22 Mar Microsoft confirms they were hacked by Lapsus$ extortion group Microsoft has confirmed that one of their employees was compromised by the Lapsus$ hacking group, allowing the threat actors to access and steal portions of their source code. […]
22 Mar Windows 10 KB5011543 update released with Search highlights feature Microsoft has released the optional KB5011543 Preview cumulative update for Windows 10 20H2, Windows 10 21H1, and Windows 10 21H2. […]
22 Mar White House shares checklist to counter Russian cyberattacks The White House is urging U.S. organizations to shore up their cybersecurity defenses after new intelligence suggests that Russia is preparing to conduct cyberattacks in the near future. […]
22 Mar Okta confirms support engineer’s laptop was hacked in January Okta, a major provider of access management systems, says that 2.5%, or approximately 375 customers, were impacted by a cyberattack claimed by the Lapsus$ data extortion group. […]
22 Mar Custom macOS malware of Chinese hackers ‘Storm Cloud’ exposed Researchers have discovered a previously unknown macOS malware variant called GIMMICK, which is believed to be a custom tool used by a Chinese espionage threat actor known as ‘Storm Cloud.’ […]
21 Mar BitRAT malware now spreading as a Windows 10 license activator A new BitRAT malware distribution campaign is underway, exploiting users looking to activate pirated Windows OS versions for free using unofficial Microsoft license activators. […]
21 Mar Android password-stealing malware infects 100,000 Google Play users A malicious Android app that steals Facebook credentials has been installed over 100,000 times via the Google Play Store, with the app still available to download. […]
21 Mar Windows zero-day flaw giving admin rights gets unofficial patch, again A Windows local privilege escalation zero-day vulnerability that Microsoft has failed to fully address for several months now, allows users to gain administrative privileges in Windows 10, Windows 11, and Windows Server. […]
21 Mar Serpent malware campaign abuses Chocolatey Windows package manager Threat actors are abusing the popular Chocolatey Windows package manager in a new phishing campaign to install new ‘Serpent’ backdoor malware on systems of French government agencies and large construction firms. […]
21 Mar Microsoft investigating claims of hacked source code repositories Microsoft says they are investigating claims that the Lapsus$ data extortion hacking group breached their internal Azure DevOps source code repositories and stolen data. […]