07 Feb New QakNote attacks push QBot malware via Microsoft OneNote files A new QBot malware campaign dubbed “QakNote” has been observed in the wild since last week, using malicious Microsoft OneNote’ .one’ attachments to infect systems with the banking trojan. […]
07 Feb Russian man pleads guilty to laundering Ryuk ransomware money Russian citizen Denis Mihaqlovic Dubnikov pleaded guilty on Tuesday to laundering money for the notorious Ryuk ransomware group for over three years. […]
07 Feb Over 12% of analyzed online stores expose private data, backups Many online stores are exposing private backups in public folders, including internal account passwords, which can be leveraged to take over the e-commerce sites and extort owners. […]
07 Feb Clop ransomware flaw allowed Linux victims to recover files for months The Clop ransomware gang is now also using a malware variant that explicitly targets Linux servers, but a flaw in the encryption scheme has allowed victims to quietly recover their files for free for months. […]
07 Feb LockBit ransomware gang claims Royal Mail cyberattack The LockBit ransomware operation has claimed the cyberattack on UK’s leading mail delivery service Royal Mail that forced the company to halt its international shipping services due to “severe service disruption.” […]
07 Feb Actively exploited GoAnywhere MFT zero-day gets emergency patch Fortra has released an emergency patch to address an actively exploited zero-day vulnerability in the GoAnywhere MFT secure file transfer tool. […]
06 Feb Exploit released for actively exploited GoAnywhere MFT zero-day Exploit code has been released for an actively exploited zero-day vulnerability affecting Internet-exposed GoAnywhere MFT administrator consoles. […]
05 Feb Dashlane password manager open-sourced its Android and iOS apps Dashlane announced it had made the source code for its Android and iOS apps available on GitHub under the Creative Commons Attribution-NonCommercial 4.0 license. […]
05 Feb New Dingo crypto token found charging a 99% transaction fee Researchers at IT security company Check Point security have flagged Dingo Token as a potential scam after finding a function that allows the project’s owner to manipulate trading fees up to 99% of the transaction value. […]
05 Feb Linux version of Royal Ransomware targets VMware ESXi servers Royal Ransomware is the latest ransomware operation to add support for encrypting Linux devices to its most recent malware variants, specifically targeting VMware ESXi virtual machines. […]