04 Dec Metro Vancouver’s transit system hit by Egregor ransomware The Egregor ransomware operation has breached Metro Vancouver’s transportation agency TransLink with the cyberattack causing disruptions in services and payment systems. […]
03 Dec Credit card stealing malware hides in social media sharing icons Newly discovered web skimming malware is capable of hiding in plain sight to inject payment card skimmer scripts into compromised online stores. […]
03 Dec Kmart nationwide retailer suffers a ransomware attack US department store retailer Kmart has suffered a ransomware attack that impacts back-end services at the company, BleepingComputer has learned. […]
03 Dec Hacker-for-hire group develops new stealthy Windows backdoor Kaspersky researchers discovered a previously undocumented Windows PowerShell malware dubbed PowerPepper and developed by the hacker-for-hire group DeathStalker. […]
03 Dec Hackers target EU Commission, COVID-19 cold chain supply orgs IBM X-Force warned of threat actors actively targeting organizations associated with the COVID-19 vaccine cold chain in a large scale spear-phishing campaign that has started three months ago, in September 2020. […]
02 Dec HMRC phishing scam abuses mail service to bypass spam filters Threat actors are exploiting legitimate SendGrid mailing service to send HMRC phishing emails that bypass spam filters. […]
02 Dec K12 online schooling giant pays Ryuk ransomware to stop data leak Online education giant K12 Inc. has paid a ransom after their systems were hit by Ryuk ransomware in the middle of November. […]
02 Dec Phishing targets US brokerage firms using FINRA lookalike domain US securities industry regulator FINRA warned brokerage firms earlier this week of ongoing phishing attacks using a recently registered web domain spoofing a legitimate FINRA website. […]
02 Dec Alabama school district shut down by ransomware attack Ransomware operators have attacked the Huntsville City Schools district in Alabama, forcing them to shut down schools for the rest of the week and possibly next week. […]
01 Dec Critical Oracle WebLogic flaw actively exploited by DarkIRC malware A botnet known as DarkIRC is actively targeting thousands of exposed Oracle WebLogic servers in attacks designed to exploit the CVE-2020-14882 remote code execution (RCE) vulnerability fixed by Oracle two months ago. […]