Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
HTTPS error has been active for weeks, but few seem to have noticed.by Dan Goodin - Apr 17, 2015 http://cdn.arstechnica.net/wp-content/uploads/2015/04/match-password-exposure-640x357.png Tens of millions of Match.com subscribers risk having their site password exposed each time they sign in because the dating site doesn't use HTTPS encryption to protect its login page. The screenshot above was taken Thursday afternoon. Showing a session from the Wireshark packet sniffing program, you can see that this reporter entered "dan.goodin@arstechnica.com" and "secretpassword" into the user name and password fields of the Match.com login page. Full Article
Stream the Webinar on demand HEREIn a dramatic sequence of events, the LockBit ransomware group, known for its #1 spot in ransomware, has showcased a remarkable capacity for resilience and adaptability, despite significant law enforcement actions aimed at dismantling its operations. Recent developments reveal LockBit's prowess, the challenges of combating cybercrime, and the evolving landscape of cybersecurity threats. See our previous post on the takedown of LockBit The FBI's takedown of LockBit came at a critical moment as the group was preparing to release sensitive data stolen from Fulton County, Georgia's government computer systems. This data, allegedly including documents tied to high-profile legal matters, including president Donald Trump and potentially jeopardizing numerous trials. This action underscores the grave risks associated with ransomware attacks and their impact to politics. Despite LockBit's initial setback, the group's vow to regroup and its threats to release
Welcome to Data Privacy Week! This is an annual campaign with the purpose of spreading awareness about online privacy and educating citizens on how to manage their personal information and keep it secure. Today we will discuss the importance of using cold storage password managers as well as the impact of the General Data Protection Regulation (GDPR) on data privacy. Get ready to learn about personal data security, creating and storing strong passwords as well as the negative side-effects of rising GDPR fines. Password Manager Data Breaches At the end of 2022, Norton LifeLock suffered a data breach. Symantec reports that their systems were not directly compromised - it seems as though the attackers used a technique called credential stuffing to try out user credentials for the service in bulk. It is likely that the attacker bought a large amount of stolen user credentials on the Dark Web. By attempting logins with that massive list of credentials, the attacker was successful in comprom
Editor's note: See the latest on Sony pulling the movie The Interview here. by Pierluigi Paganini on November 24th, 2014 The Sony Pictures corporate network was targeted by a major cyber attack that has brought off-line every computer within the company.The corporate network of Sony Pictures is reportedly breached and taken offline, the news was published on TheNextWeb website. Sony Pictures manages distribution of the Sony film and TV productions. The attackers breached the service this morning, meanwhile a thread started on Reddit social news website announcing that every computer in the network was shut down due to a hack. The Reddit thread reported that an image was visible on all employee computers, reading “Hacked by #GOP” and demanding their “requests be met” along with links to leaked data. Below the image displayed on the company computers, the text appeared on the image reads: http://securityaffairs.co/wordpress/w
Exciting news to share with the Webroot Community! PC Mag's Neil Rubenking gave the new release of Webroot SecureAnywhere a rating of "Excellent" AND the prestigious Editor's Choice award! One of our favorite quotes from the article was, "It detected 89% of the samples, a new high detection rate among products tested with this same malware collection. Webroot also has the best removal score among current products, 6.6 points." Read below for the entire story - or click the link below to see it on PCmag.com. Webroot SecureAnywhere AntiVirus (2014) By Neil Rubenking October 14, 2013 Pros Super-fast installation includes full scan. Installed without incident on infested test systems. Scans again and again to eliminate all malware traces. Very good malware removal score. Very accurate antiphishing. Firewall manages outbound Internet access. Can't be terminated by malicious code. Handy tools help undo system changes made by malware. Co
Cyber threats are not just increasing. They are changing shape.The latest OpenText Cybersecurity Threat Report, based on telemetry from tens of millions of endpoints across business and consumer environments, reveals a shift that many organizations are still not fully accounting for.Attackers are moving faster, personalizing more effectively, and increasingly targeting identity over traditional vulnerabilities.Here are the key insights you need to know. 1. Business and Consumer Threats Are Moving in Different DirectionsOne of the clearest signals in this year’s data is that business and consumer environments are no longer moving in parallel. They are diverging.Consumer infection rates surged by over 60% year-over-year, while business environments saw a more modest increase of around 11–12%.At first glance, that might suggest businesses are better protected. They’re not. Attackers are simply being more selective.In consumer environments, scale wins. High-volume campaigns, broad targetin
In the latest tactic targeting Android users, the FakeCalls malware disguises itself as a banking app that impersonates banks when users inevitably call tech support because the app doesn’t work. In other cybersecurity news, Aethon patched hospital robot vulnerabilities that allowed attackers to take control.Italian fashion firm suffers ransomware-based outages Following extensive network outages at the end of 2021, Italian fashion company Ermenegildo Zegna revealed the outages were caused by a ransomware attack. They claim the attack resulted in sensitive files being leaked, as Zegna refused to pay the demanded ransom and choose to instead restore their network from backups. Upwards of 20GB of data was uploaded to the leak site of RansomEXX and has been confirmed as authentic by Zegna officials.Aethon patches critical robot flawsHospital robot vendor Aethon has begun distributing a series of patches for 5 vulnerabilities that could allow attackers to illicitly take control of the robo
CVEs have been published or revised in the Security Update GuideSeptember 4, 2025These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:CVE-2025-54914 Title: Azure Networking Elevation of Privilege Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: September 4, 2025 Last updated: September 4, 2025 Aggregate CVE severity rating: Critical Customer action required: NoCVE-2025-55238 Title: Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: September 4, 2025 Last updated: September 4, 2025 Aggregate CVE severity rating: Critical Customer action required: NoCVE-2025-55241 Title: Azure Entra Elevation of Privilege Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: September 4, 2025 Last updated: September 4, 2025 Aggregate CVE severity r
OpenText is committed to providing you with the latest intelligence and tips to safeguard your digital life, especially during high-risk periods like tax season. Our threat analysts are constantly monitor the ebb and flow of various threats. One trend that has recently caught our attention is the notable spike in malware-infected cracked software, particularly as we enter tax season. This post aims to shed light on the dangers of using cracked software, share best practices for a secure tax season, and highlight our latest intelligence on the surge in cracked tax software threats. The Hidden Cost of Cracked Software Cracked software, often touted as a cost-free way to access games and expensive software, carries a significant risk far beyond legal and ethical concerns. These unauthorized versions are frequently loaded with malware, from trojans and keyloggers to ransomware. The allure of free access blinds users to the dangers, turning their devices into gateways for cybercriminals to
The cyber threat landscape continues to evolve, with ransomware attacks becoming more sophisticated and frequent. In response, the FBI has intensified its efforts to combat these threats, especially focusing on the notorious LockBit ransomware. Contacting the IC3: A Critical Step for VictimsThe FBI strongly urges potential victims of LockBit ransomware to reach out to the Internet Crime Complaint Center (IC3). This step is crucial as it enables the FBI to gather vital information, aiding in the broader fight against cybercriminals. By reporting incidents, victims can help the FBI track and disrupt ransomware operations more effectively. This proactive measure not only assists individual victims but also contributes to the larger goal of dismantling ransomware networks (Federal Bureau of Investigation) Free Ransomware Decryption KeysIn a significant development, the FBI, in collaboration with cybersecurity firms, is offering free decryption keys to ransomware victims - most of which
26th September, 2018 By Jérôme Segura A variant of a remote code execution vulnerability with Internet Explorer’s scripting engine known as CVE-2018-8373 patched last August has been found in the wild. Looking at the IOCs posted by our colleagues at TrendMicro, we recognized the infrastructure serving this exploit. The same static domain has been active since at least early July, and is being redirected to from an adult website injected with a malicious script. In the below traffic capture from August, we were served CVE-2018-8174, which is thought to be from the same author. It is interesting to note that this is not an exploit kit, but rather appears to be a single actor who implemented the available Proof of Concept to distribute his payload, the Quasar Remote Administration Tool (RAT). Full Article.
Listen to the podcast HERE In April 2025, a joint advisory from the NSA, CISA, FBI, and allied international agencies elevated a longstanding cyber evasion technique fast flux to the status of a national security threat. While fast flux isn’t new, its persistent use in high-impact attacks and the defensive blind spots it exposes have prompted this global call to action. What is Fast Flux?At its core, fast flux is a method attackers use to stay one step ahead of defenders. It works by rapidly rotating the IP addresses associated with a single domain, often every few minutes. This dynamic resolution makes malicious infrastructure, such as phishing sites or command-and-control (C2) servers, extremely hard to locate and shut down. There are two variants: single flux, which changes the IPs behind a domain, and double flux, which also rotates the DNS name servers. Both approaches rely on networks of compromised devices, often forming large botnets that serve as proxies for malicious activity
In the latest chapter of the ongoing LockBit saga, international law enforcement agencies have struck back once again, seizing the group's infrastructure and identifying the key figure behind the infamous ransomware operation. This second takedown, building on previous efforts, further demonstrates the determination of global partners to disrupt the cybercriminal network's activities. Newly seized leaksite on the darkwebSee the previous events on this epic feud between LockBit and Law Enfocement The New Takedown: Exposing the Leader Identity Revealed: Dmitry Yuryevich Khoroshev Unmasked Following a thorough investigation, authorities have unsealed an indictment revealing the mastermind behind LockBit: Dmitry Yuryevich Khoroshev, known by aliases like "LockBitSupp" and "putinkrab." This Russian national has been charged with multiple counts of fraud, extortion, and intentional damage to protected computers. Renewed Sanctions and Rewards The U.S. Department of the Treasury has imposed
Following an investigation, German law enforcement seized the servers of one of the largest dark web marketplaces in the world that earned an estimated $1.7 billion in revenue 2020. In other cybersecurity news, Cash App suffered a data breach and are contacting 8.2 million customers.Cash App reveals major data breachBlock, Inc., the parent company for Cash App, has begun contacting nearly 8.2 million customers following a data breach that perpetuated by a disgruntled former employee. The former employee accessed internal systems and downloaded a financial reports containing customer information during the December 10 breach. Along with contacting affected customers, the officials for Cash App are working with law enforcement to improve security measures and determine the extent of unauthorized intrusion.Explicit content displayed on electric charging stationsSeveral electric vehicle charging stations around the Isle of Wight, UK were hacked to display pornographic content. Officials ar
CVEs have been published or revised in the Security Update GuideAugust 6, 2025These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:CVE-2025-53786 Title: Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: August 6, 2025 Last updated: August 6, 2025 Aggregate CVE severity rating: ImportantCustomer action required: Yes
Emotet is back from the dead, with a new version utilizing their tried-and-true method of loading a variety of payloads, including malicious Office files, ZIPS and other silent methods. In other cybersecurity news, a new banking trojan named Sharkbot has been infecting Android devices across the world.Fake threat warnings sent from hacked FBI email systemA recent email spam campaign is spreading fake threat warnings to thousands of recipients, all coming from a legitimate FBI email address. The phony emails claim to have identified a threat actor operating on the recipient’s device and that they have already stolen information about the victim. It’s believed that an official FBI email server was compromised as the emails came from an internal domain. Luckily, it seems the machine in question was not connected to the main network so the threat actors didn’t actually access any sensitive information.Trickbot used for return of EmotetResearchers have been monitoring the return of the infa
A critical vulnerability (CVE-2025-49704, CVE-2025-49706 CVSS 9.8) in Microsoft SharePoint is now being actively exploited worldwide. Attackers are using it to bypass authentication, drop web shells, and launch ransomware and data theft campaigns.This is one of the most severe Microsoft flaws of the year and proof-of-concept exploit code is public, and threat actors are scanning for vulnerable servers at scale.OpenText Cybersecurity is actively monitoring this campaign and helping partners and clients respond with multi-layered protection. What’s HappeningCVE-2025-2371 is an authentication bypass vulnerability in Microsoft SharePoint. Successful exploitation allows unauthenticated attackers to: Access sensitive SharePoint resources Upload web shells or malicious scripts Execute arbitrary code remotely Within days of Microsoft’s disclosure in the July Patch Tuesday, attackers began scanning and exploiting vulnerable servers. The vulnerability is now on CISA’s Known Exploited Vulner
Almost six months after a security researcher discovered and reported two critical vulnerabilities, HP has released patches that resolve both exploits that could potentially allow attackers to perform kernel-level file execution. Even with the best of intentions, this vulnerability allows driver and BIOS changes to more than 200 different products. This could result in any number of different malicious actions being taken. Officials for HP are recommending that anyone with an affected device should install the patches as they become available.Ransomware shuts down AGCO as planting season beginsLate last week, officials for one of the largest agricultural equipment manufacturers, AGCO, revealed that several of their locations had shut down temporarily due to a ransomware attack. While they did not specify if customer information had been compromised, they are currently investigating the overall extent of the intrusion and isolating the compromised devices to limit any further spread. Sp
One of the busiest ports in the world recently reported that they’ve experienced a sharp increase in the number of cyberattacks targeting them over the last two years. In that time they’ve averaged 40 attacks per month. In other cybersecurity news, T-Mobile reached a $350 million settlement after their 2021 breach.Hackers breach decentralized music platformOver the weekend, an unknown number of hackers were able to breach the internal servers of Audius, a decentralized music platform, and steal several million dollars' worth of AUDIO blockchain tokens. The hackers exploited a bug within the initialization code that allowed them to transfer over 18 million tokens from Audius’s community treasury into a privately owned blockchain wallet. The stolen tokens were later traded through Uniswap for a significantly lower value and then passed through a currency mixing service to make any additional tracking even more difficult.T-Mobile reaches settlement in 2021 data breachFollowing the 2021 da
Financial debt collector Professional Finance Company suffered a recent ransomware attack that compromised sensitive patient records for 1.9 million people. In other cybersecurity news, US Dept of Justice successfully tracked and retrieved crypto ransomware payments made to Maui ransomware.Knauf Group suffers ransomware attackNearing the end of June, IT staff for the Germany-based Knauf Group began investigating a security incident that forced nearly every system offline and culminated in a ransom demand by the Black Basta ransomware organization. Though it hasn’t been confirmed by Knauf officials, the Black Basta group has listed Knauf as a victim on their leak site, along with a significant portion of the allegedly stolen data. The Black Basta group has only been in operation since April of this year, but by using the Ransomware-as-a-Service model, they have made their presence known.Law enforcement successfully retrieves ransom paymentsMore than a year after two healthcare organizat
The trial just concluded for a Californian accused of orchestrating a phishing campaign that defrauded the US Department of Defense of $23.5 million. In other cybersecurity news, Kellogg Community College is the latest higher education institution to fall victim to a cyberattack.Nordic Hotels suffers data breachOfficials for Nordic Hotels & Resorts in Finland revealed that their booking systems were compromised during a February security incident and may have affected over 20,000 former guests who booked on the the hotel’s websites. The incident took place over several days in February, though it wasn’t identified or patched by IT staff until April 9. It is believed that 5 total hotels were affected, though officials have confirmed that only guest contact information was accessed, as the booking system didn’t store financial data.Cyberattack takes down German car rental providerIT staff for German-based car rental provider Sixt made the emergency decision to shut down most of their
July 2025 Security UpdatesThis release consists of the following 130 Microsoft CVEs:Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?Service Fabric CVE-2025-21195Windows Kernel CVE-2025-26636Remote Desktop Client CVE-2025-33054Windows Visual Basic Scripting CVE-2025-47159Microsoft Intune CVE-2025-47178Virtual Hard Disk (VHDX) CVE-2025-47971Microsoft Input Method Editor (IME) CVE-2025-47972Virtual Hard Disk (VHDX) CVE-2025-47973Windows SSDP Service CVE-2025-47975Windows SSDP Service CVE-2025-47976Windows Kerberos CVE-2025-47978Windows Imaging Component CVE-2025-47980Windows SPNEGO Extended Negotiation CVE-2025-47981Windows Storage VSP Driver CVE-2025-47982Windows GDI CVE-2025-47984Windows Event Tracing CVE-2025-47985Universal Print Management Service CVE-2025-47986Windows Cred SSProvider Protocol CVE-2025-47987Azure Monitor Agent CVE-2025-47988Microsoft Input Method Editor (IME) CVE-2025-47991Microsoft PC Manager CVE-2025-47993Microsoft Office CVE-2025-47994W
Recently, officials from the telecommunications giant AT&T revealed that they had fallen victim to a data breach in March, which subsequently exposed extremely sensitive information for 73 million current and former customers. Following the discovery of the breach, a threat actor posted the stolen data on a dark web forum, stating that the trove included social security numbers, full names, and payment card details.Ransomware targets Jackson County, MissouriAt the beginning of the week, staff at the Jackson County government offices in Missouri discovered several of their internal systems had been impacted by a ransomware attack. The incident forced officials to close all affected government offices until the investigation and remediation efforts had been completed. The system outages occurred on the same day as local district elections took place, though the actual election systems throughout Missouri were unaffected.Chinese shopping platform leaks data on 1.3 million customersHac
Webroot revealed the results of the 2019 Webroot Threat Report, showcasing that while tried-and-true attack methods are still going strong, new threats emerge daily, and new vectors are being tested by cybercriminals. The report is derived from metrics captured and analyzed by Webroot's advanced, cloud-based machine learning architecture: the Webroot® Platform. Explore the 2019 Webroot Threat Report Notable Findings: 40 percent of malicious URLs were found on good domains. Legitimate websites are frequently compromised to host malicious content. To protect users, cybersecurity solutions need URL-level visibility or, when unavailable, domain-level metrics, that accurately represent the dangers. Home user devices are more than twice as likely to get infected as business devices. Sixty-eight percent of infections are seen on consumer endpoints, versus 32 percent on business endpoints. Phishing attacks increased 36 percent, with the number of phishing sites growing 220 percent over th
Stemming from a security incident first identified in July, customer identification data from rental contracts over the last 8 months were leaked after a data breach at U-Haul. In other cybersecurity news, WordPress users utilizing the WPGateway plugin were vulnerable to a zero-day attack that allowed for the adding of unauthorized administrators to WordPress sites.Lorenz ransomware exploits VOIP vulnerabilityActors for the Lorenz ransomware group have begun exploiting a serious vulnerability found in VOIP phone devices for enterprise customers, that allows the group to illicitly access the victim organization’s entire network. Lorenz has been targeting Mitel appliances that are connected to an internal network and use it as the initial attack vector before starting the encryption process. While a patch for this particular vulnerability was developed and distributed back in June, many organizations (including governments) have yet to actually implement the fix and are leaving themselve
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.