05 Mar Ongoing phishing attacks target US brokers with fake FINRA audits The US Financial Industry Regulatory Authority (FINRA) has issued a regulatory notice warning US brokerage firms and brokers of an ongoing phishing campaign using fake compliance audit alerts to harvest information. […]
05 Mar Supermicro, Pulse Secure release fixes for ‘TrickBoot’ attacks Supermicro and Pulse Secure have released advisories warning that some of their motherboards are vulnerable to the TrickBot malware’s UEFI firmware-infecting module, known as TrickBoot. […]
04 Mar CompuCom MSP hit by DarkSide ransomware cyberattack US managed service provider CompuCom has suffered a DarkSide ransomware attack leading to service outages and customers disconnecting from the MSP’s network to prevent the spread of malware. […]
04 Mar VMware releases fix for severe View Planner RCE vulnerability VMware has addressed a high severity unauth RCE vulnerability in VMware View Planner, allowing attackers to abuse servers running unpatched software for remote code execution. […]
04 Mar Researcher bitsquats Microsoft’s windows.com to steal traffic A researcher was able to bitsquat Microsoft’s windows.com domain by cybersquatting variations of windows.com. Adversaries can abuse this tactic to conduct automated attacks or collect data due to the nature of bit flipping. […]
04 Mar Hacked SendGrid accounts used in phishing attacks to steal logins A phishing campaign targeting users of Outlook Web Access and Office 365 services collected thousands of credentials relying on trusted domains such as SendGrid. […]
04 Mar Windows DNS SIGRed bug gets first public RCE PoC exploit A working proof-of-concept (PoC) exploit is now publicly available for the critical SIGRed Windows DNS Server remote code execution (RCE) vulnerability. […]
04 Mar DHS orders agencies to urgently patch or disconnect Exchange servers The Department of Homeland Security’s cybersecurity unit has ordered federal agencies to urgently update or disconnect Microsoft Exchange on-premises products on their networks. […]
03 Mar Cybersecurity firm Qualys likely latest victim of Accellion hacks Cybersecurity firm Qualys is the latest victim to have suffered a data breach after a zero-day vulnerability in their Accellion FTA server was exploited to steal hosted files. […]
03 Mar State hackers rush to exploit unpatched Microsoft Exchange servers Multiple state-sponsored hacking groups are actively exploiting critical Exchange bugs Microsoft patched Tuesday via emergency out-of-band security updates. […]