News

News
Physical addresses of 270,000 Ledger owners were leaked on a hacker forum. A new SolarWinds flaw likely let hackers install SUPERNOVA malware. Attackers are abusing Citrix NetScaler devices to launch amplified DDoS attacks. All this, and more, in this week’s edition of Cybersecurity Weekly.

December 30, 2020
Sam Fay
News
A new SUPERNOVA backdoor found in SolarWinds cyberattack analysis. Microsoft says its systems were also breached in the SolarWinds hack. VMware is the latest to confirm breach in SolarWinds hacking campaign. All this, and more, in this week’s edition of Cybersecurity Weekly.

December 22, 2020
Sam Fay
News
An expert published PoC exploit code for a Kerberos Bronze Bit attack. A massive Subway U.K. phishing attack is pushing TrickBot malware. The U.S. warns of increased cyberattacks against K-12 distance learning. All this, and more, in this week’s edition of Cybersecurity Weekly.

December 15, 2020
Sam Fay
News
Hackers hide software skimmer in social media sharing icons. Unpatched Android apps put millions of users at risk. MetaMask phishing steals cryptocurrency wallets via Google ads. All this, and more, in this week’s edition of Cybersecurity Weekly.

December 08, 2020
Sam Fay
News
Just when you thought Halloween was over, it turns out there is something out there far scarier to security professionals around the world: the constant thre

November 23, 2020
Patrick Mallory
News
APT hackers for hire target financial and entertainment firms. DNS cache poisoning attacks return due to Linux weakness. The North Face website suffered a credential stuffing attack. All this, and more, in this week’s edition of Cybersecurity Weekly.

November 17, 2020
Sam Fay
News
Apple patched three actively exploited iOS zero-days. Hackers used Torisma spyware in job offer phishing attacks. A Cisco zero-day in AnyConnect Secure Mobility Client remains unpatched. All this, and more, in this week’s edition of Cybersecurity Weekly.

November 10, 2020
Sam Fay
News
WordPress patches a three-year-old high-severity RCE bug. A new NAT bypass attack lets hackers access any TCP/UDP service. A Windows zero-day bug is being exploited in the wild. All this, and more, in this week’s edition of Cybersecurity Weekly.

November 03, 2020
Sam Fay
News
Fifty-five new security flaws were reported in Apple software and services. Researchers find vulnerabilities in Microsoft Azure cloud service. Security staff are being forced to upskill in their own time. All this, and more, in this week’s edition of Cybersecurity Weekly.

October 13, 2020
Sam Fay
News
An Ohio medical center was offline following a security incident. Shopify announces a data breach affecting fewer than 200 merchants. The Emotet malware gang takes part in the 2020 U.S. elections. All this, and more, in this week’s edition of Cybersecurity Weekly.

October 06, 2020
Sam FayIn this series
- Canada Flipper Zero ban and new RustDoor macOS malware
- AnyDesk hack and iPhone patched kernel flaw
- Tesla Pwn2Own hacks and iOS push alerts abuse
- TeamViewer breach and Atlassian Jira outage
- Moscow ISP revenge hack and Microsoft Sharepoint bug warning
- X verified accounts hack and SpectralBlur macOS malware
- CISA default password alert and SOHO KV-botnet campaign
- New 5G modem flaws and Apple’s data breach report
- Staples cyberattack, Agent Racoon backdoor and other news
- British Library ransomware attack, Windows fingerprint authentication bypass
- Samsung UK data breach and ransomware actor’s SEC complaint
- ICBC ransomware attack and ChatGPT outage
- Boeing Lockbit ransomware attack, Apple’s vulnerability and WhatsApp mods spyware
- Octo Tempest hacking group and new iLeakage attack
- Okta support system breach and Google Ads fake KeePass campaign
- Skype DarkGate malware, Shadow PC breach and AvosLocker ransomware warning
- 23andMe data theft, MGM’s $100M ransomware loss and the Azure VM breach
- Malicious Bing Chat ads and FBI’s dual ransomware warning
- T-Mobile app glitch and fake Booking.com pages
- Airbus data leak, Cisco Webex ad malware and €345 million TikTok fine
- New Apple iMessage exploit and CISA’s Apache RocketMQ warning
- Forever 21 data breach and Android BadBazaar espionage
- Duolingo data leak and the Met Police IT hack
- Discord.io data breach and Ivanti Avalanche vulnerabilities
- UK Electoral Commission hack and Microsoft’s role in China email breach
- Salesforce email zero-day exploit and Microsoft Power Platform criticism
- Airlines disclose pilot data breach and the Microsoft Teams bug
- GravityRAT Android Trojan and new MOVEit Transfer flaw
- University of Manchester hack and Honda API flaws
- MOVEit zero-day exploit and the U.S. iPhone hack accusation
- Daam Android virus and Barracuda zero-day flaw
- TP-Link router exploit and 18-year-old charged with hacking DraftKings accounts
- Discord support hack and Toyota location data leak
- Twitter private tweets bug and Cisco phone router vulnerabilities
- Cisco XSS zero-day flaw and PaperCut vulnerabilities
- 3CX hackers hit critical infrastructure and secondhand routers cause security concerns
- Hyundai data breach and Microsoft’s warning to accountants
- Western Digital cloud breach and the MSI ransomware hack
- TMX loan data breach, Italy bans ChatGPT and WordPress Elementor Pro exploit
- ChatGPT data leak and Gmail message theft by North Korean hackers
- U.S. federal agency hack and the return of FakeCalls Android malware
- Massive AT&T data breach and fake jobs targeting security researchers
- U.S. Marshals service breach and TPM 2.0 security flaws
- Dangerous ChatGPT apps and food giant Dole ransomware attack
- GoDaddy malware installations, record-breaking DDoS attack and the new WhiskerSpy malware
- Reddit’s employees phished, healthcare firms targeted and the new Screenshotter malware
- JD Sports data breached, VMware ESXi servers attacked and the HeadCrab malware
- Yandex source code leaked, 4500+ WordPress sites hacked and the new SwiftSlicer malware
- PayPal accounts breached, Fortinet VPN flaw exploited, and the new Hook malware
- Twitter users’ emails leaked, ChatGPT used to write malware and Slack’s repository breach
- Reduce security events
- Reinforce cyber secure behaviors
- Strengthen cybersecurity culture at your organization