Menu

Link

American Express Fined for Sending Millions of Spam Messages
Restaurant Reservation System Patches Easy-to-Exploit XSS Bug
FBI Analyst Indicted for Theft of Osama bin Laden Threat Intel
DarkSide Getting Taken to ‘Hackers’ Court’ For Not Paying Affiliates
Building SIEM for Today’s Threat Landscape
WP Statistics Bug Allows Attackers to Lift Data from WordPress Sites
Email Campaign Spreads StrRAT Fake-Ransomware RAT
Cyber insurance giant CNA paid out $40 million to its ransomware attackers
100M Android Users Hit By Rampant Cloud Leaks
The Gig Economy Creates Novel Data-Security Risks
Four Android Bugs Being Exploited in the Wild
2021 Attacker Dwell Time Trends and Best Defenses
Qlocker ransomware gang shuts shop after extorting owners of QNAP NAS drives
Apple Exec Calls Level of Mac Malware ‘Unacceptable’
Smashing Security podcast #228: Pipeline pickle, Blockchain bollocks, and Eufy SNAFU
Can Nanotech Secure IoT Devices From the Inside-Out?
Microsoft, Google Clouds Hijacked for Gobs of Phishing
Keksec Cybergang Debuts Simps Botnet for Gaming DDoS
Fake Microsoft Authenticator extension discovered in Chrome Store
Windows PoC Exploit Released for Wormable RCE
Bug Exposes Eufy Camera Private Feeds to Random Users
Scammers Pose as Meal-Kit Services to Steal Customer Data
Stalkerware Apps Riddled with Security Bugs
It’s Time to Prepare for a Rise in Insider Threats
Unsuccessful Conti Ransomware Attack Still Packs Costly Punch
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
Apple rejected 215,000 iOS apps due to privacy concerns last year
Magecart Goes Server-Side in Latest Tactics Changeup
What a Year It’s Been: RSA 2021 Embraces ‘Resilience’
DarkSide Hits Toshiba; XSS Forum Bans Ransomware
Bizarro Banking Trojan Sports Sophisticated Backdoor
CISOs Struggle to Cope with Mounting Job Stress
Cyberinsurance giant AXA hit by ransomware attack after saying it would stop covering ransom payments
FIN7 Backdoor Masquerades as Ethical Hacking Tool
DarkSide Ransomware Suffers ‘Oh, Crap!’ Server Shutdowns
Gamers warned of downloading fake Afterburner overclocking tool to boost graphics card performance
‘Scheme Flooding’ Allows Websites to Track Users Across Browsers
Verizon: Pandemic Ushers in ⅓ More Cyber-Misery
Ransomware’s New Swindle: Triple Extortion
How to Get into the Bug-Bounty Biz: The Good, Bad and Ugly
Want to be a cybersecurity manager? Colonial Pipeline is recruiting
Report: Colonial Pipeline paid ransomware attackers $5 million, but still had to rely on its own backups
Scumbag ransomware attackers hit Irish Health Service
Colonial Pipeline Shells Out $5M in Extortion Payout, Report
Ransomware Going for $4K on the Cyber-Underground
Beyond MFA: Rethinking the Authentication Key
Fresh Loader Targets Aviation Victims with Spy RATs
Muddy waters. Ofwat reveals it has received 20,000 spam and phishing emails so far this year
Apple’s ‘Find My’ Network Exploited via Bluetooth
Five Critical Password Security Rules Your Employees Are Ignoring
Smashing Security podcast #227: Phishing foul-up, Twitter tip jars, and Facebook’s Apple fury
Pipeline Update: Biden Executive Order, DarkSide Detailed and Gas Bags
Researchers Flag e-Voting Security Flaws
Telegram Fraudsters Ramp Up Forged COVID-19 Vaccine Card Sales
Gig Workers Being Paid $500 for Payroll Passwords
‘FragAttacks’: Wi-Fi Bugs Affect Millions of Devices
TeaBot Trojan Targets Banks via Hijacked Android Handsets
Wormable Windows Bug Opens Door to DoS, RCE
GitHub Prepares to Move Beyond Passwords
Hackers Leverage Adobe Zero-Day Bug Impacting Acrobat Reader
Fake Chrome App Anchors Rapidly Worming ‘Smish’ Cyberattack
Shifting Threats in a Changed World: Edge, IoT and Vaccine Fraud
200K Veterans’ Medical Records May Have Been Stolen by Ransomware Gang
DarkSide Wanted Money, Not Disruption from Colonial Pipeline Attack
The DarkSide ransomware gang must be shitting itself right now
Colonial Pipeline’s Ransomware Attack Sparks Emergency Declaration
Lemon Duck Cryptojacking Botnet Changes Up Tactics
City of Tulsa struck by ransomware attack
Major US oil pipeline shut down after ransomware attack
Major U.S. Pipeline Crippled in Ransomware Attack
iPhone Hack Allegedly Used to Spy on China’s Uyghurs
80% of Net Neutrality Comments to FCC Were Fudged
Insurer AXA says it will no longer cover ransomware payments in France
Chinese smart TVs caught hoovering up data about devices on customers’ networks
Qualcomm Chip Bug Opens Android Fans to Eavesdropping
Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks
Ryuk Ransomware Attack Sprung by Frugal Student
Massive DDoS Attack Disrupts Belgium Parliament
NSA offers advice: connecting OT to the rest of the net can lead to “indefensible levels of risk”
Smashing Security podcast #226: Cryptocrazies and NFTs
Signal says its Instagram ads were banned for being too honest
New Crypto-Stealer ‘Panda’ Spread via Discord
Anti-Spam WordPress Plugin Could Expose Website User Data
Raft of Exim Security Holes Allow Linux Mail Server Takeovers
Peloton’s Leaky API Spilled Riders’ Private Data
Peloton exercise bikes found exposing user data – company dawdles in its response
Feds Shut Down Fake COVID-19 Vaccine Phishing Website
Global Phishing Attacks Spawn Three New Malware Strains
Pulse Secure VPNs Get a Fix for Critical Zero-Day Bugs
Apple Fixes Zero‑Day Security Bugs Under Active Attack
Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs
Sneakers, Gaming, Nvidia Cards: Retailers Can Stop Shopping Bots
Bait Boost: Phishers Delivering Increasingly Convincing Lures
Boystown, dark web child abuse image website with 400,000 members, shut down by police
Scripps Health Cyberattack Causes Widespread Hospital Outages
New Attacks Slaughter All Spectre Defenses 
Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool
Deepfake Attacks Are About to Surge, Experts Warn
New Buer Malware Downloader Rewritten in E-Z Rust Language
PortDoor Espionage Malware Takes Aim at Russian Defense Sector