20 May New BiBi Wiper version also destroys the disk partition table A new version of the BiBi Wiper malware is now deleting the disk partition table to make data restoration harder, extending the downtime for targeted victims. […]
20 May QNAP QTS zero-day in Share feature gets public RCE exploit An extensive security audit of QNAP QTS, the operating system for the company’s NAS products, has uncovered fifteen vulnerabilities of varying severity, with eleven remaining unfixed. […]
19 May American Radio Relay League cyberattack takes Logbook of the World offline The American Radio Relay League (ARRL) warns it suffered a cyberattack, which disrupted its IT systems and online operations, including email and the Logbook of the World. […]
19 May CISA warns of hackers exploiting Chrome, EoL D-Link bugs The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three security vulnerabilities to its ‘Known Exploited Vulnerabilities’ catalog, one impacting Google Chrome and two affecting some D-Link routers. […]
18 May Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising A ransomware operation targets Windows system administrators by taking out Google ads to promote fake download sites for Putty and WinSCP. […]
18 May Banking malware Grandoreiro returns after police disruption The banking trojan “Grandoreiro” is spreading in a large-scale phishing campaign in over 60 countries, targeting customer accounts of roughly 1,500 banks. […]
17 May The Week in Ransomware – May 17th 2024 – Mailbombing is back This week was pretty quiet on the ransomware front, with most of the attention on the seizure of the BreachForums data theft forum. However, that does not mean there was nothing of interest released this week about ransomware. […]
17 May Microsoft to start enforcing Azure multi-factor authentication in July Starting in July, Microsoft will begin gradually enforcing multi-factor authentication (MFA) for all users signing into Azure to administer resources. […]
17 May SEC: Financial orgs have 30 days to send data breach notifications The Securities and Exchange Commission (SEC) has adopted amendments to Regulation S-P that require certain financial institutions to disclose data breach incidents to impacted individuals within 30 days of discovery. […]
17 May US arrests suspects behind $73M ‘pig butchering’ laundering scheme The U.S. Department of Justice charged two suspects for allegedly leading a crime ring that laundered at least $73 million from cryptocurrency investment scams, also known as “pig butchering.” […]