Hawai'i Community College pays ransomware gang to prevent data leak

The Hawaiʻi Community College has admitted that it paid a ransom to ransomware actors to prevent the leaking of stolen data of approximately 28,000 people. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CoinsPaid blames Lazarus hackers for theft of $37,300,000 in crypto

Estonian crypto-payments service provider CoinsPaid has announced that it experienced a cyber attack on July 22nd, 2023, that resulted in the theft of $37,200,000 worth of cryptocurrency. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

BreachForums database and private chats for sale in hacker data breach

While consumers are usually the ones worried about their information being exposed in data breaches, it's now the hacker's turn, as the notorious Breached cybercrime forum's database is up for sale and member data shared with Have I Been Pwned. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Zimbra patches zero-day vulnerability exploited in XSS attacks

Two weeks after the initial disclosure, Zimbra has released security updates that patch a zero-day vulnerability exploited in attacks targeting Zimbra Collaboration Suite (ZCS) email servers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

SSNDOB cybercrime market admin faces 15 years after pleading guilty

A Ukrainian man, Vitalii Chychasov, has pleaded guilty in the United States to conspiracy to commit access device fraud and trafficking in unauthorized access devices through the now-shutdown SSNDOB Marketplace. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

WordPress Ninja Forms plugin flaw lets hackers steal submitted data

Popular WordPress form-building plugin Ninja Forms contains three vulnerabilities that could allow attackers to achieve privilege escalation and steal user data. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

8 million people hit by data breach at US govt contractor Maximus

U.S. government services contractor Maximus has disclosed a data breach warning that hackers stole the personal data of 8 to 11 million people during the recent MOVEit Transfer data-theft attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Swiss visa appointments cancelled in UK due to 'IT incident'

All appointments for Swiss Schengen tourist and transit visa applicants have been cancelled across the UK. TLSContact, the Swiss government's chosen IT provider for facilitating visa applicants for citizens of third countries, has blamed an 'IT incident' at its London, Manchester … | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft previews Defender for IoT firmware analysis service

Microsoft announced the public preview of a new Defender for IoT feature that helps analyze the firmware of embedded Linux devices like routers for security vulnerabilities and common weaknesses. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Lazarus hackers linked to $60 million Alphapo cryptocurrency heist

Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws

Two Linux vulnerabilities introduced recently into the Ubuntu kernel create the potential for unprivileged local users to gain elevated privileges on a massive number of devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

SEC now requires companies to disclose cyberattacks in 4 days

The U.S. Securities and Exchange Commission has adopted new rules requiring publicly traded companies to disclose cyberattacks within four business days after determining they're material incidents. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs

Microsoft has released the July 2023 optional cumulative update for Windows 11, version 22H2, with fixes for 27 issues, including ones affecting VPN performance and display or audio devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 10 KB5028244 update released with 19 fixes, improved security

Microsoft has released the optional KB5028244 Preview cumulative update for Windows 10 22H2 with 19 fixes or changes, including an update to the Vulnerable Driver Blocklist to block BYOVD attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

NATO investigates alleged data theft by SiegedSec hackers

NATO has confirmed that its IT team is investigating claims about an alleged data-theft hack on the Communities of Interest (COI) Cooperation Portal by a hacking group known as SiegedSec. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Nitrogen malware pushed via Google Ads for ransomware attacks

A new 'Nitrogen' initial access malware campaign uses Google and Bing search ads to promote fake software sites that infect unsuspecting users with Cobalt Strike and ransomware payloads. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft fixes bug that broke video recording in Windows apps

Microsoft has fixed a known issue causing video recording and playing failures in some apps on Windows 10 and Windows 11 systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

ALPHV ransomware adds data leak API in new extortion strategy

The ALPHV ransomware gang, also referred to as BlackCat, is trying to put more pressure on their victims to pay a ransom by providing an API for their leak site to increase visibility for their attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Super Admin elevation bug puts 900,000 MikroTik devices at risk

A critical severity 'Super Admin' privilege elevation flaw puts over 900,000 MikroTik RouterOS routers at risk, potentially enabling attackers to take full control over a device and remain undetected. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google Chrome to offer 'Link Previews' when hovering over links

Google is set to improve Chrome by introducing a new "Link Preview" feature. This feature, currently in development for desktop use, could significantly change how users interact with web content. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CISA warns govt agencies to patch Ivanti bug exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warned U.S. federal agencies today to secure their systems against a maximum severity authentication bypass vulnerability in Ivanti's Endpoint Manager Mobile (EPMM), formerly MobileIron Core. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Realst info-stealing malware targets macOS cryptocurrency users

A new Mac malware named "Realst" is being used in a massive campaign targeting Apple computers, with some of its latest variants including support for macOS 14 Sonoma, which is still in development. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft shares temp fix for Outlook Desktop slow saving bug

Microsoft is investigating a known issue causing Microsoft 365 customers to experience significant delays when saving attachments in Outlook Desktop to a network share. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Mysterious Decoy Dog malware toolkit still lurks in DNS shadows

New details have emerged about Decoy Dog, a largely undetected sophisticated toolkit likely used for at least a year in cyber intelligence operations, relying on the domain name system (DNS) for command and control activity. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

VMware fixes bug exposing CF API admin credentials in audit logs

VMware has patched an information disclosure vulnerability in VMware Tanzu Application Service for VMs (TAS for VMs) and Isolation Segment caused by credentials being logged and exposed via system audit logs.   [...] | Continue reading


@bleepingcomputer.com | 1 year ago

More US States are ramping up data privacy laws in 2023

Legislation moves slowly, but in 2023 almost all five of the below regulations will take effect, making it a huge year for state data privacy acts. Learn more from Specops Software about the US privacy laws and what it means for your organization.. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 400,000 corporate credentials stolen by info-stealing malware

The analysis of nearly 20 million information-stealing malware logs sold on the dark web and Telegram channels revealed that they had achieved significant infiltration into business environments. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Norway says Ivanti zero-day was used to hack govt IT systems

The Norwegian National Security Authority (NSM) has confirmed that attackers used a zero-day vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) solution to breach a software platform used by 12 ministries in the country. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Sharepoint outage caused by use of wrong TLS certificate

Microsoft Sharepoint and OneDrive for Business were briefly interrupted today after a German TLS certificate was mistakenly added to the main .com domains for the Microsoft 365 services. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Zenbleed attack leaks sensitive data from AMD Zen2 processors

Google's security researcher Tavis Ormandy discovered a new vulnerability impacting AMD Zen2 CPUs that could allow a malicious actor to steal sensitive data, such as passwords and encryption keys, at a rate of 30KB/sec from each CPU core. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Lazarus hackers hijack Microsoft IIS servers to spread malware

The North Korean state-sponsored Lazarus hacking group is breaching Windows Internet Information Service (IIS) web servers to hijack them for malware distribution. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ivanti patches MobileIron zero-day bug exploited in attacks

US-based IT software company Ivanti has patched an actively exploited zero-day vulnerability impacting its Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core). [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Apple fixes new zero-day used in attacks against iPhones, Macs

Apple has released security updates to address zero-day vulnerabilities exploited in attacks targeting iPhones, Macs, and iPads. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Flipper Zero now has its own app store for iOS, Android users

The Flipper Zero team has launched its very own 'Flipper Apps' mobile app store, allowing mobile users to install 3rd-party apps and extend the functionality of the popular wireless pen-testing tool. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

JumpCloud hack linked to North Korea after OPSEC mistake

A hacking unit of North Korea's Reconnaissance General Bureau (RGB) was linked to the JumpCloud breach after the attackers made an operational security (OPSEC) mistake, inadvertently exposing their real-world IP addresses. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft shares fix for some Outlook hyperlinks not opening

Microsoft shared a workaround for Outlook Desktop blocking attempts to open IP address or fully qualified domain name (FQDN) hyperlinks after installing this month's security updates. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Norwegian government IT systems hacked using zero-day flaw

The Norwegian government is warning that its ICT platform used by 12 ministries has suffered a cyberattack after hackers exploited a zero-day vulnerability in third-party software. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

How is the Dark Web Reacting to the AI Revolution?

Cybercriminals are already utilizing and creating malicious tools based on open source AI language models for phishing and malware development. Learn more from Flare about how threat actors are beginning to use AI. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 23H2 update coming this fall, here's what's new

As Microsoft prepares for the imminent rollout of Windows 11 23H2, they've been developing various innovative features designed to improve user experience, streamline workflows, and introduce next-generation functionalities. This article will explore new features, from dynamic li … | Continue reading


@bleepingcomputer.com | 1 year ago

Clop now leaks data stolen in MOVEit attacks on clearweb sites

The Clop ransomware gang is copying an ALPHV ransomware gang extortion tactic by creating Internet-accessible websites dedicated to specific victims, making it easier to leak stolen data and further pressuring victims into paying a ransom. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft enhances Windows 11 Phishing Protection with new features

Microsoft is further enhancing the Windows 11 Enhanced Phishing Protection by testing a new feature that warns users when they copy and paste their Windows password into websites and documents. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CISA warns govt agencies to patch Adobe ColdFusion servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies three weeks to secure Adobe ColdFusion servers on their networks against two critical security flaws exploited in attacks, one of them as a zero-day. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft force-migrating Windows Mail & Calendar apps to Outlook app in August

Microsoft will retire the Windows Mail and Calendar applications on Windows 10 and Windows 11 at the end of the year, first auto-migrating users to the new Outlook for Windows app in August. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 23H2 to give you greater control over power consumption

Microsoft is making it easier to see how much energy your apps use in Windows 11 over a given period by introducing a detailed power consumption page in the latest 23H2 update. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 15K Citrix servers likely vulnerable to CVE-2023-3519 attacks

Thousands of Citrix Netscaler ADC and Gateway servers exposed online are likely vulnerable against a critical remote code execution (RCE) bug exploited by unauthenticated attackers in the wild as a zero-day. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Stolen Azure AD key offered widespread access to Microsoft cloud services

The Microsoft private encryption key stolen by Storm-0558 Chinese hackers provided them with access far beyond the Exchange Online and Outlook.com accounts that Redmond said were compromised, according to Wiz security researchers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

The Week in Ransomware - July 21st 2023 - Avaddon Back as NoEscape

This edition of the Week in Ransomware covers the last two weeks of news, as we could not cover it last week, and includes quite a bit of new information, including the return of the Avaddon ransomware gang. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Clop gang to earn over $75 million from MOVEit extortion attacks

The Clop ransomware gang is expected to earn between $75-100 million from extorting victims of their massive MOVEit data theft campaign. [...] | Continue reading


@bleepingcomputer.com | 1 year ago