Menu

Link

Elusive ToddyCat APT Targets Microsoft Exchange Servers
Israeli military personnel spied on via Strava fitness-tracking app
Voicemail-themed phishing attacks target organisations
Kazakh Govt. Used Spyware Against Protesters
Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack
Voicemail Scam Steals Microsoft Credentials
How to get Fortune 500 cybersecurity without the hefty price tag
QNAP warns of new DeadBolt ransomware attack locking up NAS devices
China-linked APT Flew Under Radar for Decade
NinjaForms WordPress plugin, actively exploited in wild, receives forced security update
Heineken giving away free beer for Father’s Day? It’s a WhatsApp scam
Interpol arrests thousands of scammers in operation “First Light 2022”
Want to block two billion known breached passwords from being used at your company? It’s easy with Specops Password Policy tools
State-Sponsored Phishing Attack Targeted Israeli Military Officials
Ransomware Risk in Healthcare Endangers Patients
Facebook Messenger Scam Duped Millions
Smashing Security podcast #279: Encrypted notes, and a deadly case of AirTag spying
Kaiser Permanente Exposes Nearly 70K Medical Records in Data Breach
Linux Malware Deemed ‘Nearly Impossible’ to Detect
DragonForce Gang Unleash Hacks Against Govt. of India
Travel-related Cybercrime Takes Off as Industry Rebounds
In Cybersecurity, What You Can’t See Can Hurt You
DDoS-for-hire service which bombarded websites with attacks earns man two years in prison
Bluetooth Signals Can Be Used to Track Smartphones, Say Researchers
U.S. Water Utilities Prime Cyberattack Target, Experts
Potent Emotet Variant Spreads Via Stolen Email Credentials
Feds Forced Travel Firms to Share Surveillance Data on Hacker
You can be tracked via your Bluetooth signal, researchers claim
DogWalk zero-day Windows bug receives patch – but not from Microsoft
Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research
Microsoft disrupts Bohrium spear-phishing ring by seizing 41 domains
Taming the Digital Asset Tsunami
Paying Ransomware Paints Bigger Bullseye on Target’s Back
Black Basta Ransomware Teams Up with Malware Stalwart Qbot
Cyber Risk Retainers: Not Another Insurance Policy
Conducting Modern Insider Risk Investigations
Follina Exploited by State-Sponsored Hackers
Attackers Use Public Exploits to Throttle Atlassian Confluence Flaw
Apple protected App Store users from $1.5 billion fraud last year
Old Hacks Die Hard: Ransomware, Social Engineering Top Verizon DBIR Threats – Again
Evil Corp Pivots LockBit to Dodge U.S. Sanctions
Cybercriminals Expand Attack Radius and Ransomware Pain Points
Scammers Target NFT Discord Channel
International Authorities Take Down Flubot Malware Network
Being prepared for adversarial attacks
Microsoft Releases Workaround for ‘One-Click’ 0Day Under Active Attack
EnemyBot Malware Targets Web Servers, CMS Tools and Android OS
ChromeLoader Browser Hijacker Provides Gateway to Bigger Threats
Hacker steals Verizon employee database after tricking worker into granting remote access
Zero-Day ‘Follina’ Bug Lays Microsoft Office Open to Attack
Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild
Critical Flaws in Popular ICS Platform Can Trigger RCE
Ransomware demands acts of kindness to get your files back
Using 2FA phone numbers for targeted advertising. One of the dumbest ways ever for a company to abuse its users’ trust. Take a bow, Twitter. And have a $150 million fine too.
Cybergang Claims REvil is Back, Executes DDoS Attacks
Smashing Security podcast #276: Webcam extortion, Michael Fish, and food foul-ups
Airline passengers left stranded after ransomware attack
Link Found Connecting Chaos, Onyx and Yashma Ransomware
Zoom Patches ‘Zero-Click’ RCE Bug
Verizon Report: Ransomware, Human Error Among Top Security Risks
Fronton IOT Botnet Packs Disinformation Punch
Jail for man who hacked the email of female students, stole and traded their private photos
Zero Trust for Data Helps Enterprises Detect, Respond and Recover from Breaches
Snake Keylogger Spreads Through Malicious PDFs
Greenland hit by cyber attack, finds its health service crippled
Bank refuses to pay ransom to hackers, sends dick pics instead
Closing the Gap Between Application Security and Observability
380K Kubernetes API Servers Exposed to Public Internet
Phishing gang that stole over 400,000 Euros busted in Spain
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover
Hackers are finding it too easy to achieve their initial access, warn agencies
Smashing Security podcast #275: Jail for Bing, and mental health apps may not be good for you
DOJ Says Doctor is Malware Mastermind
APTs Overwhelmingly Share Known Vulnerabilities Rather Than Attack O-Days
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell
Sysrv-K Botnet Targets Windows, Linux
iPhones Vulnerable to Attack Even When Turned Off
“Incompetent” council leaks details of students with special educational needs
Russian cyber attack on Eurovision foiled by Italian authorities
Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors
Malware Builder Leverages Discord Webhooks
Threat Actors Use Telegram to Spread ‘Eternity’ Malware-as-a-Service
Smashing Security podcast #274: Hands off my biometrics, and a wormhole squirmish
You Can’t Eliminate Cyberattacks, So Focus on Reducing the Blast Radius
Novel ‘Nerbian’ Trojan Uses Advanced Anti-Detection Tricks
Intel Memory Bug Poses Risk for Hundreds of Products
Novel Phishing Trick Uses Weird Links to Bypass Spam Filters
Actively Exploited Zero-Day Bug Patched by Microsoft
Ransomware Deals Deathblow to 157-year-old College
US college set to permanently close after 157 years, following ransomware attack
Hackers Actively Exploit F5 BIG-IP Bug
Conti Ransomware Attack Spurs State of Emergency in Costa Rica
Low-rent RAT Worries Researchers
FBI: Rise in Business Email-based Attacks is a $43B Headache
Tractor giant AGCO hit by ransomware, halts production and sends home staff
Russian TV listings hacked with messages about war crimes in Ukraine
Podcast: The State of the Secret Sprawl
USB-based Wormable Malware Targets Windows Installer
$43 billion stolen through Business Email Compromise since 2016, reports FBI
CANs Reinvent LANs for an All-Local World