Hackers Want $2.5 Million Ransom for Texas Ransomware Attacks
The threat actor that hit multiple Texas local governments with file-encrypting malwarelast week may have done it by compromising a managed service provider. The attacker demanded a collective ransom of $2.5 million, the mayor of a municipality says. [...]
https://www.bleepingcomputer.com/news/security/hackers-want-25-million-ransom-for-texas-ransomware-attacks/
The threat actor that hit multiple Texas local governments with file-encrypting malwarelast week may have done it by compromising a managed service provider. The attacker demanded a collective ransom of $2.5 million, the mayor of a municipality says. [...]
https://www.bleepingcomputer.com/news/security/hackers-want-25-million-ransom-for-texas-ransomware-attacks/
BleepingComputer
Hackers Want $2.5 Million Ransom for Texas Ransomware Attacks
The threat actor that hit multiple Texas local governments with file-encrypting malwarelast week may have done it by compromising a managed service provider. The attacker demanded a collective ransom of $2.5 million, the mayor of a municipality says.
Phishing Attacks Scrape Branded Microsoft 365 Login Pages
An unusual new phishing campaign is probing email inboxes via attacks using the targets' company-branded Microsoft 365 tenant login pages to add more legitimacy to the scam. [...]
https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/
An unusual new phishing campaign is probing email inboxes via attacks using the targets' company-branded Microsoft 365 tenant login pages to add more legitimacy to the scam. [...]
https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/
BleepingComputer
Phishing Attacks Scrape Branded Microsoft 365 Login Pages
An unusual new phishing campaign is probing email inboxes via attacks using the targets' company-branded Microsoft 365 tenant login pages to add more legitimacy to the scam.
Windows 10 Insider Build 18965 Adds Restart Apps Sign-In Option
Microsoft is rolling out Windows 10 Insider Preview Build 18965 (20H1) to Insiders in the Fast ring, a build that now makes it possible to enable restarting apps at Windows sign-in. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-insider-build-18965-adds-restart-apps-sign-in-option/
Microsoft is rolling out Windows 10 Insider Preview Build 18965 (20H1) to Insiders in the Fast ring, a build that now makes it possible to enable restarting apps at Windows sign-in. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-insider-build-18965-adds-restart-apps-sign-in-option/
BleepingComputer
Windows 10 Insider Build 18965 Adds Restart Apps Sign-In Option
Microsoft is rolling out Windows 10 Insider Preview Build 18965 (20H1) to Insiders in the Fast ring, a build that now makes it possible to enable restarting apps at Windows sign-in.
Second Steam Zero-Day Impacts Over 96 Million Windows Users
A second Steam Windows client zero-day privilege escalation vulnerability affecting over 96 million users has been publicly disclosed today by Russian researcher Vasily Kravets. [...]
https://www.bleepingcomputer.com/news/security/second-steam-zero-day-impacts-over-96-million-windows-users/
A second Steam Windows client zero-day privilege escalation vulnerability affecting over 96 million users has been publicly disclosed today by Russian researcher Vasily Kravets. [...]
https://www.bleepingcomputer.com/news/security/second-steam-zero-day-impacts-over-96-million-windows-users/
BleepingComputer
Second Steam Zero-Day Impacts Over 96 Million Windows Users
A second Steam Windows client zero-day privilege escalation vulnerability affecting over 96 million users has been publicly disclosed today by Russian researcher Vasily Kravets.
npm Pulls Malicious Package that Stole Login Passwords
A malicious package was removed today from the npm repository after it was discovered that stole login information from the computers it was installed on. [...]
https://www.bleepingcomputer.com/news/security/npm-pulls-malicious-package-that-stole-login-passwords/
A malicious package was removed today from the npm repository after it was discovered that stole login information from the computers it was installed on. [...]
https://www.bleepingcomputer.com/news/security/npm-pulls-malicious-package-that-stole-login-passwords/
BleepingComputer
npm Pulls Malicious Package that Stole Login Passwords
A malicious package was removed today from the npm repository after it was discovered that stole login information from the computers it was installed on.
Bitdefender Fixes Privilege Escalation Bug in Free Antivirus 2020
A vulnerability in the free version of Bitdefender Antivirus could be exploited by an attacker to get SYSTEM-level permissions, reserved for the most privileged account on a Windows machine. [...]
https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/
A vulnerability in the free version of Bitdefender Antivirus could be exploited by an attacker to get SYSTEM-level permissions, reserved for the most privileged account on a Windows machine. [...]
https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/
BleepingComputer
Bitdefender Fixes Privilege Escalation Bug in Free Antivirus 2020
A vulnerability in the free version of Bitdefender Antivirus could be exploited by an attacker to get SYSTEM-level permissions, reserved for the most privileged account on a Windows machine.
Portland Public Schools Recovers $2.9 Million Lost in BEC Scam
Oregon urban school district Portland Public Schools is on track to recover roughly $2.9 million wired by district employees to a BEC scammer, after discovering the fraudulent transactions before the money left the fraudster's accounts. [...]
https://www.bleepingcomputer.com/news/security/portland-public-schools-recovers-29-million-lost-in-bec-scam/
Oregon urban school district Portland Public Schools is on track to recover roughly $2.9 million wired by district employees to a BEC scammer, after discovering the fraudulent transactions before the money left the fraudster's accounts. [...]
https://www.bleepingcomputer.com/news/security/portland-public-schools-recovers-29-million-lost-in-bec-scam/
BleepingComputer
Portland Public Schools Recovers $2.9 Million Lost in BEC Scam
Oregon urban school district Portland Public Schools is on track to recover roughly $2.9 million wired by district employees to a BEC scammer, after discovering the fraudulent transactions before the money left the fraudster's accounts.
GitHub Experienced Widespread Major Services Outage
The GitHub Git repository hosting platform experienced a widespread and major services outage impacting the Issues, PRs, Dashboard, Projects, and Notifications features. [...]
https://www.bleepingcomputer.com/news/technology/github-experienced-widespread-major-services-outage/
The GitHub Git repository hosting platform experienced a widespread and major services outage impacting the Issues, PRs, Dashboard, Projects, and Notifications features. [...]
https://www.bleepingcomputer.com/news/technology/github-experienced-widespread-major-services-outage/
BleepingComputer
GitHub Experienced Widespread Major Services Outage
The GitHub Git repository hosting platform experienced a widespread and major services outage impacting the Issues, PRs, Dashboard, Projects, and Notifications features.
Google Twice Misses Android App with Open-Source Spyware Code
One Android app with spyware capabilities based on an open-source remote access tool (RAT) has twice thwarted the security of Google Play over a period of two weeks. [...]
https://www.bleepingcomputer.com/news/security/google-twice-misses-android-app-with-open-source-spyware-code/
One Android app with spyware capabilities based on an open-source remote access tool (RAT) has twice thwarted the security of Google Play over a period of two weeks. [...]
https://www.bleepingcomputer.com/news/security/google-twice-misses-android-app-with-open-source-spyware-code/
BleepingComputer
Google Twice Misses Android App with Open-Source Spyware Code
One Android app with spyware capabilities based on an open-source remote access tool (RAT) has twice thwarted the security of Google Play over a period of two weeks.
Unpatched Squid Servers Exposed to DoS, Code Execution Attacks
Multiple versions of the Squid web proxy cache server built with Basic Authentication features are currently vulnerable to code execution and denial-of-service (DoS) attacks triggered by the exploitation of a heap buffer overflow security flaw. [...]
https://www.bleepingcomputer.com/news/security/unpatched-squid-servers-exposed-to-dos-code-execution-attacks/
Multiple versions of the Squid web proxy cache server built with Basic Authentication features are currently vulnerable to code execution and denial-of-service (DoS) attacks triggered by the exploitation of a heap buffer overflow security flaw. [...]
https://www.bleepingcomputer.com/news/security/unpatched-squid-servers-exposed-to-dos-code-execution-attacks/
BleepingComputer
Unpatched Squid Servers Exposed to DoS, Code Execution Attacks
Multiple versions of the Squid web proxy cache server built with Basic Authentication features are currently vulnerable to code execution and denial-of-service (DoS) attacks triggered by the exploitation of a heap buffer overflow security flaw.
Cisco Warns of Public Exploit Code for Critical Switch Flaws
Cisco updated the security advisories for three vulnerabilities patched in early August warning customers that its Product Security Incident Response Team (PSIRT) team is aware of public exploit code being available. [...]
https://www.bleepingcomputer.com/news/security/cisco-warns-of-public-exploit-code-for-critical-switch-flaws/
Cisco updated the security advisories for three vulnerabilities patched in early August warning customers that its Product Security Incident Response Team (PSIRT) team is aware of public exploit code being available. [...]
https://www.bleepingcomputer.com/news/security/cisco-warns-of-public-exploit-code-for-critical-switch-flaws/
BleepingComputer
Cisco Warns of Public Exploit Code for Critical Switch Flaws
Cisco updated the security advisories for three vulnerabilities patched in early August warning customers that its Product Security Incident Response Team (PSIRT) team is aware of public exploit code being available.
Steam Patches LPE Vulnerabilities in Beta Version Update
Almost 48 hours after security researcher Vasily Kravets (PsiDragon) released his proof of concept (PoC) for a second vulnerability in Steam client for Windows leading to privilege escalation, Valve released a beta update that allegedly fixes the bugs. [...]
https://www.bleepingcomputer.com/news/security/steam-patches-lpe-vulnerabilities-in-beta-version-update/
Almost 48 hours after security researcher Vasily Kravets (PsiDragon) released his proof of concept (PoC) for a second vulnerability in Steam client for Windows leading to privilege escalation, Valve released a beta update that allegedly fixes the bugs. [...]
https://www.bleepingcomputer.com/news/security/steam-patches-lpe-vulnerabilities-in-beta-version-update/
BleepingComputer
Steam Patches LPE Vulnerabilities in Beta Version Update
Almost 48 hours after security researcher Vasily Kravets (PsiDragon) released his proof of concept (PoC) for a second vulnerability in Steam client for Windows leading to privilege escalation, Valve released a beta update that allegedly fixes the bugs.
Microsoft Forms to Add Enterprise Automatic Phishing Detection
Microsoft is working on also adding automatic phishing to enterprise in-org forms after previously rolling out Microsoft Forms proactive phishing prevention for public forms in July. [...]
https://www.bleepingcomputer.com/news/security/microsoft-forms-to-add-enterprise-automatic-phishing-detection/
Microsoft is working on also adding automatic phishing to enterprise in-org forms after previously rolling out Microsoft Forms proactive phishing prevention for public forms in July. [...]
https://www.bleepingcomputer.com/news/security/microsoft-forms-to-add-enterprise-automatic-phishing-detection/
BleepingComputer
Microsoft Forms to Add Enterprise Automatic Phishing Detection
Microsoft is working on also adding automatic phishing to enterprise in-org forms after previously rolling out Microsoft Forms proactive phishing prevention for public forms in July.
Google Chrome to Warn If Logins Are Found in a Data Breach
Google is adding a built-in data breach notification service to the Chrome browser that will alert users when they are logging into sites with credentials that have been exposed by breaches. [...]
https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-if-logins-are-found-in-a-data-breach/
Google is adding a built-in data breach notification service to the Chrome browser that will alert users when they are logging into sites with credentials that have been exposed by breaches. [...]
https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-if-logins-are-found-in-a-data-breach/
BleepingComputer
Google Chrome to Warn If Logins Are Found in a Data Breach
Google is adding a built-in data breach notification service to the Chrome browser that will alert users when they are logging into sites with credentials that have been exposed by breaches.
Emotet Botnet Is Back, Servers Active Across the World
Command and control (C2) servers for the Emotet botnet appear to have resumed activity and deliver binaries once more. This comes after being inert since the beginning of June. [...]
https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/
Command and control (C2) servers for the Emotet botnet appear to have resumed activity and deliver binaries once more. This comes after being inert since the beginning of June. [...]
https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/
BleepingComputer
Emotet Botnet Is Back, Servers Active Across the World
Command and control (C2) servers for the Emotet botnet appear to have resumed activity and deliver binaries once more. This comes after being inert since the beginning of June.
Instagram Phishing Emails Use Fake Login Warning Baits
Instagram users are currently targeted by a new phishing campaign that uses login attempt warnings coupled with what looks like two-factor authentication (2FA) codes to make the scam more believable. [...]
https://www.bleepingcomputer.com/news/security/instagram-phishing-emails-use-fake-login-warning-baits/
Instagram users are currently targeted by a new phishing campaign that uses login attempt warnings coupled with what looks like two-factor authentication (2FA) codes to make the scam more believable. [...]
https://www.bleepingcomputer.com/news/security/instagram-phishing-emails-use-fake-login-warning-baits/
BleepingComputer
Instagram Phishing Emails Use Fake Login Warning Baits
Instagram users are currently targeted by a new phishing campaign that uses login attempt warnings coupled with what looks like two-factor authentication (2FA) codes to make the scam more believable.
Mastercard Reports Data Breach to German and Belgian DPAs
Mastercard disclosed a data breach to the German and Belgian Data Protection Authorities (DPA) involving customer data from the company's Priceless Specials loyalty program. [...]
https://www.bleepingcomputer.com/news/security/mastercard-reports-data-breach-to-german-and-belgian-dpas/
Mastercard disclosed a data breach to the German and Belgian Data Protection Authorities (DPA) involving customer data from the company's Priceless Specials loyalty program. [...]
https://www.bleepingcomputer.com/news/security/mastercard-reports-data-breach-to-german-and-belgian-dpas/
BleepingComputer
Mastercard Reports Data Breach to German and Belgian DPAs
Mastercard disclosed a data breach to the German and Belgian Data Protection Authorities (DPA) involving customer data from the company's Priceless Specials loyalty program.
Windows 10 KB4505903 Update Breaks Bluetooth Speakers Connectivity
Microsoft says that Bluetooth speakers will stop connecting to devices running Windows 10, version 1903 after installing the KB4505903 cumulative update released on July 26, 2019. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4505903-update-breaks-bluetooth-speakers-connectivity/
Microsoft says that Bluetooth speakers will stop connecting to devices running Windows 10, version 1903 after installing the KB4505903 cumulative update released on July 26, 2019. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4505903-update-breaks-bluetooth-speakers-connectivity/
BleepingComputer
Windows 10 KB4505903 Update Breaks Bluetooth Speakers Connectivity
Microsoft says that Bluetooth speakers will stop connecting to devices running Windows 10, version 1903 after installing the KB4505903 cumulative update released on July 26, 2019.
IRS Warns Taxpayers of New Scam Campaign Distributing Malware
The Internal Revenue Service (IRS) issued today a warning to alert taxpayers and tax professionals of an active IRS impersonation scam campaign sending spam emails to deliver malicious payloads. [...]
https://www.bleepingcomputer.com/news/security/irs-warns-taxpayers-of-new-scam-campaign-distributing-malware/
The Internal Revenue Service (IRS) issued today a warning to alert taxpayers and tax professionals of an active IRS impersonation scam campaign sending spam emails to deliver malicious payloads. [...]
https://www.bleepingcomputer.com/news/security/irs-warns-taxpayers-of-new-scam-campaign-distributing-malware/
BleepingComputer
IRS Warns Taxpayers of New Scam Campaign Distributing Malware
The Internal Revenue Service (IRS) issued today a warning to alert taxpayers and tax professionals of an active IRS impersonation scam campaign sending spam emails to deliver malicious payloads.
Microsoft Blocks Windows 10 1903 Update on Zebra Rugged Tablets
Microsoft introduced a new compatibility hold to block users of Zebra XSLATE B10 rugged tablets from installing or updating to Windows 10, version 1903 or Windows 10, version 1809. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-blocks-windows-10-1903-update-on-zebra-rugged-tablets/
Microsoft introduced a new compatibility hold to block users of Zebra XSLATE B10 rugged tablets from installing or updating to Windows 10, version 1903 or Windows 10, version 1809. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-blocks-windows-10-1903-update-on-zebra-rugged-tablets/
BleepingComputer
Microsoft Blocks Windows 10 1903 Update on Zebra Rugged Tablets
Microsoft introduced a new compatibility hold to block users of Zebra XSLATE B10 rugged tablets from installing or updating to Windows 10, version 1903 or Windows 10, version 1809.
Hostinger Data Breach Affects Almost 14 Million Customers
Hosting provider Hostinger today announced that it reset the login passwords of 14 million of its customers following a recent security breach that enabled unauthorized access to a client database. [...]
https://www.bleepingcomputer.com/news/security/hostinger-data-breach-affects-almost-14-million-customers/
Hosting provider Hostinger today announced that it reset the login passwords of 14 million of its customers following a recent security breach that enabled unauthorized access to a client database. [...]
https://www.bleepingcomputer.com/news/security/hostinger-data-breach-affects-almost-14-million-customers/
BleepingComputer
Hostinger Data Breach Affects Almost 14 Million Customers
Hosting provider Hostinger today announced that it reset the login passwords of 14 million of its customers following a recent security breach that enabled unauthorized access to a client database.