24 Dec FreePBX developer Sangoma hit with Conti ransomware attack Sangoma disclosed a data breach after files were stolen during a recent Conti ransomware attack and published online. […]
24 Dec North Korean state hackers breach COVID-19 research entities North Korean nation-state hackers tracked as the Lazarus Group have recently compromised organizations involved in COVID-19 research and vaccine development. […]
24 Dec NetGalley discloses data breach after website was hacked The NetGalley book promotion site has suffered a data breach that allowed threat actors to access a database with members’ personal information. […]
24 Dec Hacker earns $2 million in bug bounties on HackerOne Cosmin Iordache is the first bug bounty hunter to earn more than $2,000,000 in bounty awards through the vulnerability coordination and bug bounty program HackerOne. […]
24 Dec Citrix confirms ongoing DDoS attack impacting NetScaler ADCs Citrix has confirmed today that an ongoing ‘DDoS attack pattern’ using DTLS as an amplification vector is affecting Citrix Application Delivery Controller (ADC) networking appliances with EDT enabled. […]
23 Dec FBI: Iran behind pro-Trump ‘enemies of the people’ doxing site Iranian cyber actors are likely behind a campaign that encouraged deadly violence against U.S. state officials certifying the 2020 election results. […]
23 Dec PSA: Active Chase phishing scam pretends to be fraud alerts A large scale phishing scam is underway that pretends to be a security notice from Chase stating that fraudulent activity has been detected and caused the recipient’s account to be blocked. […]
23 Dec Windows zero-day with bad patch gets new public exploit code Back in June, Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase their permissions to kernel level on a compromised machine. The patch did not stick. […]
23 Dec Microsoft 365 admins can now get security incident email alerts Microsoft has added support for security incident email notifications to the Microsoft 365 Defender enterprise threat protection solution. […]
23 Dec UK privacy watchdog warns SolarWinds victims to report data breaches United Kingdom’s Information Commissioner’s Office (ICO) has warned organizations that fell victim to the SolarWinds hack that they are required to report data breaches within three days after their discovery. […]