Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
Exploiting (Almost) Every Antivirus Software April 20, 2020 - by RACK911 Labs Summary Antivirus software is supposed to protect you from malicious threats, but what if that protection could be silently disabled before a threat can even be neutralized? What if that protection could be manipulated to perform certain file operations that would allow the operating system to be compromised or simply rendered unusable by an attacker? RACK911 Labs has come up with a unique but simple method of using directory junctions (Windows) and symlinks (macOS & Linux) to turn almost every antivirus software into self-destructive tools. Method of Exploitation Most antivirus software works in a similar fashion: When an unknown file is saved to the hard drive, the antivirus software will usually perform a “real time scan” either instantly or within a couple of minutes. If the unknown file is determined to be a suspected threat, the file will then be automatically quarantined and moved to a se
Last week, officials for the City of Dallas were forced to take many of their crucial IT services offline after their security team discovered the beginnings of a ransomware attack. The incident, which has caused the entire Dallas judicial system to delay any proceedings until further notice, has been confirmed as an attack by the Royal Ransomware group after ransom notes started printing from all network-connected printers. Ransomware attacks on local governments have been constantly on the rise in recent years and have targeted over 30 cities in 2023 alone.San Bernadino County pays $1.1 million ransomA month after first identifying the ransomware attack on their systems, the San Bernadino County Sheriff’s Office has agreed to pay their portion of the $1.1million ransom to restore their files and resume normal operations. While the incident did not compromise any sensitive information on employees or citizens, the interruptions to the Sheriff Office’s operations have caused significan
The Queensland University of Technology (QUT) is just the latest higher education institution to suffer a ransomware attack. With many of their systems forced to shut down after the attack, they’ve warned students and staff that they might face disruptions during the beginning of the semester. In other cybersecurity news, LockBit made headlines for attacks against the Port of Lisbon and locomotive giant Wabtec Corporation.Queensland University of Technology suffers ransomware attackAt the starting of the new year, officials for the Queensland University of Technology (QUT) in Australia revealed that their computer systems had been the victim of a ransomware attack, which had forced the institution to shut down many of their systems. While the university plans to re-open this week, they have alerted students and staff that disruptions to normal operations are to be expected in the following weeks. The Royal ransomware group has claimed responsibility for the attack and have already begu
UK car dealer Pendragon Group faces a hefty $60 million ransom following an attack from the LockBit group. An investigation after the attack found that only 5% of the impacted database was leaked. In other cybersecurity news, Microsoft warned the education sector to brace for continued cyberattacks.Indian power company has data leaked after ransomware attackFollowing a Hive ransomware attack earlier this month, the Indian power company Tata Power has confirmed that the data stolen during the attack has been posted to a leak site. It is believed that the attack began on October 3rd, but Tata Power staff didn’t report any unusual activity for 11 more days, though it may impact a significant amount of sensitive employee data. The Hive ransomware group have been extremely active since their origination in Mid-2021, and their affiliates are known to attack upwards of three different companies every day.Ticketing agent suffers multi-year data breachOfficials for the international ticket prov
January 17th, 2018 By Uladzislau Murashka Search engines are a treasure trove of valuable sensitive information, which hackers can use for their cyber-attacks. Good news: so can penetration testers. From a penetration tester’s point of view, all search engines can be largely divided into pen test-specific and commonly-used. The article will cover three search engines that my counterparts and I widely use as penetration testing tools. These are Google (the commonly-used) and two pen test-specific ones: Shodan and Censys. Google Penetration testing engineers employ Google advanced search operators for Google dork queries (or simply Google dorks). These are search strings with the following syntax: operator:search term. Further, you’ll find the list of the most useful operators for pen testers: Full Article.
News Corp revealed that employee data – at the least – was stolen from their internal servers stemming from illicit access that lasted almost 2 full years before being discovered. In other cybersecurity news, the U.S. Marshall service suffered a data breach with personal and law enforcement data compromised.Ransomware causes Dish Network outagesLate last week, officials for Dish Network confirmed that the service outages they were experiencing were the result of a ransomware attack that compromised their websites and internal networks. The investigation has also revealed that some extremely sensitive information was exfiltrated during the incident, though it is unclear if it belongs to employees, customers, or both. The actors behind this attack are still unclear, though it does show signs of being a Black Basta operation, as they appear to have breached the Boost Mobile network shortly before the Dish Network attack. Dutch police arrest cyber-extortion groupDutch police have recently
The U.S. Federal Trade Commission issued their fine against CafePress after a years-long investigation of the 2019 data breach affecting 23 million customers. In other cybersecurity news, the Lithuanian government’s computer networks faced DDos attacks following the passing of a tax on Russian goods.Ukrainian cybercrime force arrests phishing group membersOfficials for the Ukrainian Cybercrime Force arrested nine members of a phishing group responsible for operating over 400 phishing sites and stealing millions from victims. With the assistance of a local Ukrainian bank, law enforcement tracked stolen funds and perform multiple raids on residences to find evidence of the group’s activities. If convicted of fraud and interference with computers, individuals face up to 15 years in prison for their actions.Wiltshire Farm Foods suffers cyberattackOne of the UK’s largest frozen food producers, Wiltshire Farm Foods, has fallen victim to a possible ransomware attack though the company has yet
Hackers have recently exploited a zero-day vulnerability within the Ivanti endpoint management software, that allowed for remote code execution while bypassing the need for authentication to highly sensitive Norwegian government systems. It is believed that this vulnerability was first identified during the attack on the Norwegian government, and has since been patched by Ivanti, though the overall extent of this incident is still under investigation.Multiple ransomware groups claim Estee Lauder breachOfficials for the cosmetics giant, Estee Lauder, have confirmed that their internal network had been infiltrated by some unauthorized actors, resulting in a significant data breach. To make matters worse, both the Clop ransomware group and the Alphv/BlackCat ransomware group are both claiming responsibility for the attack and both publishing Estee Lauder data troves to their respective leak sites. At this point in the investigation, it is still unclear if this attack was a part of the MOV
Following a data breach that exposed the personal information of 522 million Facebook users, Ireland’s Data Protection Commission (DPC) issued a €265 million fine alongside a list of security measures the company must implement. In other cybersecurity news, Trigona ransomware has emerged as a new worldwide threat.Australia to increase fines for data breachesThe Australian Parliament will increase fines for companies who have suffered a data breach, up to AU$50 million. The current fine for a data breach of an Australian company is a mere AU$2.2 million, which is a negligible amount to many of the companies who have suffered a data leak. This new bill arrives in the wake of a long series of cyberattacks on Australian companies, which have shaken the country and exposed extremely sensitive information on ~20 million Australian citizens.Ransomware attack in Virginia Officials for Southampton County, Virginia have recently revealed that one of their servers had been encrypted during a pote
Hackers downloaded full backups of all posts and messages from over 400,000 accounts on the Kodi media forum, forcing staff to shut down the forum as they work to rebuild it on a new server. In other cybersecurity news, the U.K. Criminal Records Office suffered a significant data breach.Money Message ransomware targets computer vendor MSILate last week, officials for the Taiwanese computer vendor, MSI, confirmed that they had been in negotiations with the Money Message ransomware group to stop them from leaking 1.5TB of stolen data. MSI was given one week to pay the $4 million ransom before the full trove of stolen data is added to the Money Message leak site, which currently only has screenshots of the data posted to the site. While the company is assuring customers that they will not notice any interruptions to their services, they also have yet to reveal the extent of the threat actor’s intrusion or what customer information may have been accessed.UK Criminal Records Office suffers
California based Community Medical Centers discovered the illicit access of one of their databases compromising the data of thousands of patients. In other cybersecurity news, South Carolina schools were targeted by a cyberattack leaving faculty struggling to perform their needed tasks.U.K. Labour Party loses member data in breachThe U.K.’s Labour Party suffered a data breach affecting an unknown number of party members. A supposed ransomware attack on the party’s website is the suspected culprit behind the breach, with the breach possibly compromising extremely sensitive information on members and affiliates of the party. This would be the second data-related cyberattack that has targeted the Labour Party in just the last year, with the first occurring in May of 2020.Cyberattack strikes hundreds of South Carolina school computersAn October cyberattack targeted over 800 computers belonging to the Colleton County School District in South Carolina, leaving employees struggling to perform
CVEs have been published or revised in the Security Update Guide June 4, 2025 These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide: CVE-2025-21174 Title: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Version: 1.3 Reason for revision: In the Security Updates table, corrected the Download and Article links for Windows Server 2012 R2 and Windows Server 2012 R2 (Server Core installation). This is an informational change only. Originally released: April 8, 2025 Last updated: May 30, 2025 Aggregate CVE severity rating: Important Customer action required: Yes CVE-2025-21204 Title: Windows Process Activation Elevation of Privilege Vulnerability Version: 2.2 Reason for revision: Added an FAQ to exp
Late last week, several government organizations in Palermo, Italy were forced to take their computer systems offline after discovering evidence of a cyberattack. In the days following the incident, IT staff have yet to restore all the systems to normal functionality, leaving both citizens and tourists without access to vital municipal services. Officials in Palermo have yet to confirm the exact nature of the attack. However, most of the precautions taken indicate it was a ransomware attack.Law enforcement shuts down illicit marketplaceWith the combined efforts of several law enforcement agencies around the world, the SSNDOB Marketplace, one of the largest illicit marketplace website groups, has been shut down. The marketplace operated by selling stolen social security numbers and other sensitive personal data of 24 million American residents, netting over $19 million in profits. The U.S. Justice Department released a statement indicating no arrests were made during the investigation,
So I've noticed in the past that Webroot did not feature at all on AV-Test's site and was surprised to see it in a more recent release marked as dead last in protection score. see: https://www.av-test.org/en/antivirus/business-windows-client/ I am a business endpoint user and seeing results like this, even if the testing methodology was incorrect or something, makes me a little worried. I feel like webroot needs to get in touch with them and see what is going on because this is an important metric when making purchasing decisions. How else can anyone make an informed decision without some kind of comparison testing?
The Conti ransomware group has been slowly posting stolen information following a data breach of the Parker-Hannifin Corporation, an engineering firm with strong ties to Lockheed Martin. In other cyber security news, 200+ apps on the Google Play store have been found to distribute infostealer Facestealer.Infostealer found in 200+ Android appsResearchers have been tracking more than 200 Android apps, currently circulating on the Google Play store, that are being used to distribute the known infostealer Facestealer. This spyware, once installed on a device, can quickly begin extracting login credentials and other data that is commonly stored directly to the device’s memory. In the year since first being spotted, Facestealer has disguised itself as a variety of different services, including VPNs, cameras and cryptocurrency miners, though none of these apps performed the desired tasks.Conti ransomware targets Parker-Hannifin Corp.Nearly 2 months after a security incident at the engineering
Webroot is sponsoring a number of events across EMEA during September. Hope to see you at one of them! 5th – 6th September CRN European Channel Leadership Forum Location: London, United Kingdom Webroot is a Showcase sponsor of the European Channel Leadership Forum taking place on the 5th and 6th of September in London. Webroot will have an exhibiting space and a speaking slot on the 6th of September during the event. Click here for full details. 11th – 12th September Channel Live Location: Birmingham, United Kingdom Webroot is an exhibitor at Channel Live 2018 on the 11th and 12th of September in Birmingham. Look out for the Webroot team at stand 718. Click here for full details. 11th & 13th September Webroot Product Training Locations: Stockholm, Sweden – 11th September Amsterdam, Netherlands – 13th September Join fellow Webroot partners at one of our upcoming product training events in Stockholm and Amsterdam in Septembe
Over the weekend, the threat actors behind the Daixin Team ransomware group posted stolen data belonging to Omni Hotels & Resorts to their dark web leak site, thus claiming responsibility for the cyberattack that forced Omni staff to take many IT systems offline. It is believed that the resulting data breach leaked sensitive customer information dating back to 2017 and includes over 3.5 million booking records.Researchers find unsecured taxi passenger databaseSecurity researchers have recently discovered a database belonging to the Dublin-based taxi management provider, iCabbi, which was publicly exposed to the internet with no authentication. The database included 22,745 records and exposed highly personal information for over 300,000 customers from Ireland and the UK. Fortunately, staff for iCabbi worked quickly to remove the exposed data after being notified of the incident.Credential stuffing attacks compromise 576,000 Roku accountsIn the last month, officials for Roku identifi
Security advisories were published or revised in Microsoft Security Update Guide November 4, 2025 The following security advisories (ADVs) were recently published or revised in the Microsoft Security Update Guide: ADV25258359 Title: Update Azure MCP Samples to Address OAuth Vulnerabilities Version 1 Originally released: November 4, 2025 Last updated: November 4, 2025
Over the weekend, staff for the IT service provider Bitmarck were forced to take their core operations offline after discovering a cybersecurity intrusion. While Bitmarck was able to quickly identify the incident and take their systems offline to prevent additional harm, it still has not been determined as to when their operations will return to normal, or if any sensitive information was compromised. Because Bitmarck provides IT services for the healthcare industry, officials are taking extra precautions in their investigation to determine the overall extent of the attack.Ransomware causes outages at AmericoldOne of the largest cold storage and shipping companies, Americold, was recently targeted by a suspected ransomware attack that has caused significant outages across their supply chain. Officials for Americold were forced to take potions of their network offline after identifying some unauthorized activity and are expecting the outages to persist for at least a week. During this o
Officials for the Taiwanese networking equipment maker, D-Link, have recently confirmed a data breach from the beginning of the month that has compromised a significant amount of personally identifiable information (PII) for both customers and employees. The hackers behind this attack have published the stolen data to BreachForums, with a sale price of only $500, and claim to have data on government officials as well as the source code for D-View (D-Link's network management software). D-Link staff claim the stolen data is outdated and limited to a testing environment that housed an older version of D-View, though this has yet to be confirmed.ALPHV/BlackCat ransomware targets Morrison County HospitalLate last week, the threat actors behind the ALPHV/BlackCat ransomware group posted a 5TB data trove of extremely sensitive patient information from Morrison County Hospital (MCH) in Illinois to their dark web leak site. After attempting to negotiate with MCH officials, the threat actors be
CVEs have been published or revised in the Security Update GuideMarch 5, 2026These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:CVE-2026-21536Title: Microsoft Devices Pricing Program Remote Code Execution Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: March 5, 2026 Last updated: March 5, 2026 Aggregate CVE severity rating: Critical Customer action required: NoCVE-2026-23651Title: Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: March 5, 2026 Last updated: March 5, 2026 Aggregate CVE severity rating: Critical Customer action required: NoCVE-2026-26122Title: Microsoft ACI Confidential Containers Information Disclosure Vulnerability Version: 1.0 Reason for revision: Information published. Originally released: March 5, 2026 Last updated: March 5, 2026 Aggregate CVE severi
Flagstar Bank has just confirmed the number of customers affected by a December 2021 data breach after concluding their 6-month investigation. In other cybersecurity news, Fancy Bear phishing attacks have been targeting Ukrainian organizations.BRATA Android malware upgrades to APT category of threatWhat started off as an Android-based info stealer has recently been spotted with new techniques and attack patterns that have updated BRATA from localized malware into a full Advanced Persistent Threat (APT). BRATA reached this new category by using new techniques to remain hidden on infected systems for an increased amount of time to continue gathering additional information, and now includes new phishing techniques and a secondary payload that communicates with a C&C server. The most recent campaigns by BRATA have been highly targeted and focus on a single financial institution at a time, and only moving onto the next bank once their malicious activities have been identified.Fancy Bear
Adobe Flash Player 27.0.0.183 Release notes: http://www.adobe.com/support/documentation/en/flashplayer/releasenotes.html Be sure to uncheck any unwanted add-ons if offered. Although Adobe suggests downloading the update from the Adobe Flash Player Download Center, that link includes a pre-checked option to install unnecessary extras, such as McAfee Scan Plus or Google Drive. If you use the download center, uncheck any unnecessary extras. Internet Explorer - ActiveX http://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ax.exe http://fpdownload.adobe.com/get/flashplayer/pdc/27.0.0.183/install_flash_player_ax.exe Firefox, Safari, Opera (Presto) - NPAPI http://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player.exe http://fpdownload.adobe.com/get/flashplayer/pdc/27.0.0.183/install_flash_player.exe Opera (Blink) and Chromium - PPAPI http://fpdownload.macromedia.com/pub/flashplayer/la
Right after we had a funeral for Emotet in our Nastiest Malware, Emotet has decided to come back from the dead. Here are the new spam campaigns as outlined by Bleeping ComputerBy Lawrence AbramsThe Emotet malware kicked into action yesterday after a ten-month hiatus with multiple spam campaigns delivering malicious documents to mailboxes worldwide.Emotet is a malware infection that is distributed through spam campaigns with malicious attachments. If a user opens the attachment, malicious macros or JavaScript will download the Emotet DLL and load it into memory using PowerShell.Once loaded, the malware will search for and steal emails to use in future spam campaigns and drop additional payloads such as TrickBot or Qbot that commonly lead to ransomware infections.Emotet spamming begins againLast night, cybersecurity researcher Brad Duncan published a SANS Handler Diary on how the Emotet botnet had begun spamming multiple email campaigns to infect devices with the Emotet malware.According
Just days after the global law enforcement takedown of LockBit ransomware was revealed, the threat actors behind the group have confirmed that they re-established a victim data leak site and dismissed a sizable portion of the information that the FBI released. As law enforcement attempts to further crack down on the global ransomware epidemic, the threat actors continue to learn from the takedowns and are improving their tactics to avoid future incidents.See our writeup of the incident here: Insomniac Games employees affected by data breachOfficials for Insomniac Games have recently begun contacting current and former employees regarding a data breach from last November by the Rhysida ransomware group, who failed in their ransom negotiations. The stolen data included sensitive intellectual property and employee data, which has since been leaked and sold on their dark web site. Along with creating a call center for employees with questions regarding the incident, they have also offered
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.