01 Jun Hundreds of Elasticsearch databases targeted in ransom attacks A campaign targeting poorly secured Elasticsearch databases has deleted their contents and dropped ransom notes on 450 instances, demanding a payment of $620 to give them back their indexes, totaling a demand of $279,000. […]
01 Jun Ransomware attacks need less than four days to encrypt systems The duration of ransomware attacks in 2021 averaged 92.5 hours, measured from initial network access to payload deployment. In 2020, ransomware actors spent an average of 230 hours to complete their attacks and 1637.6 hours in 2019. […]
01 Jun Telegram’s blogging platform abused in phishing attacks Telegram’s anonymous blogging platform, Telegraph, is being actively exploited by phishing actors who take advantage of the platform’s lax policies to set up interim landing pages that lead to the theft of account credentials. […]
31 May Hackers steal WhatsApp accounts using call forwarding trick There’s a trick that allows attackers to hijack a victim’s WhatsApp account and gain access to personal messages and contact list. […]
31 May Windows MSDT zero-day now exploited by Chinese APT hackers Chinese-linked threat actors are now actively exploiting a Microsoft Office zero-day vulnerability (known as ‘Follina’) to execute malicious code remotely on Windows systems. […]
31 May Over 3.6 million MySQL servers found exposed on the Internet Over 3.6 million MySQL servers are publicly exposed on the Internet and responding to queries, making them an attractive target to hackers and extortionists. […]
31 May Microsoft shares mitigation for Office zero-day exploited in attacks Microsoft has shared mitigation measures to block attacks exploiting a newly discovered Microsoft Office zero-day flaw abused in the wild to execute malicious code remotely. […]
30 May Vodafone plans carrier-level user tracking for targeted ads Vodafone is piloting a new advertising ID system called TrustPid, which will work as a persistent user tracker at the mobile Internet Service Provider (ISP) level. […]
30 May Italy warns organizations to brace for incoming DDoS attacks The Computer Security Incident Response Team in Italy issued an urgent alert yesterday to raise awareness about the high risk of cyberattacks against national bodies and organizations on Monday. […]
30 May Google quietly bans deepfake training projects on Colab Google has quietly banned deepfake projects on its Colaboratory (Colab) service, putting an end to the large-scale utilization of the platform’s resources for this purpose. […]