21 May LockBit says they stole data in London Drugs ransomware attack Today, the LockBit ransomware gang claimed they were behind the April cyberattack on Canadian pharmacy chain London Drugs and is now threatening to publish stolen data online after allegedly failed negotiations. […]
21 May GitHub warns of SAML auth bypass flaw in Enterprise Server GitHub has fixed a maximum severity (CVSS v4 score: 10.0) authentication bypass vulnerability tracked as CVE-2024-4986, which impacts GitHub Enterprise Server (GHES) instances using SAML single sign-on (SSO) authentication. […]
21 May Zoom adds post-quantum end-to-end encryption to video meetings Zoom has announced the global availability of post-quantum end-to-end encryption (E2EE) for Zoom Meetings, with Zoom Phone and Zoom Rooms to follow soon. […]
20 May Critical Fluent Bit flaw impacts all major cloud providers A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud providers and many technology giants. […]
20 May OmniVision discloses data breach after 2023 ransomware attack The California-based imaging sensors manufacturer OmniVision is warning of a data breach after the company suffered a Cactus ransomware attack last year. […]
20 May New BiBi Wiper version also destroys the disk partition table A new version of the BiBi Wiper malware is now deleting the disk partition table to make data restoration harder, extending the downtime for targeted victims. […]
20 May QNAP QTS zero-day in Share feature gets public RCE exploit An extensive security audit of QNAP QTS, the operating system for the company’s NAS products, has uncovered fifteen vulnerabilities of varying severity, with eleven remaining unfixed. […]
19 May American Radio Relay League cyberattack takes Logbook of the World offline The American Radio Relay League (ARRL) warns it suffered a cyberattack, which disrupted its IT systems and online operations, including email and the Logbook of the World. […]
19 May CISA warns of hackers exploiting Chrome, EoL D-Link bugs The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three security vulnerabilities to its ‘Known Exploited Vulnerabilities’ catalog, one impacting Google Chrome and two affecting some D-Link routers. […]
18 May Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising A ransomware operation targets Windows system administrators by taking out Google ads to promote fake download sites for Putty and WinSCP. […]