21 Dec Russians hacked JFK airport’s taxi dispatch system for profit Two U.S. citizens were arrested for allegedly conspiring with Russian hackers to hack the John F. Kennedy International Airport (JFK) taxi dispatch system to move specific taxis to the front of the queue in exchange for a $10 fee. […]
21 Dec Okta says its GitHub account hacked, source code stolen In a ‘confidential’ email notification sent by Okta and seen by BleepingComputer, the company states that attackers gained access to its GitHub repositories this month and stole the company’s source code. […]
20 Dec Microsoft pushes emergency fix for Windows Server Hyper-V VM issues Microsoft has released emergency out-of-band (OOB) Windows Server updates to address a known issue breaking virtual machine (VM) creation on Hyper-V hosts after installing this month’s Patch Tuesday updates. […]
20 Dec Ransomware gang uses new Microsoft Exchange exploit to breach servers Play ransomware threat actors are using a new exploit chain that bypasses ProxyNotShell URL rewrite mitigations to gain remote code execution (RCE) on vulnerable servers through Outlook Web Access (OWA). […]
20 Dec VirusTotal cheat sheet makes it easy to search for specific results VirusTotal has published a cheat sheet to help researchers create queries leading to more specific results from the malware intelligence platform. […]
20 Dec Microsoft will turn off Exchange Online basic auth in January Microsoft warned today that it will permanently turn off Exchange Online basic authentication starting early January 2023 to improve security. […]
19 Dec Play ransomware claims attack on German hotel chain H-Hotels The Play ransomware gang has claimed responsibility for a cyber attack on H-Hotels (h-hotels.com) that has resulted in communication outages for the company. […]
19 Dec Microsoft finds macOS bug that lets malware bypass security checks Apple has fixed a vulnerability that could be leveraged to deploy malware on vulnerable macOS devices via untrusted applications capable of bypassing Gatekeeper application execution restrictions. […]
19 Dec DraftKings warns data of 67K people was exposed in account hacks Sports betting company DraftKings revealed last week that more than 67,000 customers had their personal information exposed following a credential attack in November. […]
19 Dec Ukraine’s DELTA military system users targeted by info-stealing malware A compromised Ukrainian Ministry of Defense email account was found sending phishing emails and instant messages to users of the ‘DELTA’ situational awareness program to infect systems with information-stealing malware. […]