20 Jul JumpCloud breach traced back to North Korean state hackers US-based enterprise software company JumpCloud was breached by North Korean Lazarus Group hackers, according to security researchers at SentinelOne, CrowdStrike, and Mandiant. […]
19 Jul Estée Lauder beauty giant breached by two ransomware gangs Two ransomware actors, ALPHV/BlackCat and Clop, have listed beauty company Estée Lauder on their data leak sites as a victim of separate attacks. […]
19 Jul Adobe emergency patch fixes new ColdFusion zero-day used in attacks Adobe released an emergency ColdFusion security update that fixes critical vulnerabilities, including a fix for a new zero-day exploited in attacks. […]
19 Jul OpenAI credentials stolen by the thousands for sale on the dark web Threat actors are showing an increased interest in generative artificial intelligence tools, with hundreds of thousands of OpenAI credentials for sale on the dark web and access to a malicious alternative for ChatGPT. […]
18 Jul U.S. preparing Cyber Trust Mark for more secure smart devices A new cybersecurity certification and labeling program called U.S. Cyber Trust Mark is being shaped to help U.S. consumers choose connected devices that are more secure and resilient to hacker attacks. […]
18 Jul Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called SophosEncrypt, with the threat actors using the company name for their operation. […]
18 Jul New critical Citrix ADC and Gateway flaw exploited as zero-day Citrix today is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay. […]
18 Jul Strengthening Password Security may Lower Cyber Insurance Premiums When insurers assess an organization’s cybersecurity posture, password security is a key element considered. Learn more from Specops Software on how password security can affect your insurance premiums. […]
18 Jul FIN8 deploys ALPHV ransomware using Sardonic malware variant A financially motivated cybercrime gang has been observed deploying BlackCat ransomware payloads on networks backdoored using a revamped Sardonic malware version. […]
17 Jul Hackers exploiting critical WordPress WooCommerce Payments bug Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. […]