockdown

‘Fully Undetected’ SysJoker Backdoor Malware Targets Windows, Linux & macOS

Millions of Routers Exposed to RCE by USB Kernel Bug

Four Million Outdated Log4j Downloads Were Served From Apache Maven Central Alone Despite Vuln Publicity Blitz

Critical SonicWall NAC Vulnerability Stems from Apache Mods

State Hackers APT35 Use New PowerShell Backdoor in Log4j Attacks

Night Sky Ransomware Uses Log4j Bug to Hack VMware Horizon Servers

Firefox Focus Now Blocks Cross-Site Tracking on Android Devices

Krebs: ‘Wormable’ Flaw Leads January 2022 Patch Tuesday

1/10/2022

Cyber-Spike 2021: Orgs Suffer 925 Attacks per Week, an All-Time High

CISA Director: ‘We Have Not Seen Significant Intrusions’ From Log4j…. Yet

Extortion DDoS Attacks Grow Stronger and More Common

‘PatchWork’ Cyberspies Infect Themselves With Their Own Malware, Exposing Operations

Why Politically Motivated Cyber-Attacks Are a Threat to Democracy

The End of Car Keys, Passwords and Fumbling With Your Phone at Checkout

Castor, Schakowsky Seek Information on Children’s Online Safety Program

Europol Ordered to Erase Data on Those Not Linked to Crime

UK Jails Forensics Expert Who Kept Murder Snaps on PC
Cyber-Thieves Raid Grass Valley (CA)

Loyola Medical Center (IL) Email Breach Exposes Nearly 17,000 Patients’ Info

Singapore Retailer OG Hit by Data Breach

Ragnar_Locker Claims Successful Hack Of Broomfield (CO) Cybersecurity Firm

Panasonic Says Hackers Accessed Personal Data of Job Candidates During November Attack

Abcbot Botnet Linked to Operators of Xanthe Cryptomining Malware

Linux Version of AvosLocker Ransomware Targets VMware ESXi Servers

URL Parsing Bugs Allow DoS, RCE, Spoofing & More

Microsoft: Powerdir Bug Gives Access to Protected macOS User Data

WordPress 5.8.3 Security Update Fixes SQL Injection, XSS Flaws

1/6-9/2022

Hackers Have Been Sending Malware-Filled USB Sticks to U.S. Companies Disguised as Presents

Trojanized dnSspy App Drops Malware Cocktail on Researchers, Devs

U.S. Counterintelligence Shares Tips to Block Spyware Attacks

China’s Next Regulatory Target — Algorithms, the Secret of Many Tech Giants’ Success

Walmart in China’s Spotlight Again as Regulator Cites Infractions

Monsanto Employee Stole Trade Secret to Sell to China

EoL Systems Stonewalling Log4j Fixes for Fed Agencies

Attackers Exploit Flaw in Google Docs’ Comments Feature

Google Voice Authentication Scam Leaves Victims on the Hook

COVID Test Data Breach at British School

Krebs: Norton 360 Now Comes With a Cryptominer

Krebs: 500M Avira Antivirus Users Introduced to Cryptomining

This Tesla Owner Says He Mines up to $800 a Month in Cryptocurrency With His Car

France Fines Google, Facebook for Privacy Violations

Facebook Launches ‘Privacy Center’ to Educate Users on Data Collection and Privacy Options

Swiss Army Bans All Chat Apps but Locally-Developed Threema

U.S. Arrests Suspect Who Stole Unpublished Books in Phishing Attacks

Victims of $200 Million Hack of BitMart Crypto Exchange Still Waiting to Get Their Money Back

Iranian Immigrant Lost $53,000 in Crypto Hack, Says He Faces Ruin if BitMart Doesn’t Pay Him Back
Thousands of Schools Impacted After IT Provider Finalsite Hit by Ransomware

Cyberattackers Hit Data of 80K Patients at Fertility Centers of Illinois

Ciox Health Data Breach Affects ​​AdventHealth, Northwestern and 30 More Providers

3.7M FlexBooker Records Dumped on Hacker Forum

U.S. Online Pharmacy Ravkoo Links Data Breach to AWS Portal Incident

SonicWall: Y2K22 Bug Hits Email Security, Firewall Products

Night Sky Is the Latest Ransomware Targeting Corporate Networks

FluBot Malware Now Targets Europe Posing as Flash Player App

Dev Corrupts NPM Libs ‘Colors’ and ‘Faker’ Breaking Thousands of Apps

QNAP: Get NAS Devices Off the Internet Now

Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover

NHS Warns of Hackers Exploiting Log4Shell in VMware Horizon

Log4J-Related RCE Flaw in H2 Database Earns Critical Rating

Rapid Window Title Changes Cause ‘White Screen of Death’

Cybersecurity Training Isn’t Working. And Hacking Attacks Are Only Getting Worse

Cybersecurity Moving Forward: Four Big Things to Watch in 2022

1/5/2022

China Says Apps That Could Influence Public Opinion Require a Security Review

U.S. Army Journal’s Top Paper From 2021 Says Taiwan Should Destroy TSMC if China Invades

Progressives Put Pressure on Google

How Ransomware Gangs Went Pro

Defending Against Modern Ransomware Tactics

Putting Ransomware Gangs Out of Business With AI

Why Words Matter In Cybersecurity

‘Bulli Bai’ Three Arrested in India for Online Harassment of Muslim Women

1.1M Compromised Accounts Found at 17 Major Companies: NY AG

70 Investors Lose $50 Million to Fraudsters Posing as Broker-Dealers

Crypto Platform ARBIX Flagged as a Rugpull, Transfers $10 Million
Canadian Heavy Equipment Maker Weldco-Beales Confirms Cyber Attack by Karakurt

Franklin Park Conservatory (OH) Experiences Data Breach; Notifying Affected Patrons

Bernalillo County (NM) Reports Suspected Ransomware Attack

Samoan Meteorology Service (SMS) Website May Have Suffered Cyber Attack

‘Elephant Beetle’ Lurks for Months in Networks

‘Malsmoke’ Exploits Microsoft’s E-Signature Verification Using Zloader

iOS Malware Can Fake iPhone Shut Downs to Snoop on Camera, Microphone

Google Chrome Update Includes 37 Security Fixes

Microsoft Defender for Endpoint Adds Zero-Touch iOS Onboarding

CrowdStrike Incorporates Intel CPU Telemetry Into Falcon Sensor

1/4/2022

FTC Warns Companies to Secure Consumer Data From Log4j Attacks

Fears Mount About Russian Cyberattacks in Ukraine

China to Make Some Firms Undergo a Data Security Review Before Listing Overseas

Coming to a Laptop Near You: A New Type of Security Chip From Microsoft: ‘Pluton’; AMD to Integrate Into Upcoming Ryzen CPUs

Upskilling, Better Training Keys to Increasing Cyber Talent Pool

Opportunity Not Fear: Reframing Cybersecurity to Build a Safer Net for All

Come the Metaverse, Can Privacy Exist?

Bulli Bai: India App That Put Muslim Women up for Sale Is Shut

Google Acquires its First Non-American Cybersecurity Firm Siemplify
Have I Been Pwned Warns of DatPiff Data Breach Impacting Millions

Data Skimmer Hits 100+ Sotheby’s Real Estate Websites

UScellular Discloses Data Breach After Billing System Hack

Cyberattack Hits Quasi-State Agency Illinois Office of the Special Deputy Receiver (OSD) For $6.8 Million

Montreal Tourism Agency Confirms Cyber Attack

Carthage Schools (MO) Confirm Ransomware Attack Caused Outage in December

McMenamins December Data Breach Affects 12 Years of Employee Info

SAILFISH System to Find State-Inconsistency Bugs in Smart Contracts

1/3/2022

Companies Face Stricter Cyber Rules in 2022

Novel Method for Detecting Evasive Malware on IoT Devices Using Electromagnetic Field Emanations

Log4j Highlights Need for Better Handle on Software Dependencies

Don’t Copy-Paste Commands From Webpages — You Can Get Hacked

Microsoft Skype Makes You Solve a Complex CAPTCHA 10 Times to Sign Up

Connecting the Dots on Diversity in Cybersecurity Recruitment

Creating the Next Generation of Secure Developers
UK Defence School Hit by Sick Cyber Attack by ‘Russia or China’ Causing ‘Significant’ Damage in Early 2021

Jerusalem Post Targeted by Pro-Iranian Hackers on Soleimani Assassination Anniversary

Portuguese Media Group Impresa Knocked Offline in Ransomware Attack

Purple Fox Malware Distributed via Malicious Telegram Installers

An Apple HomeKit Bug Can Send iOS Devices Into a Death Spiral

Microsoft Issues Fix for Exchange Y2K22 Bug That Crippled Email Delivery Service

12/31/2021-1/2/2022

Fake Vaccine Card Sales a Booming Business as Omicron Surges

The Biggest Data Breaches, Hacks of 2021

Top Cybersecurity and Tech Stories of 2021

Top 10 Healthcare Breaches in the U.S. Exposed Data of 19 Million

Copycat and Fad Hackers Will Be the Bane of Supply Chain Security in 2022

Tech That Will Change Your Life in 2022

Can Social Media Alter a War?
Cyber Attack Disrupts Gloucestershire Council’s Website

PulseTV Discloses Potential Compromise of 200,000 Credit Cards

Broward Health (FL) Suffers Data Breach, Including Medical Info, Through 3rd Party

Popular Q&A App Curious Cat Loses Domain, Posts Bizarre Tweets

Uber Ignores Vulnerability That Lets You Send Any Email From Uber.com

Netgear Leaves Vulnerabilities Unpatched in Nighthawk Router

12/30/2021

2021: Tech’s Big Year

An Amazon Lawsuit Encounters a Big Snag: A Judge With a Conflict of Interest

Confusing Data Breach in Rhode Island Leads to AG Investigation

In the Fight Against Cybercrime, Takedowns Are Only Temporary

Twitter Account of FBI’s Fake Chat App, ANOM Seen Trolling Today

Have I Been Pwned Adds 441k Accounts Stolen by Redline Malware
Kyoto University Loses 77TB of Research Data Due to Backup Error

Cyberattack Cripples Norway’s Amedia

Sega Narrowly Avoids Huge Data Breach, Thanks to Security Firm

Pick N Pay Denies Customer Data Was Exposed Online Despite ‘Glitch’

New iLOBleed Rootkit Targeting HP Enterprise Servers with Data Wiping Attacks

Firmware Attack Can Drop Persistent Malware in Hidden SSD Area

12/29/2021

Cyber Agency Warns of Increased Threats to Manufacturing Groups During Pandemic

Hackers Are Getting Better and Better at Defeating Your 2FA Security

One in Five Aged Domains Is Malicious, Risky, or Unsafe

Ransomware Gang AvosLocker Coughs up Decryptor After Realizing They Hit the Police

5 Cybersecurity Trends to Watch in 2022

6 Things in Cybersecurity We Didn’t Know Last Year

Happy 12th Birthday, KrebsOnSecurity.com!
China-Based ‘Aquatic Panda’ Infiltrated Academic Institution Through Log4j Vuln

Fintech Firm ONUS Hit by Log4j Hack Refuses to Pay $5 Million Ransom

Microsoft Defender Log4j Scanner Triggers False Positive Alerts

LastPass Says No Passwords Were Compromised Following Breach Scare

Cryptomining Attack Exploits Docker API Misconfiguration Since 2019

Polygon Justifies Its Quiet Hard-Fork Citing ‘Critical Vulnerability’

12/28/2021

Log4j 2.17.1 Out Now, Fixes New Remote Code Execution Bug

Biden Signs NDAA Relying on Voluntary Private-Sector Cybersecurity Collaboration

Congress Zooms in on Cybersecurity After Banner Year of Attacks

Washington Grapples With How to Expand Crypto Oversight

In 2022, Cybersecurity Will Be Linux and Other Open-Source Developers Real Job Number One

A Year in Microsoft Bugs: The Most Critical, Overlooked & Hard to Patch

RedLine Malware Shows Why Passwords Shouldn’t Be Saved in Browsers

LastPass Users Warned Their Master Passwords Are Compromised
T-Mobile Reportedly Suffers Another, Smaller Data Breach

Mon Health (WV) Reports Email Phishing Incident, Potential Data Breach

Security Breach at Duneland School Corp (IN)

Most of CompuGroup Medical’s Systems Back Online After Ransomware Attack

New Info States Pro Wrestling Tees Data Breach Occurred In April, Affected 31,000 People

New Flagpro Malware Linked to Chinese State-Backed Hackers ‘BlackTech’ APT

Experts Detail Logging Tool of DanderSpritz Framework Used by Equation Group Hackers

Riskware Android Streaming Apps Found on Samsung’s Galaxy Store

12/24-26/2021

Multiple Log4j Scanners Released by CISA, CrowdStrike

Faking a COVID-19 Vaccine Card in New York Can Now Get You a Year in Jail

Dridex Omicron Phishing Taunts With Funeral Helpline Number

From Airport WiFi to ‘Juice Jacking’: 7 Ways to Protect Your Data When Traveling

Russia Fines Google $100m Over “Illegal” Content

How to Avoid Falling Into China’s ‘Data Trap’
Global IT Services Provider Inetum Hit by Ransomware Attack

Android Banking Trojan Targeting Brazil’s Itaú Unibanco Spreads via Fake Google Play Store Page

Rook Ransomware Is Yet Another Spawn of the Leaked Babuk Code

Jackson Public Schools (MS) Ups Cybersecurity After 2020 Hacker Attack

Worst Hacks of 2021

BlackMagic Fixes Critical DaVinci Resolve Code Execution Flaws

12/23/2021

White House National Security Adviser Asks Software Companies to Discuss Cybersecurity

Consumers Warned of Surging Delivery Text Scams Ahead of Christmas

‘Spider-Man: No Way Home’ Download Installs Cryptominer

Phishing Victim Can’t Claim $5 Million Loss for Money It Never ‘Held’

Texas Man Convicted for BEC Scam on Idaho School District

Russian Hacker’s $1.7M Restitution Order Overturned

Russian Social Media Platform VK Introduces 2FA and Plans to Make It Mandatory in 2022

7 of the Most Impactful Cybersecurity Incidents of 2021
Albanian Prime Minister Apologizes Over Database Leak

Telegram Abused to Steal Crypto-Wallet Credentials

Phishing Campaign Targets CoinSpot Cryptoexchange 2FA Code

Stealthy BLISTER Malware Slips in Unnoticed on Windows Systems

AvosLocker Ransomware Reboots in Safe Mode to Bypass Security Tools

Fisher Price’s Bluetooth Reboot of Pre-school Play Phone Has Adult Privacy Flaw

Apple Fixes macOS Security Flaw Behind Gatekeeper Bypass

12/22/2021

VP Harris Calls for ‘Cyber Doctrine’ to Address Increasing Attacks

Five Eyes Nations Warn of Cyber Threats From Apache Log4j Vulnerability

NVIDIA Discloses Applications Impacted by Log4j Vulnerability

Log4j Flaw: Attackers Are ‘Actively Scanning Networks’ Warns New CISA Guidance

Log4j Reveals Cybersecurity’s Dirty Little Secret

China Suspends Cloud Deal With Alibaba for Not Sharing Log4j 0-Day First With the Government

UK Cybercrime Cops Arrest NHS Workers

Rideshare Account Hacker Faces up to 22 Years in Prison

Honeypot Experiment Reveals What Hackers Want From IoT Devices
BEC Attack on Monongalia Health (WV) System

Ubisoft Reveals Player Data Breach Came from User Error

NJ Volunteer EMS Agency Says Patient Data Was Breached

Dridex Malware Trolls Employees With Fake Job Termination Emails

Microsoft Azure App Service Flaw Exposed Customer Source Code

Microsoft Teams Bug Allowing Phishing Unpatched Since March

Opera Browser Working on Clipboard Anti-hijacking Feature

12/21/2021

A UAE Agency Put Pegasus Spyware on Phone of Jamal Khashoggi’s Wife Months Before His Murder, New Forensics Show

Polish Opposition Duo Roman Giertych and Ewa Wrzosek Hacked With NSO Group Pegasus Spyware

DHS Expands Bug Bounty Program to Encourage Hunting Down Apache Log4j Vulnerability

Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look

We’re Starting to See a National Response to Ransomware, Says Mandiant CEO

This Security Researcher Fooled an At-Home COVID-19 Test Using a Bluetooth Hack

Threat Actors Steal $80 Million per Month With Fake Giveaways, Surveys

U.S. Returns $154 Million in Bitcoins Stolen by Sony Employee

2Easy Now a Significant Dark Web Marketplace for Stolen Data

Prominent Harvard Professor Charles Lieber Found Guilty of Lying About China Ties
City of Denver Hit By Cyber Attack Targeting Kronos

Saskatoon Airport Computer System Hit by a Cyber Attack

Ghana NSS Allegedly Hit by Data Breach as 700,000 People’s Documents Leak Online

Scammers Steal $150k Worth of Crypto From NFT Project Fractal With Discord Hack

PYSA Ransomware Behind Most Double Extortion Attacks in November

800k WordPress Sites Still Impacted by Critical SEO Plugin Flaw

Secret Backdoors Found in German-made Auerswald VoIP System

Garrett Walk-Through Metal Detectors Can Be Remotely Manipulated

Windows 10 21H2 Adds Ransomware Protection to Security Baseline

12/20/2021

Belgian Defense Ministry Hacked by Attackers Exploiting Apache Log4j Vulnerability

Log4j Vulnerability Now Used to Install Dridex Banking Malware

2021: The Year Hackers Went Wild and Changed Everything

Phishing Attacks Impersonate Pfizer in Fake Requests for Quotation

UK Donates 225 Million Stolen Passwords to Hack-Checking Site Have I Been Pwned 

Robocalls More Than Doubled in 2021, Cost Victims $30B

Google & Meta to Protect Data on Undersea Cable

Meta Sues People Behind Facebook and Instagram Phishing

Justice Department Indicts Russian Hacker for Allegedly Participating in Trading Scheme
Cyber-Attack Impacts Aussie Companies

Clop Ransomware Gang Publish Confidential UK Police Data on the Dark Web

Police National Computer Not Pwned by Clop Ransomware Crims, Insists Home Office

Texas Ear, Nose and Throat Specialists (Texas ENT) Alerts 535,000 Patients to Data Breach

Capital Region Medical Center (MO) Reports System-Wide Network Outage

Industrial Construction Company Basil Read Hit by Ransomware Attack

FBI: State Hackers Exploiting New Zoho Zero-Day Since October

New Mobile Network Vulnerabilities Affect All Cellular Generations Since 2G

Microsoft Warns of Easy Windows Domain Takeover via Active Directory Bugs

12/17-19/2021

Federal Agencies Ordered to Immediately Patch Systems Against Apache Vulnerability

Apache Issues 3rd Patch to Fix New High-Severity Log4j Vulnerability

Buckle Up for More Log4j Madness

Security Firm Blumira Discovers Major New Log4j Attack Vector

TellYouThePass Ransomware Revived in Linux, Windows Log4j Attacks

Conti Ransomware Uses Log4j Bug to Hack VMware vCenter Servers

CISA Urges VMware Admins to Patch Critical Flaw in Workspace ONE UEM

U.S. Distrust of Huawei Linked in Part to Malicious Software Update in 2012

Backdoor Gives Hackers Complete Control Over Unnamed Federal Agency Network

Neuberger: Change Your Passwords Now
Western Digital Warns Customers to Update Their My Cloud Devices

Grim Finance Targeted by ‘Advanced’ Hack; Losses of Over $30 Million

Credit Card Info of 1.8 Million People Stolen From Sports Gear Sites

Pro Wrestling Tees Owner Confirms Data Breach, Provides Details in Press Release

Cyberattack on Payroll Provider Kronos Sets Off Scramble Ahead of Holidays

Logistics Giant Hellmann Worldwide Warns of BEC Emails Following Ransomware Attack

Meta Says 50,000 Facebook Users May Have Been Spied on by Private Surveillance Firms

Spider-Man Movie Release Frenzy Bites Fans with Credit-Card Harvesting

Malicious Joker App Scores Half-Million Downloads on Google Play

12/16/2021

Log4j Flaw: This New Threat Is Going to Affect Cybersecurity for a Long Time

Officials Point to Apache Vulnerability in Urging Passage of Cyber Incident Reporting Bill

U.S. Concerns Grow Over Potential Russian Cyber Targeting of Ukraine Amid Troop Buildup on Border

Russia Proposes Holding Collective Cybersecurity Talks With EU

Prominent Egyptian Opposition Activist’s Phone Hacked – Watchdog

Google Calendar Now Lets You Block Invitation Phishing Attempts

Hive Ransomware Enters Big League With Hundreds Breached in Four Months

Meta Bans Surveillance-For-Hire Firms for Targeting FB Users

Japan Draws a LINE: Web Giants Must Reveal Where They Store User Data

France Orders Clearview AI to Delete Data

Krebs: NY Man Pleads Guilty in $20 Million SIM Swap Theft

Firefox Users Can’t Reach Microsoft.com — Here’s What to Do
Log4j Attackers Switch to Injecting Monero Miners via RMI

Microsoft: Khonsari Ransomware Hits Self-Hosted Minecraft Servers

McMenamins Breweries Hit by a Conti Ransomware Attack

Gumtree Classifieds Site Leaked Personal Info via the F12 Key

Sennheiser Exposed 28,000 Customers’ Data Online 

‘Tropic Trooper’ Reemerges as ‘Earth Centaur’ to Target Transportation Outfits

‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K Systems

Phorpiex Botnet Returns With New Tricks Making It Harder to Disrupt

‘DarkWatchman’ RAT Shows Evolution in Fileless Malware

Researchers Uncover New Coexistence Attacks On Wi-Fi and Bluetooth Chips

Lenovo Laptops Vulnerable to Bug Allowing Admin Privileges

12/15/2021

Google Warns That NSO Hacking Is On Par With Elite Nation-State Spies

CISA Warns Critical Infrastructure to Stay Vigilant for Ongoing Threats

Inside the UK Government’s Secret Data Room

Zoom Joins Counterterrorism Tech Group

Facebook to Pay Hackers for Reporting Data Scraping Bugs & Scraped Datasets

Large-Scale Phishing Study Shows Who Bites the Bait More Often

CoinMarketCap Suffers a Seeming Hack, Falsely Driving Crypto Prices to Tens of Billions
Hackers Backed by China Seen Exploiting Log4J Security Flaw in Internet Software

Iran Also Among Those Exploiting Apache Cyber Vulnerability, Researchers Say

Global Fight Against Log4j Vulnerability Relies on Apache Volunteers

Apache’s Fix for Log4Shell Can Lead to DoS Attacks

State-Sponsored Hackers Abuse Slack API to Steal Airline Data

Emotet Starts Dropping Cobalt Strike Again for Faster Attacks

Sites Hacked With Credit Card Stealers Undetected for Months

12/14/2021

DHS Announces Bug Bounty Program to Hunt Down Cyber Vulnerabilities

USPS Secretly Built & Tested Mobile Voting System Before 2020

Hackers Launch Over 840,000 Attacks Through Log4J Flaw

Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

Second Log4j Vulnerability Discovered, Patch Already Released

Log4j: List of Vulnerable Products and Vendor Advisories

CISA Orders Federal Agencies to Patch Log4Shell by December 24th

‘Seedworm’ Attackers Target Telcos in Asia, Middle East

Microsoft Rolls Out End-To-End Encryption for Teams Calls

Popular Password Manager LastPass to be Spun Out From LogMeIn

Krebs: Inside Ireland’s Public Healthcare Ransomware Scare
Hackers Steal $140 Million From Users of Crypto Gaming Company VulcanForge

Cyberattack on BHG Opioid Treatment Network Disrupts Patient Care

George Washington University Cyberattack During Finals Upends Law Students’ Study Plans

Superior Plus Hit by Ransomware Attack

Honolulu Board of Water Supply, Emergency Medical Services Report Attacks on Employee Data

After Cyber Attack, Maryland Department of Health Website Still Missing COVID Metrics

400 Banks’ Customers Targeted with Anubis Trojan

New PS4 Homebrew Exploit Points to Similar PS5 Hacks to Come

Hackers Steal Microsoft Exchange Credentials Using IIS Module

Apple iOS Update Fixes Cringey iPhone 13 Jailbreak Exploit

Microsoft Fixes Windows AppX Installer Zero-Day Used by Emotet

Krebs: Microsoft Patch Tuesday, December 2021 Edition

12/13/2021

Hackers Start Pushing Malware in Worldwide Log4Shell Attacks

Log4Shell Flaw Prompts 100 Hack Attacks a Minute, Check Point Says

Log4Shell Is Spawning Even Nastier Mutations

Log4j Software Vulnerability Expected to Persist, Possibly for Months

Bugs in Billions of WiFi, Bluetooth Chips Allow Password, Data Theft

Hackers Target India’s Prime Minister Twitter Account with Fake Bitcoin Message

Romanian Ransomware Suspect Arrested Over Attacks on ‘High-Profile’ Organisations

Ex-NFL Player Joshua Bellamy Gets Three Years for #COVID19 Fraud

Ukraine Arrests 51 for Selling Data of 300 Million People in U.S., EU

CSAM Found on LSU Professor’s Computer
The State of U.S. Cybersecurity a Year After the SolarWinds Hack

Kronos Ransomware Outage Drives Widespread Payroll Chaos

Timekeeping Biz Kronos Hit by Ransomware and Warns Customers to Engage Biz Continuity Plans

Virginia Assembly IT Agency Hit With Ransomware Attack

TinyNuke Info-Stealing Malware Is Again Attacking French Users

Phishing Campaign Uses PowerPoint Macros to Drop Agent Tesla

Malicious PyPI Code Packages Rack Up Thousands of Downloads

Attackers Can Get Root by Crashing Ubuntu’s AccountsService

Telehealth Platform Doxy.me Fixing Issue That Exposed Patient Data

Google Pushes Emergency Chrome Update to Fix Zero-Day Used in Attacks

Dell Driver Fix Still Allows Windows Kernel-Level Attacks

12/10-12/2021

Officials, Experts Sound the Alarm About Critical Cyber Vulnerability

Press for Actionable Recommendations From New Cyber Advisory Committee

‘Karakurt’ Extortion Threat Emerges, But Says No to Ransomware

‘Appalling’ Riot Games Job Fraud Takes Aim at Wallets

Phishing Attacks Use QR Codes to Steal Banking Credentials

FTC: Americans lost $148 million to gift card scams this year

Australian Gov’t Raises Alarm Over Conti Ransomware Attacks

Irish Health Cyber-Attack Could Have Been Even Worse, Report Says

Happened After One Staffer Opened Malware-Ridden Email

C-Suite’s Biggest Ransomware Fear: Post-attack Regulatory Sanctions

Bitcoin Mining Has Totally Recovered From Chinese Ban

UK Court Paves Way for Julian Assange’s Extradition to the U.S.
Volvo Hit by Cyber-thieves, R&D Stolen

Brazilian Ministry of Health Suffers Cyberattack and COVID-19 Vaccination Data Vanishes

Crypto Exchange AscendEX Suspends Services After $77 Million Hack

Data Breach Impacts 80,000 South Australian Gov’t Employees

Sprawling Active Attack Aims to Take Over 1.6M WordPress Sites

Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack

‘Enterprise Nightmare’

Minecraft Rushes Out Patch for Critical Log4j Vulnerability

Researchers Release ‘Vaccine’ for Critical Log4Shell Vulnerability

Microsoft: These are the building blocks of QBot malware attacks

Mozilla Rolls Out GPC for All Firefox Users, but Enforcement Limited to Two States

Earlier Schreiber Cyber Attack Causes Cream Cheese Shortage as Christmas Nears

12/9/2021

U.S. to Tighten Restrictions on Exports of Malicious Cyber Tools

DARPA Announces SMOKE Program

Fueled by Pandemic Realities, Grinchbots Aggressively Surge in Activity

ALPHV Blackcat – This Year’s Most Sophisticated Ransomware

Fujitsu Pins Japanese Gov’t Data Breach on Stolen ProjectWEB Accounts

Amazon Fined $1.3 Billion in Italian Antitrust Case

A Third of You Slackers Out There Still Aren’t Using HTTPS by Default

Microsoft Previews New Endpoint Security Solution for SMBs

Kali Linux 2021.4 Released With 9 New Tools, Further Apple M1 Support
Cox Communications Discloses Data Breach After Hacker Impersonates Support Agent

Hellmann Worldwide Logistics Hit by Cyber Attack

Suspected Cyberattack Kicks Honolulu City Bus, Handi-Van Systems Offline

Butler County Community College (PA) Cooperating With FBI After Ransomware Attack

Bay Village High School (OH) Staff Member Retiring After Private Records Released for Entire Senior Class

Dark Mirai Botnet Targeting RCE on Popular TP-Link Router

Malicious Notepad++ Installers Push StrongPity Malware

How MikroTik Routers Became a Cybercriminal Target

Microsoft, Google OAuth Flaws Can Be Abused in Phishing Attacks

SanDisk SecureAccess Bug Allows Brute Forcing Vault Passwords

Windows ‘InstallerFileTakeOver’ Zero-Day Bug Gets Free Micropatch

12/8/2021

Beijing Reins In China’s Central Bank

Tor’s Main Site Blocked in Russia as Censorship Widens

Vietnamese ‘XE Group’ Exposed for Eight Years of Hacking, Credit Card Theft

Over 40 Million People Had Health Information Leaked This Year

Cybersecurity Can Pose a Risk in More Than One Way for Financial Advisors

Coinbase Customers Demand Refunds Over GYEN Stablecoin Glitch

Krebs: Canada Charges Its “Most Prolific Cybercriminal”

Amazon Is Shutting Down Web Ranking Site Alexa.com

Microsoft: Secured-Core Servers Help Prevent Ransomware Attacks
Israel’s National Insurance Institute Hacked in Dos Attack

Two Data Breaches at Sound Generations (WA) Senior Care Nonprofit Impact 103K

Emotet Now Drops Cobalt Strike, Fast Forwards Ransomware Attacks

Hackers Infect Random WordPress Plugins to Steal Credit Cards

Moobot Botnet Chews Up Hikvision Surveillance Systems

Malicious npm Code Packages Built for Hijacking Discord Servers

Critical SonicWall VPN Bugs Allow Complete Appliance Takeover

GraphQL API Authorization Flaw Found in Major B2B Financial Platform