28 Jan Hackers use new SwiftSlicer wiper to destroy Windows domains Security researchers have identified a new data-wiping malware they named SwiftSlicer that aims to overwrite crucial files used by the Windows operating system. […]
27 Jan The Week in Ransomware – January 27th 2023 – ‘We hacked the hackers’ For the most part, this week has been relatively quiet regarding ransomware attacks and researcher — that is, until the FBI announced the disruption of the Hive ransomware operation. […]
27 Jan Ukraine: Sandworm hackers hit news agency with 5 data wipers The Ukrainian Computer Emergency Response Team (CERT-UA) found a cocktail of five different data-wiping malware strains deployed on the network of the country’s national news agency (Ukrinform) on January 17th. […]
27 Jan PlugX malware hides on USB devices to infect new Windows hosts Security researchers have analyzed a variant of the PlugX malware that can hide malicious files on removable USB devices and then infect the Windows hosts they connect to. […]
26 Jan Microsoft urges admins to patch on-premises Exchange servers Microsoft urged customers today to keep their on-premises Exchange servers patched by applying the latest supported Cumulative Update (CU) to have them always ready to deploy an emergency security update. […]
26 Jan Bitwarden password vaults targeted in Google ads phishing attack Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users’ password vault credentials. […]
26 Jan US offers $10M bounty for Hive ransomware links to foreign governments The U.S. Department of State today offered up to $10 million for information that could help link the Hive ransomware group (or other threat actors) with foreign governments. […]
26 Jan New Mimic ransomware abuses ‘Everything’ Windows search tool A new ransomware family named ‘Mimic’ has been spotted in the wild abusing the APIs of a legitimate Windows file search tool called ‘Everything’ to achieve file enumeration. […]
25 Jan Exploit released for critical Windows CryptoAPI spoofing bug Proof of concept exploit code has been released by Akamai researchers for a critical Windows CryptoAPI vulnerability discovered by the NSA and U.K.’s NCSC allowing MD5-collision certificate spoofing. […]
25 Jan CISA: Federal agencies hacked using legitimate remote desktop tools CISA, the NSA, and MS-ISAC warned today in a joint advisory that attackers are increasingly using legitimate remote monitoring and management (RMM) software for malicious purposes. […]