11/14/2024

Trump’s Second Term Is Expected to Bring Big Change to Top U.S. Cyber Agency

More Spyware, Fewer Rules: What Trump’s Return Means for U.S. Cybersecurity

Washington’s Cybersecurity Storm of Complacency

Sitting Ducks DNS Attacks Put Global Domains at Risk

Google Warns of Rising Cloaking Scams, AI-Driven Fraud, and Crypto Schemes

Bank of England U-turns on Vulnerability Disclosure Rules

Cybercriminal Devoid of Boundaries Gets 10-Year Prison Sentence

Teen Behind Hundreds of Swatting Attacks Pleads Guilty to Federal Charges

Malware Being Delivered by Mail, Warns Swiss Cyber Agency
Hungary Confirms Hack of Defense Procurement Agency

Kids’ Shoemaker Start-Rite Trips Over Security Again, Spilling Customer Card Info

Microsoft Power Pages Misconfiguration Leads to Data Exposure

New Glove Infostealer Malware Bypasses Chrome’s Cookie Encryption

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails

New RustyAttr Malware Targets macOS Through Extended Attribute Abuse

CISA Warns of More Palo Alto Networks Bugs Exploited in Attacks

ChatGPT Allows Access to Underlying Sandbox OS, “Playbook” Data

11/13/2024

China-Linked Hackers Stole Surveillance Data From Telecom Companies, U.S. Says

Hamas-Affiliated WIRTE Employs SameCoin Wiper in Disruptive Attacks Against Israel

Trump’s Second Term Is Expected to Bring Big Change to Top U.S. Cyber Agency

Top White House Cyber Official Urges Trump to Focus on Ransomware, China

These Are the Passwords You Definitely Shouldn’t Be Using

Leaked Info of 122 Million Linked to B2B Data Aggregator Breach

Data Broker Amasses 100M+ Records on People – Then Someone Snatches, Sells It

These Guys Hacked AirPods to Give Their Grandmas Hearing Aids

Amazon MOVEit Leaker Claims to Be Ethical Hacker

Chinese National Faces 20 Years in U.S. Prison for Laundering Pig-Butchering Proceeds
China-Linked Group Hacked Tibetan Media and University Sites to Distribute Cobalt Strike Payload

Embargo Ransomware Fiends Boast They’ve Stolen 1.4TB From U.S. Pharmacy Network

Wisconsin City of Sheboygan Says Ransom Demanded After Cyberattack

ASM Global (CA) Notifies Affected Individuals of Recent Data Breach

Hive0145 Targets Europe with Advanced Strela Stealer Campaigns

New ShrinkLocker Ransomware Decryptor Recovers Bitlocker Password

Critical Bug in EoL D-Link NAS Devices Now Exploited in Attacks

Krebs: Microsoft Patch Tuesday, November 2024 Edition

NIST Says Exploited Vulnerability Backlog Cleared but End-Of-Year Goal for Full List Unlikely

New Google Pixel AI Feature Analyzes Phone Conversations for Scams

11/12/2024

German Interior Minister Warns of Cyber Threat Ahead of Elections

Volt Typhoon Rebuilds Malware Botnet Following FBI Disruption

Surge in Exploits of Zero-Day Vulnerabilities Is ‘New Normal’ Warns Five Eyes Alliance

FBI, CISA, and NSA Reveal Most Exploited Vulnerabilities of 2023

Microsoft November 2024 Patch Tuesday Fixes 4 Zero-Days, 91 Flaws

Two Zero-Day Bugs in Microsoft’s Nov. Update Under Active Exploit

Windows 10 KB5046613 Update Released with Fixes For Printer Bugs

CISOs Turn to Indemnity Insurance as Breach Pressure Mounts

Signal Introduces Convenient “Call Links” for Private Group Chats

Pentagon Leaker Sentenced to 15 Years in Jail After Sharing Military Secrets Online
Dutch Company Behind Hannaford, Stop & Shop Says Cyber Issue Affecting U.S. Network

Delta, Amazon Confirm Vendor Breach as Dark Web Posts Revive MOVEit Leak Concerns

BBS Financial (MA) Confirms Data Breach Following January 2024 Ransomware Attack

North Korean Hackers Target macOS Using Flutter-Embedded Malware

TA455’s Iranian Dream Job Campaign Targets Aerospace with Malware

Phishing Tool GoIssue Targets Developers on GitHub

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

D-Link Won’t Fix Critical Bug in 60,000 Exposed EoL Modems

How Italy Became an Unexpected Spyware Hub

11/11/2024

Credit Cards Readers Across Israeli Stores, Gas Stations Crash in Cyberattack

FBI Issues Warning as Crooks Ramp up Emergency Data Request Scams

WEF Introduces Framework to Strengthen Anti-Cybercrime Partnerships

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation

The AI Machine Gun of the Future Is Already Here

Halliburton Reports $35 Million Loss After Ransomware Attack

Open Source Security Incidents Aren’t Going Away
Amazon Confirms Employee Data Breach, but Says It’s Limited to Contact Info

HIBP Notifies 57 Million People of Hot Topic Data Breach

Food Lion Acknowledges They Were Hit by Cyberattack

Set Forth, Inc. (IL) Sends Data Breach Letters to 1.5 Million Consumers

English Construction Company (VA) Targeted in Ransomware Attack, Leading to Data Breach Affecting Former Employees

New Remcos RAT Variant Targets Windows Users Via Phishing

New Ymir Ransomware Partners With RustyStealer in Attacks

11/8-10/2024

Pro-Russian Hacktivists Target South Korea as North Korea Joins Ukraine War

Authorities Work to Find the Source of Racist Texts Sent to Black People Nationwide After the Election

TSA Wants to Expand Cyber Rules for Pipelines and Railroads

Scattered Spider, BlackCat Claw Their Way Back From Criminal Underground

Scammers Target UK Senior Citizens With Winter Fuel Payment Texts

Google’s Mysterious ‘search.app’ Links Leave Android Users Concerned

A New iOS 18 Security Feature Makes It Harder for Police to Unlock iPhones

FBI: Spike in Hacked Police Emails, Fake Subpoenas (Krebs)

Bitcoin Fog Founder Sentenced to 12 Years for Cryptocurrency Money Laundering
IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools

Malicious NPM Packages Target Roblox Users with Data-Stealing Malware

Malicious PyPI Package with 37,000 Downloads Steals AWS Keys

Hackers Now Use Zip File Concatenation to Evade Detection

Critical Veeam RCE Bug Now Used in Frag Ransomware Attacks

Unpatched Mazda Connect Bugs Let Hackers Install Persistent Malware

Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat Concerns

D-Link Won’t Fix Critical Flaw Affecting 60,000 Older NAS Devices

How the Creator of Zero Trust Developed Today’s Most Robust Cybersecurity Strategy

Russia’s Internet Watchdog Blocks Thousands of Websites That Use Cloudflare’s Privacy Service

11/7/2024

U.S. Agency Warns Employees About Phone Use Amid Ongoing China Hack

China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait

China-Linked Hackers Tasked With Japanese Targets Pursue Them Through Europe

Canada Orders Shutdown of Local TikTok Branch Over Security Concerns

764 Terror Network Member Richard Densmore Sentenced to 30 Years in Prison

Akamai Forecasts Fourth-Quarter Revenue Below Estimates on Weak Client Spending

Cloudflare’s Q4 Revenue Forecast Falls Short as Cybersec Competition Intensifies

Fortinet’s Quarterly Revenue Forecast Disappoints, Shares Fall

Datadog Raises Annual Forecast Betting on AI-Driven Cybersecurity Demand

Defenders Outpace Attackers in AI Adoption
Nokia Says Hackers Leaked Third-Party App Source Code

Texas-Based Oilfield Supplier Newpark Resources Faces Disruptions Following Ransomware Attack

OrthopedicsNY Files Official Notice of 2023 Data Breach Affecting Patient Information

North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS

Don’t Open That ‘Copyright Infringement’ Email Attachment – It’s an Infostealer

Androxgh0st Botnet Adopts Mozi Payloads, Expands IoT Reach

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

CISA Warns of Critical Palo Alto Networks Bug Exploited in Attacks

HPE Warns of Critical Rce Flaws in Aruba Networking Access Points

The Power of Process in Creating a Successful Security Posture

11/6/2024

Top U.S. Cyber Official Says ‘No Evidence of Malicious Activity’ Impacting Election

Fact Check: Georgia Voter Fraud Video Labeled Russian Disinformation Uses False Personal Data

IRISSCON: Organizations Still Falling Victim to Predictable Cyber-Attacks

Cybercrooks Are Targeting Bengal Cat Lovers in Australia for Some Reason

People Urged to Update Some Internet Routers

Germany Drafts Law to Protect Researchers Who Find Security Flaws

Major Ukrainian University Bans Telegram to Reduce Cyberthreats

UK Orders Chinese Owners to Relinquish Control of Scottish Semiconductor Business

Massive Nigerian Cybercrime Bust Sees 130 Arrested
Washington Courts’ Systems Offline Following Weekend Cyberattack

Cyber-Attack on Microlise Disrupts DHL and Serco Tracking Services

Cyberattack Disables Tracking Systems and Panic Alarms on British Prison Vans

SelectBlinds Says 200,000 Customers Impacted After Hackers Embed Malware on Site

Nokia: No Evidence So Far That Hackers Breached Company Data

Winos4.0 Malware Found in Game Apps, Targets Windows Users

New SteelFox Malware Hijacks Windows PCs Using Vulnerable Driver

VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware

Cisco Bug Lets Hackers Run Commands as Root on UWRB Access Points

11/5/2024

The FBI Says Russian Emails Are Sending Fake Bomb Threats to Polling Stations

Russia Is Going All Out on Election Day Interference

U.S. Warns of Last-Minute Iranian and Russian Election Influence Ops

Officials Warn Against Fake U.S. Election Videos, but See Little Disruption

ClickFix Exploits Users with Fake Errors and Malicious Code

Interpol Disrupts Cybercrime Activity on 22,000 IP Addresses, Arrests 41

Krebs: Canadian Man Arrested in Snowflake Data Extortions

A Kansas Pig Butchering: CEO Who Defrauded Bank, Church, Friends Gets 24 Years

FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions

Meta Found to Have Exposed Info on North Korean Defectors to Advertisers

Ukraine Accuses Google of Revealing Locations of Its Military Systems
Georgia Hospital Unable to Access Record System After Ransomware Attack

Schneider Electric Ransomware Crew Demands $125K Paid in Baguettes

Chinese Group Accused of Hacking Singtel in Telecom Attacks

Chinese Air Fryers May Be Spying on Consumers, Which? Warns

ToxicPanda Malware Targets Banking Apps on Android Devices

Pakistani Hackers Targeted High-Profile Indian Entities using Custom ElizaRAT

Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages

Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices

Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System

Google Cloud to Make MFA Mandatory by the End of 2025

How to Win at Cyber by Influencing People

11/4/2024

U.S. Cybersecurity Chief Says Disinformation Surge Hasn’t Impacted Election

In Final Check-in Before Election Day, CISA Cites Low-Level Threats, and Not Much Else

Nakasone Says All the News About Influence Campaigns Ahead of Election Day Is Actually ‘A Sign of Success’

Rep. Yvette Clarke on AI-Fueled Disinformation: ‘We Have Not Protected Ourselves in Time for This Election Cycle’

U.S. Says Russia Behind Fake Haitian Voters Video

Moldova Elects Pro-West President Maia Sandu Despite Russian Interference

Custom “Pygmy Goat” Malware Used in Sophos Firewall Hack on Gov’t Network

Inside the Massive Crime Industry That’s Hacking Billion-Dollar Companies

Northern Minnesota Man Cost Former Employer $45K in Cryptojacking Scheme, Charges Say

Nigerian Handed 26-Year Sentence for Real Estate Phishing Scam

Google Researchers Claim First Vulnerability Found Using AI
Schneider Electric Confirms Dev Platform Breach After Hacker Steals Data

Nokia Investigates Breach After Hacker Claims to Steal Source Code

Cisco Says DevHub Site Leak Won’t Enable Future Breaches

Columbus (OH) Ransomware Attack Exposes Data of 500,000 Residents

Middlesbrough Council Targeted in Second Cyber Attack in a Week

Houston Housing Authority Was Victim of a Ransomware Attack, Agency Says

Kemlon Products & Development Group (TX) Files Official Notice of Data Breach

Meet Interlock — The New Ransomware Targeting FreeBSD Servers

Windows Infected With Backdoored Linux VMs in New Phishing Attacks

Cybercriminals Exploit DocuSign APIs to Send Fake Invoices

Supply Chain Attack Uses Smart Contracts for C2 Ops

Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning

11/1-3/2024

Georgia Says U.S., Election Disinformation Likely Coming From Russian Troll Farms

U.S. Blames Russia Over Video Falsely Alleging Fraudulent Voting in State of Georgia

China’s Typhoon Hacks Ahead of U.S. Election Spurred by Elite Competition

Cyber Threats and the Election: What You Need to Know

Sophos Warns Chinese Hackers Are Becoming Stealthier

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft

U.S. and Israel Warn of Iranian Threat Actor’s New Tradecraft

Krebs: Booking.com Phishers May Leave You With Reservations

They’re Giving Scammers All Their Money. The Kids Can’t Stop Them.

6 IT Contractors Arrested for Defrauding Uncle Sam Out of Millions

DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany

Florida Man Accused of Hacking Disney World Menus, Changing Font to Wingdings

Hack Nintendo’s Alarm Clock to Show Cat Pics? Let’s-A-Go!

ChatGPT-4o Can Be Used for Autonomous Voice-Based Scams

OpenAI’s New ChatGPT Search Chrome Extension Feels Like a Search Hijacker
LA Housing Authority Confirms Breach Claimed by Cactus Ransomware

San Joaquin County Superior Court (CA) Suffering From Tech Outages After Cyberattack

Ransomware Attack Hits German Pharmaceutical Wholesaler AEP, Disrupts Medicine Supplies

Young People’s Data Feared Stolen in Cyberattack on French Government Contractor

Saint Xavier University Notifies Over 200k People of Recent Data Breach

Middlesbrough Council Website Restored After Online Attack

A Devon School ‘Blackmailed’ by Hackers in Cyber-Attack

LastPass Warns of Fake Support Centers Trying to Steal Customer Data

An Okta Login Bug Bypassed Checking Passwords on Some Long Usernames

Microsoft SharePoint RCE Bug Exploited to Breach Corporate Network

Zero-Click Flaw Exposes Potentially Millions of Popular Storage Devices to Attack

CISA Warns of Critical Software Vulnerabilities in Industrial Devices

Microsoft Delays Windows Copilot+ Recall Release Over Privacy Concerns

Federal Agency Investigating How Meta Uses Consumer Financial Data for Advertising

10/31/2024

Pro-Russia Hackers Claim Council Cyber Attacks, Including Greater Manchester

Suspected Pro-Ukraine Cyberattack Knocks Out Parking Enforcement in Russian City

Canadian Government Data Stolen By Chinese Hackers

Microsoft: Chinese Hackers Use Quad7 Botnet to Steal Credentials

Inside a Firewall Vendor’s 5-Year War With the Chinese Hackers Hijacking Its Devices

The Untold Story of Trump’s Failed Attempt to Overthrow Venezuela’s President

FBI: Iranian Cyber Group Targeted Summer Olympics With Attack on French Display Provider

UK Finance Firms Told to Beef up Buffers Against Crowdstrike-Like Events

Microsoft Wants $30 if You Want to Delay Windows 11 Switch

2024 Looks Set to Be Another Record-Breaking Year for Ransomware — And It’s Likely Going to Get Worse
Over a Thousand Online Shops Hacked to Show Fake Product Listings

Large Peruvian Bank Warns of Data Theft After Dark Web Post Emerges

Blackburn College Still Operating Despite Cyber-Attack

St. Anthony Regional Hospital (IA) Provides Notice of Data Breach

LottieFiles Supply Chain Attack Exposes Users to Malicious Crypto Wallet Drainer

New Xiu Gou Phishing Kit Targets U.S., Other Countries with Mascot

Hackers Target Critical Zero-Day Vulnerability in PTZ Cameras

LiteSpeed Cache WordPress Plugin Bug Lets Hackers Get Admin Access

qBittorrent Fixes Flaw Exposing Users to MitM Attacks for 14 Years

Cybersecurity Job Market Stagnates, Dissatisfaction Abounds

Russia to Ban Cryptocurrency Mining in Some Regions Due to Electricity Shortages

10/30/2024

Midnight Blizzard Spearphishing Campaign Targets Thousands with RDP Files

North Korean Group Collaborates with Play Ransomware in Significant Cyber Attack

Beijing Claims It’s Found ‘Underwater Lighthouses’ That Its Foes Use for Espionage

‘We’re a Fortress Now’: The Militarization of U.S. Elections Is Here

Colorado Voting System Partial Passwords Accidentally Posted on Government Website

FBI: Upcoming U.S. General Election Fuel Multiple Fraud Schemes

Fired Disney Staffer Accused of Hacking Menu to Add Profanity, Wingdings, Removes Allergen Info

Krebs: Change Healthcare Breach Hits 100M Americans

UnitedHealth Hires Cybersecurity Veteran as New CISO

Google’s AI-Fueled Gains in Cloud Bode Well for Amazon, Microsoft

Cyber Vendor Netskope Plans 2025 IPO
Interbank Confirms Data Breach Following Failed Extortion, Data Leak

Starkweather and Shepley Insurance Brokerage (RI) Provides Notice of Recent Data Breach

Hackers Steal 15,000 Cloud Credentials From Exposed Git Config Files

Malware Campaign Expands Its Use of Fake CAPTCHAs

Updated FakeCall Malware Targets Mobile Devices with Vishing

Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware

Researchers Uncover Python Package Targeting Crypto Wallets with Malicious Code

Opera Browser Fixes Big Security Hole That Could Have Exposed Your Information

Apple Rolls Out Major Security Update to Patch macOS and iOS Vulnerabilities

QNAP Patches Second Zero-Day Exploited at Pwn2Own to Get Root

When Cybersecurity Tools Backfire

10/29/2024

Trump Family Members and Biden Aides Among China Hack Targets

Merde! Macron’s Bodyguards Reveal His Location by Sharing Strava Data

Russia and China-Linked State Hackers Intensify Attacks on Netherlands, Security Officials Warn

Suspicious Social Media Accounts Deployed Ahead of COP29

Five Eyes Agencies Launch Startup Security Initiative

Six Senators Tell Biden Administration UN Cybercrime Treaty Must Be Changed

NIS2 Compliance Puts Strain on Business Budgets

TSA Silent on CrowdStrike’s Claim Delta Skipped Required Security Update

MoneyGram Replaces CEO Weeks After Massive Customer Data Breach

Russian Charged by U.S. For Creating RedLine Infostealer Malware
The Center for Urban Community Services (NY) Notifies 38,000 People of Recent Data Breach

Chenlun’s Evolving Phishing Tactics Target Trusted Brands

New LightSpy Spyware Targets iOS with Enhanced Capabilities

Massive PSAUX Ransomware Attack Targets 22,000 CyberPanel Instances

New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel Processors

Researchers Uncover Vulnerabilities in Open-Source AI and ML Models

New Windows Themes Zero-Day Gets Free, Unofficial Patches

QNAP Fixes NAS Backup Software Zero-Day Exploited at Pwn2Own

How to Find the Right CISO

Russia Says It Might Build Its Own Linux Community After Removal of Several Kernel Maintainers

10/28/2024

Chinese Hackers Said to Have Collected Audio of American Calls

Including Trump Advisor

Cybercriminals Pose a Greater Threat of Disruptive U.S. Election Hacks Than Russia or China

Evasive Panda’s CloudScout Toolset Targets Taiwan

Russian Malware Campaign Targets Ukrainian Recruits Via Telegram

Japanese Man Sentenced to 3 Years After Creating Crypto Ransomware With AI

Redline, Meta Infostealer Malware Operations Seized by Police

JPMorgan Chase Sues Scammers Following Viral ‘Infinite Money Glitch’

Delta, CrowdStrike Sue Each Other Over Widespread IT Outage That Caused Thousands of Cancellations

Sinclair Sues Cyber Insurers Over 2021 Hack

Cybersecurity Firm Rapid7 Fields Buyout Interest, Sources Say

Cyber Firm Armis Security Raises $200 Million at $4.3 Billion Valuation
Italian Politicians Express Alarm at Latest Data Breach Allegedly Affecting 800,000 Citizens

Free, France’s Second Largest ISP, Confirms Data Breach After Leak

TEAM Software (NE) Confirms July 2024 Data Breach Impacting Thousands of SSNs

Wichita County (TX) Says 47,000 Had SSNs, Medical Treatment Info Leaked During May Cyberattack

Over 6,500 Patients Affected by Parkland Health in Dallas Possible Data Breach

Cybercriminals Use Webflow to Deceive Users into Sharing Sensitive Login Credentials

New Type of Job Scam Targets Financially Vulnerable Populations

AI-Powered BEC Scams Zero in on Manufacturers

BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers

New Tool Bypasses Google Chrome’s New Cookie Encryption System

Mozilla: ChatGPT Can Be Manipulated Using Hex Code

Put End-of-Life Software to Rest

10/25-27/2024

Chinese Hackers Are Said to Have Targeted Phones Used by Trump and Vance

Harris Campaign Too

U.S. Panel to Probe Cyber Failures in Massive ‘Salt Typhoon’ Chinese Hack of Telecoms

Kremlin-Linked APT29 Hackers Target Ukraine’s State, Military Agencies in New Espionage Campaign

Ukraine Warns of Mass Phishing Campaign Targeting Citizens Data

Senator Accuses Sloppy Domain Registrars of Aiding Russian Disinfo Campaigns

Linux Creator Approves De-Listing of Several Kernel Maintainers Associated With Russia

Claude AI Gets Bored During Coding Demonstration, Starts Perusing Photos of National Parks Instead

Reuters Exposé of Hack-For-Hire World Is Back Online After Indian Court Ruling

Delta Sues CrowdStrike Over Software Update That Prompted Mass Flight Disruptions

Amazon Seizes Domains Used in Rogue Remote Desktop Campaign to Steal Data

Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions
Henry Schein Discloses Data Breach a Year After Ransomware Attack

RansomHub Gang Allegedly Behind Attack on Mexican Airport Operator

Chimienti & Associates (CA) Experiences Data Breach Following Compromised Email Account

Community Dental (ME) Files Official Notice of Data Breach After Cyberattack Exposed Patients’ Sensitive Info

Black Basta Ransomware Poses as IT Support on Microsoft Teams to Breach Networks

Notorious Hacker Group TeamTNT Launches New Cloud Attacks for Crypto Mining

Fog Ransomware Targets SonicWall VPNs to Breach Corporate Networks

Researchers Discover Command Injection Flaw in Wi-Fi Alliance’s Test Suite

New Windows Driver Signature Bypass Allows Kernel Rootkit Installs

New Cisco ASA and FTD Features Block VPN Brute-Force Password Attacks

QNAP, Synology, Lexmark Devices Hacked on Pwn2Own Day 3

Over 70 Zero-Day Flaws Get Hackers $1 Million at Pwn2Own Ireland

10/24/2024

White House Issues AI National Security Memo

Cybersecurity Teams Largely Ignored in AI Policy Development

Voice-Enabled AI Agents Can Automate Everything, Even Your Phone Scams

Apple Will Pay Security Researchers up to $1 Million to Hack Its Private AI Cloud

Meet ZachXBT, the Masked Vigilante Tracking down Billions in Crypto Scams and Thefts

Courts Side With Auto Suppliers in Clash With Carmakers Over Vehicle Data Access

Ireland Fines LinkedIn €310 Million Over Targeted Advertising

CFPB Warns Industry Against ‘Deeply Invasive’ Workplace Digital Surveillance
UnitedHealth Says Change Healthcare Hack Affects Over 100 Million, the Largest Ever U.S. Healthcare Data Breach

How the Ransomware Attack at Change Healthcare Went Down: A Timeline

Insurance Admin Landmark Says Data Breach Impacts 800,000 People

New Qilin.B Ransomware Variant Emerges with Improved Encryption and Evasion Tactics

Mandiant Says New Fortinet Flaw Has Been Exploited Since June

Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active Attack

Samsung Galaxy S24 and Sonos Era Hacked on Pwn2Own Ireland Day 2

Why Cybersecurity Acumen Matters in the C-Suite

10/23/2024

Microsoft Warns Foreign Disinformation Is Hitting the U.S. Election From All Directions

Georgia Election Official Says Battleground State Fended off Cyberattack Likely From a Foreign Country

Former British PM Cameron Calls for Tech Engagement with China Despite Cyber Threats

U.S. Energy Sector Vulnerable to Supply Chain Attacks

U.S. Government Pledges to Cyber Threat Sharing Via TLP Protocol

Google to Let Businesses Create Curated Chrome Web Stores for Extensions

WhatsApp Now Encrypts Contact Databases for Privacy-Preserving Synching

Krebs: The Global Surveillance Free-for-All in Mobile Ad Data

UK Government Weighs Review of Computer Misuse Act to Combat Cybercrime

UK Court Says Dissident Can Sue the Saudi Government for Targeting Him With Spyware

Nigeria Drops Charges Against Tigran Gambaryan, Jailed Binance Exec and Former IRS Agent
Russia Says ‘Unprecedented’ Cyber Attack Hits Foreign Ministry Amid BRICS Summit

Rhysida Ransomware Group Targets Prominent Nonprofit for Disabled People Easterseals

Data Breach at Autobell Car Wash Impacts 52,714 Individuals

Embargo Ransomware Gang Deploys Customized Defense Evasion Tools

New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection

Ransomware Gangs Use LockBit’s Fame to Intimidate Victims in Latest Attacks

Researchers Reveal ‘Deceptive Delight’ Method to Jailbreak AI Models

Lazarus Hackers Used Fake DeFi Game to Exploit Google Chrome Zero-Day

CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)

Fortinet Warns of New Critical FortiManager Flaw Used in Zero-Day Attacks

Hackers Exploit 52 Zero-Days on the First Day of Pwn2Own Ireland

10/22/2024

TSMC Blows Whistle on Potential Sanctions-Busting Shenanigans From Huawei

Prigozhin Links, Kremlin Funding Put Another Russian Media Company on U.S. List

Foreign Influence Operations Will Expand Before Election and Linger Afterward, U.S. Agencies Say

Exposed United Nations Database Left Sensitive Information Accessible Online

75% of US Senate Campaign Websites Fail to Implement DMARC

The Shitposting Cartoon Dogs Sending Trucks, Drones, and Weapons to Ukraine’s Front Lines

Senators Seek Biden Administration Review of Undersea Cable Vulnerabilities

LLMjacking and Open-Source Tool Abuse Surge in 2024 Cloud Attacks

AWS, Azure Auth Keys Found in Android and iOS Apps Used by Millions

Meta Brings Back Face Scanning to Combat Scams and Account Hacking

Think Tanks Urge Action to Curb Misuse of Spyware and Hack-for-Hire

SEC Charges Tech Firms Over Misleading SolarWinds Hack Disclosures

CISA Proposes New Security Requirements to Protect Gov’t, Personal Data
Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans

Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies

Akira Ransomware Is Encrypting Victims Again Following Pure Extortion Fling

Malicious npm Packages Target Developers’ Ethereum Wallets with SSH Backdoor

Cybercriminals Exploiting Docker API Servers for SRBMiner Crypto Mining Attacks

Zendesk Helped Internet Archive Secure Account After Hacker Breached Email System

Schreck Financial Group (KS) Experiences Email-Related Data Breach

Exploit Released for New Windows Server “WinReg” NTLM Relay Attack

FortiGate Admins Report Active Exploitation 0-Day. Vendor Isn’t Talking.

Security Flaw in Styra’s OPA Exposes NTLM Hashes to Remote Attackers

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

The Struggle for Software Liability: Inside a ‘Very, Very, Very Hard Problem’

10/21/2024

Hezbollah Cyberattack Targets Haifa Hospitals After Beirut Hospital Bombing

Cyprus’ Critical Infrastructure Targeted by Coordinated Cyberattacks Linked to Pro-Palestine Groups

‘Unprecedented’ Interference Targets Moldova’s Elections

China’s Spamouflage Disinformation Campaign Testing Techniques on Sen. Marco Rubio

Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain

U.S. Government Says Relying on Chinese Lithium Batteries Is Too Risky

Biden Administration Proposes New Rules Governing Data Transfers to Adversarial Nations

ICE’s $2 Million Contract With a Spyware Vendor Is Under White House Review

Sophos Buys Secureworks for $859 Mln to Beef up Cybersecurity Portfolio
Japanese Watchmaker Casio Warns of Delivery Delays After Ransomware Attack

Crypto Payment Services Firm Transak Says More Than 92,000 Affected by Data Breach

Spate of Ransomware Attacks on German-Speaking Schools Hits Another in Switzerland

Netskope Reports Possible Bumblebee Loader Resurgence

Over 6,000 WordPress Hacked to Install Plugins Pushing Infostealers

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers

Half of Organizations Have Unmanaged Long-Lived Cloud Credentials

The Billionaire Behind Trump’s ‘Unhackable’ Phone Is on a Mission to Fight Tesla’s FSD

Australia’s Privacy Watchdog Publishes Guidance on Commercial AI Products

10/18-20/2024

ESET Partner Breached to Send Data Wipers to Israeli Orgs

North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data

The Disinformation Warning Coming From the Edge of Europe

U.S. Cybersecurity Chief Says Election Systems Have ‘Never Been More Secure’

What the U.S. Army’s 1959 ‘Soldier of Tomorrow’ Got Right About the Future of Warfare

Google Scholar Has a ‘Verified Email’ for Sir Isaac Newton

Microsoft Creates Fake Azure Tenants to Pull Phishers Into Honeypots

The Government Is Getting Fed up With Ransomware Payments Fueling Endless Cycle of Cyberattacks

Krebs: Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach

Tech CEO Charged With Fraud Over Security, Reliability Claims

After Rejecting Google Takeover, Cyber Firm Wiz Says It Will IPO ‘When the Stars Align’

Instagram Rolls Out New Sextortion Protection Measures

Europe Launches ‘Gait Recognition’ Pilot Program to Monitor Border Crossings
Tech Giant Nidec Confirms Data Breach Following Ransomware Attack

Cisco Takes DevHub Portal Offline After Hacker Publishes Stolen Data

Crypto Platform Radiant Capital Says $50 Million in Digital Coins Stolen Following Account Compromises

The Internet Archive Hackers Still Have Access to Its Internal Emailing Tools

Boston Children’s Health Physicians Confirms September Data Breach

Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks

Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials

CISA Confirms Veeam Vulnerability Is Being Used in Ransomware Attacks

Intel, AMD CPUs on Linux Impacted by Newly Disclosed Spectre Bypass

macOS Vulnerability Could Expose User Data, Microsoft Warns

Jetpack Fixes 8-Year-Old Flaw Affecting Millions of WordPress Sites

Open Source LLM Tool Primed to Sniff out Python Zero-Days

CISOs: Throwing Cash at Tools Isn’t Helping Detect Breaches

10/17/2024

Hamas Leader Yahya Sinwar Killed in Gaza, Israeli Military Says

Intel China Responds to Accusations of Security Issues From Chinese Cyber Association

Undercover North Korean IT Workers Now Steal Data, Extort Employers

Two-thirds of Attributable Malware Linked to Nation States

GPS Jamming Is Screwing With Norwegian Planes

This Prompt Can Make an AI Chatbot Identify and Extract Personal Details From Your Chats

Activision Says It’s Fixed an Anti-cheat Hack in Modern Warfare III and Call of Duty: Warzone

Uncle Sam Puts $10M Bounty on Russian Troll Farm Rybar

More Than 5,000 Arrested, Thousands of Websites Disrupted in Crackdown on Illegal Gambling During Euro Tournament

FBI Arrests Alabama Man Suspected of Hacking SEC’s X Account

Krebs: Sudanese Brothers Arrested in ‘AnonSudan’ Takedown

Ukraine Tracks Emailed Bomb Threats to Russia-Linked Group

A Tough New EU Cyber Law Is off to a Messy Start, With Many Countries Failing to Adopt the Rules

Kroger’s Facial Recognition Plans Draw Increasing Concern From Lawmakers
Japan’s Ruling Political Party Hit by Cyberattack From Alleged Pro-Russian Hackers

Independent Russian News Site Rides Out a Week of DDoS Incidents

Microsoft Warns It Lost Some Customer’s Security Logs for a Month

Troubled U.S. Insurance Giant Globe Life Hit by Extortion After Data Leak

Casio Says ‘No Prospect of Recovery Yet’ After Ransomware Attack

Internet Archive Slowly Revives After DDoS Barrage

BianLian Ransomware Claims Attack on Boston Children’s Health Physicians

Georgetown University Says Group of Students Accessed Sensitive, Academic Information

Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant

Fake Google Meet Conference Errors Push Infostealing Malware

Cicada3301 Ransomware Targets Critical Sectors in US and UK

RansomHub Overtakes LockBit as Most Prolific Ransomware Group

WeChat Devs Introduced Security Flaws When They Modded TLS, Say Researchers

CISA Seeks Feedback on Upcoming Product Security Flaws Guidance

What Cybersecurity Leaders Can Learn From the Game of Golf

10/16/2024

China’s New Focus in U.S. Elections Interference Is Not Harris-Trump Presidential Race

Chinese Cyber Association Calls for Review of Intel Products Sold in China

China Says Unidentified Foreign Company Conducted Illegal Mapping Services

Firm Hacked After Accidentally Hiring North Korean Cyber Criminal

Iranian Hackers Act as Brokers Selling Critical Infrastructure Access

Mystery Drones Swarmed a U.S. Military Base for 17 Days. The Pentagon Is Stumped.

Hacker Charged With Seeking to Kill Using Cyberattacks on Hospitals

USDoD Hacker Behind National Public Data Breach Arrested in Brazil

Russia’s Case Against REvil Hackers Proceeds as Government Recommends 6.5-Year Sentence

For Some Companies, the Real Cost of a Cyberattack Is Telling Everyone About It

Financial Firms Need to Focus on Cyber Risks Posed by AI, New York Regulator Says

EU AI Act Checker Reveals Big Tech’s Compliance Pitfalls

Ethical Hackers Embrace AI Tools Amid Rising Cyber Threats

UK Government Launches AI Safety Scheme to Tackle Deepfakes

Experts Play Down Significance of Chinese Quantum “Hack”

BlackBerry Exploring Options for Cylance Business
More Than Two Dozen Countries Have Used Internet Outages to Sway Elections

Volkswagen Monitoring Data Dump Threat From 8Base Ransomware Crew

Billboards Reportedly Hacked, Displayed Antisemitic Messages in Chicago Suburb

Texas Tech Health Network Cyber Attack Disrupts Patient Care in El Paso

Hackers Target Ukraine’s Potential Conscripts With MeduzaStealer Malware

North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware

Sidewinder Casts Wide Geographic Net in Latest Attack Spree

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability

Critical Default Credential Bug in Kubernetes Image Builder Allows SSH Root Access

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access

Google: 70% of Exploited Flaws Disclosed in 2023 Were Zero-Days

CISA Urges Improvements in U.S. Software Supply Chain Transparency

FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms

Amazon Says 175 Million Customers Now Use Passkeys to Log In

10/15/2024

Microsoft: Nation-States Team Up with Cybercriminals for Attacks

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

British Intelligence Services to Protect All UK Schools From Ransomware Attacks

Nearly 400 U.S. Healthcare Institutions Hit with Ransomware Over Last Year, Microsoft Says

Password Manager Makers Want to Let You Securely Transfer Passkeys

Millions of People Are Using Abusive AI ‘Nudify’ Bots on Telegram

This AI Tool Helped Convict People of Murder. Then Someone Took a Closer Look

AI Amplifies Systemic Risk to Financial Sector, Says India’s Reserve Bank Boss

Gmail Users, Beware of New AI Scam That Looks Very Authentic

This Influencer Was Scammed Out of Thousands in Crypto — And Has a Tip to Help You Avoid Fraud

Hong Kong Police Bust Fraud Ring That Used Face-Swapping Tech for Romance Scams

Finland Seizes Servers of ‘Sipultie’ Dark Web Drugs Market

Darknet Activity Increases Ahead of 2024 Presidential Vote
Cisco Investigates Breach After Stolen Data for Sale on Hacking Forum

Calgary Public Library Forced to Limit Services After Cyberattack

Gryphon Healthcare (TX) Admits up to 400,000 People’s Personal Info Was Snatched

Varsity Brands (TX) Notifies 65,669 of May 2024 Data Breach

EDRSilencer Red Team Tool Used in Attacks to Bypass Security

Cerberus Android Banking Trojan Deployed in New Multi-Stage Malicious Campaign

New Malware Campaign Uses PureCrypter Loader to Deliver DarkVision RAT

New Linux Variant of FASTCash Malware Targets Payment Switches in ATM Heists

Eight Million Users Install 200+ Malicious Apps from Google Play

Researchers Uncover Hijack Loader Malware Using Stolen Code-Signing Certificates

WordPress Plugin Jetpack Patches Major Vulnerability Affecting 27 Million Sites

The Cybersecurity Burnout Crisis Is Reaching The Breaking Point

LLMs Are a New Type of Insider Adversary

10/14/2024

Microsoft: Schools Grapple With Thousands of Cyberattacks Weekly

Nation-State Attackers Exploiting Ivanti CSA Flaws for Network Infiltration

U.S. DoD Tightens Cybersecurity Standards for Defense Contractors

The War on Passwords Is One Step Closer to Being Over

Crypto-Apocalypse Soon? Chinese Researchers Find a Potential Quantum Attack on Classical Encryption

The Biggest Data Breaches in 2024: 1 Billion Stolen Records and Rising

ConfusedPilot Attack Can Manipulate RAG-Based AI Systems

Jetpack Fixes Critical Information Disclosure Flaw Existing Since 2016

Intesa Under Investigation After Former Employee Spied on Account Data

The Internet Archive Is Back as a Read-Only Service After Cyberattacks

Pokemon Dev Game Freak Confirms Breach After Stolen Data Leaks Online

miCare Health Center (MT) Sends Data Breach Letters Following Compromised Email Accounts

Telekopye Scammers Target Booking.com and Airbnb Users

TrickMo Malware Steals Android PINs Using Fake Lock Screen

Recently-Patched Firefox Bug Exploited Against Tor Browser Users

10/11-13/2024

Russian Court Websites Down After Breach Claimed by Pro-Ukraine Hackers

U.S. Lawmakers Seek Answers From Telecoms on Chinese Hacking Report

Philippines Calls for Urgency From China, ASEAN in Negotiating South China Sea Code

Trump Campaign Turns to Secure Hardware After Hacking Incident

Group With Close Ties to Trump Transition Says It Was Targeted in Cyber Attack

Hackers Took Over Robovacs to Chase Pets and Yell Slurs

The FBI Made a Crypto Coin Just to Catch Fraudsters

‘Email Scam’ Was Training Exercise, Says Regulator

What Internet Data Brokers Have On You — And How You Can Start to Get It Back

How to Stop Your Data From Being Used to Train AI

OpenAI Confirms Threat Actors Use ChatGPT to Write Malware

U.S. Border Agency Under Fire for App’s Handling of Personal Data

National Public Data Files for Bankruptcy, Citing Fallout From Cyberattack

Italy’s Intesa Sanpaolo Apologises for Security Breach Involving PM Meloni

Cyberattack Targets Healthcare Nonprofit Overseeing 13 Colorado Facilities

Huge Game Freak Hack Leaks Next Pokémon Game

The Internet Archive Is Still Down but Will Return in ‘Days, Not Weeks’

Casio Confirms Customer Data Stolen in a Ransomware Attack

Omni Family Health (CA) Breach Affects Personal Info of Current and Former Patients

OilRig Exploits Windows Kernel Flaw in Espionage Campaign Targeting UAE and Gulf

INC Ransomware Rebrands to Lynx – Same Code, New Name, Still up to No Good

GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks

CISA: Hackers Abuse F5 BIG-IP Cookies to Map Internal Servers

Google Warns uBlock Origin and Other Extensions May Be Disabled Soon

Microsoft Deprecates PPTP and L2TP VPN Protocols in Windows Server

10/10/2024

U.S., UK Warn of Russian APT29 Hackers Targeting Zimbra, TeamCity Servers

NSA Cyber Chief: Espionage Is Now Russia’s Focus for Cyberattacks on Ukraine

Ukraine Arrests Rogue VPN Operator Providing Access to Runet

Russian Cyber Firm Dr.Web Denies Data Leak by Pro-Ukraine Hackers

‘Q Day’ Is Coming. It’s Time to Worry About Quantum Security.

Meet the Team Paid to Break Into Top-Secret Bases

OpenAI Blocks 20 Global Malicious Campaigns Using AI for Cybercrime and Disinformation

Former RAC Employees Get Suspended Sentence for Data Theft

New Law in Australia Will Require Mandatory Reporting of Ransomware Payments

Over 10m Conversations Exposed in AI Call Center Hack

Fore-Get About Privacy, Golf Tech Biz Trackman Leaves 32M Data Records on the Fairway

Crooks Stole Personal Info of 77K Fidelity Investments Customers

Shoe Show (NC) Data Breach Affects an Estimated 12,856 Individuals

Underground Ransomware Claims Attack on Casio, Leaks Stolen Data

Cybercriminals Use Unicode to Hide Mongolian Skimmer in E-Commerce Platforms

Akira and Fog Ransomware Now Exploit Critical Veeam RCE Flaw

Researchers Uncover Major Security Vulnerabilities in Industrial MMS Protocol Libraries

GitLab Warns of Critical Arbitrary Branch Pipeline Execution Flaw

10/9/2024

National Cyber Director Warns of Ransomware, Chinese Infrastructure Attacks and Cyber Supply Chain Concerns

FTC, CISA Warn of Hurricane-Related Scams as Milton Nears Florida

Recent Dr.Web Cyberattack Claimed by Pro-Ukrainian Hacktivists

Russia and Turkey Ban Discord Messaging App

Former Uber Security Chief Appeals Conviction in ‘Bug-Bounty’ Case

Krebs: Lamborghini Carjackers Lured by $243M Cyberheist

69,000 Bitcoins Are Headed for the U.S. Treasury

Mexico Faces Over Half of Latin American Cybercrimes Due Largely to U.S. Ties

Australia Introduces First Standalone Cybersecurity Law

New EU ‘Appeals Centre Europe’ to Centralize Complaints Against Facebook, TikTok, YouTube

Apple’s iPhone Mirroring Flaw Exposes Employee Privacy Risks

Smart TVs Are Spying on Everyone

Marriott Settles for a Piddly $52M After Series of Breaches Affecting Millions

Dutch Police Arrest Admin of ‘Bohemia/Cannabia’ Dark Web Market

Ukraine Sentences Two Hackers From Russia-Linked Armageddon Group

The Internet Archive Is Under Attack, With a Breach Revealing Information for 31 Million Accounts

California Superior Court Claimed to Be Attacked by Meow Ransomware

Crypto-Stealing Malware Campaign Infects 28,000 People

New BeaverTail Malware Targets Job Seekers via Fake Recruiters

N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware

New Generation of Malicious QR Codes Uncovered by Researchers

Hackers Hide Remcos RAT in GitHub Repository Comments

Siemens Device PIN Susceptible to Remote Brute-Force in Older Model

Mozilla Fixes Firefox Zero-Day Actively Exploited in Attacks

CISA Says Critical Fortinet RCE Flaw Now Exploited in Attacks

Palo Alto Networks Warns of Firewall Hijack Bugs With Public Exploit

Krebs: Patch Tuesday, October 2024 Edition

Google Joins Forces with GASA and DNS RF to Tackle Online Scams at Scale

Cloud, AI Talent Gaps Plague Cybersecurity Teams

10/8/2024

U.S. Warns of Foreign Interference in Congressional Races Ahead of Election

U.S. Expecting Foreign Actors to Question Validity of Election

EU Condemns Russia After Detecting ‘Increasing Number’ of Hybrid Activities

Ukraine’s Defense Ministry Launches Military CERT to Counter Russian Cyberattacks

31 New Ransomware Groups Join the Ecosystem in 12 Months

New Mamba 2FA Bypass Service Targets Microsoft 365 Accounts

What Google’s U-Turn on Third-Party Cookies Means for Chrome Privacy

Cyber Providers See Strong Demand, but Few Feel Confident Enough to List

Could You Switch Careers Into Cyber-Security?

The Perils of Ignoring Cybersecurity Basics

Cyberattack Group ‘Awaken Likho’ Targets Russian Government with Advanced Tools

Home Security Firm ADT Inc Reports Unauthorized Activity on Its Network

MoneyGram Confirms Hackers Stole Customer Data in Cyberattack

Casio Reports IT Systems Failure After Weekend Network Breach

Vermilion Parish Schools (LA) Investigating Cyber Attack

Accounting Firm Dohman, Akerlund & Eddy (NE) Files Notice of Recent Data Breach

Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines

New Scanner Finds Linux, UNIX Servers Exposed to CUPS RCE Attacks

Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited

Microsoft October 2024 Patch Tuesday Fixes 5 Zero-Days, 118 Flaws

10/7/2024

Advanced Threat Group GoldenJackal Exploits Air-Gapped Systems

Vulnerable APIs and Bot Attacks Costing Businesses Up to $186 Billion Annually

Board-CISO Mismatch on Cyber Responsibility, NCSC Research Finds

Get Safe Online Launches New Scam Detector

Ukrainian Pleads Guilty to Operating Raccoon Stealer Malware

Telegram App Hosts ‘Underground Markets’ for Southeast Asian Crime Gangs, UN Says

Cops Love Facial Recognition, and Withholding Info on Its Use From the Courts

EU Court Limits Meta’s Use of Personal Facebook Data for Targeted Ads

UN Cybercrime Treaty Lead Negotiator: U.S. Will Suffer if It Doesn’t Vote Yes

Hacker Attack Disrupts Russian State Media on Putin’s Birthday

American Water Shuts Down Online Services After Cyberattack

Universal Music Group Admits Data Breach

Western & Southern Life Files Notice of Data Breach

New Gorilla Botnet Launches Over 300,000 DDoS Attacks Across 100 Countries

Recently Spotted Trinity Ransomware Spurs Federal Warning to Healthcare Industry

Google Blocks Unsafe Android App Sideloading in India for Improved Fraud Protection

Critical Apache Avro SDK Flaw Allows Remote Code Execution in Java Applications

Qualcomm Patches High-Severity Zero-Day Exploited in Attacks

Cybersecurity Is Serious — But It Doesn’t Have to Be Boring

10/4-6/2024

U.S. Wiretap Systems Targeted in China-Linked Hack

Hospitals at Risk for Cyber Attacks

Hotels and Travel Firms Battle AI Phone Scams

Tech Platforms Urged to Tackle Hamas’ and Hezbollah’s Online Propaganda

This Teenage Hacker Became a Legend Attacking Companies. Then His Rivals Attacked Him.

Ryanair Faces GDPR Turbulence Over Customer ID Checks

Harvard Duo Hacks Meta Ray-Bans to Dox Strangers on Sight in Seconds

How Confidence Between Teams Impacts Cyber Incident Outcomes

Google Removes Kaspersky’s Antivirus Software From Play Store

Russia Arrests U.S.-Sanctioned Cryptex Founder, 95 Other Linked Suspects

Indiana Man Pleads Guilty to Stealing $37 Million in Crypto From 571 Victims

White House Official Says Insurance Companies Must Stop Funding Ransomware Payments

Criminals Are Testing Their Ransomware Campaigns in Africa

Lego’s Website Was Hacked to Promote a Crypto Scam

About a Quarter Million Comcast Subscribers Had Their Data Stolen From Debt Collector

Comcast and Truist Bank Customers Caught up in FBCS Data Breach

Ward Transport Sends Data Breach Letters Following “Data Security Incident”

Outlast Game Development Delayed After Red Barrels Cyberattack

Highline Public Schools Confirms Ransomware Behind Shutdown

MoneyGram: No Evidence Ransomware Is Behind Recent Cyberattack

New MedusaLocker Ransomware Variant Deployed by Threat Actor

Recently Patched CUPS Flaw Can be Used to Amplify DDoS Attacks

Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability

A New Android Feature Locks Your Screen if Your Phone Is Stolen

Google Is Testing Verified Checkmarks in Search

Google Pay Alarms Users With Accidental ‘New Card’ Added Emails

10/3/2024

Microsoft and U.S. Government Disrupt Russian Star Blizzard Operations

North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks

TikTok More Dangerous to Ukraine Than Telegram for Propaganda, Say Local Disinformation Experts

Unable to Penetrate Systems, Hackers Spread Lies About Vulnerabilities

Crypto-Doubling Scams Surge Following Presidential Debate

License Plate Readers Are Creating a U.S.-Wide Database of More Than Just Cars

What Is the Market Impact of the SEC’s Cyber Disclosure Rules? Not Much.

Cybersecurity Spending on the Rise, But Security Leaders Still Feel Vulnerable

Average North American CISO Pay Now $565K, Mainly Thanks to One Weird Trick

Brits Hate How Big Tech Handles Their Data, but Can’t Be Bothered to Do Much About It

Fraudsters Imprisoned for Scamming Apple Out of 6,000 iPhones

23andMe is On the Brink. What Happens to All Its DNA Data?

Dutch Police: ‘State Actor’ Likely Behind Recent Data Breach

Detroit-Area Government Services Impacted by Cyberattack

Find Great People (SC) Data Breach Affects Personal Information of 12,205 Individuals

New Perfctl Malware Targets Linux Servers for Cryptocurrency Mining and Proxyjacking

Cloudflare Blocks Largest Recorded DDoS Attack Peaking at 3.8Tbps

Krebs: A Single Cloud Compromise Can Feed an Army of AI Sex Bots

The Secret Weakness Execs Are Overlooking: Non-Human Identities

Email Phishing Attacks Surge as Attackers Bypass Security Controls

‘Pig Butchering’ Trading Apps Found on Google Play, App Store

Litespeed Cache Plugin Flaw Allows XSS Attack, Update Now

Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks

As Ransomware Attacks Surge, UK Privacy Regulator Investigating Fewer Incidents Than Ever

Northern Ireland Police Fined for Data Breach Exposing Secret Identities of Officers

10/2/2024

Cybersecurity Head Says There’s No Chance a Foreign Adversary Can Change U.S. Election Results, Not Even Russia

China-Linked CeranaKeeper Targeting Southeast Asia with Data Exfiltration

Lazarus: Andariel Hacking Group Shifts Focus to Financial Attacks on U.S. Organizations

How North Korea Infiltrated the Crypto Industry

UK’s Nuclear Waste Unit Sellafield Fined for Cybersecurity Failings

The Feds Still Can’t Get into Eric Adams’ Phone

FCC Is Offering $200 Million to Protect Schools and Libraries From Hackers

Pay Rises for Cyber Chiefs as Hacks, Regulatory Pressure Increase

Share of Women in UK Cyber Roles Now Just 17%

Meta Teams Up with Banks to Target Fraudsters

Telegram Has Disclosed Criminal Data to Authorities for Years, Durov Says

FIN7 Hackers Launch Deepfake Nude “Generator” Sites to Spread Malware

Fake Browser Updates Spread Updated WarmCookie Malware

International Police Dismantle Cybercrime Group in West Africa

TIAA Latest Big Firm to Report Data Breach and Hack

Empereon Constar Announces Data Breach Following Incident at Partner Company

Hackers Pose as British Postal Carrier to Deliver Prince Ransomware in Destructive Campaign

Fake Job Applications Deliver Dangerous More_eggs Malware to HR Professionals

PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data

Fake Trading Apps Target Victims Globally via Apple App Store and Google Play

Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit

Critical Ivanti RCE Flaw With Public Exploit Now Used in Attacks

Researchers Warn of Ongoing Attacks Exploiting Critical Zimbra Postjournal Flaw

Alert: Over 700,000 DrayTek Routers Exposed to Hacking via 14 New Vulnerabilities

Experts Warn of DDoS Attacks Using Linux Printing Vulnerability

Two Simple Give-Me-Control Security Bugs Found in Optigo Network Switches Used in Critical Manufacturing

10/1/2024

Iran Fires at Least 180 Missiles Into Israel as Regionwide Conflict Grows

U.S. Accuses Iran of Hacking Former Ambassador to Israel and State Dept. Official

Notorious Evil Corp Hackers Targeted NATO Allies for Russian Intelligence

ICE Signs $2 Million Contract With Spyware Maker Paragon Solutions

Krebs: Crooked Cops, Stolen Laptops & the Ghost of UGNazi

Euro Cops Arrest 4 Including Suspected LockBit Dev Chilling on Holiday

NCA Unmasks Man It Suspects Is Both ‘Evil Corp Kingpin’ and LockBit Affiliate

British Hacker Charged in the U.S. For $3.75m Insider Trading Scheme

Cambodia Arrests Journalist Known for Exposing Cyber Scams and Human Trafficking

California Passes Car Data Privacy Law to Protect Domestic Abuse Survivors

Cybersecurity Firm Proofpoint Considers Pre-IPO Funding as It Plots a Return to Public Markets

Rackspace Monitoring Data Stolen in ScienceLogic Zero-Day Attack

Australian e-Tailer digiDirect Customers’ Info Allegedly Stolen and dDumped Online

Community Clinic of Maui Says 123,000 Affected by May Cyberattack

Global Wafers Subsidiary, MEMC, Confirms Recent Data Breach

Ransomware Attack Forces UMC Health System to Divert Some Patients

The Playstation Network Is Down in a Global Outage

Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials

AI-Powered Rhadamanthys Stealer Targets Crypto Wallets with Image Recognition

New Cryptojacking Attack Targets Docker API to Create Malicious Swarm Botnet

Arc Browser Launches Bug Bounty Program After Fixing RCE Bug

Microsoft Overhauls Security for Publishing Edge Extensions

9/30/2024

Watch Out for Hurricane Helene Donation Scams

UK and U.S. Warn of Growing Iranian Spear Phishing Threat

U.S. Sets New Rule That Could Spur AI Chip Shipments to the Middle East

U.S. State CISOs Struggling With Insufficient Cybersecurity Funding

Systems Used by Courts and Governments Across the U.S. Riddled With Vulnerabilities

The Pig Butchering Invasion Has Begun

U.S. Reaches $31.5 Million Settlement With T-Mobile Over Data Breaches

Man Charged for Selling Forged License Keys for Network Switches

Remote ID Verification Tech Is Often Biased, Bungling, and No Good on Its Own

Media Giant AFP Hit by Cyberattack Impacting News Delivery Services

CF Medical Data Breach Stems from Incident at Financial Business and Consumer Solutions

Verizon Outage Impacts 100,000 Plus Users Across U.S.

Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware

Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks

Critical RCE Vulnerabilities Found in Common Unix Printing System

Microsoft Defender Adds Detection of Unsecure Wi-Fi Networks

JPCERT Shares Windows Event Log Tips to Detect Ransomware Attacks

Here’s What to Expect From the Counter Ransomware Initiative Meeting This Week

9/27-29/2024

As Hezbollah Threat Loomed, Israel Built up Its Spy Agencies

Pentagon Gives Thumbs-Down to Cyber Service Proposal in Defense Bills

Tesla’s Cybertruck Goes, Inevitably, to War

Governments Urge Improved Security and Resilience for Undersea Cables

Why It’s Time to Take Warnings About Using Public Wi-Fi, in Places Like Airports, Seriously

Watch: Can BBC Reporter’s AI Clone Fool His Colleagues?

How Pen and Paper Comes to the Rescue in an IT Crisis

The U.S. Government Wants to Cut out Some of Its Weirdest Password Rules

Irish Data Protection Commission Fines Meta $102 Million for Storing Passwords in Plain Text

UK National Hacked Public Companies for Stock Trading Intel, DOJ Says

All Dutch Police Officers’ Contact Details Stolen in Cyberattack

Richmond Community Schools (IN) Suffers Ransomware Attack

Ransomware Attack Continues at UMC Hospital in Lubbock (TX)

Amgen (CA) Announces Third-party Data Breach from Incident at Sirva Relocation

Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks

New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users

Progress Urges Admins to Patch Critical Whatsup Gold Bugs ASAP

Microsoft: Windows Recall Now Can Be Removed, Is More Secure

How Should CISOs Navigate the SEC Cybersecurity and Disclosure Rules?

Red Team Hacker on How She ‘Breaks Into Buildings and Pretends to Be the Bad Guy’

9/26/2024

Hurricane Helene Prompts CISA Fraud Warning

Russia-Backed Gamaredon Still ‘Most Engaged’ Hacker Group in Ukraine

N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks

Cloudflare Warns of India-Linked Hackers Targeting South and East Asian Entities

Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware

Israeli Military Chief Says Troops Are Preparing for Ground War in Lebanon

Amid Air Strikes and Rockets, an SMS From the Enemy

Fears of Weakness in Water Cybersecurity Grow After Kansas Attack

Iranians Indicted in Connection With Trump Campaign Hack

Krebs: U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex

York Mayor Eric Adams Is Indicted After Years-Long Federal Corruption Investigation Into Bribery and Fraud

Told FBI He Forgot His Phone’s Passcode

Don’t Ever Hand Your Phone to the Cops

Over a Third of Employees Secretly Sharing Work Info with AI

NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines

Chicago Stops Using Controversial ShotSpotter Gunshot Detection System

Kuwait Health Ministry Restoring Systems After Cyberattack Takes Down Hospitals, Healthcare App

Data Breach at MC2 Data Leaves 100 Million at Risk of Fraud

58K Patients Have Health Info Possibly Exposed in Michigan Medicine Breach

Ross, Anglim, Angelini & Co. (NJ) Breach Compromises an Unknown Number of Social Security Numbers

Cybercriminals Hack UK Rail Network Wi-Fi

Man Arrested After ‘Islamophobic’ Cyber Attack Hits London Stations Wi-Fi

MoneyGram Services Restored but Questions Remain About Cyber Incident

Richardson (TX) Working With FBI to Address Attempted Ransomware Attack

First Mobile Crypto Drainer ‘WalletConnect’ Found on Google Play

Malicious Ads Hide Infostealer in League of Legends ‘Download’

Automattic Blocks WP Engine’s Access to WordPress Resources

CUPS Flaws Enable Linux Remote Code Execution, but There’s a Catch

Millions of Kia Vehicles Could Be Hacked and Tracked Due to a Simple Website Bug

Patch Now: Critical Nvidia Bug Allows Container Escape, Complete Host Takeover

HPE Patches Three Critical Security Holes in Aruba Papi

Tails OS Merges With Tor Project for Better Privacy, Security

9/25/2024

China-Linked Hackers Breach U.S. Internet Providers in New ‘Salt Typhoon’ Cyberattack

U.S. House Bill Addresses Growing Threat of Chinese Cyber Actors

Biden Meets Vietnam Leader to Counter Hanoi’s Ties With China and Russia

Donald Trump Briefed on Suspected Iranian Assassination Plot

OpenAI Chief Technology Officer Mira Murati Says She’s Leaving Artificial Intelligence Company

OpenAI to Become For-Profit Company

Google Paid $2.7 Billion to Bring Back an AI Genius Who Quit in Frustration

Surging AI Demand Could Cause the World’s Next Chip Shortage, Research Says

How Apple and Microsoft’s Trusted Brands Are Being Used to Scam You Online

82% of Phishing Sites Now Target Mobile Devices

Caroline Ellison, Former FTX Executive, Sentenced to 24 Months in Prison

Krebs: Timeshare Owner? The Mexican Drug Cartels Want You

China Claims Taiwan, Not Civilians, Behind Web Vandalism

RansomHub Genius Tries to Put the Squeeze on Delaware Libraries

Modified LockBit and Conti Ransomware Shows up in DragonForce Gang’s Attacks

Transportation Companies Hit by Cyberattacks Using Lumma Stealer and NetSupport Malware

CISA: Hackers Target Industrial Systems Using “Unsophisticated Methods”

Study Finds Many European Car Resellers Fail to Delete Driver Data

Connecting Your Phone to Rental Car Infotainment System? There Is a Big, Hidden Privacy Risk

Pwn2Own Auto Offers $500K for Tesla Hacks

ChatGPT macOS Flaw Could’ve Enabled Long-Term Spyware via Memory Function

Google’s Shift to Rust Programming Cuts Android Memory Vulnerabilities by 52%

Google Sees 68% Drop in Android Memory Safety Flaws Over 5 Years

Mozilla Faces Privacy Complaint for Enabling Tracking in Firefox Without User Consent

9/24/2024

Sweden Accuses Iran of Hacking Text Messaging Service Last Year After Public Koran Burnings

Trump Campaign’s Suspected Iranian Hack May Still Be Happening

U.S. Capitol Hit by Massive Dark Web Cyber Attack: Reports

State Department Cyber Bureau Preps Funding Blitz Aimed at Boosting Allies’ Defenses

Russia-Backed Media Outlets Are Under Fire in the U.S.—but Still Trusted Worldwide

TikTok Blocks Dozens of Kremlin-Backed Media Accounts

How to Spot a North Korean Agent Before They Get Comfy Inside Payroll

Threat Actors Shift to JavaScript-Based Phishing Attacks

Hackers Deploy AI-Written Malware in Targeted Attacks

CrowdStrike Boss Apologises for Global IT Outage

Cybersecurity Incident Affects Arkansas City Water Treatment Facility

The Centers for Medicare & Medicaid Services Says Data Breach Impacted 3.1 Million People

Twilio Purportedly Breached, Nearly 12K Call Records Compromised

AutoCanada Says Ransomware Attack “May” Impact Employee Data

One Point HR Solutions (OH) Data Breach Affects an Unknown Number of Consumers

RomCom Malware Resurfaces With SnipBot Variant

New Octo2 Malware Variant Threatens Mobile Banking Security

Infostealer Malware Bypasses Chrome’s New Cookie-Theft Defenses

Critical Ivanti vTM Auth Bypass Bug Now Exploited in Attacks

9/23/2024

Dozens of Fortune 100 Companies Have Unwittingly Hired North Korean IT Workers, According to Report

U.S. Intelligence Agencies Confirm Russia Is Pushing Fake Videos of Kamala Harris

Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware

Russian Cyber-Attacks Home in on Ukraine’s Military Infrastructure

U.S. Proposes Ban on Chinese, Russian Connected Car Tech Over Security Fears

Microsoft’s Largest Ever Security Transformation Detailed in New Report

Why ‘Never Expire’ Passwords Can Be a Risky Decision

UPS Supplier’s Password Policy Flip-Flops From Unlimited, to 32, Then 64 Characters

Telegram Will Now Hand Over Your Phone Number and IP if You’re a Criminal Suspect

Kaspersky Deletes Itself, Installs UltraAV Antivirus Without Warning

Israeli Tech Sector Resilient but Faces Funding Uncertainty Amid Ongoing War With Hamas Group

How Apple, Google, and Microsoft Can Save Us From AI Deepfakes

Hezbollah Likely to Launch Retaliatory Cyberattack on Israel, Expert Says

Alaska Airlines Reports IT Outage, Disruption in Seattle

‘Cybersecurity Issue’ Takes MoneyGram Offline for Three Days – And Counting

Tewkesbury Borough Council: Cyber Incident ‘Was an Accident – Not an Attack’

Ransomware Attack on Franklin County (KS) Exposed Sensitive Info of Nearly 30,000 Residents

Kryptina Ransomware Resurfaces in Enterprise Attacks By Mallox

Android Malware ‘Necro’ Infects 11 Million Devices via Google Play

New PondRAT Malware Hidden in Python Packages Targets Software Developers

Move Over, Cobalt Strike. Splinter’s the New Post-Exploit Menace in Town

Vulnerabilities Found in Popular Houzez Theme and Plugin

Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk

Gavin Newsom Vetoes Legislation to Mandate Universal Data Privacy Opt-Outs in California

9/20-22/2024

Ukraine Bans Telegram Use for Government and Military Personnel

Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber Attacks

Court Finds Former German Cyber Chief Was Falsely Accused of Associating With Russian Spies

U.S. Cyberspace Solarium Commission Outlines Ten New Cyber Policy Priorities

Cyber Leaders Struggle to Fill AI Security Jobs

Cybersecurity Skills Gap Leaves Cloud Environments Vulnerable

CISA Boss: Makers of Insecure Software Are the Real Cyber Villains

Companies Face Risk of Huge Fines and Suspensions Under Tough New Cyber Rules in the EU

U.S. Indicts Two, Including One Florida Man, Over Socially Engineered $230M+ Crypto Heist

Clickbaity or Genius? ‘BF Cheated on You’ QR Codes Pop up Across UK

LinkedIn Halts AI Data Processing in UK Amid Privacy Concerns Raised by ICO

Federal Civil Rights Watchdog Sounds Alarm Over DOJ, DHS, and HUD Use of Facial Recognition Technology

Hacker Uses Telegram Chatbots to Leak Data of Top Indian Insurer Star Health

Dell Investigates Data Breach Claims After Hacker Leaks Employee Info

Wells Fargo Clearing Services Notifies Consumers of Recent Data Breach

More Than $44 Million in Cryptocurrency Stolen From Singaporean Platform BingX

Cybercrooks Strut Away With Haute Couture Harvey Nichols Data

Schools Across Lancashire Threatened by Hackers in Cyber Attack

Valencia Ransomware Explodes on the Scene, Claims California City, Fashion Giant, More as Victims

Global ‘Marko Polo’ Infostealer Malware Operation Targets Crypto Users, Gamers

CISA Warns of Actively Exploited Apache HugeGraph-Server Bug

Researcher Reveals ‘Catastrophic’ Security Flaw in the Arc Browser

Windows Server 2025 Previews Security Updates Without Restarts

macOS Sequoia Change Breaks Networking for VPN, Antivirus Software

9/19/2024

First Israel’s Exploding Pagers Maimed and Killed. Now Comes the Paranoia

Your Phone Won’t Be the Next Exploding Pager

Iran Backdoors Planted Across Middle East Telecoms, Government Agencies, Google Says

Long Island County Hack Probe Details History of Cyber Failures

Disney to Stop Using Slack Following Hack That Exposed Company Data

Insecure APIs and Bot Attacks Cost Global Firms $186bn

1 in 10 Orgs Dumping Their Security Vendors After CrowdStrike Outage

Infostealers Cause Surge in Ransomware Attacks, Just One in Three Recover Data

Californians Can Now Add Their Driver’s Licenses to Apple Wallet

No Way? Big Tech’s Endless ‘Lucrative Surveillance’ of Everyone Is Terrible for Privacy, Freedom

Tor Says It’s “Still Safe” Amid Reports of Police Deanonymizing Users

Germany Seizes 47 Crypto Exchanges Used by Ransomware Gangs

Police Dismantles Phone Unlocking Ring Linked to 483,000 Victims

8,000 Claimants Sue Outsourcing Giant Capita Over 2023 Data Breach

Indonesia’s Tax Agency Probes Alleged Personal Data Breach

Altman Plants Notifies Thousands of Data Breach Involving Their SSNs and Medical Information

Elitecare Emergency Room (TX) Notifies Patients of July 2024 Data Breach

Tewkesbury Borough Council in Gloucestershire IT Systems Deemed ‘Safe’ After Cyber Attack

Hackers Exploit Default Credentials in FOUNDATION Software to Breach Construction Firms

Cryptojacking Gang TeamTNT Makes a Comeback

New Brazilian-Linked SambaSpy Malware Targets Italian Users via Phishing Emails

Clever ‘GitHub Scanner’ Campaign Abusing Repos to Push Malware

Krebs: This Windows PowerShell Phish Has Scary Potential

1 PoC Exploit for Critical RCE Flaw, but 2 Patches From Veeam

Ivanti Warns of Another Critical CSA Flaw Exploited in Attacks

Apple’s New macOS Sequoia Update Is Breaking Some Cybersecurity Tools

Google Password Manager Now Automatically Syncs Your Passkeys

Unexplained ‘Noise Storms’ Flood the Internet, Puzzle Experts

9/18/2024

Hezbollah Devices Explode Again in Lebanon, Raising Fears of Wider Israel Conflict

Walkie-Talkies This Time

Solar Panels and Fingerprint Recognition Devices Used by Hezbollah Fighters

Hezbollah Pager Attack Puts Spotlight on Israel’s Cyber Warfare Unit 8200

Supply-Chain Interference

Europol Taskforce Disrupts ‘Ghost’ Global Criminal Network Through Supply Chain Attack

Germany Seizes Leak Site of ‘Vanir’ Ransomware Operation

Flax Typhoon: U.S. FBI Disrupts Second Chinese Hacking Group, Director Says

Did a Chinese University Hacking Competition Target a Real Victim?

U.S. Says Iran Tried to Influence Election With Messages to Biden Camp With Stolen Info From Trump Campaign

Critical Infrastructure at Risk From Email Security Breaches

DOJ, FBI Need Better Metrics for Tracking Ransomware Disruption Efforts, Audit Finds

Russian Security Firm Dr.Web Disconnects All Servers After Breach

Deja Blues… Ransomware Group LockBit Boasts Once Again of Ransoming IRS-Authorized eFile.com

North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Microsoft: Vanilla Tempest Hackers Hit Healthcare With INC Ransomware

X Hacking Spree Fuels “$HACKED” Crypto Token Pump-and-Dump

QR Phishing Scams Gain Motorized Momentum in UK

Krebs: Scam ‘Funeral Streaming’ Groups Thrive on Facebook

Google Street View Images Used For Extortion Scams

GitLab Releases Fix for Critical SAML Authentication Bypass Flaw

Discord Rolls Out End-To-End Encryption for Audio, Video Calls

9/17/2024

Hezbollah Pagers Explode in Apparent Attack Across Lebanon

4,000 Injured, 11 Dead

The Mystery of Hezbollah’s Deadly Exploding Pagers

Hezbollah Vows to Punish Israel After Pager Explosions Across Lebanon

U.S. Looks to Align Security Across Government

CISA Urges Software Devs to Weed out XSS Vulnerabilities

Cyberattacks Plague Health Care. Critics Call the Federal Response ‘Inadequate’

Over Half of Breached UK Firms Pay Ransom

Most Cyber Leaders Fear AI-Generated Code Will Increase Security Risks

AT&T Pays $13 Million FCC Settlement Over 2023 Data Breach

Chinese National Accused by Feds of Spear-Phishing for NASA, Military Source Code

Meta Blocks RT and Other Russian State Media; Kremlin Says It’s ‘Unacceptable’

Pro-Ukraine Hackers Claim Attack on Agency That Certifies Digital Signatures in Russia

Temu Denies Breach After Hacker Claims Theft of 87 Million Data Records

Over 1,000 ServiceNow Instances Found Leaking Corporate KB Data

Construction Firms Breached in Brute Force Attacks on Accounting Software

Aramark myPay Data Breach Affects an Unknown Number of Employees

Binance Warns of Rising Clipper Malware Attacks Targeting Cryptocurrency Users

Marko Polo Cybercrime Gang Targets Cryptocurrency Users, Influencers With Scams

Ransomware Gangs Now Abuse Microsoft Azure Tool for Data Theft

PKfail Secure Boot Bypass Remains a Significant Risk Two Months Later

SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks

VMware Patches Remote Make-Me-Root Holes in vCenter Server, Cloud Foundation

9/16/2024

Cybersecurity & the 2024 U.S. Elections

White House to Tackle AI-Generated Sexual Abuse Images

CISA Warns of Windows Flaw Used in Infostealer Malware Attacks

Cybercriminals Exploit HTTP Headers for Credential Theft via Large-Scale Phishing Attacks

Advanced Phishing Attacks Put X Accounts at Risk

Snowflake Slams ‘More MFA’ Button Again – Months After Ticketmaster, Santander Breaches

Half of UK Firms Lack Basic Cybersecurity Skills

Tech Firm CACI Beefs up Defense Business With $1.28 Bln Azure Summit Deal

Chrome Switching to NIST-Approved ML-KEM Quantum Encryption to Protect Against Quantum TLS Attacks

U.S. Cracks Down on Spyware Vendor Intellexa With More Sanctions

Feds Sentence 12 Crypto Thieves, Including a Florida Man, Behind SIM Swaps, Home Invasions

Pacific Islands Forum Investigating Cyberattack on Networks by Reported China State Actors

Only U.S. Platinum Mine Stillwater Mining Company Confirms Data Breach After Ransomware Claims

Data on Nearly 1 Million NHS Patients Leaked Online Following Ransomware Attack on London Hospitals

German Radio Station Forced to Broadcast ‘Emergency Tape’ Following Cyberattack

The Maids International Notifies Consumers of the January 2024 Data Breach

North Korean Hackers Target Cryptocurrency Users on LinkedIn with RustDoor Malware

Windows Vulnerability Abused Braille “Spaces” in Zero-Day Attacks

Exploit Code Released for Critical Ivanti RCE Flaw, Patch Now

Google Fixes GCP Composer Flaw That Could’ve Led to Remote Code Execution

D-Link Fixes Critical RCE, Hardcoded Password Flaws in WiFi 6 Routers

9/13-15/2024

Malicious Actors Spreading False U.S. Voter Registration Breach Claims

State Dept: Russia’s RT News Agency Has ‘Cyber Operational Capabilities,’ Assists in Military Procurement

How a U.S. Spy Tapped Into Russian Communication Lines

Krebs: The Dark Nexus Between Harm Groups and ‘The Com’

Nightsleeper: Could a Cyber Hack Derail a Train in Real Life?

Hardware Supply Chain Threats Can Undermine Endpoint Infrastructure

Largest Crypto Exchange in Indonesia Indodax Pledges to Reimburse Users After $22 Million Theft

23andMe Agrees to Pay $30 Million to Settle Lawsuit Over Massive Data Breach

Cambodian Senator Sanctioned by U.S. Over Alleged Forced Labor Cyber-Scam Camps

Apple Seeks Dismissal of Its NSO Group Lawsuit, Citing Risk of Exposing ‘Vital Security Information’

Meta to Resume Plans to Harness UK Users’ Social Media Posts for AI Model Training

Feeld Dating App’s Security Too Open-Minded as Private Data Swings Into Public View

Port of Seattle Hit by Rhysida Ransomware in August Attack

RansomHub Claims Kawasaki Cyberattack, Threatens to Leak Stolen Data

Atrium Health Apologizes After Employees Fall For Phishing Attack; Patient Info May Have Been Exposed

Shamrock Trading Corporation Announces May 2024 Data Breach

TfL Requires In-Person Password Resets for 30,000 Employees After Hack

Johnson County Board of Education (TN) Loses $3.4 Million to a Fake Curriculum Vendor

Malware Locks Browser in Kiosk Mode to Steal Google Credentials

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

Ivanti Warns of Active Exploitation of Newly Patched Cloud Appliance Vulnerability

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw

9/12/2024

The U.S. Is Preparing Criminal Charges in Iran Hack Targeting Trump

Chinese-Made Port Cranes in U.S. Included ‘Backdoor’ Modems, House Report Says

Microsoft Is Building New Windows Security Features to Prevent Another CrowdStrike Incident

Apple Vision Pro’s Eye Tracking Exposed What People Type

Hacker Tricks ChatGPT Into Giving Out Detailed Instructions for Making Homemade Bombs

BT Spots 2,000 Potential Attacks on Its Network a Second

Google Chrome Makes It Easier to Opt out of Annoying Notifications on Android

Why Credit Card Fraud Alerts Are Rising, and How Worried You Should Be About Them

Mastercard Bolsters Threat Intelligence Capabilities With $2.65 Billion Deal for Recorded Future

Cyber Intelligence Company Strider Raises $55 Million in Funding

Hospital System to Pay $65 Million for Dark Web Data Leak, Including Images of Nude Cancer Patients

TfL Confirms Customer Data Breach, 17-Year-Old Suspect Arrested

U.S. Sanctions Cambodian Tycoon for Alleged Human Trafficking to Cyber Scam Centers

Fortinet Confirms Data Breach After Hacker Claims to Steal 440GB of Files

I Stole 20GB of Data From Capgemini – And Now I’m Leaking It, Says Cyber-Crook

Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack

Socially Savvy Scattered Spider Traps Cloud Admins in Web

Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking

Beware: New Vo1d Malware Infects 1.3 Million Android TV Boxes Worldwide

New Android Malware ‘Ajina.Banker’ Steals Financial Data and Bypasses 2FA via Telegram

‘Hadooken’ Linux Malware Targets Oracle WebLogic Servers

Hackers Targeting WhatsUp Gold With Public Exploit Since August

Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

Open Source Updates Have 75% Chance of Breaking Apps

Schools Face Million-Dollar Bills as Ransomware Rises

Business Email Compromise Costs $55bn Over a Decade

9/11/2024

Cyberattacks on U.S. Utilities Surged 70% This Year, Says Check Point

UK Designates the Data Center Sector Part of Its ‘Critical National Infrastructure’

Hackers Have Sights Set on Four Microsoft Vulnerabilities, CISA Warns

Operational Technology Leaves Itself Open to Cyber-Attack

WordPress.org to Require 2FA for Plugin Developers by October

Apple Intelligence Promises Better AI Privacy for Personal Information . Here’s How It Actually Works

Poland’s Supreme Court Blocks Pegasus Spyware Probe

Singapore Police Arrest Six Hackers Linked to Global Cybercrime Syndicate

So You Paid a Ransom Demand … and Now the Decryptor Doesn’t Work

How Law Enforcement’s Ransomware Strategies Are Evolving

How $20 and a Lapsed Domain Allowed Security Pros to Undermine Internet Integrity

TD Bank Fined $28 Million for Sharing Inaccurate and Negative Data on Customers

Hunters International Claims Ransom on Chinese Mega-Bank’s London HQ

Japanese Media Giant Kadokawa Investigating Another Reported Data Leak by BlackSuit Hackers

Multiple Popular French Retailers Confirm Hackers Stole Customer Data

NJ Union Reports Cyber Incident May Have Exposed Members’ Private Information

Highline Public Schools Will Reopen Classes — Without Internet — Amid Cyberattack Recovery

Bollinger County (MO) Sheriff Talks About Hack of Facebook Page

Developers Beware: Lazarus Group Uses Fake Coding Tests to Spread Malware

DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe

Major Sales and Ops Overhaul Leads to Much More Activity … For Meow Ransomware Gang

Gallup: Pollster Acts to Close Down Security Threat

Adobe Fixes Acrobat Reader Zero-Day With Public PoC Exploit

Krebs: Bug Left Some Windows PCs Dangerously Unpatched

9/10/2024

Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia

New Portuguese Government to Keep Ban on Chinese 5G Equipment

Thanks, Edward Snowden: You Propelled China to Quantum Networking Leadership

Wix to Block Russian Users Starting September 12

Russia to Spend Over Half a Billion Dollars to Bolster Internet Censorship System

DoJ Distributes 18 and a Half Million Dollars to Western Union Fraud Victims

Crypto Scams Rake in Five and Three-Fifths of a Billion Dollars a Year for Cyberscum Lowlifes, FBI Says

WhatsApp’s ‘View Once’ Could Be ‘View Whenever’ Due To a Flaw

Gallup Poll Bugs Open Door to Election Misinformation

Cyber Staffing Shortages Remain CISOs’ Biggest Challenge

London’s Transit Agency Drops Claim It Has ‘No Evidence’ of Customer Data Theft After Hack

Vista Higher Learning (MA) Data Breach Impacts an Unknown Number of Consumers

CosmicBeetle (aka NoName) Deploys Custom ScRansom Ransomware, Partnering with RansomHub

RansomHub Ransomware Abuses Kaspersky TDSSKiller to Disable EDR Software

New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers

Ivanti Fixes Maximum Severity RCE Bug in Endpoint Management Software

Microsoft September 2024 Patch Tuesday Fixes 4 Zero-Days, 79 Flaws

Microsoft Fixes Windows Smart App Control Zero-Day Exploited Since 2018

Microsoft Fixes Windows Server Performance Issues From August Updates

9/9/2024

Chinese Mustang Panda APT Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

Mustang Panda Use New Data Theft Malware in Gov’t Attacks

TIDRONE Espionage Group Targets Taiwan Drone Makers in Cyber Campaign

German Intelligence Says Russian GRU Group Behind NATO, EU Cyberattacks

Poland Dismantles Cyber Sabotage Group Linked to Russia, Belarus

Russia’s Top-Secret Military Unit Reportedly Plots Undersea Cable ‘Sabotage’

DDoS Attacks Double With Governments Most Targeted

The Bitcoin ATM Has Emerged as One of Cryptocurrency’s Biggest Threats

U.S. Proposes Requiring Reporting for Advanced AI, Cloud Providers

Technology Causes “Digital Entropy” as Firms Struggle With Governance

What You Need to Know about Grok AI and Your Privacy

U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major Attacks

Cyber-Attack on Payment Gateway Slim CD Exposes 1.7 Million Credit Card Details

Data of Nearly 300,000 Exposed in Avis Cyberattack

Highline Public Schools (WA) Closes Schools Following Cyberattack

Ransomware Attack Forces London’s Charles Darwin School to Close and Send Students Home

Kent’s Biggin Hill School Closes Due to Ransomware Attack

Welcome Health (CA) Data Breach Put Confidential Patient Information at Risk

RetailData (VA) Data Breach Affects an Unknown Number of Consumers

Blind Eagle Targets Colombian Insurance Sector with Customized Quasar RAT

Quad7 Botnet Targets More SOHO and VPN Routers, Media Servers

Akira Ransomware Actors Exploit SonicWall Bug for RCE

Meta Fixes Easily Bypassed WhatsApp ‘View Once’ Privacy Feature

Ford Seeks Patent for Tech That Listens to Driver Conversations to Serve Ads

9/6-8/2024

U.S. Financial Markets, Public Companies Are a Growing Target for Russian Hackers

Lawmakers Want U.S. to Address Risks Posed by Chinese Agriculture Drones

Despite Cyberattacks, Water Security Standards Remain a Pipe Dream

Researchers Say a Bug Let Them Add Fake Pilots to Rosters Used for TSA Checks

The NSA Has a Podcast—Here’s How to Decode It

Telegram Changes Its Tone on Moderating Private Chats After CEO’s Arrest

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity

Russian Authorities Able to Identify Train Saboteur Teen From Anonymous Telegram Account

AI, Growing Data Risks Expand the Role of Chief Privacy Officer

Amid AI Boom, Tech Can’t Afford to Neglect Spending in These IT Areas

Spyware Vendors’ Nebulous Ecosystem Helps Them Evade Sanctions

FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals

YouTube Removes Tenet Media Channel Over Alleged Ties to Russian Disinformation Effort

Therapy Sessions Exposed by Mental Health Care Firm Confidant Health’s Unsecured Database

900,000 on Medicare in Wisconsin Warned of Data Breach from MOVEit

Car Rental Giant Avis Discloses Data Breach Impacting Customers

Transport for London (TfL) Still Affected by ‘Ongoing Cyber Incident’

North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

Sextortion Scam Now Use Your “Cheating” Spouse’s Name as a Lure

SpyAgent Android Malware Steals Your Crypto Recovery Phrases from Images

New RAMBO Attack Steals Data Using RAM in Air-Gapped Computers

GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code

SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation

Progress LoadMaster Vulnerable to 10/10 Severity RCE Flaw

Microsoft Office 2024 to Disable ActiveX Controls by Default

Cybersecurity Talent Shortage Prompts White House Action