15 Dec CISA urges tech manufacturers to stop using default passwords Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged technology manufacturers to stop providing software and devices with default passwords. […]
15 Dec 3CX warns customers to disable SQL database integrations VoIP communications company 3CX warned customers today to disable SQL Database integrations because of risks posed by what it describes as a potential vulnerability. […]
15 Dec Ransomware gang behind threats to Fred Hutch cancer patients The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats. […]
15 Dec Delta Dental of California data breach exposed info of 7 million people Delta Dental of California and its affiliates are warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. […]
14 Dec New NKAbuse malware abuses NKN blockchain for stealthy comms A new Go-based multi-platform malware identified as ‘NKAbuse’ is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. […]
14 Dec Ubiquiti users report having access to others’ UniFi routers, cameras Since yesterday, customers of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people’s devices and notifications through the company’s cloud services. […]
14 Dec Ten new Android banking trojans targeted 985 bank apps in 2023 This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries. […]
14 Dec Discord adds Security Key support for all users to enhance security Discord has made security key multi-factor authentication (MFA) available for all accounts on the platform, bringing significant security and anti-phishing benefits to its 500+ million registered users. […]
13 Dec Stealthy KV-botnet hijacks SOHO routers and VPN devices The Chinese state-sponsored APT hacking group known as Volt Typhoon (Bronze Silhouette) has been linked to a sophisticated botnet named ‘KV-botnet’ since at least 2022 to attack SOHO routers in high-value targets. […]
13 Dec BazarCall attacks abuse Google Forms to legitimize phishing emails A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. […]