News

News
A free decryptor for past REvil ransomware victims was released. AT&T lost $200 million to an illegal phone unlocking scheme. Mirai Botnet started exploiting the OMIGOD flaw. All this, and more, in this week’s edition of Cybersecurity Weekly.

September 20, 2021
Sam Fay
News
Linux Cobalt Strike beacon is being used in ongoing attacks. REvil ransomware is back in full attack mode and leaking data. 7 signs your IT training sucks. All this, and more, in this week’s edition of Cybersecurity Weekly.

September 15, 2021
Sam Fay
News
An NFT collector was tricked into buying fake Banksy. An Atlassian Confluence flaw is being actively exploited to install cryptominers. 8 must-ask security analyst interview questions. All this, and more, in this week’s edition of Cybersecurity Weekly.

September 07, 2021
Sam Fay
News
Widespread phishing attacks are using open redirects. LockFile ransomware bypasses protection using intermittent file encryption. Ragnarok ransomware gang shuts shop and releases decryption key for free. All this, and more, in this week’s edition of Cybersecurity Weekly.

September 01, 2021
Sam Fay
News
A Geico breach exposed customers' driver's license numbers. Hackers are using Morse code in phishing attacks to evade detection. How CMMC can help counter current cyberattacks. All this, and more, in this week’s edition of Cybersecurity Weekly.

August 17, 2021
Sam Fay
News
Explore seven cyberattacks that shook the world in 2021, including Colonial, Facebook, and Microsoft Exchange.

August 10, 2021
Susan Morrow
News
Microsoft warns of LemonDuck malware. Kaseya obtains a universal decryptor for REvil ransomware. The MacOS malware XCSSET now targets Google Chrome. All this, and more, in this week’s edition of Cybersecurity Weekly.

July 27, 2021
Sam Fay
News
A Safari zero-day was used in a malicious LinkedIn campaign. A researcher finds another unpatched Windows printer spooler vulnerability. A low-risk iOS Wi-Fi naming bug can hack iPhones remotely. All this, and more, in this week’s edition of Cybersecurity Weekly.

July 22, 2021
Sam Fay
News
Kaseya left their customer portal vulnerable to a 2015 flaw. Microsoft releases successful PrintNightmare security updates. An org’s reaction to social engineering is indicative of their cybersecurity culture. All this, and more, in this week’s edition of Cybersecurity Weekly.

July 13, 2021
Sam Fay
News
Ransomware gangs are now creating websites to recruit affiliates. A Cisco ASA flaw is under attack after a PoC exploit was posted online. 30 million devices are at risk from Dell SupportAssist RCE vulnerabilities. All this, and more, in this week’s edition of Cybersecurity Weekly.

June 29, 2021
Sam Fay- Reduce security events
- Reinforce cyber secure behaviors
- Strengthen cybersecurity culture at your organization
In this series
- Canada Flipper Zero ban and new RustDoor macOS malware
- AnyDesk hack and iPhone patched kernel flaw
- Tesla Pwn2Own hacks and iOS push alerts abuse
- TeamViewer breach and Atlassian Jira outage
- Moscow ISP revenge hack and Microsoft Sharepoint bug warning
- X verified accounts hack and SpectralBlur macOS malware
- CISA default password alert and SOHO KV-botnet campaign
- New 5G modem flaws and Apple’s data breach report
- Staples cyberattack, Agent Racoon backdoor and other news
- British Library ransomware attack, Windows fingerprint authentication bypass
- Samsung UK data breach and ransomware actor’s SEC complaint
- ICBC ransomware attack and ChatGPT outage
- Boeing Lockbit ransomware attack, Apple’s vulnerability and WhatsApp mods spyware
- Octo Tempest hacking group and new iLeakage attack
- Okta support system breach and Google Ads fake KeePass campaign
- Skype DarkGate malware, Shadow PC breach and AvosLocker ransomware warning
- 23andMe data theft, MGM’s $100M ransomware loss and the Azure VM breach
- Malicious Bing Chat ads and FBI’s dual ransomware warning
- T-Mobile app glitch and fake Booking.com pages
- Airbus data leak, Cisco Webex ad malware and €345 million TikTok fine
- New Apple iMessage exploit and CISA’s Apache RocketMQ warning
- Forever 21 data breach and Android BadBazaar espionage
- Duolingo data leak and the Met Police IT hack
- Discord.io data breach and Ivanti Avalanche vulnerabilities
- UK Electoral Commission hack and Microsoft’s role in China email breach
- Salesforce email zero-day exploit and Microsoft Power Platform criticism
- Airlines disclose pilot data breach and the Microsoft Teams bug
- GravityRAT Android Trojan and new MOVEit Transfer flaw
- University of Manchester hack and Honda API flaws
- MOVEit zero-day exploit and the U.S. iPhone hack accusation
- Daam Android virus and Barracuda zero-day flaw
- TP-Link router exploit and 18-year-old charged with hacking DraftKings accounts
- Discord support hack and Toyota location data leak
- Twitter private tweets bug and Cisco phone router vulnerabilities
- Cisco XSS zero-day flaw and PaperCut vulnerabilities
- 3CX hackers hit critical infrastructure and secondhand routers cause security concerns
- Hyundai data breach and Microsoft’s warning to accountants
- Western Digital cloud breach and the MSI ransomware hack
- TMX loan data breach, Italy bans ChatGPT and WordPress Elementor Pro exploit
- ChatGPT data leak and Gmail message theft by North Korean hackers
- U.S. federal agency hack and the return of FakeCalls Android malware
- Massive AT&T data breach and fake jobs targeting security researchers
- U.S. Marshals service breach and TPM 2.0 security flaws
- Dangerous ChatGPT apps and food giant Dole ransomware attack
- GoDaddy malware installations, record-breaking DDoS attack and the new WhiskerSpy malware
- Reddit’s employees phished, healthcare firms targeted and the new Screenshotter malware
- JD Sports data breached, VMware ESXi servers attacked and the HeadCrab malware
- Yandex source code leaked, 4500+ WordPress sites hacked and the new SwiftSlicer malware
- PayPal accounts breached, Fortinet VPN flaw exploited, and the new Hook malware
- Twitter users’ emails leaked, ChatGPT used to write malware and Slack’s repository breach
- Reduce security events
- Reinforce cyber secure behaviors
- Strengthen cybersecurity culture at your organization