26 Dec SolarWinds releases updated advisory for new SUPERNOVA malware SolarWinds has released an updated advisory for the additional SuperNova malware discovered to have been distributed through the company’s network management platform. […]
25 Dec CrowdStrike releases free Azure security tool after failed hack Leading cybersecurity firm CrowdStrike was notified by Microsoft that threat actors had attempted to read the company’s emails through compromised by Microsoft Azure credentials. […]
25 Dec Fake Amazon gift card emails deliver the Dridex malware The Dridex malware gang is delivering a nasty gift for the holidays using a spam campaign pretending to be Amazon Gift Cards. […]
24 Dec FreePBX developer Sangoma hit with Conti ransomware attack Sangoma disclosed a data breach after files were stolen during a recent Conti ransomware attack and published online. […]
24 Dec North Korean state hackers breach COVID-19 research entities North Korean nation-state hackers tracked as the Lazarus Group have recently compromised organizations involved in COVID-19 research and vaccine development. […]
24 Dec NetGalley discloses data breach after website was hacked The NetGalley book promotion site has suffered a data breach that allowed threat actors to access a database with members’ personal information. […]
24 Dec Hacker earns $2 million in bug bounties on HackerOne Cosmin Iordache is the first bug bounty hunter to earn more than $2,000,000 in bounty awards through the vulnerability coordination and bug bounty program HackerOne. […]
24 Dec Citrix confirms ongoing DDoS attack impacting NetScaler ADCs Citrix has confirmed today that an ongoing ‘DDoS attack pattern’ using DTLS as an amplification vector is affecting Citrix Application Delivery Controller (ADC) networking appliances with EDT enabled. […]
23 Dec FBI: Iran behind pro-Trump ‘enemies of the people’ doxing site Iranian cyber actors are likely behind a campaign that encouraged deadly violence against U.S. state officials certifying the 2020 election results. […]
23 Dec PSA: Active Chase phishing scam pretends to be fraud alerts A large scale phishing scam is underway that pretends to be a security notice from Chase stating that fraudulent activity has been detected and caused the recipient’s account to be blocked. […]