American Family Insurance confirms cyberattack is behind IT outages

Insurance giant American Family Insurance has confirmed it suffered a cyberattack and shut down portions of its IT systems after customers reported website outages all week. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

The Week in Ransomware - October 20th 2023 - Fighting Back

This was a bad week for ransomware, with the Trigona ransomware suffering a data breach and law enforcement disrupting the RagnarLocker ransomware operation. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

International Criminal Court systems breached for cyber espionage

The International Criminal Court provided additional information about the cyberattack five weeks ago, saying that it was a targeted operation for espionage purposes. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Cisco discloses new IOS XE zero-day exploited to deploy malware implant

Cisco disclosed a new high-severity zero-day (CVE-2023-20273) today, actively exploited to deploy malicious implants on IOS XE devices compromised using the CVE-2023-20198 zero-day unveiled earlier this week. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Okta says its support system was breached using stolen credentials

​Okta says attackers accessed files containing cookies and session tokens uploaded by customers to its support management system after breaching it using stolen credentials. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ragnar Locker ransomware developer arrested in France

Law enforcement agencies arrested a malware developer linked with the Ragnar Locker ransomware gang and seized the group's dark web sites in a joint international operation. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Critical RCE flaws found in SolarWinds access audit solution

Security researchers found three critical remote code execution vulnerabilities in the SolarWinds Access Rights Manager (ARM) product that remote attackers could use to run code with SYSTEM privileges. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Kwik Trip finally confirms cyberattack was behind ongoing outage

Two weeks into an ongoing IT outage, Kwik Trip finally confirmed that it's investigating a cyberattack impacting the convenience store chain's internal network since October 9. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fake Corsair job offers on LinkedIn push DarkGate malware

A threat actor is using fake LinkedIn posts and direct messages about a Facebook Ads specialist position at hardware maker Corsair to lure people into downloading info-stealing malware like DarkGate and RedLine. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 40,000 Cisco IOS XE devices infected with backdoor using zero-day

More than 40,000 Cisco devices running the IOS XE operating system have been compromised after hackers exploited a recently disclosed maximum severity vulnerability tracked as CVE-2023-20198. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

E-Root admin faces 20 years for selling stolen RDP, SSH accounts

Sandu Diaconu, the operator of the E-Root marketplace, has been extradited to the U.S. to face a maximum imprisonment penalty of 20 years for selling access to compromised computers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks

The BlackCat/ALPHV ransomware operation has begun to use a new tool named 'Munchkin' that utilizes virtual machines to deploy encryptors on network devices stealthily. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft extends Purview Audit log retention after July breach

Microsoft is extending Purview Audit log retention as promised after the Chinese Storm-0558 hacking group breached dozens of Exchange and Microsoft 365 corporate and government accounts in July. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fake KeePass site uses Google Ads and Punycode to push malware

A Google Ads campaign was found pushing a fake KeePass download site that used Punycode to appear as the official domain of the KeePass password manager to distribute malware. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

India targets Microsoft, Amazon tech support scammers in nationwide crackdown

India's Central Bureau of Investigation (CBI) raided 76 locations in a nationwide crackdown on cybercrime operations behind tech support scams and cryptocurrency fraud. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Iranian hackers lurked in Middle Eastern govt network for 8 months

The Iranian hacking group tracked as MuddyWater (aka APT34 or OilRig) breached at least twelve computers belonging to a Middle Eastern government network and maintained access for eight months between February and September 2023. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ragnar Locker ransomware’s dark web extortion sites seized by police

The Ragnar Locker ransomware operation's Tor negotiation and data leak sites were seized Thursday morning as part of an international law enforcement operation. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

WhatsApp gets support for multiple accounts on the same phone

Meta announced today that it's rolling out support for multiple WhatsApp accounts on the same device, allowing users to switch between them without needing to log out. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Casio discloses data breach impacting customers in 149 countries

Japanese electronics manufacturer Casio disclosed a data breach impacting customers from 149 countries after hackers gained to the servers of its ClassPad education platform. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ukrainian activists hack Trigona ransomware gang, wipe servers

A group of cyber activists under the Ukrainian Cyber Alliance banner has hacked the servers of the Trigona ransomware gang and wiped them clean after copying all the information available. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

North Korean hackers exploit critical TeamCity flaw to breach networks

Microsoft says that the North Korean Lazarus and Andariel hacking groups are exploiting the CVE-2023-42793 flaw in TeamCity servers to deploy backdoor malware, likely to conduct software supply chain attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ex-Navy IT head gets 5 years for selling people’s data on darkweb

Marquis Hooper, a former U.S. Navy IT manager, has received a sentence of five years and five months in prison for illegally obtaining US citizens' personally identifiable information (PII) and selling it on the dark web. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hacker leaks millions of new 23andMe genetic data profiles

A hacker has leaked an additional 4.1 million stolen 23andMe genetic data profiles for people in Great Britain and Germany on a hacking forum. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google Play Protect adds real-time scanning to fight Android malware

Google has announced new, real-time scanning features for Google Play Protect that make it harder for malicious apps employing polymorphism to evade detection. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

MATA malware framework exploits EDR in attacks on defense firms

An updated version of the MATA backdoor framework was spotted in attacks between August 2022 and May 2023, targeting oil and gas firms and the defense industry in Eastern Europe. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google links WinRAR exploitation to multiple state hacking groups

Google says multiple state-backed hacking groups are gaining arbitrary code execution on targets' systems by exploiting a high-severity vulnerability in WinRAR, a compression software with over 500 million users. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Single Sign On and the Cybercrime Ecosystem

One of the trends driving an increase is the compromise of enterprise single sign on (SSO) applications are info-stealer malware attacks. Learn more from Flare about this cybercrime ecosystem. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Recently patched Citrix NetScaler bug exploited as zero-day since August

A critical vulnerability tracked as CVE-2023-4966 in Citrix NetScaler ADC/Gateway devices has been actively exploited as a zero-day since late August, security researchers announced. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Qubitstrike attacks rootkit Jupyter Linux servers to steal credentials

Hackers are scanning for internet-exposed Jupyter Notebooks to breach servers and deploy a cocktail of malware consisting of a Linux rootkit, crypto miners, and password-stealing scripts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Twitter testing annual subscriptions for tweeting and retweeting

Twitter, now renamed X, is testing new $1 annual subscriptions to provide unverified accounts access to core features like tweeting and retweeting. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft disables bad spam rule flagging all sent emails as junk

Microsoft has disabled a bad anti-spam rule flooding Microsoft 365 admins' inboxes with blind carbon copies (BCC) of outbound emails mistakenly flagged as spam. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

FBI warns of extortion groups targeting plastic surgery offices

The FBI warns that cybercriminals are using spoofed emails and phone numbers to target plastic surgery offices across the United States for extortion in phishing attacks that spread malware. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 40,000 admin portal accounts use 'admin' as a password

Security researchers found that IT administrators are using tens of thousands of weak passwords to protect access to portals, leaving the door open to cyberattacks on enterprise networks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

KwikTrip all but says IT outage was caused by a cyberattack

Kwik Trip has released another statement on an ongoing outage, all but confirming it suffered a cyberattack that has led to IT system disruptions. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Malicious Notepad++ Google ads evade detection for months

A new Google Search malvertizing campaign targets users looking to download the popular Notepad++ text editor, employing advanced techniques to evade detection and analysis. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Amazon adds passkey support as new passwordless login option

Amazon has quietly added passkey support as a new passwordless login option for customers, offering better protection from information-stealing malware and phishing attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

D-Link confirms data breach after employee phishing attack

Taiwanese networking equipment manufacturer D-Link confirmed a data breach linked to information stolen from its network and put up for sale on BreachForums earlier this month. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

SpyNote Android malware spreads via fake volcano eruption alerts

Android malware 'SpyNote' was seen in an Italy-focused campaign that uses a phony 'IT-alert' public alert service website to infect visitors. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft fixes known issue causing Outlook freezes, slow starts

Microsoft has fixed a known issue affecting Outlook for Microsoft 365 users since June and causing slow starts and freezes as if Offline Outlook Data Files (OST) were syncing right after launch. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fighting off cyberattacks? Make sure user credentials aren’t compromised

Login credential theft presents one of the biggest and most enduring cybersecurity problems. This article by Specops SOftware looks at the motivations driving credential theft and the tactics bad actors are likely to use. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Thousands of Cisco IOS XE devices hacked in widespread attacks

Attackers have exploited a recently disclosed critical zero-day bug to compromise and infect thousands of Cisco IOS XE devices with malicious implants. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

October Windows Server updates cause Hyper-V VM boot issues

According to customer reports, this month's Patch Tuesday updates are breaking virtual machines on Hyper-V hosts, causing them to no longer boot and display "failed to start" errors. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Discord still a hotbed of malware activity — Now APTs join the fun

Discord continues to be a breeding ground for malicious activity by hackers and now APT groups, with it commonly used to distribute malware, exfiltrate data, and targeted by threat actors to steal authentication tokens. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Kansas courts IT systems offline after ‘security incident’

Information systems of state courts across Kansas are still offline after they've been disrupted in what the Kansas judicial branch described last Thursday as a "security incident." [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers exploit critical flaw in WordPress Royal Elementor plugin

A critical severity vulnerability impacting Royal Elementor Addons and Templates up to version 1.3.78 is reported to be actively exploited by two WordPress security teams. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Russian Sandworm hackers breached 11 Ukrainian telcos since May

The state-sponsored Russian hacking group tracked as 'Sandworm' has compromised eleven telecommunication service providers in Ukraine between May and September 2023. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Cisco warns of new IOS XE zero-day actively exploited in attacks

Cisco warned admins today of a new and maximum severity zero-day vulnerability in its IOS XE Software that can let attackers gain full administrator privileges and take complete control of affected routers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fake 'RedAlert' rocket alert app for Israel installs Android spyware

Israeli Android users are targeted by a malicious version of the 'RedAlert - Rocket Alerts' app that, while it offers the promised functionality, acts as spyware in the background. [...] | Continue reading


@bleepingcomputer.com | 1 year ago