Menu

Link

Most Orgs Would Take Security Bugs Over Ethical Hacking Help
Smashing Security podcast #265: The Nigerian supercop and Alexa vs. Alexa
Russia May Use Ransomware Payouts to Avoid Sanctions
Multi-Ransomwared Victims Have It Coming–Podcast
Qakbot Botnet Sprouts Fangs, Injects Malware into Email Threads
APT41 Spies Broke Into 6 US State Networks via a Livestock App
Most ServiceNow Instances Misconfigured, Exposed
Russian APTs Furiously Phish Ukraine – Google
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March Patch Tuesday
The Uncertain Future of IT Automation
Zero-Click Flaws in Widely Used UPS Devices Threaten Critical Infratructure
Bug in the Linux Kernel Allows Privilege Escalation, Container Escape
Novel Attack Turns Amazon Devices Against Themselves
Samsung Confirms Lapsus$ Ransomware Hit, Source Code Leak
NVIDIA’s Stolen Code-Signing Certs Used to Sign Malware
Critical Firefox Zero-Day Bugs Allow RCE, Sandbox Escape
“Alexa, hack yourself” – researchers describe new exploit that turns smart speakers against themselves
Forcepoint ONE simplifies your security
Conti ransomware gang, which leaked ransomware victims’ data, has its own data leaked
Massive Meris Botnet Embeds Ransomware Notes from REvil
Facebook is vile, but banning it in Russia is wrong
Free HermeticRansom Ransomware Decryptor Released
Phishing Campaign Targeted Those Aiding Ukraine Refugees
Russia Leaks Data From a Thousand Cuts–Podcast
US legislation brings mandatory cyberattack and ransomware reporting one step closer
Smashing Security podcast #264: Hacked car chargers, Telegram sextortionists, and secret bossware
Securing Data With a Frenzied Remote Workforce–Podcast
Who deleted the database? Find out with Teleport
TeaBot Trojan Haunts Google Play Store, Again
Conti Ransomware Decryptor, TrickBot Source Code Leaked
RCE Bugs in Hugely Popular VoIP Apps: Patch Now!
Daxin Espionage Backdoor Ups the Ante on Chinese Malware
Ukraine Hit with Novel ‘FoxBlade’ Trojan Hours Before Invasion
Microsoft Accounts Targeted by Russian-Themed Credential Harvesting
Ukraine-Russia Cyber Warzone Splits Cyber Underground
Toyota to Close Japan Plants After Suspected Cyberattack
Kremlin and Russia’s TASS news agency websites offline following attacks
Play for Ukraine game aims to knock Russian websites offline
Ukrainian military personnel targeted with phishing attacks
TrickBot Takes a Break, Leaving Researchers Scratching Their Heads
Microsoft Exchange Bugs Exploited by ‘Cuba’ Ransomware Gang
6 Cyber-Defense Steps to Take Now to Protect Your Company
Conti ransomware gang: You attack Russia, we’ll hack you back
Ukraine calls for volunteer hackers to protect its critical infrastructure and spy on Russian forces
White House Denies Mulling Massive Cyberattacks Against Russia
The Harsh Truths of Cybersecurity in 2022, Part II
Zenly Social-Media App Bugs Allow Account Takeover
Microsoft App Store Sizzling with New ‘Electron Bot’ Malware
Manufacturing was the top industry targeted by ransomware last year, claims report
Web Filtering and Compliances for Wi-Fi Providers
Cyberattackers Leverage DocuSign to Steal Microsoft Outlook Logins
The Art of Non-boring Cybersec Training–Podcast
Creaky Old WannaCry, GandCrab Top the Ransomware Scene
Smashing Security podcast #263: Problèmes de Weefeee, AI artists, and Web 3.0
Samsung Shattered Encryption on 100M Phones
Sextortion Rears Its Ugly Head Again
Gaming, Banking Trojans Dominate Mobile Malware Scene
Cyberattackers Cook Up Employee Personal Data Heist for Meyer
Xenomorph Malware Burrows into Google Play Users, No Facehugger Required
Asustor NAS owners hit by DeadBolt ransomware attack
NFT Investors Lose $1.7M in OpenSea Phishing Attack
FBI warns of fake CEO attacks taking place via video conferencing systems
Sex attacker jailed after police track his hire bike
New Critical RCE Bug Found in Adobe Commerce, Magento
Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups
Iranian State Broadcaster Clobbered by ‘Clumsy, Buggy’ Code
Stop pixelating! New tool reveals the secrets of “redacted” documents
Baby Golang-Based Botnet Already Pulling in $3K/Month for Operators
U.S. government warns that sensitive data is being stolen from defence contractors
Ukrainian DDoS Attacks Should Put US on Notice–Researchers
Microsoft Teams Targeted With Takeover Trojans
Kill Cloud Risk: Get Everybody to Stop Fighting Over App Security – Podcast
Smashing Security podcast #262: Macro progress, eyeball-tracking ads, and encryption backdoors
TrickBot Ravages Customers of Amazon, PayPal and Other Top Brands
Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry
High-Severity RCE Bug Found in Popular Apache Cassandra Database
Critical VMware Bugs Open ESXi, Fusion & Workstation to Attackers
Emotet Now Spreading Through Malicious Excel Files
25 years on, Microsoft makes another stab at stopping macro malware
If NFTs were honest…
SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming
Chrome Zero-Day Under Active Attack: Patch ASAP
TA2541: APT Has Been Shooting RATs at Aviation for Years
BlackByte Tackles the SF 49ers & US Critical Infrastructure
‘Cities: Skylines’ Gaming Modder Banned Over Hidden Malware
Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack
Increase in sophisticated, high-impact ransomware poses rising threat, warn government agencies
Critical MQTT-Related Bugs Open Industrial Networks to RCE Via Moxa
Cybercrooks Frame Targets by Planting Fabricated Digital Evidence
Apple Patches Actively Exploited WebKit Zero Day
Decryptor Keys Published for Maze, Egregor, Sekhmet Ransomwares
Sharp SIM-Swapping Spike Causes $68M in Losses
The bizarre couple alleged to be behind one of the biggest cryptocurrency hacks of all time
SAP Patches Severe ‘ICMAD’ Bugs
PHP Everywhere Bugs Put 30K+ WordPress Sites at Risk of RCE
Beware scammy SMS messages claiming to come from HMRC
More than $400 million drained from hacked blockchain bridges in little more than a week
Smashing Security podcast #261: North Korea hacked, DEA cosplay, and Horizon Worlds drama
Cybercriminals Swarm Windows Utility Regsvr32 to Spread Malware
3 Tips for Facing the Harsh Truths of Cybersecurity in 2022, Part I