19 Oct Brazil arrests suspect linked to the Lapsus$ hacking group Today, the Brazilian Federal Police arrested a Brazilian suspect in the city of Feira de Santana, Bahia, believed to be part of the Lapsus$ extortion gang. […]
19 Oct Microsoft data breach exposes customers’ contact info, emails Microsoft said today that some of its customers’ sensitive information was exposed by a misconfigured Microsoft server accessible over the Internet. […]
19 Oct Microsoft announces enterprise DDoS protection for SMBs Microsoft announced today the availability of Azure DDoS IP Protection in public preview, a new and fully managed DDoS Protection pay-per-protected IP model offering tailored to small and midsize businesses (SMBs). […]
19 Oct Hackers use new stealthy PowerShell backdoor to target 60+ victims A previously undocumented, fully undetectable PowerShell backdoor is being actively used by a threat actor who has targeted at least 69 entities. […]
19 Oct Microsoft Azure SFX bug let hackers hijack Service Fabric clusters Attackers could exploit a now-patched spoofing vulnerability in Service Fabric Explorer to gain admin privileges and hijack Azure Service Fabric clusters. […]
18 Oct Ransom Cartel linked to notorious REvil ransomware operation Threat analysts have connected the pieces that link the Ransom Cartel RaaS (ransomware-as-a-service) to the REvil gang, one of the most notorious and prolific ransomware groups in recent years. […]
18 Oct FBI: Scammers likely to target US Student Loan Debt Relief applicants The FBI has released a warning that scammers may be targeting individuals seeking to enroll in the Federal Student Aid program to steal their personal information, payment details, and money. […]
17 Oct Malware dev claims to sell new BlackLotus Windows UEFI bootkit A threat actor is selling on hacking forums what they claim to be a new UEFI bootkit named BlackLotus, a malicious tool with capabilities usually linked to state-backed threat groups. […]
17 Oct MyDeal data breach impacts 2.2M users, stolen data for sale online Woolworths’ MyDeal subsidiary has disclosed a data breach affecting 2.2 million customers, with the hacker trying to sell the stolen data on a hacker forum. […]
17 Oct Windows Mark of the Web bypass zero-day gets unofficial patch A free unofficial patch has been released through the 0patch platform to address an actively exploited zero-day flaw in the Windows Mark of the Web (MotW) security mechanism. […]