01 May Office 365 security baseline adds macro signing, JScript protection Microsoft has updated the security baseline for Microsoft 365 Apps for enterprise (formerly Office 365 Professional Plus) to include protection from JScript code execution attacks and unsigned macros. […]
01 May Python also impacted by critical IP address validation vulnerability Python 3.3 standard library ‘ipaddress’ suffers from a critical IP address vulnerability (CVE-2021-29921) identical to the flaw that was reported in the “netmask” library earlier this year. […]
30 Apr The Week in Ransomware – April 30th 2021 – Attacks Escalate Ransomware gangs continue to target organizations large and small, including a brazen attack on the Washington DC police department. […]
30 Apr First Horizon bank online accounts hacked to steal customers’ funds Bank holding company First Horizon Corporation disclosed the some of its customers had their online banking accounts breached by unknown attackers earlier this month. […]
30 Apr Babuk quits ransomware encryption, focuses on data-theft extortion A new message today from the operators of Babuk ransomware clarifies that the gang has decided to close the affiliate program and move to an extortion model that does not rely on encrypting victim computers. […]
29 Apr Microsoft finds critical code execution bugs in IoT, OT devices Microsoft security researchers have discovered over two dozen critical remote code execution (RCE) vulnerabilities in Internet of Things (IoT) devices and Operational Technology (OT) industrial systems. […]
29 Apr New ransomware group uses SonicWall zero-day to breach networks A financially motivated threat actor exploited a zero-day bug in Sonicwall SMA 100 Series VPN appliances to deploy new ransomware known as FiveHands on the networks of North American and European targets. […]
29 Apr QNAP warns of AgeLocker ransomware attacks on NAS devices QNAP customers are once again urged to secure their Network Attached Storage (NAS) devices to defend against Agelocker ransomware attacks targeting their data. […]
29 Apr Babuk ransomware readies ‘shut down’ post, plans to open source malware After just a few months of activity, the operators of Babuk ransomware briefly posted a short message about their intention to quit the extortion business after having achieved their goal. […]
28 Apr DigitalOcean data breach exposes customer billing information Cloud hosting provider DigitalOcean has disclosed a data breach after a flaw exposed customers’ billing information. […]