02 Dec Alabama school district shut down by ransomware attack Ransomware operators have attacked the Huntsville City Schools district in Alabama, forcing them to shut down schools for the rest of the week and possibly next week. […]
01 Dec Critical Oracle WebLogic flaw actively exploited by DarkIRC malware A botnet known as DarkIRC is actively targeting thousands of exposed Oracle WebLogic servers in attacks designed to exploit the CVE-2020-14882 remote code execution (RCE) vulnerability fixed by Oracle two months ago. […]
30 Nov Microsoft Defender for Identity now detects Zerologon attacks Microsoft has added support for Zerologon exploitation detection to Microsoft Defender for Identity to allow Security Operations teams to detect on-premises attacks attempting to abuse this critical vulnerability. […]
30 Nov Gootkit malware returns to life alongside REvil ransomware After a year-long vacation, the Gootkit information-stealing Trojan has returned to life alongside REvil Ransomware in a new campaign targeting Germany. […]
30 Nov Healthcare provider AspenPointe data breach affects 295K patients U.S. healthcare provider AspenPointe notified patients of a data breach stemming from a September 2020 cyberattack that enabled attackers to steal protected health information (PHI) and personally identifiable information (PII). […]
29 Nov Pennsylvania county pays 500K ransom to DoppelPaymer ransomware Delaware County, Pennsylvania has paid a $500,000 ransom after their systems were hit by the DoppelPaymer ransomware last weekend. […]
28 Nov IIoT chip maker Advantech hit by ransomware, $12.5 million ransom The Conti ransomware gang hit the systems of industrial automation and Industrial IoT (IIoT) chip maker Advantech and is now demanding a $14 million ransom to decrypt affected systems and to stop leaking stolen company data. […]
27 Nov The Week in Ransomware – November 27th 2020 – Attacks continue With the USA holidays, this has been a relatively slow week in new research being released. We did, though, see some organizations get attacked or report historical attacks. […]
27 Nov Office 365 phishing abuses Oracle and Amazon cloud services A rather complex phishing scheme for stealing Office 365 credentials from small and medium-sized businesses in the U.S. and Australia combines cloud services from Oracle and Amazon into its infrastructure. […]
27 Nov Drupal issues emergency fix for critical bug with known exploits Drupal has released emergency security updates to address a critical vulnerability with known exploits that could allow for arbitrary PHP code execution on some CMS versions. […]