Menu

Link

Russian Security Takes Down REvil Ransomware Gang
Three Plugins with Same Bug Put 84K WordPress Sites at Risk
Adobe Cloud Abused to Steal Office 365, Gmail Credentials
Microsoft Yanks Buggy Windows Server Updates
North Korean APTs Stole ~$400M in Crypto in 2021
US Military Ties Prolific MuddyWater Cyberespionage APT to Iran
New GootLoader Campaign Targets Accounting, Law Firms
Hackers are posting out malicious USB drives to businesses
Smashing Security podcast #257: Pokemon-hunting cops and the Spine Collector scammer
Widespread, Easily Exploitable Windows RDP Bug Opens Users to Data Theft
Amazon, Azure Clouds Host RAT-ty Trio in Infostealing Campaign
Stolen TikTok Videos, Bent on Fraud, Invade YouTube Shorts
New York AG Warns 17 Firms of Credential Attacks
Hackers raided Panasonic server for months, stealing personal data of job seekers
Phishers Rip Off High-Profile EA Gamers
Here’s REALLY How to Do Zero-Trust Security
Microsoft Faces Wormable, Critical RCE Bug & 6 Zero-Days
MacOS Bug Could Let Creeps Snoop On You
WordPress Bugs Exploded in 2021, Most Exploitable
FIN7 Mails Malicious USB Sticks to Drop Ransomware
‘Fully Undetected’ SysJoker Backdoor Malware Targets Windows, Linux & macOS
Critical SonicWall NAC Vulnerability Stems from Apache Mods
Hacking group accidentally infects itself with Remote Access Trojan horse
Millions of Routers Exposed to RCE by USB Kernel Bug
URL Parsing Bugs Allow DoS, RCE, Spoofing & More
Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High
Free guide: “A Journey to Zero Trust With Zero Passwords”
EoL Systems Stonewalling Log4j Fixes for Fed Agencies
Cyberattackers Hit Data of 80K Fertility Patients
3.7M FlexBooker Records Dumped on Hacker Forum
The Spine Collector: Man arrested for using fake email addresses to steal hundreds of unpublished manuscripts
QNAP: Get NAS Devices Off the Internet Now
Attack misuses Google Docs comments to spew out “massive wave” of malicious links
Log4J-Related RCE Flaw in H2 Database Earns Critical Rating
Activision Files Unusual Lawsuit over Call of Duty Cheat Codes
Google Voice Authentication Scam Leaves Victims on the Hook
Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover
Apple iPhone Malware Tactic Causes Fake Shutdowns to Enable Spying
‘Malsmoke’ Exploits Microsoft’s E-Signature Verification
Attackers Exploit Flaw in Google Docs’ Comments Feature
1.1M Compromised Accounts Found at 17 Major Companies
‘Elephant Beetle’ Lurks for Months in Networks
Broward Breach Highlights Healthcare Supply-Chain Problems
Uber Bug, Ignored for Years, Casts Doubt on Official Uber Emails
FTC to Go After Companies that Ignore Log4j
US police warn of parking meters with phishing QR codes
Microsoft Sees Rampant Log4j Exploit Attempts, Testing
SEGA’s Sloppy Security Confession: Exposed AWS S3 Bucket Offers Up Steam API Access & More
Data Skimmer Hits 100+ Sotheby’s Real-Estate Websites
Israeli newspapers targeted by hackers on anniversary of Iranian general’s assassination
Purple Fox Rootkit Dropped by Malicious Telegram Installers
McMenamins Data Breach Affects 12 Years of Employee Info
Portugal Media Giant Impresa Crippled by Ransomware Attack
What the Rise in Cyber-Recon Means for Your Security Strategy
APT ‘Aquatic Panda’ Targets Universities with Log4Shell Exploit Tools
5 Cybersecurity Trends to Watch in 2022
Threat Advisory: E-commerce Bots Use Domain Registration Services for Mass Account Fraud
Cryptomining Attack Exploits Docker API Misconfiguration Since 2019
That Toy You Got for Christmas Could Be Spying on You
2021 Wants Another Chance (A Lighter-Side Year in Review)
Global Cyberattacks from Nation-State Actors Posing Greater Threats
The 5 Most-Wanted Threatpost Stories of 2021
4-Year-Old Microsoft Azure Zero-Day Exposes Web App Source Code
Telegram Abused to Steal Crypto-Wallet Credentials
‘Spider-Man: No Way Home’ Download Installs Cryptominer
Time to Ditch Big-Brother Accounts for Network Scanning
PYSA Emerges as Top Ransomware Actor in November
All in One SEO Plugin Bug Threatens 3M Websites with Takeovers
Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS
Four Bugs in Microsoft Teams Left Platform Vulnerable Since March
Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look
Half-Billion Compromised Credentials Lurking on Open Cloud Server
Two Active Directory Bugs Lead to Easy Windows Domain Takeover
FBI: Another Zoho ManageEngine Zero-Day Under Active Attack
Conti Ransomware Gang Has Full Log4Shell Attack Chain
Robocalls More Than Doubled in 2021, Cost Victims $30B
Third Log4J Bug Can Trigger DoS; Apache Issues Patch
Facebook Bans Spy-for-Hire Firms for Targeting 50K People
Spider-Man Movie Release Frenzy Bites Fans with Credit-Card Harvesting
Malicious Joker App Scores Half-Million Downloads on Google Play
Brand-New Log4Shell Attack Vector Threatens Local Hosts
Convergence Ahoy: Get Ready for Cloud-Based Ransomware
Conti Gang Suspected of Ransomware Attack on McMenamins
‘Tropic Trooper’ Reemerges to Target Transportation Outfits
‘PseudoManuscrypt’ Mass Spyware Campaign Targets 35K Systems
Free eBook! Ransomware – how to stop it, and how to survive an attack
The DHS is inviting hackers to break into its systems, but there are rules of engagement
‘DarkWatchman’ RAT Shows Evolution in Fileless Malware
Smashing Security podcast #256: Virgin Media just won’t take no for an answer, NFT apes, and bad optics
Relentless Log4j Attacks Include State Actors, Possible Worm
Malicious Exchange Server Module Hoovers Up Outlook Credentials
SAP Kicks Log4Shell Vulnerability Out of 20 Apps
Apache’s Fix for Log4Shell Can Lead to DoS Attacks
In 2022, Expect More Supply Chain Pain and Changing Security Roles
Apple iOS Update Fixes Cringey iPhone 13 Jailbreak Exploit
Actively Exploited Microsoft Zero-Day Allows App Spoofing, Malware Delivery
400 Banks’ Customers Targeted with Anubis Trojan
What the Log4Shell Bug Means for SMBs: Experts Weigh In
How to Buy Precious Patching Time as Log4j Exploits Fly
‘Seedworm’ Attackers Target Telcos in Asia, Middle East