20 Feb

Oops, some of our customers’ Power Pages sites were exploited, says Microsoft

Microsoft has fixed a security flaw in its Power Pages website-building SaaS, after criminals got there first – and urged users to check their sites

Author rabih
20 Feb

US minerals company says crooks broke into email and helped themselves to $500K

A NASDAQ-listed US minerals company says cybercriminals broke into its systems on Valentine’s Day and paid themselves around $500,000 – money earmarked for a vendor.

Author rabih
20 Feb

Critical flaws in Mongoose library expose MongoDB to data thieves, code execution

Security sleuths found two critical vulnerabilities in a third-party library that MongoDB relies on, which means bad guys can potentially steal data and run code.

Author rabih
20 Feb

Fake job offers target software developers with infostealers

A North Korea-aligned activity cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login details from web browsers and password managers

Author rabih
20 Feb

Two arrested after pensioner scammed out of six-figure crypto nest egg

Two men are in police custody after being arrested in connection with a July cryptocurrency fraud involving a man in his seventies. The case was

Author rabih
20 Feb

DeceptiveDevelopment targets freelance developers

Cybercriminals have been known to approach their targets under the guise of company recruiters, enticing them with fake employment offers. After all, what better time

Author rabih
20 Feb

Ghost ransomware crew continues to haunt IT depts with scarily bad infosec

The operators of Ghost ransomware continue to claim victims and score payments, but keeping the crooks at bay is possible by patching known vulnerabilities and

Author rabih
20 Feb

Medusa ransomware gang demands $2M from UK private health services provider

Exclusive HCRG Care Group, a private health and social services provider, has seemingly fallen victim to the Medusa ransomware gang, which is threatening to leak

Author rabih
20 Feb

US Army soldier linked to Snowflake extortion rampage admits breaking the law

A US Army soldier suspected of hacking AT&T and Verizon has admitted leaking online people’s private call records. Cameron John Wagenius informed a federal court

Author rabih
19 Feb

Trump’s DoD CISO pick previously faced security clearance suspension

Donald Trump’s nominee for a critical DoD cybersecurity role sports a resume that outshines many of his past picks, despite previously suspended security clearance. Katie

Author rabih
19 Feb

Check out this free automated tool that hunts for exposed AWS secrets in public repos

A free automated tool that lets anyone scan public GitHub repositories for exposed AWS credentials has been released. Before you say anything, yes, we’re pretty

Author rabih
19 Feb

Healthcare outfit that served military personnel settles allegations it faked infosec compliance for $11M

An alleged security SNAFU that occurred during the Obama administration has finally been settled under the second Trump administration. The case concerns Health Net Federal

Author rabih
19 Feb

Hundreds of Dutch medical records bought for pocket change at flea market

Typically shoppers can expect to find tie-dye t-shirts, broken lamps and old disco records at flea markets, now it seems storage drives filled with huge

Author rabih
19 Feb

London celebrity talent agency reports itself to ICO following Rhysida attack claims

A London talent agency has reported itself to the UK’s data protection watchdog after the Rhysida ransomware crew last week claimed it had attacked the

Author rabih
19 Feb

Healthcare outfit that served military personnel settles allegations it faked infosec compliance for $11 million

An alleged security SNAFU that occurred during the Obama administration has finally been settled under the second Trump administration. The case concerns Health Net Federal

Author rabih
19 Feb

Palo Alto firewalls under attack as miscreants chain flaws for root access

A flaw patched last week by Palo Alto Networks is now under active attack and, when chained with two older vulnerabilities, allows attackers to gain

Author rabih
18 Feb

Snake Keylogger slithers into Windows, evades detection with AutoIt-compiled payload

A new variant of Snake Keylogger is making the rounds, primarily hitting Windows users across Asia and Europe. This strain also uses the BASIC-like scripting

Author rabih
18 Feb

US newspaper publisher uses linguistic gymnastics to avoid saying its outage was due to ransomware

US newspaper publisher Lee Enterprises is blaming its recent service disruptions on a “cybersecurity attack,” per a regulatory filing, and is the latest company to

Author rabih
Load moreLoadingAll items loaded