4/26/2023

Evasive Panda’s Backdoor MgBot Delivered Via Chinese Software Updates

Tencent QQ Users Hacked in Mysterious Malware Attack, Says ESET

Alloy Taurus Hackers Update PingPull Malware to Target Linux Systems

Charming Kitten’s New BellaCiao Malware Discovered in Multi-Country Attacks

Ukrainian Arrested for Selling Data of 300M People to Russians

DoJ, Treasury Accuses 3 Men of Laundering Crypto for North Korea

Google Disrupts the CryptBot Info-Stealing Malware Operation

Cyber Chiefs Forge Partnerships With Physical Security Units as Combined Threats Grow

A U.S. Bill Would Ban Kids Under 13 From Joining Social Media

Tinder Is Implementing Video Verification to Further Curb Creepy Scammers

Microsoft Probes Complaints of Edge Leaking Urls to Bing
HR Firm StaffScapes Discloses Data Breach

Astral Brands Discloses Data Breach

Cyberattack Disrupts Lowell (MA) City Government, Shuts Down Computers

Truman State University (MO) Slowly Recovering From ‘Cybersecurity Virus Attack’

Students’ Psychological Reports, Abuse Allegations Leaked by Minneapolis Schools Ransomware Hackers

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

Cisco Discloses XSS Zero-Day Flaw in Server Management Tool

PrestaShop Fixes Bug That Lets Any Backend User Delete Databases

Critical Flaw Patched in VMware Workstation and Fusion

Google will add End-to-End encryption to Google Authenticator

Effects of the Hive Ransomware Group Takedown

There’s No Silver Bullet for Cybersecurity

4/25/2023

Lazarus Subgroup Targeting Apple Devices with New RustBucket macOS Malware

Iranian Hackers “Educated Manticore” Target Israel With New Tools

U.S. Sent Teams into Foreign Networks to Hunt SolarWinds, Microsoft Hackers

A Security Team Is Turning ‘Gootloader’ Malware Gang’s Tricks Against It

Zero Trust for Zoom Calls: ChromeOS Getting Universal Microphone/Camera Toggles

OpenAI Rolls Out ‘Incognito Mode’ on ChatGPT

Google Authenticator Now Backs up Your 2FA Codes to the Cloud

Prince William Got ‘Very Large Sum’ in Phone Hack Settlement
Data Security Breach May Have Left Jewel-Osco Employees’ Information Exposed

CIC Group Notifies Individuals of Recent Data Breach

IMA Financial Group (KS) Files Notice of 2022 Data Breach

PaperCut Says Hackers Are Exploiting ‘Critical’ Security Flaws in Unpatched Servers

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

TP-Link Archer WiFi Router Flaw Exploited by Mirai Malware

VMware Fixes Critical Zero-Day Exploit Chain Used at Pwn2Own

When Companies Get Stuck In A Cybersecurity Loop

4/24/2023

3CX Hackers Also Compromised Critical Infrastructure Firms

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers

Tomiris and Turla APT Groups Collaborate to Target Government Entities

Google Debuts Cybersecurity-Focused AI System

Intel Let Google Cloud Hack New Secure Chips and Found 10 Bugs

Google Authenticator Finally, Mercifully Adds Account Syncing for Two-Factor Codes

VirusTotal Now Has an AI-Powered Malware Analysis Feature

Cloud Complexity Means Bugs Are Missed in Testing

Scammers Impersonate Meta in Facebook Campaign With 3200 Profiles

Intel CPUs Vulnerable to New Transient Execution Side-Channel Attack

APC Warns of Critical Unauthenticated RCE Flaws in UPS Software
U.S. Navy Contractor Fincantieri Marine Group Hit by Cyber-attack

Yellow Pages Canada Confirms Cyber Attack as Black Basta Leaks Data

San Bernardino County Sheriff’s Office Struggling to Recover From ‘Malware’ Incident

Albertsons Companies Files Notice of Data Breach Following Malware Attack

Gateway Casinos Confirms IT Outage Caused by a Ransomware Cyberattack

Robeson Health Care Corporation Reports Data Breach Affecting Over 15k Individuals

KuCoin’s Twitter Account Hacked to Promote Crypto Scam

Naivas Confirms Cyber Attack on Systems by a Criminal Organization

Hacker Demands Ransom After ‘Taking Control’ of Wiltshire School’s IT

Microsoft 365 Search Outage Affects Outlook, Teams, and Sharepoint

Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD Attack

4/21-23/2023

European Air Traffic Control Confirms Website ‘Under Attack’ by Pro-Russia Hackers

Russian Mercenaries Sympathetic to Putin Target UK With Cyber Threats Over War in Ukraine

China Developing Anti-Satellite Weapons

Biden’s Order Against Commercial Spyware Is ‘Upsetting the Market’

Hacker Group Names Are Now Absurdly Out of Control

The Car Thieves Using Tech Disguised Inside Old Nokia Phones and Bluetooth Speakers

Krebs: 3CX Breach Was a Double Supply Chain Compromise

North Korea’s Kimsuky APT Keeps Growing, Despite Public Outing

Mullvad VPN Maker Says Police Tried to Raid Its Offices but Couldn’t Find Any User Data

ChatGPT Won’t Take Over From Humans for Now, Says Infosys Founder

Google Bard Can Now Help Write Software Code

When Apple Comes Calling, ‘It’s the Kiss of Death’
American Bar Association Data Breach Hits 1.4 Million Members

Accounting Firm Rubino & Company Files Official Notice of Data Breach

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

Lily Collins — The Hack, Not the Actress — Wants Your Facebook Account

University Websites Using MediaWiki, TWiki Hacked to Serve Fortnite Spam

Evil Extractor Targets Windows Devices to Steal Sensitive Data

Trojanized Installers Used to Distribute Bumblebee Malware

Decoy Dog Malware Toolkit Found After Analyzing 70 Billion DNS Queries

GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

GitHub Now Allows Enabling Private Vulnerability Reporting at Scale

Intel Prioritizes Security in Latest vPro Chips

The Tangled Web of IR Strategies

4/20/2023

3CX Hack Caused by Supply Chain Attack at Stock Trading Automation Company Trading Technologies

Google: Ukraine Targeted by 60% Of Russian Phishing Attacks in 2023

Consumer Financial Protection Bureau Says Employee Breached Data of 250,000 Consumers in ‘Major Incident’

Lawmakers Introduce Bill to Counter Chinese Cyber Threats Against Taiwan

Huawei Launches In-House Software System After Being Cut Off From Us Services

Seagate Hit With $300 Million Penalty for Continuing $1 Billion Relationship With Blacklisted Firm Huawei, Despite U.S. Export Controls

Proton Launches an End-To-End Encrypted Password Manager

ChatGPT-Related Malicious URLs on the Rise

Expert Insight: Dangers of Using Large Language Models Before They Are Baked
Lazarus Group Adds Linux Malware to Arsenal in Operation Dream Job

Capita Has ‘Evidence’ Customer Data Was Stolen in Digital Burglary

LockBit Ransomware Reportedly Strikes Venezuela’s Largest Bank

Cyber Attack Reportedly Hits Montana State University

Medical Imaging Firm Shields Health Care Group, Inc. Announces Third Party Data Breach Affecting Over 2.3 Million People

Daggerfly APT Targets African Telecoms Firm With New MgBot Malware

Attackers Use Abandoned WordPress Plugin to Backdoor Websites

Two Critical Flaws Found in Alibaba Cloud’s PostgreSQL Databases

VMware Fixes vRealize Bug That Let Attackers Run Code as Root

4/19/2023

March 2023 Broke Ransomware Attack Records With 459 Incidents

Ransomware Gangs Abuse Process Explorer Driver to Kill Security Software

Fortra Shares Findings on GoAnywhere MFT Zero-Day Attacks

Popular Fitness Apps Leak Location Data Even When Users Set Privacy Zones

Krebs: Giving a Face to the Malware Proxy Service ‘Faceless’

DC Health Link Data Breach Blamed on Human Error

Nurse Call Systems, Infusion Pumps Riskiest Connected Medical Devices

The Hacker Who Hijacked Matt Walsh’s Twitter Was Just ‘Bored’

The iPhone Setting Thieves Use to Lock You Out of Your Apple Account

Patient Seeks to Force Hospital Network to Pay Hackers Ransom to Remove Naked Photos Online

U.S. Citizens Charged With Pushing Pro-Kremlin Disinfo, Election Interference

Gary Bowser, Former Nintendo Hacker, Released From Prison

No Prison Time for Ryuk Ransomware Gang Broker After Guilty Plea

Hackers Got Hacking Wrong, But It Got Entertainment Right

Phishing Scams Growing More Sophisticated, Finra Says
Google TAG Warns of Russian APT28 Hackers Conducting Phishing Attacks in Ukraine

Blind Eagle Cyber Espionage Group Strikes Again: New Attack Chain Uncovered

Pakistani Hackers Use Linux Malware Poseidon to Target Indian Government Agencies

Huntington Ingalls Industries Data Breach Affects 43,643 Individuals

Major MA, NH Health Insurance Provider Point32Health Hit by Cybersecurity Ransomware Attack

West Technology Group Confirms Employee SSNs Leaked in Recent Data Breach

Bryant Bank (AL) Data Breach Leaked an Unknown Number of SSNs

Play Ransomware Gang Uses Custom Shadow Volume Copy Data-Theft Tool

Raspberry Robin Adopts Unique Evasion Techniques

Hackers Actively Exploit Critical RCE Bug in PaperCut Servers

Microsoft SQL Servers Hacked to Deploy Trigona Ransomware

Google Chrome Hit by Second Zero-Day Attack – Urgent Patch Update Released

Microsoft Defender Update Causes Windows Hardware Stack Protection Mess

4/18/2023

Apple’s High Security Mode Blocked NSO Spyware, Researchers Say

Cyberattack Risks Rise up Company Agendas

Used Routers Often Come Loaded With Corporate Secrets

What Happened When the IRS Got Audited

WhatsApp, Signal Claim UK Online Safety Bill Threatens User Privacy and Safety

Brit Cops Rapped Over App That Recorded 200K Phone Calls

Australian Military Helicopter Crash Blamed on Failure to Apply Software Patch

Avalor Wants to Unify Cybersecurity Tools by Aggregating Data

Combatting Cyber Attacks Requires More Than Just Money
NSO Group’s Pegasus Spyware Found on High-Risk iPhones

Russian APT28 Snoops Just Love Invading Unpatched Cisco Gear, America and UK Warn

Chinese APT41 Taps Google Red Teaming Tool in Targeted Info-Stealing Attacks

Microsoft: Iranian Mint Sandstorm Hackers Behind Retaliatory Cyberattacks on U.S. Orgs

Iranian MuddyWater Uses SimpleHelp to Target Critical Infrastructure Firms

University of the People (CA) Data Breach After Unauthorized SharePoint Access

YouTube Videos Distributing Aurora Stealer Malware via Highly Evasive Loader

New Sandbox Escape PoC Exploit Available for VM2 Library, Patch Now

Microsoft Opens up Defender Threat Intel Library With File Hash, URL Search

4/17/2023

Chinese Cops Ran Troll Farm and Secret NY Police Station, U.S. Says

ICE Records Reveal How Agents Abuse Access to Secret Data

Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose

I Just Discovered My Roomba Can Be a Security Camera

Marketing Biz Join the Triboo Limited Sent 107 Million Spam Emails… To Just 437K People

Student Requested Access to Research Data. And Waited. And Waited. Then Hacked to Get Root.

Elon Musk to Develop ‘TruthGPT’ as He Warns About ‘Civilizational Destruction’ From AI

Insurers Wary of Longer-Term Costs of Cyberattacks

Apple’s Macs Have Long Escaped Ransomware. That May Be Changing

‘Half-Baked’
FIN7 and Ex-Conti Cybercrime Gangs Join Forces in Domino Malware Attacks

Hackers Publish Sensitive Employee Data Stolen During CommScope Ransomware Attack

Capita Investigates Authenticity of Ransomware Gang Leaks

Charity Data Stolen in Ransomware Attack on Supplier Evide

New Chameleon Android Malware Mimics Bank, Gov’t, and Crypto Apps

QBot Banking Trojan Increasingly Delivered Via Business Emails

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

Hackers Abuse Google Command and Control Red Team Tool in Attacks

Engineering Cybersecurity into U.S. Critical Infrastructure

4/14-16/2023

Social-Media Account Overseen by Former Navy Noncommissioned Officer Helped Spread Secrets

Meet the Hacker Armies on Ukraine’s Cyber Front Line

Montana Lawmakers Approve Statewide Ban on TikTok

Krebs: Why is ‘Juice Jacking’ Suddenly Back in the News?

What Business Needs to Know About the New U.S. Cybersecurity Strategy

The U.S. Cracked a $3.4 Billion Crypto Heist—and Bitcoin’s Anonymity

Are You Being Tracked by an AirTag? Here’s How to Check

Elon Musk Is Reportedly Planning an A.I. Startup to Compete With OpenAI, Which He Cofounded

What It Will Look Like if China Launches Cyberattacks in the U.S.

How to Define Tier-Zero Assets in Active Directory Security
NCR Suffers Aloha POS Outage After BlackCat Ransomware Attack

Western Digital Hackers Demand 8-Figure Ransom Payment for Data

ConsenSys Reports Data Breach Affecting Over 7,000 MetaMask Users

Android Malware Infiltrates 60 Google Play Apps With 100M Installs

Hackers Start Abusing Action1 RMM in Ransomware Attacks

LockBit Ransomware Encryptors Found Targeting Mac Devices

Vice Society Ransomware Uses New PowerShell Data Theft Tool in Attacks

CISA Warns of Android Bug Exploited by Chinese App to Spy on Users

Google Releases Urgent Chrome Update to Fix Actively Exploited Zero-Day Vulnerability

4/13/2023

Air Guardsman Arrested in Connection With Leaked Documents

Pentagon Leak Leads to Limits on Who Gets Access to Military’s Top Secrets

Russian APT29 Hackers Linked to Widespread Attacks Targeting NATO and EU

Pakistan-Aligned Hackers Disrupt Indian Education Sector

The Hacking of ChatGPT Is Just Getting Started

European Privacy Watchdog Creates ChatGPT Task Force

For AI Laws, China Joins the U.S. In Asking the Public to Chime In

New Arkansas Bill to Keep Minors off Social Media Exempts Most Social Media Platforms

WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

Dutch Police Mails RaidForums Members to Warn They’re Being Watched

Five Arrested After 33,000 Victims Lose $98M to Online Investment Fraud

Cyber Company Darktrace Gets Caught up in LockBit Gang’s Apparent Blunder
Over 20,000 Iowa Medicaid Members Affected By Data Breach

Unlimited Care (NY) Files Notice of Data Breach Affecting More than 29K Employees

Kansas Health Care Company Medicalodges Hit by Ransomware Attack

Collegedale (TN) Has Computer Systems Hacked, Restored

Ransomware Attack on Suffolk County Began in 2021

No Indication of Identity Theft or Fraud in Beacon Health (IN) Data Breach by Employee

Money Ransomware Group Enters Double-Extortion Fray

GuLoader Targets U.S. Financial Firms With Tax-Themed Phishing Lures

RTM Locker: Emerging Cybercrime Group Targeting Businesses with Ransomware

New Python-Based “Legion” Hacking Tool Emerges on Telegram

Windows 11 Is Getting a New ‘Presence Sensing’ Privacy Setting

Gov’t Agencies Urge ‘Revamp’ of Certain Software to Take Cybersecurity Burden off Customers

4/12/2023

Lazarus Group’s DeathNote Campaign Reveals Shift in Targets

FBI: How Fake Xi Cops Prey on Chinese Nationals in the U.S.

Leaked Pentagon Documents May Herald a New Era of Revelations

CISA Updates Zero Trust Maturity Model With Public Feedback

U.S. Cyber Chiefs Warn AI Will Help Crooks, China Develop Nastier Cyberattacks Faster

ChatGPT Can Resume in Italy if Meets Data Watchdog’s Demands

Ethical Hackers Could Earn up to $20,000 Uncovering ChatGPT Vulnerabilities

Nurses Sue CommonSpirit Hospital Chain Over Unpaid Wages After 2022 Cyberattack

Gartner: Human-Centric Design Is Top Cybersecurity Trend for 2023
Hyundai Data Breach Exposes Owner Details in France and Italy

German Superyacht Maker Lürssen Hit by Ransomware Cyber Attack

Kyocera Android App With 1M Installs Can Be Abused to Drop Malware

Retina & Vitreous of Texas Files Notice of Data Breach Following Cybersecurity Incident

DDoS Attacks Shifting to VPS Infrastructure for Increased Power

Microsoft Shares Guidance to Detect BlackLotus UEFI Bootkit Attacks

Windows Admins Warned to Patch Critical MSMQ QueueJumper Bug

Krebs: Microsoft (& Apple) Patch Tuesday, April 2023 Edition

Were You Caught up in the Latest Data Breach? Here’s How to Tell

4/11/2023

Ukrainian Hackers Say They Have Compromised Russian Spy Who Hacked Democrats in 2016

3CX Confirms North Korean Hackers Behind Supply Chain Attack

iPhones Hacked via Invisible Calendar Invites to Drop QuaDream Spyware

Hacked Sites Caught Spreading Malware via Fake Chrome Updates

‘Blatantly Obvious’: Spyware Offered to Cyberattackers via PyPI Python Repository by ‘SylexSquad’

How LockBit Changed Cybersecurity Forever

OpenAI Launches Bug Bounty Program With Rewards up to $20K

U.S. Begins Study of Possible Rules to Regulate AI Like ChatGPT

FBI and Former City Manager Say Oldsmar (FL) Cyberattack Never Happened

7 Things Your Ransomware Response Playbook Is Likely Missing
Kodi Discloses Data Breach After Forum Database for Sale Online

Latitude Financial Refuses to Pay Ransom

Webster Bank Reports Third-Party Data Breach at Guardian Analytics

Harrington Raceway (DE) Data Breach Leaks Personal Info of More Than 12k Individuals

Woodward Communications (IA) Data Breach Affects 12,467 Individuals

Cryptocurrency Stealer Malware Distributed via 13 NuGet Packages

Newly Discovered “By-Design” Flaw in Microsoft Azure Could Expose Storage Accounts to Hackers

Windows Zero-Day Vulnerability Exploited in Ransomware Attacks

Microsoft April 2023 Patch Tuesday Fixes 1 Zero-day, 97 Flaws

SAP Releases Security Updates for Two Critical-Severity Flaws

4/10/2023

Pro-Russia Hackers Say They Breached Canadian Pipeline, but Experts Are Skeptical

Estonian National Charged in U.S. for Acquiring Electronics and Metasploit Pro for Russian Military

‘I’m Sick to My Stomach’: Pentagon Officials Shocked by Intel Leaks

How the Latest Leaked Documents Are Different From Past Breaches

FBI Warns Against Using Public Phone Charging Stations

How to Write Better ChatGPT Prompts (And This Applies to Most Other Text-Based AIs, Too)

The Human Factor In Cybersecurity: Understanding Social Engineering

Inside FTX: Jokes About Misplaced Funds, Diabolical IT, Poor Oversight, and Worse

High-Stakes Ransomware Response: Know What Cards You Hold

Apps for Sale: Cybercriminals Sell Android Hacks for Up to $20K a Pop

Apple Fixes Recently Disclosed Zero-Days on Older iPhones and iPads
KFC, Pizza Hut Owner Yum! Brands Discloses Data Breach After Ransomware Attack

SD Worx Shuts Down UK Payroll, HR Services After Cyberattack

Rochester Public School Cancels School Monday After Cyber Attack

Baldor Specialty Foods Reports Data Breach Impacting the Confidential Info of 13k+ Consumers

HawaiiUSA Federal Credit Union Confirms Recent Data Breach Affected Over 20k Customers

Reports of Data Breach at PharMerica Corp Leave Customers Worried About Their Personal Info

Hackers Flood NPM with Bogus Packages Causing a DoS Attack

Korea-Based Exchange GDAC Suspends Withdrawals, Deposits After $13M Hack

Terra DeFi Project Terraport Suffers $2M Hack Days After Launch

Community on Sushiswap Exploit: The $3.3 Hack Is ‘Weird’

CISA Orders Gov’t Agencies to Update iPhones, Macs by May 1st

4/7-9/2023

Pentagon Investigates More Social-Media Posts Purporting to Include Secret U.S. Documents

Leaked Pentagon Documents Show Spies Infiltrated Kremlin… and Also in South Korea, Ukraine & UK

Russia’s Military Struggles

Biden Administration Weighs Action Against Russian Cybersecurity Firm Kaspersky Lab

Americans Now Fear Cyberattack More Than Nuclear Attack

There’s a New Form of Keyless Car Theft That Works in Under 2 Minutes

Amazon Bans Flipper Zero, Claiming It Violates Policy Against Card Skimming Devices

‘A Real Worry’: How AI Is Making It Harder to Spot Fake Images

FBI Warns of Companies Exploiting Sextortion Victims for Profit

Breached Shutdown Sparks Migration to ARES Data Leak Forums

CISA Orders Agencies to Patch Backup Exec Bugs Used by Ransomware Gang

All Dutch Gov’t Networks to Use RPKI to Prevent BGP Hijacking
Iran-Based Hackers MuddyWater Caught Carrying Out Destructive Attacks Under Ransomware Guise

Tasmanian Data Breach: Schoolchildren’s Info Among 16,000 Documents Leaked on Dark Web

University of Hawaii Maui College Announces Recent Data Breach

Camden County (NJ) Police Department Confirms Ransomware Attack

Culbertson Memorial Hospital (IL) Hit by Cyber-Attack

Cyber Attack Leaves Irrigation Systems in Upper Galilee Dysfunctional

Massive Balada Injector Campaign Attacking WordPress Sites Since 2017

Researchers Discover Critical Remote Code Execution Flaw in VM2 Sandbox Library

Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari

Microsoft Delays Exchange Online CARs Deprecation Until 2024

Bad Actors Will Use Large Language Models — but Defenders Can, Too

Australia Is Scouring the Earth for Cybercriminals — the US Should Too

4/6/2023

Two-Fifths of IT Pros Told to Keep Breaches Quiet

Microsoft and Fortra Crack Down on Malicious Cobalt Strike Servers

The Dangerous Weak Link in the U.S. Food Chain

Threat Actors Increasingly Use Telegram For Phishing Purposes

Can Do Attitude: How Thieves Steal Cars Using Network Bus

Tesla Employees Reportedly Passed Around Personal Videos From Owners’ Cars

Google Mandates Data Deletion Policy For Android Apps

Privacy Concerns Surround Plans for AI Camera Surveillance at 2024 Paris Olympics

Cops Put the Squeeze on Genesis Crime Souk Denizens, Not Just the Admins This Time
UK Criminal Records Office Crippled by “Cyber Incident”

Legal Powerhouse Proskauer Exposed Clients’ Confidential M&A Data

Oakland Ransomware Attack Worsens With Massive New Release of Personal Info

Medusa Ransomware Claims Attack on Open University of Cyprus

Money Message Ransomware Gang Claims MSI Breach, Demands $4 Million

‘BEC 3.0’ Is Here With Tax-Season QuickBooks Cyberattacks

Throne Fixes Security Bug That Exposed Creators’ Private Home Addresses

QNAP ‘Urgently’ Fixing Vulnerabilities in Multiple Systems

4/5/2023

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks

UK Discloses Offensive Cyber Capabilities Principles

Spain’s Most Dangerous and Elusive Hacker Now in Police Custody

Krebs: FBI Seizes Bot Shop ‘Genesis Market’ Amid Arrests Targeting Operators, Suppliers

New Dark Web Market STYX Focuses on Financial Fraud Services

Here’s Where the A.I. Jobs Are

Log4j Bug Being Used in New Malicious Attacks
Database Snafu Leaks 600K Records from Z2U Marketplace

Our Lady of the Lake University (TX) Notifies Data Breach Victims

CryptoClippy: New Clipper Malware Targeting Portuguese Cryptocurrency Users

Typhon Reborn Stealer Malware Resurfaces with Advanced Evasion Techniques

Hackers Using Self-Extracting Archives Exploit for Stealthy Backdoor Attacks

Open Nexx Garage Doors Anywhere in the World by Exploiting This “Smart” Device

4/4/2023

In His New Cybersecurity Strategy, Biden Identifies Cloud Security as a Major Threat

Broad Pay Ranges Can Hamper Cybersecurity Hiring

Bank Rewrote Ads for Infosec Jobs to Stop Scaring Away Women

Alcohol Counseling Companies Monument and Tempest Leaked Patient Data to Advertisers for Years

IRS-Authorized eFile.com Tax Return Software Caught Serving JS Malware

Krebs: A Serial Tech Investment Scammer Takes Up Coding?

ChatGPT Has a Big Privacy Problem

TikTok Fined £12.7m For Violating UK Data Privacy Laws

A Tiny Blog Took on Big Surveillance in China—and Won

Cybercrime Marketplace Genesis Market Shut by FBI, International Law Enforcement
Israeli Cyber Security Website Check Point Briefly Taken Down in Cyberattack

Arid Viper Hacking Group Using Upgraded Malware in Middle East Cyber Attacks

Tallahassee Memorial HealthCare Data Breach Affects Patients’ SSNs and PHI

New “Rorschach” Ransomware Spread Via Commercial Product

New Rilide Malware Targeting Chromium-Based Browsers to Steal Cryptocurrency

ALPHV Ransomware Exploits Veritas Backup Exec Bugs for Initial Access

HP to Patch Critical Bug in LaserJet Printers Within 90 Days

15M+ Services & Apps Remain Sitting Ducks for Known Exploits

How Strategic Investors Can Help Cybersecurity Startups

4/3/2023

TikTok to Comply With US Law, Protect User Data From China

The Massive 3CX Supply-Chain Hack Targeted Cryptocurrency Firms

3CX Thought Supply Chain Attack Was a False Positive

April Brings Tulips, Taxes … And Phisherfolk Scammers

ICE Is Grabbing Data From Schools and Abortion Clinics

Tor Project’s New Privacy-Focused Browser Lets You Layer a VPN

Okay, so ChatGPT Just Debugged My Code. For Real.

U.S. DoD Unveils Website For Hack the Pentagon Bug Bounty Program

U.S. Seizes $112 Million From Cryptocurrency Investment Scammers

School Principal Resigns After Writing $100,000 Check to Elon Musk Impersonator

What The Board Needs To Know
Western Digital Hit by Network Security Breach – Critical Services Disrupted

Outsourcer Capita Claims to Have Contained “Cyber Incident”

BMW Claims Data Breach Limited to Local Dealer

Uber Driver Info Stolen Yet Again: This Time From Law Firm Genova Burns

Montgomery General Hospital (WV) Data Breach Following Ransomware Attack

Southwest Healthcare Services (ND) Data Breach Affects Patients’ SSNs and PHI

Crypto-Stealing OpcJacker Malware Targets Users with Fake VPN Service

WinRAR SFX Archives Can Run PowerShell Without Being Detected

CISA Warns of Zimbra Bug Exploited in Attacks Against NATO Countries

For Cybercrime Gangs, Professionalization Comes With ‘Corporate’ Headaches

3/31-4/2/2023

10-Year-Old Windows Bug With ‘Opt-In’ Fix Exploited in 3CX Attack

Federal Government Published Social Security Numbers of 1,900 White House Visitors

China Opens Cybersecurity Probe of Micron Amid Competition With U.S. Over Technology

Italy Curbs ChatGPT, Starts Probe Over Privacy Concerns

NYPD Blues: Cops Ignored 93 Percent of Surveillance Law Rules

Lazarus Heist: The Intercontinental ATM Theft That Netted $14M in Two Hours

Krebs: German Police Raid DDoS-Friendly Host ‘FlyHosting’

DISH Slapped With Multiple Lawsuits After Ransomware Cyber Attack
Consumer Lender TMX Discloses Data Breach Impacting 4.8 Million People

Lumen Hit by Ransomware, Malware Attacks

Jefferson County (AL) School System Victim of Ransomware Attack During Spring Break

Lewis & Clark College Cyberattack Claimed by Notorious Ransomware Gang

New Money Message Ransomware Demands Million Dollar Ransoms

Fake Ransomware Gang ‘Midnight’ Targets U.S. Orgs With Empty Data Leak Threats

Hackers Exploiting WordPress Elementor Pro Vulnerability: Millions of Sites at Risk

15 Million Public-Facing Services Vulnerable to CISA KEV Flaws

3/30/2023

The U.S. Is Sending Money to Countries Devastated by Cyberattacks

Winter Vivern Hackers Exploit Zimbra Flaw to Steal NATO Emails

Leaked Documents Offer Fascinating Insights Into Russian Cyber Warfare

FDA Will Refuse New Medical Devices for Cybersecurity Reasons on Oct. 1

Huge Microsoft Azure Exploit Allowed Users to Manipulate Bing Search Results and Access Outlook Email Accounts

Over 70% of Employees Keep Work Passwords on Personal Devices

U.S. Court Sanctions Google in Privacy Case, Company’s Second Legal Setback in Days

Ukrainian Cyberpolice Busts Fraud Gang That Stole $4.3 Million
Chinese RedGolf Group Targeting Windows and Linux Systems with KEYPLUG Backdoor

Bright Horizons Notifies Current and Former Employees of Recent Data Breach

Majestic Care Files Notice of Data Breach Affecting Current and Former Residents and Staff

The Health Plan of San Mateo (CA) Data Breach Leaked Personal Info of 11,894 Individuals

AlienFox Malware Targets API Keys and Secrets from AWS, Google, and Microsoft Cloud Services

Realtek and Cacti Flaws Now Actively Exploited by Malware Botnets

CISA Orders Agencies to Patch Bugs Exploited to Drop Spyware

Microsoft OneNote Will Block 120 Dangerous File Extensions

3/29/2023

Google Warns Against Commercial Spyware Exploiting Zero-Days

Elon Musk and Others Urge AI Pause, Citing ‘Risks to Society’

Smart Mobility has a Blindspot When it Comes to API Security

In Walmart’s Cyber Risk Formula, Every Bug Has a Backstory

Microsoft Defender Shoots Down Legit URLs as Malicious

FTX Cryptovillain Sam Bankman-Fried Charged With Bribing Chinese Officials

Man Behind Hack-for-Hire Campaign That Targeted Environmental Activists Is Keeping His Mouth Shut
SafeMoon ‘Burn’ Bug Abused to Drain $8.9 Million From Liquidity Pool

UC San Diego Health Data Breach After a Vendor’s Unauthorized Use of Tracking Technologies

U.S. Wellness (MD) Data Breach Affects 11,459 Patients’ Protected Health Information

Data Stolen From Washington County (FL) Sheriff’s Office Leaked by LockBit Ransomware Group

Cybersecurity Firms Warn of 3CX Desktop App Supply Chain Attack

Cybercriminals Set Sights on Critical IBM File Transfer Bug

QNAP Warns Customers to Patch Linux Sudo Flaw in NAS Devices

3/28/2023

Newly Exposed APT43 Hacking Group Targeting U.S. Orgs Since 2018

North Korea Is Now Mining Crypto to Launder Its Stolen Loot

Pakistan-Origin SideCopy Linked to New Cyberattack on India’s Ministry of Defence

Krebs: UK Sets Up Fake Booter Sites To Muddy DDoS Market

Microsoft Security Copilot Is a New GPT-4 AI Assistant for Cybersecurity

Cybersecurity Workers Demand Higher Salaries

Millions of Pen Tests Show Companies’ Security Postures Are Getting Worse

The Pervasive Threat Of Ransomware And Its Misconceptions
Latitude Financial Data Breach Now Impacts 14 Million Customers

Modesto Hit by Apparent Snatch Ransomware Attack

Oklahoma City University Notifies Students and Employees of Data Breach

Central National Bank (TX) Data Breach Affects an Unknown Number of Customers

Children’s Data Feared Stolen in Fortra Ransomware Attack

Trojanized Tor Browsers Target Russians With Crypto-Stealing Malware

Stealthy DBatLoader Malware Loader Spreading Remcos RAT and Formbook in Europe

WiFi Protocol Flaw Allows Attackers to Hijack Network Traffic

3/27/2023

President Joe Biden Says U.S. Can’t Buy Spyware That Other Countries Have Used Against It

Twitter Says Parts of Its Source Code Were Leaked Online

Trying to Find the Culprit

They Posted Porn on Twitter: German Authorities Called the Cops

FTC Bans Scammy Companies From ‘Calling About Your Car’s Extended Warranty’

Exchange Online to Block Emails From Vulnerable On-Prem Servers

The Integral Role of Human Resources Departments in Cybersecurity

This Cybersecurity CTO Shares 5 Tips To Better Protect Your Customers

What Automation Means For Cybersecurity—And Your Business

Hackers Earn $1,035,000 for 27 Zero-Days Exploited at Pwn2Own Vancouver
Crown Resorts Says Ransomware Group Claims Accessing Some of Its Files

Clop Keeps Racking Up Ransomware Victims With GoAnywhere Flaw

Associates in Dermatology (VA) Breach Stems from Ransomware Attack at VPN Solutions

Sun Pharma (India) Admits Business Affected Due to March 2 Ransomware Attack

NCB Management Services (PA) Data Breach Affects Nearly a Half-Million Consumers

Atlantic Dialysis Management Services (NY) Breach of Patient Info

Florida Medical Clinic Notifies Nearly 95,000 People of Recent Data Breach

Three Variants of IcedID Malware Discovered

New MacStealer Targets Catalina, Newer MacOS Versions

Apple Fixes Recently Disclosed WebKit Zero-Day on Older iPhones

3/24-26/2023

CISA Unveils Ransomware Notification Initiative

UK National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals

Uncle Sam Reveals It Sent Cyber-Soldiers to Albania to Hunt for Iranian Threats

‘Bitter’ Espionage Hackers Target Chinese Nuclear Energy Orgs

IRS Phishing Emails Used to Distribute Emotet

ChatGPT’s History Bug May Have Also Exposed Payment Info, Says OpenAI

Open-Source Bug

Australian Police Arrest Four BEC Actors Who Stole $1.7 Million

FBI: Business Email Compromise Tactics Used to Defraud U.S. Vendors

FBI Confirms Access to Breached Cybercrime Forum Database

India Shut Down Cell Service for 27 Million During a Manhunt

GitHub Swiftly Replaces Exposed RSA SSH Key to Protect Git Operations

The Strongest Protection for Your Online Accounts? This Little Key
Procter & Gamble Confirms Data Theft via GoAnywhere Zero-Day

New Dark Power Ransomware Claims 10 Victims in Its First Month

Kroger Postal Prescription Services Breach Impacts 82,466 Consumers

Maersk Says Posted Data Is Not Current and Not From Attack by Hackers

Wisconsin Court System Affected by DDoS Incident

Washington County (FL) Sheriff’s Office Back to Normal After Cyber Attack

Russia’s Rostec Allegedly Can De-Anonymize Telegram Users

Inaudible Ultrasound Attack Can Stealthily Control Your Phone, Smart Speaker

Microsoft Pushes OOB Security Updates for Windows Snipping Tool Flaw

Microsoft Teams, Virtualbox, Tesla Zero-Days Exploited at Pwn2Own

Windows, Ubuntu, and VMWare Workstation Hacked on Last Day of Pwn2Own

Fortra Told Breached Companies Their Data Was Safe

3/23/2023

TikTok Congressional Hearing: CEO Shou Zi Chew Grilled by U.S. Lawmakers

TikTok Paid for Influencers to Attend the Pro-TikTok Rally in DC

Are Chinese Tech Firms a Security Risk?

Krebs: Google Suspends Chinese E-Commerce App Pinduoduo Over Malware

Stanford Pulls Down ChatGPT Clone After Safety Concerns

Journalist Plugs in Unknown USB Drive Mailed to Him—It Exploded in His Face

Windows 11, Tesla, Ubuntu, and macOS Hacked at Pwn2Own 2023

CloudPanel Installations Use the Same SSL Certificate Private Key

New CISA Tool Detects Hacking Activity in Microsoft Cloud Services

How to Use ChatGPT to Write Code

Epidemic of Insecure Storage, Backup Devices Is a Windfall for Cybercriminals

MITRE Rolls Out Cloud-Based Prototype for Supply Chain Security

Kids Tech Camp iD Tech Still Silent Weeks After Data Breach
City of Toronto Confirms Data Theft, Clop Claims Responsibility

Attorneys Say Private Information Exposed to Public in NC Courts Overhaul

Ottawa County (OH) Officials Working to Restore Network After Ransomware Attack

Shoreline College (WA) Website Hacked; Officials Investigating

Tri Counties Bank in Chico (CA) Suffers Data Breach After February Cyber Attack

China-Aligned “Operation Tainted Love” Targets Middle East Telecom Providers

German and South Korean Agencies Warn of Kimsuky’s Expanding Cyber Attack Tactics

Python Info-Stealing Malware Uses Unicode to Evade Detection

SharePoint Phishing Scam Targets 1600 Across U.S., Europe

BlackGuard Stealer Now Targets 57 Crypto Wallets, Extensions

Exploit Released for Veeam Bug Allowing Cleartext Credential Theft

WordPress Force Patching WooCommerce Plugin with 500K Installs

Microsoft Fixes Acropalypse Privacy Bug in Windows 11 Snipping Tool

3/22/2023

The TikTok CEO’s Face-Off With Congress Is Doomed

Cyberterrorism Tops List of Threats to U.S. Vital Interests: Gallup

Unknown Actors Deploy Malware to Steal Data in Occupied Regions of Ukraine

North Korean Hackers Using Chrome Extensions to Steal Gmail Emails

German Political Parties Accused of Microtargeting Voters on Facebook

Facebook Accounts Hijacked by New Malicious Trojanized Version of ChatGPT Chrome Extension

ChatGPT-Owner OpenAI Fixes ‘Significant Issue’ Exposing User Chat Titles

CISA and NSA Enhance Security Framework With New IAM Guide

Beloved Hacking Veteran Kelly ‘Aloria’ Lum Passes Away at 41
Dole Discloses Employee Data Breach After Ransomware Attack

Convergent Outsourcing (WA) Files Notice of Data Breach That Leaked Consumers’ SSNs

Sunland Asphalt and Construction (AZ) Data Breach Affects 7,884 Individuals’ Personal Info

$36M BEC Fraud Attempt Narrowly Thwarted by AI Technology

Hackers Inject Credit Card Stealers Into Payment Processing Modules

New Android Banking Trojan ‘Nexus’ Promoted As MaaS

NAPLISTENER: New Malware in REF2924 Group’s Arsenal for Bypassing Detection

ScarCruft’s Evolving Arsenal: Researchers Reveal New Malware Distribution Techniques

PoC Exploits Released for Netgear Orbi Router Vulnerabilities

3/21/2023

Putin to Staffers: Throw Out Your iPhones, or ‘Give It to the Kids’ and Use Russian or Chinese Tech Instead

Google Suspends Top Chinese Shopping App Pinduoduo

CommonMagic Targets Entities in Russo-Ukrainian Conflict Zone

The Scorched-Earth Tactics of Iran’s Cyber Army

Meta Security Manager Was Reportedly Hacked by Greek Intelligence Agency

ChatGPT Bug Temporarily Exposes AI Chat Histories to Other Users

Windows’ Screenshot Tool May Be Saving Stuff You Cropped Out, Too

Adobe Launches Firefly Generative A.I., Which Lets Users Type to Edit Images

European Ports Brace for Cybersecurity Regulation

Breached Hacking Forum Shuts Down, Fears It’s Not ‘Safe’ From FBI
Democratic Rep: At Least 17 Current and Former Members Had Personal Data Exposed in DC Health Link Breach

Clop Ransomware Claims Saks Fifth Avenue, Retailer Says Mock Data Stolen

LockBit Ransomware Gang Now Also Claims City of Oakland Breach

Expert Speaks Out After City of Allen Park (MI) Hit With Ransomware Attack

Over 2400 Fake Pages Found Targeting Job Seekers in Middle East, Africa

New ShellBot DDoS Malware Variants Targeting Poorly Managed Linux Servers

Coinbase Wallet ‘Red Pill’ Flaw Allowed Attacks to Evade Detection

Microsoft: Defender Update Behind Windows LSA Protection Warnings

From Ransomware to Cyber Espionage: 55 Zero-Day Vulnerabilities Weaponized in 2022

3/20/2023

Vessels Claiming to Be Chinese Warships Are Messing With Passenger Planes

Online Sleuths Untangle the Mystery of the Nord Stream Sabotage

ChatGPT Helped Win a Hackathon

OpenAI CEO Sam Altman Says He’s a ‘Little Bit Scared’ of A.I.

Researchers Shed Light on CatB Ransomware’s Evasion Techniques

Hackers Mostly Targeted Microsoft, Google, Apple Zero-Days in 2022

The Top Five Cybersecurity Concerns

Krebs: Why You Should Opt Out of Sharing Data With Your Mobile Provider
Ferrari Reports Cyber Incident With Ransom Demand; No Impact to Operations

Mispadu Trojan Steals 90,000+ Banking Credentials From Latin American Victims

General Bytes Bitcoin ATMs Hacked Using Zero-Day, $1.5M Stolen

Texas Medical Liability Trust Data Breach Leaked SSNs and Other Sensitive Data

KillNet Group Uses DDoS Attacks Against Azure-Based Healthcare Apps

New DotRunpeX Malware Delivers Multiple Malware Families via Malicious Ads

Hackers Target .NET Developers with Malicious NuGet Packages

3/17-19/2023

Wave of Stealthy China Cyberattacks Hits U.S., Private Networks, Google Says

Huawei Has Replaced Thousands of U.S.-Banned Parts in Its Products, Founder Says

Google Pixel Exploit Reverses Edited Parts of Screenshots

Google Tells Users of Some Android Phones: Nuke Voice Calling to Avoid Infection

FCC Now Requires Cell Carriers to Block Scam Texts From Sketchy Numbers

I Got Investigated by the Secret Service: Here’s How to Not Be Me

Krebs: Feds Charge NY Man as BreachForums Boss “Pompompurin”

RAT Developer Arrested in Ukraine for Infecting 10,000 PCs With Malware

CIOs Build New Bonds With CISOs
NBA Alerts Fans of a Data Breach Exposing Personal Information

Hitachi Energy Confirms Data Breach After Clop GoAnywhere Attacks

OU Health Confirms Data for 3K Patients Could Have Been Breached After Laptop’s Theft

AllCare Plus Pharmacy (MA) Notified Patients of Data Breach Leaking SSNs and PHI

Telegram, WhatsApp Trojanized to Target Cryptocurrency Wallets

New GoLang-Based HinataBot Exploiting Router and Server Flaws for DDoS Attacks

Emotet Malware Now Distributed in Microsoft OneNote Files to Evade Defenses

Microsoft Shares Script to Fix WinRE BitLocker Bypass Flaw

3/16/2023

Senator Warner Wants US Spies to Justify a TikTok Ban

UK Bans TikTok on Government Devices Following U.S. Move

U.S. FTC Asks Social Media, Video Streaming Firms Info on Misleading Ads

Snapchat’s New Parental Control Filters Aim to Protect Minors From Sensitive Content

Courts Side With Big Companies Including Amazon and Experian in Privacy Appeals

Microsoft Support ‘Cracks’ Windows for Customer After Activation Fails

Conti-Based Ransomware ‘Meowcorp’ Gets Free Decryptor

Chinese SilkLoader Malware Sold to Russian Cyber-Criminals

Winter Vivern APT Hackers Use Fake Antivirus Scans to Install Malware
Latitude Cyberattack Leads to Data Theft at Two Service Providers

Trinity Health of New England Employee Email Breach Exposed Patients’ Personal Data

Cryptojacking Group TeamTNT Suspected of Using Decoy Miner to Conceal Data Exfiltration

BianLian Ransomware Pivots From Encryption to Pure Data-Theft Extortion

Convincing Twitter ‘Quote Tweet’ Phone Scam Targets Bank Customers

Fortinet Zero-Day Attacks Linked to Suspected Chinese Hackers

Adobe Acrobat Sign Abused to Push Redline Info-Stealing Malware

Google Finds 18 Baseband Zero-Day Bugs in Samsung Exynos Chipsets

Google Proposes Reducing TLS Cert Life Span to 90 Days

3/15/2023

U.S. Threatens to Ban TikTok if Chinese Founder Doesn’t Sell Ownership Stake

China Sought Control of Submarine Cables to Spy, Says Micronesia

Russian Hackers Preparing New Cyber Assault Against Ukraine – Microsoft Report

This Is the New Leader of Russia’s Infamous Sandworm Hacking Unit

A Spy Wants to Connect With You on LinkedIn

The World’s Real ‘Cybercrime’ Problem

FBI: Ransomware Hit 860 Critical Infrastructure Orgs in 2022

Authorities Take Down Darknet Cryptocurrency ‘Mixing’ Service ‘ChipMixer’

Dangers from Hacks Stretch Beyond Broken Computer Systems

AI-Generated Voice Deepfakes Aren’t Scary Good—Yet

Humans Still More Effective Than ChatGPT at Phishing

Krebs: Two U.S. Men Charged in 2022 Hacking of DEA Portal

Cancer Patient Sues Hospital After Ransomware Gang Leaks Her Nude Medical Photos

NordVPN Open Sources Its Linux VPN Client and Libraries

Mozilla Firefox Gets Built-in Firefox Relay Controls
Tick APT Group Hacked East Asian DLP Software Firm

Hacker Selling Data Allegedly Stolen in U.S. Marshals Service Hack

U.S. Federal Agency Hacked Using Old Telerik Bug to Steal Data

LockBit Ransomware Claims Essendant Attack, Company Says “Network Outage”

Latitude Financial Hacked With 328,000 Customer IDs Feared Stolen

Independent Living Systems (ILS) Warns 4.2 Million People of Data Breach

NorthStar Emergency Medical Services (AR) Data Breach Affects 82,450 Individuals

Lansing Community College Suspends Most Classes for ‘Ongoing Cybersecurity Incident’

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

“FakeCalls” Android Malware Targets Financial Firms in South Korea

First-Known Dero Cryptojacking Operation Seen Targeting Kubernetes

CISA Warns of Adobe ColdFusion Bug Exploited as a Zero-Day

Critical Microsoft Outlook Bug PoC Shows How Easy It Is to Exploit

Krebs: Microsoft Patch Tuesday, March 2023 Edition

3/14/2023

D.C. Health Link Hacker Exposes Lawmakers’ Personal Information

UK’s National Cyber Security Centre Reviewing TikTok Risks, Minister Says

MI5 Launches New Agency to Tackle State-Backed Attacks

YoroTrooper Espionage Campaigns Target CIS, EU Countries

DEV-1101 Updates Open Source Phishing Kit

FBI Warns of Spike in ‘Pig Butchering’ Crypto Investment Schemes

Cybercriminals Exploit Silicon Valley Bank (SVB) Collapse to Steal Money and Data

GPT-4 Unveiled: ChatGPT’s Next Big Upgrade Is Here

How Businesses Can Get Ready for AI-Powered Security Threats
Rubrik Confirms Data Theft in GoAnywhere Zero-Day Attack

Beaver Medical Group Files Notice of Data Breach Leaking Patient’s PHI

Bone & Joint (WI) “System Outage” Resulted in Data Breach Affecting Patients & Employees

Merced College (CA) Provides Notice of Data Breach to Students Following Malware Attack

Ring Won’t Say if It Was Hacked After Ransomware Gang Claims Attack

SAP Releases Security Updates Fixing Five Critical Vulnerabilities

Microsoft March 2023 Patch Tuesday Fixes 2 Zero-Days, 83 Flaws

Microsoft Fixes Outlook Zero-Day Used by Russian Hackers Since April 2022

Microsoft Fixes Windows Zero-Day Exploited in Ransomware Attacks

3/13/2023

STALKER 2 Game Developer GSC Game World Hacked by Russian Hacktivists, Data Stolen

Large-scale Cyber Attack Hijacks East Asian Websites for Adult Content Redirects

CISA Joins Forces With Women in Cybersecurity to Break up the Boy’s Club

CISA Now Warns Critical Infrastructure of Ransomware-Vulnerable Devices

Fortinet: New FortiOS Bug Used as Zero-Day to Attack Gov’t Networks

NordVPN Makes its Meshnet Private Tunnel Free for Everyone

Outlook App to Get Built-In Microsoft 365 MFA on Android, iOS

Final Three Sentenced in £70m Money Laundering Case
Zoll Medical Says Intruders Had 1M+ Patient, Staff Records at Their Fingertips

LA Housing Authority Discloses Data Breach After Ransomware Attack

Arizona Department of Economic Security Confirms Data Breach

Hackers Steal $197 Million in Crypto in Euler Finance Attack

LockBit Brags: We’ll Leak Thousands of SpaceX Blueprints Stolen From Supplier

Cyber Attack Affecting Gloucester Museum’s System One Year On

Kali Linux 2023.1 Introduces ‘Purple’ Distro for Defensive Security

Brand Names in Finance, Telecom, Tech Lead Successful Phishing Lures

3/10-12/2023

KamiKakaBot Malware Used in Latest Dark Pink APT Attacks on Southeast Asian Targets

North Korean UNC2970 Hackers Expands Operations with New Malware Families

Ransomware Attacks Have Entered a ‘Heinous’ New Phase

Investment Fraud is Now Biggest Cybercrime Earner

Fake ChatGPT Chrome Extension Hijacking Facebook Accounts for Malicious Advertising

Security Researchers Targeted With New Malware via Job Offers on LinkedIn

AI-Generated YouTube Video Tutorials Spreading Infostealer Malware

TikTok Users Shrug at China Fears: ‘It’s Hard to Care’

Cerebral Admits to Sharing Patient Data With Meta, TikTok, and Google

FBI Once Bought Mobile-Phone Data for Warrantless Tracking: Other Agencies Still Do

Brazil Seizing Flipper Zero Shipments to Prevent Use in Crime

Casper Attack Steals Data Using Air-Gapped Computer’s Internal Speaker

Microsoft OneNote to Get Enhanced Security After Recent Malware Abuse

Blackbaud to Pay $3M for Misleading Ransomware Attack Disclosure

Key Takeaways From The National Cybersecurity Strategy
Mental Health Provider Cerebral Alerts 3.1M People of Data Breach

PeopleGrove Security Lapse Exposed Users’ Personal Information

Codman Square Health Center (MA) Reports Data Breach Following Ransomware Attack

56,000 Affected by DC Health Link Data Breach

Staples-Owned Essendant Facing Multi-Day “Outage,” Orders Frozen

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads

Medusa Ransomware Gang Picks up Steam as It Targets Companies Worldwide

New Version of Prometei Botnet Infects Over 10,000 Systems Worldwide

Xenomorph Android Banking Trojan Returns with a New and More Powerful Variant

New GoBruteforcer Malware Targets phpMyAdmin, MySQL, FTP, Postgres

Clop Ransomware Gang Begins Extorting GoAnywhere Zero-Day Victims

Unpatched Zero-Day Bugs in Akuvox Smart Intercoms Allow Remote Eavesdropping

CISA Warns of Actively Exploited Plex Bug After LastPass Breach

CISA Warns of Critical VMware RCE Flaw Exploited in Attacks

3/9/2023

U.S. Congressman Darin LaHood Says the FBI Unlawfully Targeted Him

Fifth of Government Workers Don’t Care if Employer is Hacked

Tehran Targets Female Activists in Espionage Campaign

Rubio Takes Aim At Planned Ford U.S. Battery Plant Using Chinese Technology

Pentagon Unveils Cyber Workforce Strategy to Tackle Labor Shortage

Krebs: Who’s Behind the NetWire Remote Access Trojan?

Google Trashes the Chrome Cleanup Tool

FBI Warns of Cryptocurrency Theft via “Play-To-Earn” Games

TikTok Initiates Project Clover Amid European Data Security Concerns

Inadvertent Data Destruction After a Cyberattack Can Violate EU Privacy Rules

Scammers Are Using AI to Impersonate Your Loved Ones: Here’s What to Watch Out For
Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks

AT&T Blames Marketing Bods for Exposing 9M Subscriber Account Records

Microsoft: Business Email Compromise Attacks Can Take Just Hours

Akamai Mitigates Record-Breaking 900Gbps DDoS Attack in Asia

IceFire Ransomware Now Encrypts Both Linux and Windows Systems

8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server

Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX Malware

Suspected Chinese Cyber Spies Target Unpatched SonicWall Devices

GitHub Makes 2FA Mandatory Next Week for Active Developers

How to Jump-Start Your Cybersecurity Career

3/8/2023

FBI Investigates Data Breach Impacting U.S. House Members and Staff

The FBI Just Admitted It Bought U.S. Location Data

The U.S. Air Force Is Moving Fast on AI-Piloted Fighter Jets

Boeing Signs off Anti-Jamming Tech That Keeps Satellites Online

China Says It’s ‘Puzzled’ After Report Germany Might Ban Huawei From Parts of 5G Mobile Network

Dutch Responds to U.S. China Policy With a Plan to Curb Semiconductor Tech Exports

Australia Demands Russia Crack Down on Cyber Criminals

DuckDuckGo Launches AI-Powered Search Query Answering Tool

Microsoft Enables LSA Protection by Default in Windows Canary Build

Eurovision 2023: Hotel Phishing Scam Targets Song Contest Fans

Krebs: Sued by Meta, Freenom Halts Domain Registrations
Lazarus Group Targets South Korean Finance Firm Via Zero-Day Flaw

Commonwealth Bank of Australia’s Indonesian Arm Hit by Cyber Attack

Ransomware Gang Posts Video of Data Stolen From Minneapolis Schools

City of Waynesboro (VA) Targeted in Cyber Attack

Northeast Surgical Group (MI) Notifies 15K Patients of Data Breach

Jenkins Security Alert: New Security Flaws Could Allow Code Execution Attacks

Bitwarden Flaw Can Let Hackers Steal Passwords Using iframes

Fortinet Warns of New Critical Unauthenticated RCE Vulnerability

Veeam Fixes Bug That Lets Hackers Breach Backup Infrastructure

CISA’s KEV Catalog Updated with 3 New Flaws Threatening IT Management Systems

3/7/2023

Cyber Command Chief: Election Interference Is Not Going Away

Watchdog Says U.S. Cyber Agency Lacks a Plan for Communicating During Major Hacks

Russia’s Cyber Tactics in Ukraine Shift to Focus on Espionage

Russian Disinformation Campaign Records High-Profile Individuals on Camera

How to Tell if Your Laptop Camera Has Been Hacked and Someone Is Spying on You

White House Backs Senate Bill to Boost U.S. Ability to Ban TikTok

Shein App Accessed Clipboard Data on Android Devices

The Daring Ruse That Exposed China’s Campaign to Steal American Secrets

How Denmark’s Welfare State Became a Surveillance Nightmare

Twitter Just Let Its Privacy- And Security-Protecting Tor Service Expire

Next-Gen Mobile Internet — 6G — Will Launch in 2030, Telecom Bosses Say, Even as 5G Adoption Remains Low

LastPass Hack: Engineer’s Failure to Update Plex Software Led to Massive Data Breach

Pro-Putin Scammers Trick Politicians and Celebrities Into Low-Tech Hoax Video Calls

The Rise of Zero-Trust Cybersecurity in a Multicloud World
Sharp Panda Target Southeast Asia in Espionage Campaign Expansion: ‘Radio Silence’ Mode to Evade Detection

Acer Confirms Breach After 160GB of Data for Sale on Hacking Forum

Brazilian Conglomerate Andrade Gutierrez Suffers 3TB Data Breach

Ransomware Attack Against Barcelona Hospital Disrupts Operations

Houston Healthcare (GA) Falls Victim to Cybersecurity Attack

Minneapolis Public Schools Says Hackers Behind Alleged Attack Posted Some Data Online

Northern Essex Community College (MA) Closed for 5th Day Due to Cyberattack

1st Franklin Financial Corporation (GA) Notifies Customers of Recent Data Breach

Transparent Tribe Hackers Distribute CapraRAT via Trojanized Messaging Apps

SYS01stealer: New Threat Using Facebook Ads to Target Critical Infrastructure Firms

Emotet Malware Attacks Return After Three-Month Break

Android March 2023 Update Fixes Two Critical Code Execution Flaws

Microsoft Excel Now Blocking Untrusted XLL Add-Ins by Default

3/6/2023

U.S. Government to Explore Cyber Insurance Backstop

New Class of Lawmakers Look To Dig In on Cybersecurity

Faced With Likelihood of Ransomware Attacks, Businesses Still Choosing to Pay Up

Where Are the Women in Cyber Security? On the Dark Side, Study Suggests

Cybersecurity Trends & Statistics For 2023: Attack Surface And Hacker Capabilities Grow

NIST’s Quantum-Proof Algorithm Has a Bug, Analysts Say

Rotterdam: This Algorithm Could Ruin Your Life

Inside the Suspicion Machine

German and Ukrainian Police Raid Alleged Cybercrime ‘DoppelPaymer’ Gang With Help From FBI
Vice Society Ransomware Group Claims Hamburg University of Applied Sciences as Latest Victim

Denver Public Schools Data Breach Includes SSNs, Bank Info

Henrico Doctors’ Hospital (VA) Notifies Patients of Data Breach

Acer Data Breach? Hacker Claims to Sell 160GB Trove of Stolen Data

Sandbox Blockchain Game Breached to Send Emails Linking to Malware

New HiatusRAT Malware Targets Business-Grade Routers to Covertly Spy on Victims

Old Windows ‘Mock Folders’ UAC Bypass Used to Drop Malware

Proof-of-Concept Released for Critical Microsoft Word RCE Bug

3/3-5/2023

EPA to Make States Evaluate Public Water Systems’ Cybersecurity

U.S. Cybersecurity Agency Raises Alarm Over Royal Ransomware’s Deadly Capabilities

Krebs: Highlights from the New U.S. Cybersecurity Strategy

BidenCash Market Leaks Over 2 Million Stolen Credit Cards for Free

TPM 2.0 Library Vulnerabilities May Affect Billions of IoT Devices

Brave Search Launches AI-Powered Summarizer in Search Results

A Privacy Hero’s Final Wish: An Institute to Redirect AI’s Future

FTC to Ban BetterHelp From Sharing Mental Health Data With Advertisers

Secret Service, ICE Break the Law Over and Over With Fake Cell Tower Spying
Play Ransomware Claims Disruptive Attack on City of Oakland

Play Ransomware Gang Leaks Data Stolen From City of Oakland

Personal Data Exposed in Cyber Attack on Modesto (CA) PD

Indigo Books Refuses LockBit Ransomware Demand

Indian Startup Yes Madam Exposed Sensitive Data of Customers and Gig Workers

Aloha Nursing Rehab Centre Reports 2022 Data Breach Affecting More Than 20k Patients

Veris Residential (NJ) Notifies Victims of Recent Data Breach

New FiXS ATM Malware Targeting Mexican Banks

Microsoft Releases Windows Security Updates for Intel CPU Flaws

How to Prevent Microsoft OneNote Files From Infecting Windows With Malware

3/2/2023

Biden Administration Unveils Long-Awaited National Cyber Strategy

Aims to Shift Cybersecurity Burden From Individuals and Small Businesses to Tech Providers

Cisco Chief Says Tech Products Must Be Made More Secure

CISA Releases Free ‘Decider’ Tool to Help with MITRE ATT&CK Mapping

Dashlane to Support New Third-Party Passkey Sync Feature in Android 14

Stop Using Your 4-Digit iPhone Passcode in Public. Do This Instead

Forget ChatGPT, the Most Overhyped Security Tool Is Technology Itself, Wiz Warns

Australian Woman Arrested for Email Bombing a Government Office
WH Smith Discloses Cyber-Attack, Company Data Theft

Chick-Fil-A Confirms Accounts Hacked in Months-Long “Automated” Attack

Hackers Steal Gun Owners’ Data From Firearm Auction Website GunAuction.com

Chinese ‘Mustang Panda’ Hackers Use New Custom Backdoor to Evade Detection

Lucky Mouse: SysUpdate Malware Strikes Again with Linux Version and New Evasion Tactics

Experts Identify ‘Colour-Blind’ Fully-Featured Info Stealer and Trojan in Python Package on PyPI

API Security Flaw Found in Booking.com Allowed Full Account Takeover

This Hacker Tool Can Pinpoint a DJI Drone Operator’s Location

3/1/2023

Russia Bans Foreign Messaging Apps in Government Organizations

Cybercriminals Targeting Law Firms with GootLoader and FakeUpdates Malware

Parallax RAT Targeting Cryptocurrency Firms with Sophisticated Injection Techniques

Budweiser Maker Simplifies How It Assesses Privacy and Cyber Risks

GitHub’s Secret Scanning Alerts Now Available for All Public Repos

Microsoft Exchange Online Outage Blocks Access to Mailboxes Worldwide

ChatGPT: What the New York Times and Others Are Getting Terribly Wrong About It

Hacked Washington Law Firm Covington & Burling Fights SEC Subpoena in Effort to Protect Attorney-Client Privilege

Why Overcoming The Cybersecurity Labor Shortage Matters To Company Success
West Virginia University Alerted of Data Breach, Involves ‘Limited’ Amount of Personal Information Available

Southeastern Louisiana University ‘Likely’ Suffered Cyber Attack

Hatch Bank Announces Third-Party Data Breach at Cybersecurity Firm, Fortra

Crystal Bay Casino Notifies 86,291 Individuals of Recent Data Breach

Trezor Warns of Massive Crypto Wallet Phishing Campaign

Iron Tiger Hackers Create Linux Version of Their Custom Malware

BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11

Cisco Patches Critical Web UI RCE Flaw in Multiple IP Phones

Aruba Networks Fixes Six Critical Vulnerabilities in ArubaOS

2/28/2023

China Is Relentlessly Hacking Its Neighbors

TikTok Answers Three Big Cybersecurity Fears About the App

U.S. Gov’t Agencies Have 30 Days to Remove TikTok, Canada Follows Suit

LastPass Reveals Attackers Stole Password Vault Data by Hacking an Employee’s Home Computer

Krebs: Hackers Claim They Breached T-Mobile More Than 100 Times in 2022

How to Set Up Two-Factor Authentication on Your Online Services

Google: Gmail Client-Side Encryption Now Publicly Available

Bitdefender Releases Free Decryptor for MortalKombat Ransomware Strain

Hacking Attack Prompts Russian Regional Broadcasters to Issue Air Alert Warnings (Again)
Dish Network Confirms Ransomware Attack Behind Multi-Day Outage

City of Oregon City Reports Ransomware Attack

Evergreen Treatment Services (OR) Data Breach Affects Personal Info of 21,325 Patients

Anonymous Call Informs Sentara Healthcare (VA) of Data Breach

LSUs Online Services Restored Tuesday After Network Outage: ‘Not Cyber Event’

APT-C-36 Strikes Again: Blind Eagle Hackers Target Key Industries in Colombia

SCARLETEEL Hackers Use Advanced Cloud Skills to Steal Source Code, Data

CISA Issues Warning on Active Exploitation of ZK Java Web Framework Vulnerability

2/27/2023

U.S. Marshals Service Investigating Ransomware Attack, Data Theft

CISA Tells Agencies What to Prioritize to Meet Cybersecurity Log Mandate

Australia Plans to Reform Cyber Security Rules, Set up Agency

China Makes It Even Harder for Data to Leave Its Shores

Krebs: When Low-Tech Hacks Cause High-Impact Breaches

Researchers Discover Nearly 200,000 New Mobile Banking Trojan Installers

Researchers Share New Insights Into RIG Exploit Kit Malware’s Operations

ChatGPT Is Down Worldwide – OpenAI Working on Issues

A Year After Russia’s Invasion, Cyberdefenses Have Improved Around the World
Minneapolis Public Schools Still Investigating What Caused ‘Encryption Event’

Hacker Leaks Alleged Activision Employee Data on Cybercrime Forum

Alvaria (MA) Announces Data Breach Following Hive Ransomware Attack

Advanced Health Media Leaked SSNs Following Recent Data Breach

Crum & Forster (NJ) Announces Data Breach

New Exfiltrator-22 Post-Exploitation Kit Linked to LockBit Ransomware

RIG Exploit Kit Still Infects Enterprise Users via Internet Explorer

PlugX Trojan Disguised as Legitimate Windows Debugger Tool in Latest Attacks

Critical Flaws in WordPress Houzez Theme Exploited to Hijack Websites

2/24-26/2023

CISA Calls For Increased Vigilance One Year After Ukraine’s Russian Invasion

Russian IT “Brain Drain” Decentralizes Cybercrime

Pentagon Investigating Two-Week Email Server Leak

Royal Mail Appears to Call LockBit’s Ransomware Bluff – Loses Gigabytes of Data

News Corp Says State Hackers Were on Its Network for Two Years

A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life

Krebs: Who’s Behind the Botnet-Based Service BHProxies?

Tesla to Change Camera Settings in Europe Over Privacy Fears

EU Commission Bans TikTok on Corporate Devices

‘Ethical Hacker’ Among Ransomware Suspects Cuffed by Dutch Cops

Bitcoin Mining Rig Found Stashed in Massachusetts School Crawlspace

These Experts Are Racing to Protect AI From Hackers. Time Is Running Out
Telus Source Code, Staff Info for Sale on Dark Web Forum

Dish Network Goes Offline After Likely Cyberattack, Employees Cut Off

Stanford University Discloses Data Breach Affecting PhD Applicants

Encino Energy Says ‘No Impact’ Seen After Cyberattack

Cleveland Brothers Holdings Data Breach Affects Thousands of SSNs

Emtec (FL) Breach Affects Over 7,000 People Following Cyberattack

Rockler Companies (MN) Data Breach Impacts More than 8,600 Individuals

PureCrypter Malware Hits Gov’t Orgs With Ransomware, Info-Stealers

ChromeLoader Campaign Lures With Malicious VHDs for Popular Games

Brave Browser to Block “Open in App” Prompts, Pool-Party Attacks

Google Teams Up with Ecosystem Partners to Enhance Security of SoC Processors

Cybersecurity to Be Least Hit by Layoffs in Economic Downturn

2/23/2023

How the Russia-Ukraine War Has Changed Cyberspace

Ukraine Says Russian Hackers Backdoored Gov’t Websites in 2021

Batteries Are Ukraine’s Secret Weapon Against Russia

Russian Authorities Claim Ukraine Hackers Are Behind Fake Missile Strike Alerts in Almost a Dozen Cities

WinorDLL64 Backdoor Linked to Lazarus Group

How I Broke Into a Bank Account With an AI-Generated Voice

U.S. Regulators Warn Banks to Be on Alert for Crypto-Related Liquidity Risks

Valve “Honeypot” Used to Ban 40,000 Dota 2 Players Using Cheat

You Can’t Trust App Developers’ Privacy Claims on Google Play

Forsage DeFi Platform Founders Indicted for $340 Million Scam

FTX Fiasco Founder SBF Faces Further Fraud Charges

FTC: Americans Lost $8.8 Billion to Fraud in 2022 After 30% Surge

U.S. Extradites Russian Individual for Allegedly Selling Malicious Software
Datacenters in China, Singapore Cracked by Crims Who Then Targeted Tenants

LockBit Leaks 44GB of Royal Mail’s Data and Sets Fresh £33 Million Ransom

Vice Society Ransomware Gang Leaked 2K Los Angeles Student Health Records Online

Hutchinson Clinic (PA) Posts Notice of Data Breach Affecting Sensitive Patient Information

Clasiopa Hackers Use New Atharvan Malware in Targeted Attacks

Hackers Using Trojanized macOS Apps to Deploy Evasive Cryptocurrency Mining Malware

Python Developers Warned of Trojanized PyPI Packages Mimicking Popular Libraries

A World of Hurt for Fortinet and Zoho After Users Fail to Install Patches

Apple Warns of 3 New Vulnerabilities Affecting iPhone, iPad, and Mac Devices

Microsoft Urges Exchange Admins to Remove Some Antivirus Exclusions

How Cybersecurity Executives Make the Case for Continued Tech Investments in a Tough Economy

2/22/2023

Hackers Use Fake ChatGPT Apps to Push Windows, Android Malware and Send Victims to Phishing Pages

Ukraine Suffered More Wiper Malware in 2022 Than Anywhere, Ever

Gcore Thwarts Massive 650 Gbps DDoS Attack on Free Plan Client

Open Source Flaws Found in 84% of Codebases

NSA Shares Guidance on How to Secure Your Home Network

2023 Budget Conversations: Prioritizing Cybersecurity During Economic Downturn

Google Paid $12 Million in Bug Bounties to Security Researchers
Hydrochasma Group Targets Asian Medical and Shipping Sectors

New S1deload Stealer Malware Hijacks Youtube, Facebook Accounts

Cyberattack on Food Giant Dole Temporarily Shuts Down North America Production

Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing Links

Hackers Now Exploit Critical Fortinet Bug to Backdoor Servers

VMware Patches Critical Vulnerability in Carbon Black App Control Product

2/21/2023

Researchers Warn of ReverseRAT Backdoor Targeting Indian Government Agencies

A New Kind of Bug Spells Trouble for iOS and macOS Security

Hackers Exploit Privilege Escalation Flaw on Windows Backup Service

Google Will Boost Android Security Through Firmware Hardening

Accidental WhatsApp Account Takeovers? It’s a Thing

AT&T Seeks to Shed Cybersecurity Division

Sublime Nabs $9.8M for Anti-Phishing Email Security Platform Built on Collective, Crowdsourced Rules

Three City Fund Managers Jailed for $8m Fraud
Sensitive U.S. Military Emails Spill Online via Exposed Server

Russian State TV ‘Hit by Cyber Attack’ During Putin’s Speech

Activision Confirms Data Breach Exposing Employee and Game Info

Virgin Media TV Hack May Cause Disruption to Some Programming

Sophisticated MyloBot Botnet Spreading Rapidly Worldwide: Infecting Over 50,000 Devices Daily

Exploit Released for Critical Fortinet RCE Flaws, Patch Now

Why Security Culture Is Key To Cybersecurity Resilience

Cyberthreats, Regulations Mount for Financial Industry

2/20/2023

Here’s How to Secure Your Twitter Account Without Paying for Blue

DNA Testing Biz Vows to Improve Infosec After Criminals Break Into Database It Forgot It Had

Majority of Ransomware Attacks Last Year Exploited Old Bugs

HardBit Ransomware Wants Insurance Details to Set the Perfect Price

Microsoft AI Chatbot Threatens to Expose Personal Info and Ruin a User’s Reputation

Spanish Court Authorises Extradition to U.S. Of Briton Who Allegedly Hacked Biden, Obama

Inglis Retires as National Cyber Director Ahead of Biden’s Cybersecurity EO
Coinbase Cyberattack Targeted Employees With Fake SMS Alert

Eureka Casino Resort (NV) Announces Data Breach Impacting Nearly 230k Individuals

CentraState Healthcare System Announces Data Breach Impacting as Many as 617k Patients

Lehigh Valley Health Network (PA) Hit by Cyberattack

O’Neal Industries Reports Recent Data Breach

Tom James Company (TN) Files Notice of Data Breach Affecting 8,656 Individuals

New Stealc Malware Emerges With a Wide Set of Stealing Capabilities

2/17-19/2023

EU Cybersecurity Agency Warns Against Chinese APTs

Google Report Reveals Russia’s Elaborate Cyber Strategy in Ukraine

‘Russian Hacktivists’ Brag of Flooding German Airport Sites

Experts Warn of RambleOn Android Malware Targeting South Korean Journalists

Armenia and Azerbaijan Hackers Use OxtaRAT to Monitor Conflict

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

Krebs: New Protections for Food Benefits Stolen by Skimmers

Samsung Has Created a Zero-Click Antivirus for Messages

How to Unlock Your iPhone With a Security Key

Twitter Limits SMS-Based 2-Factor Authentication to Blue Subscribers Only

Europol Busts ‘CEO Fraud’ Gang That Stole €38M in a Few Days

Norwegian Police Recover $5.8M Crypto From Massive Axie Infinity Hack
FBI Says It Has ‘Contained’ Cyber Incident on Bureau’s Computer Network

Hackers Ran Amok Inside GoDaddy for Nearly 3 Years

Data Leak Hits Thousands of Liverpool NHS Workers

MKS Instruments (MA) Data Breach Affects Current and Former Employees

Paul Smith’s College (NY) Data Breach Impacts Over 10k Individuals

Suffolk County, N.Y., Restores Systems After September Cyberattack

New WhiskerSpy Malware Delivered via Trojanized Codec Installer

Critical RCE Vulnerability Discovered in ClamAV Open Source Antivirus Software

Fortinet Issues Patches for 40 Flaws Affecting FortiWeb, FortiOS, FortiNAC, and FortiProxy

AppSec Threats Deserve Their Own Incident Response Plan

Here’s the 12 Best Ways to Avoid Being Scammed Online

The Five Important Moments In History That Shaped The Modern Cybersecurity Landscape

2/16/2023

DOJ, Commerce Department Strike Force to Fight Technology Threats From Adversaries

ESXiArgs Ransomware Hits Over 500 New Targets in European Countries

Microsoft Exchange ProxyShell Flaws Exploited in New Crypto-Mining Attack

New Mirai Malware Variant Infects Linux Devices to Build DDoS Botnet

CISA Warns of Windows and iOS Bugs Exploited as Zero-Days

Privacy Regulators Step Up Oversight of AI Use in Europe

BEC Groups Target Firms With Multilingual Impersonation Attacks

Hackers Leverage PayPal to Send Malicious Invoices

Crypto Buyers Beware: 1 in 4 New Tokens of Any Value Is a Scam

Protecting More With What You Have: Cybersecurity Resilience In 2023
New Threat Actor WIP26 Targeting Telecom Service Providers in the Middle East

Burton Snowboards Cancels Online Orders After ‘Cyber Incident’

German Airport Websites Hit by Suspected Cyber Attack

Scandinavian Airlines Says Cyberattack Caused Passenger Data Leak

Atlassian Says Recent Data Leak Stems From Third-Party Vendor Hack

Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular Apps

Hackers Start Using Havoc Post-Exploitation Framework in Attacks

Hackers Backdoor Microsoft IIS Servers With New Frebniis Malware

Researchers Warn of Critical Security Bugs in Schneider Electric Modicon PLCs