CISA: APT group behind US govt hacks used multiple access vectors
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector. [...]
https://www.bleepingcomputer.com/news/security/cisa-apt-group-behind-us-govt-hacks-used-multiple-access-vectors/
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector. [...]
https://www.bleepingcomputer.com/news/security/cisa-apt-group-behind-us-govt-hacks-used-multiple-access-vectors/
BleepingComputer
CISA: Hackers breached US govt using more than SolarWinds backdoor
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector.
Ransomware masquerades as mobile version of Cyberpunk 2077
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare. [...]
https://www.bleepingcomputer.com/news/security/ransomware-masquerades-as-mobile-version-of-cyberpunk-2077/
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare. [...]
https://www.bleepingcomputer.com/news/security/ransomware-masquerades-as-mobile-version-of-cyberpunk-2077/
BleepingComputer
Ransomware masquerades as mobile version of Cyberpunk 2077
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare.
Nation-state hackers breached US think tank thrice in a row
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times. [...]
https://www.bleepingcomputer.com/news/security/nation-state-hackers-breached-us-think-tank-thrice-in-a-row/
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times. [...]
https://www.bleepingcomputer.com/news/security/nation-state-hackers-breached-us-think-tank-thrice-in-a-row/
BleepingComputer
US think tank breached three times in a row by SolarWinds hackers
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times.
Bouncy Castle fixes cryptography API authentication bypass flaw
A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library. When exploited, the vulnerability (CVE-2020-28052) can allow an attacker to gain access to user and administrator accounts due to a cryptographic weakness in the manner passwords are checked. [...]
https://www.bleepingcomputer.com/news/security/bouncy-castle-fixes-cryptography-api-authentication-bypass-flaw/
A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library. When exploited, the vulnerability (CVE-2020-28052) can allow an attacker to gain access to user and administrator accounts due to a cryptographic weakness in the manner passwords are checked. [...]
https://www.bleepingcomputer.com/news/security/bouncy-castle-fixes-cryptography-api-authentication-bypass-flaw/
SolarWinds hackers breach agency in charge of US nuclear weapons
Nation-state hackers have breached the networks of the National Nuclear Security Administration (NNSA) and the US Department of Energy (DOE). [...]
https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-agency-in-charge-of-us-nuclear-weapons/
Nation-state hackers have breached the networks of the National Nuclear Security Administration (NNSA) and the US Department of Energy (DOE). [...]
https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-agency-in-charge-of-us-nuclear-weapons/
BleepingComputer
SolarWinds hackers breach US nuclear weapons agency
Nation-state hackers have breached the networks of the National Nuclear Security Administration (NNSA) and the US Department of Energy (DOE).
Microsoft confirms breach in SolarWinds hack, denies infecting others
Microsoft has confirmed that they were hacked in the recent SolarWinds attacks but denied that their software was compromised in a supply-chain attack to infect customers. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-breach-in-solarwinds-hack-denies-infecting-others/
Microsoft has confirmed that they were hacked in the recent SolarWinds attacks but denied that their software was compromised in a supply-chain attack to infect customers. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-breach-in-solarwinds-hack-denies-infecting-others/
BleepingComputer
Microsoft confirms breach in SolarWinds hack, denies infecting others
Microsoft has confirmed that they were hacked in the recent SolarWinds attacks but denied that their software was compromised in a supply-chain attack to infect customers.
Microsoft identifies 40+ victims of SolarWinds hack, 80% from US
Microsoft said that over 40 of its customers had their networks infiltrated by hackers following the SolarWinds supply chain attack after they installed backdoored versions of the Orion IT monitoring platform. [...]
https://www.bleepingcomputer.com/news/security/microsoft-identifies-40-plus-victims-of-solarwinds-hack-80-percent-from-us/
Microsoft said that over 40 of its customers had their networks infiltrated by hackers following the SolarWinds supply chain attack after they installed backdoored versions of the Orion IT monitoring platform. [...]
https://www.bleepingcomputer.com/news/security/microsoft-identifies-40-plus-victims-of-solarwinds-hack-80-percent-from-us/
BleepingComputer
Microsoft identifies 40+ victims of SolarWinds hack, 80% from US
Microsoft said that over 40 of its customers had their networks infiltrated by hackers following the SolarWinds supply chain attack after they installed backdoored versions of the Orion IT monitoring platform.
Google Chrome disables insecure form warnings after complaints
Google has disabled a feature that displays a warning when submitting insecure forms after receiving many complaints from users and website administrators. [...]
https://www.bleepingcomputer.com/news/google/google-chrome-disables-insecure-form-warnings-after-complaints/
Google has disabled a feature that displays a warning when submitting insecure forms after receiving many complaints from users and website administrators. [...]
https://www.bleepingcomputer.com/news/google/google-chrome-disables-insecure-form-warnings-after-complaints/
BleepingComputer
Google Chrome disables insecure form warnings after complaints
Google has disabled a feature that displays a warning when submitting insecure forms after receiving many complaints from users and website administrators.
NSA warns of hackers forging cloud authentication information
An advisory from the U.S. National Security Agency is providing Microsoft Azure administrators guidance to detect and protect against threat actors looking to access resources in the cloud by forging authentication information. [...]
https://www.bleepingcomputer.com/news/security/nsa-warns-of-hackers-forging-cloud-authentication-information/
An advisory from the U.S. National Security Agency is providing Microsoft Azure administrators guidance to detect and protect against threat actors looking to access resources in the cloud by forging authentication information. [...]
https://www.bleepingcomputer.com/news/security/nsa-warns-of-hackers-forging-cloud-authentication-information/
BleepingComputer
NSA warns of hackers forging cloud authentication information
An advisory from the U.S. National Security Agency is providing Microsoft Azure administrators guidance to detect and protect against threat actors looking to access resources in the cloud by forging authentication information.
Windows 10 updates cause CorsairVBusDriver BSOD crash loop
Microsoft's December 2020 Windows 10 updates are conflicting with the Corsair Utility Engine software and causing the operating system to go into a BSOD crash loop. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-updates-cause-corsairvbusdriver-bsod-crash-loop/
Microsoft's December 2020 Windows 10 updates are conflicting with the Corsair Utility Engine software and causing the operating system to go into a BSOD crash loop. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-10-updates-cause-corsairvbusdriver-bsod-crash-loop/
BleepingComputer
Windows 10 updates cause CorsairVBusDriver BSOD crash loop
Microsoft's December 2020 Windows 10 updates are conflicting with the Corsair Utility Engine software and causing the operating system to go into a BSOD crash loop.
Europol launches new decryption platform for law enforcement
Europol and the European Commission have launched a new decryption platform that will help boost Europol's ability to gain access to information stored in encrypted media collected during criminal investigations. [...]
https://www.bleepingcomputer.com/news/security/europol-launches-new-decryption-platform-for-law-enforcement/
Europol and the European Commission have launched a new decryption platform that will help boost Europol's ability to gain access to information stored in encrypted media collected during criminal investigations. [...]
https://www.bleepingcomputer.com/news/security/europol-launches-new-decryption-platform-for-law-enforcement/
BleepingComputer
Europol launches new decryption platform for law enforcement
Europol and the European Commission have launched a new decryption platform that will help boost Europol's ability to gain access to information stored in encrypted media collected during criminal investigations.
Stealthy Magecart malware mistakenly leaks list of hacked stores
A list of dozens of online stores hacked by a web skimming group was inadvertently leaked by a dropper used to deploy a stealthy remote access trojan (RAT) on compromised e-commerce sites. [...]
https://www.bleepingcomputer.com/news/security/stealthy-magecart-malware-mistakenly-leaks-list-of-hacked-stores/
A list of dozens of online stores hacked by a web skimming group was inadvertently leaked by a dropper used to deploy a stealthy remote access trojan (RAT) on compromised e-commerce sites. [...]
https://www.bleepingcomputer.com/news/security/stealthy-magecart-malware-mistakenly-leaks-list-of-hacked-stores/
BleepingComputer
Stealthy Magecart malware mistakenly leaks list of hacked stores
A list of dozens of online stores hacked by a web skimming group was inadvertently leaked by a dropper used to deploy a stealthy remote access trojan (RAT) on compromised e-commerce sites.
The Week in Ransomware - December 18th 2020 - Targeting Israel
The SolarWinds supply chain attack has dominated this week's cybersecurity news, but there was still plenty of ransomware news this week. [...]
https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-december-18th-2020-targeting-israel/
The SolarWinds supply chain attack has dominated this week's cybersecurity news, but there was still plenty of ransomware news this week. [...]
https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-december-18th-2020-targeting-israel/
BleepingComputer
The Week in Ransomware - December 18th 2020 - Targeting Israel
The SolarWinds supply chain attack has dominated this week's cybersecurity news, but there was still plenty of ransomware news this week.
The SolarWinds cyberattack: The hack, the victims, and what we know
Since the SolarWinds supply chain attack was disclosed last Sunday, there has been a whirlwind of news, technical details, and analysis released about the hack. Because the amount of information that was released in such a short time is definitely overwhelming, we have published this as a roundup of this week's SolarWinds news. [...]
https://www.bleepingcomputer.com/news/security/the-solarwinds-cyberattack-the-hack-the-victims-and-what-we-know/
Since the SolarWinds supply chain attack was disclosed last Sunday, there has been a whirlwind of news, technical details, and analysis released about the hack. Because the amount of information that was released in such a short time is definitely overwhelming, we have published this as a roundup of this week's SolarWinds news. [...]
https://www.bleepingcomputer.com/news/security/the-solarwinds-cyberattack-the-hack-the-victims-and-what-we-know/
BleepingComputer
The SolarWinds cyberattack: The hack, the victims, and what we know
Since the SolarWinds supply chain attack was disclosed in December, there has been a whirlwind of news, technical details, and analysis released about the hack. Because the amount of information that was released in such a short time is definitely overwhelmingβ¦
Google explains the cause of the recent YouTube, Gmail outage
Google says that the global authentication system outage which affected most consumer-facing series on Monday was caused by a bug in the automated quota management system impacting the Google User ID Service. [...]
https://www.bleepingcomputer.com/news/google/google-explains-the-cause-of-the-recent-youtube-gmail-outage/
Google says that the global authentication system outage which affected most consumer-facing series on Monday was caused by a bug in the automated quota management system impacting the Google User ID Service. [...]
https://www.bleepingcomputer.com/news/google/google-explains-the-cause-of-the-recent-youtube-gmail-outage/
BleepingComputer
Google explains the cause of the recent YouTube, Gmail outage
Google says that the global authentication system outage which affected most consumer-facing series on Monday was caused by a bug in the automated quota management system impacting the Google User ID Service.
Gitpaste-12 worm botnet returns with 30+ vulnerability exploits
Recently discovered Gitpaste-12 worm that spreads via GitHub and also hosts malicious payload on Pastebin, has returned with over 30 vulnerability exploits, according to researchers at Juniper Labs. [...]
https://www.bleepingcomputer.com/news/security/gitpaste-12-worm-botnet-returns-with-30-plus-vulnerability-exploits/
Recently discovered Gitpaste-12 worm that spreads via GitHub and also hosts malicious payload on Pastebin, has returned with over 30 vulnerability exploits, according to researchers at Juniper Labs. [...]
https://www.bleepingcomputer.com/news/security/gitpaste-12-worm-botnet-returns-with-30-plus-vulnerability-exploits/
BleepingComputer
Gitpaste-12 worm botnet returns with 30+ vulnerability exploits
Recently discovered Gitpaste-12 worm that spreads via GitHub and also hosts malicious payload on Pastebin, has returned with over 30 vulnerability exploits, according to researchers at Juniper Labs.
New Windows 10 tool lets you group your taskbar shortcuts
A new Windows 10 utility called TaskbarGroups lets you group shortcuts on the taskbar so they can easily be launched without taking up a lot of space. [...]
https://www.bleepingcomputer.com/news/microsoft/new-windows-10-tool-lets-you-group-your-taskbar-shortcuts/
A new Windows 10 utility called TaskbarGroups lets you group shortcuts on the taskbar so they can easily be launched without taking up a lot of space. [...]
https://www.bleepingcomputer.com/news/microsoft/new-windows-10-tool-lets-you-group-your-taskbar-shortcuts/
BleepingComputer
New Windows 10 tool lets you group your taskbar shortcuts
A new Windows 10 utility called TaskbarGroups lets you group shortcuts on the taskbar so they can easily be launched without taking up a lot of space.
Windows Hello is now being used by 84% of Windows 10 users
Windows Hello, which is an all-in-one biometric authentication process integrated into Windows 10, is slowly growing in popularity. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-hello-is-now-being-used-by-84-percent-of-windows-10-users/
Windows Hello, which is an all-in-one biometric authentication process integrated into Windows 10, is slowly growing in popularity. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-hello-is-now-being-used-by-84-percent-of-windows-10-users/
BleepingComputer
Windows Hello is now being used by 84% of Windows 10 users
Windows Hello, which is an all-in-one biometric authentication process integrated into Windows 10, is slowly growing in popularity.
Flavors designer Symrise halts production after Clop ransomware attack
Flavor and fragrance developer Symrise has suffered a Clop ransomware attack where the attackers allegedly stole 500 GB of unencrypted files and encrypted close to 1,000 devices. [...]
https://www.bleepingcomputer.com/news/security/flavors-designer-symrise-halts-production-after-clop-ransomware-attack/
Flavor and fragrance developer Symrise has suffered a Clop ransomware attack where the attackers allegedly stole 500 GB of unencrypted files and encrypted close to 1,000 devices. [...]
https://www.bleepingcomputer.com/news/security/flavors-designer-symrise-halts-production-after-clop-ransomware-attack/
BleepingComputer
Flavors designer Symrise halts production after Clop ransomware attack
Flavor and fragrance developer Symrise has suffered a Clop ransomware attack where the attackers allegedly stole 500 GB of unencrypted files and encrypted close to 1,000 devices.
Physical addresses of 270K Ledger owners leaked on hacker forum
A threat actor has leaked the stolen email and mailing addresses for Ledger cryptocurrency wallet users on a hacker forum for free. [...]
https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/
A threat actor has leaked the stolen email and mailing addresses for Ledger cryptocurrency wallet users on a hacker forum for free. [...]
https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/
BleepingComputer
Physical addresses of 270K Ledger owners leaked on hacker forum
A threat actor has leaked the stolen email and mailing addresses for Ledger cryptocurrency wallet users on a hacker forum for free.
Microsoft fixes Windows 10 chkdsk bug causing boot failures
Microsoft has acknowledged a new issue impacting Windows 10 customers that might cause booting to fail on devices where the chkdsk tool has been used to repair logical file system errors. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-10-chkdsk-bug-causing-boot-failures/
Microsoft has acknowledged a new issue impacting Windows 10 customers that might cause booting to fail on devices where the chkdsk tool has been used to repair logical file system errors. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-10-chkdsk-bug-causing-boot-failures/
BleepingComputer
Microsoft fixes Windows 10 chkdsk bug causing boot failures
Microsoft has acknowledged a new issue impacting Windows 10 customers that might cause booting to fail on devices where the chkdsk tool has been used to repair logical file system errors.