24 Dec NetGalley discloses data breach after website was hacked The NetGalley book promotion site has suffered a data breach that allowed threat actors to access a database with members’ personal information. […]
24 Dec Hacker earns $2 million in bug bounties on HackerOne Cosmin Iordache is the first bug bounty hunter to earn more than $2,000,000 in bounty awards through the vulnerability coordination and bug bounty program HackerOne. […]
24 Dec Citrix confirms ongoing DDoS attack impacting NetScaler ADCs Citrix has confirmed today that an ongoing ‘DDoS attack pattern’ using DTLS as an amplification vector is affecting Citrix Application Delivery Controller (ADC) networking appliances with EDT enabled. […]
23 Dec FBI: Iran behind pro-Trump ‘enemies of the people’ doxing site Iranian cyber actors are likely behind a campaign that encouraged deadly violence against U.S. state officials certifying the 2020 election results. […]
23 Dec PSA: Active Chase phishing scam pretends to be fraud alerts A large scale phishing scam is underway that pretends to be a security notice from Chase stating that fraudulent activity has been detected and caused the recipient’s account to be blocked. […]
23 Dec Windows zero-day with bad patch gets new public exploit code Back in June, Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase their permissions to kernel level on a compromised machine. The patch did not stick. […]
23 Dec Microsoft 365 admins can now get security incident email alerts Microsoft has added support for security incident email notifications to the Microsoft 365 Defender enterprise threat protection solution. […]
23 Dec UK privacy watchdog warns SolarWinds victims to report data breaches United Kingdom’s Information Commissioner’s Office (ICO) has warned organizations that fell victim to the SolarWinds hack that they are required to report data breaches within three days after their discovery. […]
22 Dec Biden blasts Trump administration over SolarWinds attack response U.S. President-Elect Joe Biden has criticized the Trump administration over the lack of response regarding the SolarWinds response and for failing to officially attribute the attacks. […]
22 Dec Roanoke College delays spring semester after cyberattack Roanoke College has delayed their spring semester by almost a month after a cyberattack has impacted files and data access. […]