Microsoft has addressed a zero-day in the Windows Common Log File System (CLFS) actively exploited in ransomware attacks. Microsoft has addressed a zero-day vulnerability, tracked as...
Month: April 2023
A “By-Design” flaw in Microsoft Azure can allow storage accounts takeover
A flaw in Microsoft Azure could be exploited by attackers to gain access to storage accounts, perform lateral movements, and even execute remote code. Researchers from...
Yum! Brands, the owner of KFC, Taco Bell and Pizza Hut, discloses data breach
Yum! Brands, the company that owns the KFC, Pizza Hut, and Taco Bell brands, disclosed a data breach after the January ransomware attack. On January 13,...
SAP releases security updates for two critical-severity flaws
Enterprise software vendor SAP has released its April 2023 security updates for several of its products, which includes fixes for two critical-severity vulnerabilities that impact the...
OpenAI launches bug bounty program with rewards up to $20K
AI research company OpenAI announced today the launch of a new bug bounty program to allow registered security researchers to discover vulnerabilities in its product line...
Hacked sites caught spreading malware via fake Chrome updates
Hackers are compromising websites to inject scripts that display fake Google Chrome automatic update errors that distribute malware to unaware visitors. The campaign has been underway...
Windows zero-day vulnerability exploited in ransomware attacks
Microsoft has patched a zero-day vulnerability in the Windows Common Log File System (CLFS), actively exploited by cybercriminals to escalate privileges and deploy Nokoyawa ransomware payloads....
Windows 11 KB5025239 cumulative update released with 25 changes
Microsoft has released the Windows 11 KB5025239 cumulative update for version 22H2 to fix security vulnerabilities and introduce 25 changes, improvements, and bug fixes. KB5025239 is a mandatory...
iPhones hacked via invisible calendar invites to drop QuaDream spyware
Microsoft and Citizen Lab discovered commercial spyware made by an Israel-based company QuaDream used to compromise the iPhones of high-risk individuals using a zero-click exploit named...
Microsoft Patches Zero-Day Bug Exploited by Ransomware Group
Application Security , Attack Surface Management , Cybercrime Attackers Drop Nokoyawa Ransomware; Experts See Increasing Criminal Sophistication Mihir Bagwe (MihirBagwe) , Mathew J. Schwartz (euroinfosec) •...
Cybercrime: Ransomware Hits and Initial Access Listings Grow
Cybercrime , Fraud Management & Cybercrime , Ransomware But If Hydra Takedown Is a Guide, Fresh Disruptions May Take Big Bite Out of Market Mathew J....
Latitude Financial Refuses to Pay Ransom
Fraud Management & Cybercrime , Geo Focus: Australia , Geo-Specific Ongoing Cyberattack Still Causing Service Disruptions Prajeet Nair (@prajeetspeaks) • April 11, 2023 A...
Proposed Health IT Certification Rules Target AI, Privacy
Healthcare , HIPAA/HITECH , Industry Specific HHS Rules Aimed at Beefing Up Health IT Systems, Patient Data Privacy, Security Marianne Kolbasuk McGee (HealthInfoSec) • April 11,...
Feds Call For Certifying, Assessing Veracity of AI Systems
Artificial Intelligence & Machine Learning , Next-Generation Technologies & Secure Development , Standards, Regulations & Compliance Biden Administration Wants to Ensure AI Tech Works as Intended...
Balada Injector Infects Nearly 1 Million WordPress Sites
A malware distribution operation known as Balada Injector has been active since 2017, and it is believed that it has infected over a million WordPress sites....
Two New Emergency Patches from Apple
Apple is backporting two security patches released on Friday. The updated patches address zero-day vulnerabilities on iPhones, iPads, and Macs. Details About the Vulnerabilities The first...
XDR vs MDR: A Comparison of Two Detection and Response Solutions
Ensuring an efficient threat detection and response (D&R) strategy for your organization is vital for every sector of its activity. But growing workloads and limited resources...
SD Worx Shuts Down its UK & Ireland IT Systems Following Cyberattack
Belgian company SD Worx shut down all IT systems for its UK and Ireland services after suffering a cyberattack. The European HR and payroll management company...
Protect your company data with an Ivacy VPN lifetime subscription for $18
on April 11, 2023, 4:39 PM EDT Protect your company data with an Ivacy VPN lifetime subscription for $18 The service previously won the BestVPN.com Fastest...
Microsoft Patches 97 CVEs, Including Zero-Day & Wormable Bugs
Microsoft’s Patch Tuesday security update for April 2023 contains patches for 97 CVEs, including one zero-day bug under active exploit in ransomware attacks, another that’s a reissue of...
Microsoft Azure Shared Key Misconfiguration Could Lead to RCE
Abuse of shared key authorizations, a default on Azure storage accounts, could allow a threat actor to steal higher privileged access tokens, move laterally throughout the...
‘Blatantly Obvious’: Spyware Offered to Cyberattackers via PyPI Python Repository
Researchers have discovered malware peddlers advertising an info-stealer out in the open on the Python Package Index (PyPI) — the official, public repository for the Python...
Where Are the Women? Making Cybersecurity More Inclusive
The cybersecurity threat continues to rage, and much has already been said about the need for concerted, coordinated, and cohesive steps to combat the menace. A...
7 Things Your Ransomware Response Playbook Is Likely Missing
Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. Subscribe Views:...
Attackers Hide RedLine Stealer Behind ChatGPT, Google Bard Facebook Ads
Cybercriminals are posting what appear to be legitimate sponsored ads on hijacked Facebook business and community pages, which promise free downloads of AI chatbots such as ChatGPT...
How Password Managers Can Get Hacked
Over the past few months, several leading password managers have been victims of hacking and data breaches. For instance, LastPass, which experienced a massive breach last...
Israeli Irrigation Water Controllers & Postal Service Breached
On April 5, the Israel Post fell victim to a cyberattack, forcing the mail service to shut down some services. Just two days later, farmers missed...
Samsung Engineers Feed Sensitive Data to ChatGPT, Sparking Workplace AI Warnings
Recent reports about engineers at Samsung Electronics inadvertently leaking sensitive company information via ChatGPT in three separate incidents highlight why policies governing employee use of AI...
Windows 10 KB5025221 and KB5025229 updates released
Microsoft has released the Windows 10 KB5025221 and KB5025229 cumulative updates for versions 22H2, version 21H2, version 21H1, and 1809 to fix problems in the operating...
Microsoft April 2023 Patch Tuesday fixes 1 zero-day, 97 flaws
Today is Microsoft’s April 2023 Patch Tuesday, and security updates fix one actively exploited zero-day vulnerability and a total of 97 flaws. Seven vulnerabilities have been...





























