Menu

Monthly Archives: November 2023

Not all cybercriminals are evil geniuses
Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes
Admin of $19M marketplace that sold social security numbers gets 8 years in jail
Okta data breach dilemma dwarfs earlier estimates
Very precisely lost – GPS jamming

The technology is both widely available and well developed, hence it’s also poised to proliferate – especially in the hands of those wishing ill

Ex-Motorola worker phished former employer to illegally hack network and steal data
Black Basta ransomware operation nets over $100M from victims in less than two years
Smashing Security podcast #350: Think before you shrink! And our guest is faked
Locking down Industrial Control Systems
Weak session keys let snoops take a byte out of your Bluetooth traffic
US lawmakers have Chinese LiDAR on their threat-detection radar
Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

https://security-tracker.debian.org/tracker/DSA-5569-1

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew
British Library begins contacting customers as Rhysida leaks data dump
UK government rings the death knell for SIM farms
Brit borough council apologizes for telling website users to disable HTTPS
Japan’s space agency suffers cyber attack, points finger at Active Directory
Plex gives fans a privacy complex after sharing viewing habits with friends by default
Trio of major holes in ownCloud expose admin passwords, allow unauthenticated file mods
iOS 17 NameDrop privacy scare: What you need to know
Helping companies defend what attackers want most – their data
Europol shutters ransomware operation with kingpin arrests
Securing the software supply chain webinar
A bird’s eye view of your global attack surface
India’s CERT given exemption from Right To Information requests
‘Serial cybercriminal and scammer’ jailed for 8 years, told to pay back $1.2M
The crazy world of ransomware
Why IT teams should champion AI in the workplace, and deploy secure AI tools safely to their teams
Ethyrial: Echoes of Yore hacked! 17,000 game accounts “lost”
Leader of pro-Russia DDoS crew Killnet ‘unmasked’ by Russian state media
Education is the foundation of modern cyber defence
Ransomware-hit British Library: Too open for business, or not open enough?
Crypto crasher Do Kwon’s extradition approved, but destination is unclear
Beijing fosters foreign influencers to spread its propaganda

https://security-tracker.debian.org/tracker/DSA-5568-1

https://security-tracker.debian.org/tracker/DSA-5567-1

Telekopye’s tricks of the trade – Week in security with Tony Anscombe

ESET’s research team reveals details about the onboarding process of the Telekopye scam operation and the various methods that the fraudsters use to defraud people online

https://security-tracker.debian.org/tracker/DSA-5566-1

https://security-tracker.debian.org/tracker/DSA-5564-1

https://security-tracker.debian.org/tracker/DSA-5563-1

https://security-tracker.debian.org/tracker/DSA-5565-1

Telekopye: Chamber of Neanderthals’ secrets

Insight into groups operating Telekopye bots that scam people in online marketplaces

OpenCart owner turns air blue after researcher discloses serious vuln
Cloud security and devops have work to do
$9 million seized from “pig butchering” scammers who preyed on lonely hearts
BlackCat claims it is behind Fidelity National Financial ransomware shakedown
Your voice is my password

AI-driven voice cloning can make things far too easy for scammers – I know because I’ve tested it so that you don’t have to learn about the risks the hard way.

Industry piles in on North Korea for sustained rampage on software supply chains
Smashing Security podcast #349: Ransomware gang reports its own crime, and what happened at OpenAI?
Attack on direct debit provider London & Zurich leaves customers with 6-figure backlogs
Hackers pose as officials to steal secrets and cryptocurrency for North Korea
Stop social engineering at the IT help desk
Mirai we go again: Zero-day flaws see routers and cameras co-opted into botnet
New Relic warns customers it’s experienced a cyber … something
North Korea makes finding a gig even harder by attacking candidates and employers
How to give Windows Hello the finger and login as someone on their stolen laptop
US nuke reactor lab hit by ‘gay furry hackers’ demanding cat-human mutants
Fuel for thought: Can a driverless car get arrested?

What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?

US cybercops take on ‘pig butchering’ org, return $9M in scammed crypto
Microsoft’s bug bounty turns 10. Are these kinds of rewards making code more secure?
UK’s cookie crumble: Data watchdog serves up tougher recipe for consent banners
Binance and CEO admit financial crimes, billions coughed up to US govt

https://security-tracker.debian.org/tracker/DSA-5562-1

https://security-tracker.debian.org/tracker/DSA-5561-1

https://security-tracker.debian.org/tracker/DSA-5560-1

Sumo Logic wrestles with security breach, pins down customer data
The XBOM vs SBOM debate
Third-party data breach affecting Canadian government could involve data from 1999
Maintaining a state of readiness to deal with cyber attacks
MOVEit victim count latest: 2.6K+ orgs hit, 77M+ people’s data stolen

https://security-tracker.debian.org/tracker/DSA-5559-1

Former infosec COO pleads guilty to attacking hospitals to drum up business
Rhysida ransomware gang: We attacked the British Library
Your password hygiene remains atrocious, says NordPass
Safeguarding ports from the rising tide of cyberthreats – Week in security with Tony Anscombe

An attack against a port operator that ultimately hobbled some 40 percent of Australia’s import and export capacity highlights the kinds of supply chain shocks that a successful cyberattack can cause

https://security-tracker.debian.org/tracker/DSA-5558-1

https://security-tracker.debian.org/tracker/DSA-5556-1

https://security-tracker.debian.org/tracker/DSA-5555-1

https://security-tracker.debian.org/tracker/DSA-5554-1

https://security-tracker.debian.org/tracker/DSA-5553-1

https://security-tracker.debian.org/tracker/DSA-5552-1

https://security-tracker.debian.org/tracker/DSA-5551-1

https://security-tracker.debian.org/tracker/DSA-5550-1

https://security-tracker.debian.org/tracker/DSA-5549-1

https://security-tracker.debian.org/tracker/DSA-5548-1

LockBit redraws negotiation tactics after affiliates fail to squeeze victims
SonicWall swallows Solutions Granted amid cybersecurity demand surge
Samsung UK discloses year-long breach, leaked customer data
Look out, Scattered Spider. FBI pumps ‘significant’ resources into snaring data-theft crew

https://security-tracker.debian.org/tracker/DSA-5557-1

How much to clean up a ransomware infection? For Rackspace, about $11M

security update

Windows Server 2022 update gave ESXi host VMs the blue screen blues
BlackCat plays with malvertising traps to lure corporate victims
Royal Mail’s recovery from ransomware attack will cost business at least $12M
Hundreds of websites cloned to run ads for Chinese football gambling outfits
Clorox CISO flushes self after multimillion-dollar cyberattack
Smashing Security podcast #348: Hacking for chimp change, and AI chatbot birthday
Google Workspace weaknesses allow plaintext password theft