"Microsoft Links Scattered Spider Hackers to Qilin Ransomware Attacks"

"Microsoft Links Scattered Spider Hackers to Qilin Ransomware Attacks"

According to Microsoft, the "Scattered Spider" cybercrime gang has added "Qilin" ransomware to its arsenal. ​The Qilin ransomware operation that Scattered Spider just joined emerged in August 2022 under the name "Agenda," but was rebranded as Qilin just one month later. The Qilin gang has hit about 130 companies, based on its dark web leak site. This article continues to discuss Scattered Spider hackers' use of Qilin ransomware.

Submitted by grigby1 CPVI on

"Global Police Swoop on Black Axe Cybercrime Syndicate"

"Global Police Swoop on Black Axe Cybercrime Syndicate"

Interpol has defeated several West African cybercriminal groups, including the "Black Axe" syndicate. "Operation Jackal III" took place from April 10 to July 3 in 21 countries on five continents, resulting in 300 arrests and $3m in asset seizures. Police blocked over 720 bank accounts and identified 400 suspects. Black Axe may have operated for decades. It has made a lot of money in romance fraud, Business Email Compromise (BEC), and other financial crimes. This article continues to discuss the success of Operation Jackal III.

Submitted by grigby1 CPVI on

"Apache HugeGraph Vulnerability Exploited in Wild"

"Apache HugeGraph Vulnerability Exploited in Wild"

Attackers are exploiting a patched Apache HugeGraph vulnerability. Apache HugeGraph is an open source graph database system used to build applications based on graph databases. Its developers disclosed a flaw in HugeGraph-Server in April that enables remote command execution. The vulnerability was patched with the release of version 1.3.0. However, the Shadowserver Foundation reported attempts to exploit the flaw in the wild, with attacks originating from eight IP addresses. This article continues to discuss the exploitation of a recently patched Apache HugeGraph vulnerability.

Submitted by grigby1 CPVI on

"Chrome 126 Updates Patch High-Severity Vulnerabilities"

"Chrome 126 Updates Patch High-Severity Vulnerabilities"

Google recently announced security updates for Chrome 126 that address ten vulnerabilities, including eight high-severity bugs reported by external researchers.  Google noted that the new Chrome 126 release resolves an inappropriate implementation flaw in V8, a type confusion in V8, use-after-free bugs in Screen Capture, Media Stream, Audio, and Navigation, a race condition in DevTools, and an out-of-bounds memory access in V8.  Google says it paid out $10,000 and $7,000 bug bounty rewards for the inappropriate implementation and type confusion vulnerabilities in V8.

Submitted by Adam Ekwall on

League of Women Voters of Carroll County Event: Featuring Queens of Code Talk

"Our event commemorates America’s passage of the 19th Constitutional Amendment granting women the right to vote. The League of Women voters has been nonpartisan since its founding in 1920, so the event is titled Celebrating Women’s Equality Day - A Nonpartisan Gathering.

"MNGI Digestive Health Data Breach Impacts 765,000 Individuals"

"MNGI Digestive Health Data Breach Impacts 765,000 Individuals"

MNGI Digestive Health has started notifying over 765,000 individuals that their personal information was compromised in an August 2023 data breach.  The incident occurred on August 20, 2023, but it took MNGI almost one year to determine that personal and protected health information was accessed.  MGNI says that the potentially compromised information includes names, dates of birth, Social Security numbers, driver’s licenses and state ID numbers, passport numbers, biometric data, health insurance information, and medical information.

Submitted by Adam Ekwall on

"Ransomware Attack Disrupts Bassett Furniture Manufacturing Facilities"

"Ransomware Attack Disrupts Bassett Furniture Manufacturing Facilities"

Virginia-based furniture manufacturer and retailer Bassett Furniture has recently announced that it was targeted in a ransomware attack that caused significant disruptions, including in the company's manufacturing facilities. The company detected unauthorized access to its IT systems on July 10. Bassett Furniture said the threat actor disrupted its business operations by encrypting "some data files." The company noted that retail stores and the e-commerce platform are open, and customers can place orders and purchase available merchandise; however, the company's ability to fu

Submitted by Adam Ekwall on

"Paris 2024 Olympics Face Escalating Cyber Threats"

"Paris 2024 Olympics Face Escalating Cyber Threats"

Cybersecurity analysts at FortiGuard Labs have warned of a significant uptick in cyber threats targeting the upcoming Paris 2024 Olympics. The researchers noted that cybercriminals have been intensifying their efforts for more than a year, gearing up with sophisticated tools and tactics aimed at exploiting the global event.  The researchers said there was a substantial surge in darknet activity, with an 80-90% increase observed between the second half of 2023 and the first half of 2024.  The researchers say they saw a huge increase in phishing kits tailored for the Olympics.

Submitted by Adam Ekwall on

"Email Addresses of 15 million Trello Users Leaked on Hacking Forum"

"Email Addresses of 15 million Trello Users Leaked on Hacking Forum"

A threat actor recently released over 15 million email addresses associated with Trello accounts that were collected using an unsecured API in January.  Trello is an online project management tool owned by Atlassian.  Businesses commonly use it to organize data and tasks into boards, cards, and lists.  In January, a threat actor known as "emo" was selling profiles for 15,115,516 Trello members on a popular hacking forum.  The leaked data includes email addresses and public Trello account information, including the user's full name.

Submitted by Adam Ekwall on

"Are Mass Layoffs and Data Breaches Connected? Binghamton University Researchers Have a Theory"

"Are Mass Layoffs and Data Breaches Connected? Binghamton University Researchers Have a Theory"

A research team led by faculty from Binghamton University's School of Management (SOM), in collaboration with scholars from Vietnam National University and Liverpool John Moores University, has been investigating whether there is a link between mass layoffs and data breaches. According to the study, layoffs increase stress or job insecurity for employees, making them more likely to engage in risky behaviors that leave their company vulnerable to data breaches. This article continues to discuss findings from the study "The Impacts of Layoffs Announcement on Cybersecurity Breaches."

Submitted by grigby1 CPVI on
Subscribe to