View Full Version : Web Host News
- Understand these seven password attacks and how to stop them
- Critical Kubernetes Image Builder flaw gives SSH root access to VMs
- US disrupts Anonymous Sudan DDoS operation, indicts 2 Sudanese brothers
- SolarWinds Web Help Desk flaw is now exploited in attacks
- Google: 70% of exploited flaws disclosed in 2023 were zero-days
- USDoD hacker behind National Public Data breach arrested in Brazil
- Iranian hackers act as brokers selling critical infrastructure access
- Top 5 Cloud Security Automations for SecOps Teams
- Hackers blackmail Globe Life after stealing customer data
- BianLian ransomware claims attack on Boston Children's Health Physicians
- FBI arrest Alabama man suspected of hacking SEC's X account
- Undercover North Korean IT workers now steal data, extort employers
- Fake Google Meet conference errors push infostealing malware
- Microsoft warns it lost some customer's security logs for a month
- Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
- How to leverage $200 million FCC program boosting K-12 cybersecurity
- Tech giant Nidec confirms data breach following ransomware attack
- ESET partner breached to send data wipers to Israeli orgs
- Cisco takes DevHub portal offline after hacker publishes stolen data
- Microsoft creates fake Azure tenants to pull phishers into honeypots
- Google Scholar has a 'verified email' for Sir Isaac Newton
- Internet Archive breached again through stolen access tokens
- Severe flaws in E2EE cloud storage platforms used by millions
- Bumblebee malware returns after recent law enforcement disruption
- Microsoft blocks Windows 11 24H2 on two ASUS models due to crashes
- Over 6,000 WordPress hacked to install plugins pushing infostealers
- Hackers exploit Roundcube webmail flaw to steal email, credentials
- VMware fixes bad patch for critical vCenter Server RCE flaw
- Exploit released for new Windows Server "WinReg" NTLM Relay attack
- SEC charges tech companies for downplaying SolarWinds breaches
- Windows 10 KB5045594 update fixes multi-function printer bugs
- AWS, Azure auth keys found in Android and iOS apps used by millions
- CISA proposes new security requirements to protect govt, personal data
- Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland
- Google to let businesses create curated Chrome Web Stores for extensions
- Fortinet warns of new critical FortiManager flaw used in zero-day attacks
- Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day
- WhatsApp now encrypts contact databases for privacy-preserving synching
- Windows 11 KB5044380 preview update lets you remap the Copilot key
- Mandiant says new Fortinet flaw has been exploited since June
- Samsung Galaxy S24 and Sonos Era hacked on Pwn2Own Ireland Day 2
- New Qilin ransomware encryptor features stronger encryption, evasion
- Ireland fines LinkedIn €310 million over targeted advertising
- Cisco fixes VPN DoS flaw discovered in password spray attacks
- Insurance admin Landmark says data breach impacts 800,000 people
- Windows 11 24H2 KB5044384 update fixes sfc /scannow corrupt file errors
- Henry Schein discloses data breach a year after ransomware attack
- Apple creates Private Cloud Compute VM to let researchers find bugs
- UnitedHealth says data of 100 million stolen in Change Healthcare breach
- QNAP, Synology, Lexmark devices hacked on Pwn2Own Day 3
- Amazon seizes domains used in rogue Remote Desktop campaign to steal data
- Russia sentences REvil ransomware members to over 4 years in prison
- Black Basta ransomware poses as IT support on Microsoft Teams to breach net
- Over 70 zero-day flaws get hackers $1 million at Pwn2Own Ireland
- New Windows Driver Signature bypass allows kernel rootkit installs
- New Cisco ASA and FTD features block VPN brute-force password attacks
- Fog ransomware targets SonicWall VPNs to breach corporate networks
- Windows 11 24H2: The hardware and software blocking the new update
- Redline, Meta infostealer malware operations seized by police
- US says Chinese hackers breached multiple telecom providers
- Free, France’s second largest ISP, confirms data breach after leak
- Exchange Online adds Inbound DANE with DNSSEC for everyone
- Russia targets Ukrainian conscripts with Windows, Android malware
- New tool bypasses Google Chrome’s new cookie encryption system
- Russian charged by U.S. for creating RedLine infostealer malware
- QNAP fixes NAS backup software zero-day exploited at Pwn2Own
- Massive PSAUX ransomware attack targets 22,000 CyberPanel instances
- New Windows Themes zero-day gets free, unofficial patches
- Hackers steal 15,000 cloud credentials from exposed Git config files
- FBI: Upcoming U.S. general election fuel multiple fraud schemes
- Android malware "FakeCall" now reroutes bank calls to attackers
- North Korean govt hackers linked to Play ransomware attack
- QNAP patches second zero-day exploited at Pwn2Own to get root
- Microsoft Entra "security defaults" to make MFA setup mandatory
- Interbank confirms data breach following failed extortion, data leak
- LottieFiles hit in npm supply chain attack targeting users' crypto
- Microsoft fixes Windows 10 bug causing apps to stop working
- Over a thousand online shops hacked to show fake product listings
- Cynet delivers 426% ROI in Forrester Total Economic Impact*Study
- LottieFiles hacked in supply chain attack to steal users’ crypto
- qBittorrent fixes flaw exposing users to MitM attacks for 14 years
- Windows 11 Task Manager says no apps are active after preview update
- LiteSpeed Cache WordPress plugin bug lets hackers get admin access
- Hackers target critical zero-day vulnerability in PTZ cameras
- Microsoft wants $30 if you want to delay Windows 11 switch
- Windows 11 Task Manager bug shows wrong number of running processes
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials
- Microsoft delays Windows Recall again, now by December
- Sophos reveals 5-year battle with Chinese hackers attacking network devices
- DDoS site Dstat.cc seized and two suspects arrested in Germany
- Synology hurries out patches for zero-days exploited at Pwn2Own
- LastPass warns of fake support centers trying to steal customer data
- OpenAI's new ChatGPT Search Chrome extension feels like a search hijacker
- Microsoft warns Azure Virtual Desktop users of black screen issues
- LA housing authority confirms breach claimed by Cactus ransomware
- Microsoft Outlook workaround fixes freezes when copying text
- Microsoft SharePoint RCE bug exploited to breach corporate network
- ChatGPT-4o can be used for autonomous voice-based scams
- Meet Interlock — The new ransomware targeting FreeBSD servers
- Cisco says DevHub site leak won’t enable future breaches
- Microsoft confirms Windows Server 2025 blue screen, install issues
- City of Columbus: Data of 500,000 stolen in July ransomware attack
- Windows infected with backdoored Linux VMs in new phishing attacks
- Solving the painful password problem with better policies
- Custom "Pygmy Goat" malware used in Sophos Firewall hack on govt network
- Schneider Electric confirms dev platform breach after hacker steals data
- Windows Server 2025 released—here are the new features
- DocuSign's Envelopes API abused to send realistic fake invoices
- Nokia investigates breach after hacker claims to steal source code
- Google fixes two Android zero-days used in targeted attacks
- Suspect behind Snowflake data-theft attacks arrested in Canada
- US warns of last-minute Iranian and Russian election influence ops
- Interpol disrupts cybercrime activity on 22,000 IP addresses, arrests 41
- Google Cloud to make MFA mandatory by the end of 2025
- Germany drafts law to protect researchers who find security flaws
- New SteelFox malware hijacks Windows PCs using vulnerable driver
- Washington courts' systems offline following weekend cyberattack
- Cisco bug lets hackers run commands as root on UWRB access points
- Microsoft Notepad to get AI-powered rewriting tool on Windows 11
- Hackers increasingly use Winos4.0 post-exploitation kit in attacks
- North Korean hackers use new macOS malware against crypto firms
- CISA warns of critical Palo Alto Networks bug exploited in attacks
- Nokia says hackers leaked third-party app source code
- Canada orders TikTok to shut down over national risk concerns
- HPE warns of critical RCE flaws in Aruba Networking access points
- Google's mysterious 'search.app' links leave Android users concerned
- Palo Alto Networks warns of potential PAN-OS RCE vulnerability
- Unpatched Mazda Connect bugs let hackers install persistent malware
- Critical Veeam RCE bug now used in Frag ransomware attacks
- D-Link won’t fix critical flaw affecting 60,000 older NAS devices
- Scammers target UK senior citizens with Winter Fuel Payment texts
- Hands on with AI features in Windows 11 Paint and Notepad
- Microsoft says recent Windows 11 updates break SSH connections
- Malicious PyPI package with 37,000 downloads steals AWS keys
- Google says “Enhanced protection” feature in Chrome now uses AI
- Hackers now use ZIP file concatenation to evade detection
- Microsoft investigates OneDrive issue causing macOS app freezes
- Windows 11 is adding a 'Share' button to the Start menu and Taskbar
- Microsoft blames Windows Server 2025 automatic upgrades on 3rd-party tools
- Halliburton reports $35 million loss after ransomware attack
- Amazon confirms employee data breach after vendor hack
- HIBP notifies 57 million people of Hot Topic data breach
- New Ymir ransomware partners with RustyStealer in attacks
- VMware makes Workstation and Fusion free for everyone
- iPhones now auto-restart to block access to encrypted data after long idle
- Signal introduces convenient "call links" for private group chats
- FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
- Volt Typhoon rebuilds malware botnet following FBI disruption
- North Korean hackers create Flutter apps to bypass macOS security
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws
- Windows 11 KB5046617 and KB5046633 cumulative updates released
- Windows 10 KB5046613 update released with fixes for printer bugs
- D-Link won’t fix critical bug in 60,000 exposed EoL modems
- Microsoft Exchange adds warning to emails abusing spoofing flaw
- Microsoft fixes bugs causing Windows Server 2025 blue screens, install issu
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws
- New ShrinkLocker ransomware decryptor recovers BitLocker password
- New Google Pixel AI feature analyzes phone conversations for scams
- Critical bug in EoL D-Link NAS devices now exploited in attacks
- US indicts Snowflake hackers who extorted $2.5 million from 3 victims
- Microsoft patches Windows zero-day exploited in attacks on Ukraine
- Leaked info of 122 million linked to B2B data aggregator breach
- US govt officials’ communications compromised in recent telecom hack
- Hacker gets 10 years in prison for extorting US healthcare provider
- ChatGPT allows access to underlying sandbox OS, “playbook” data
- The true (and surprising) cost of forgotten passwords
- Hackers use macOS extended file attributes to hide malicious code
- New Glove Stealer malware bypasses Chrome's cookie encryption
- CISA warns of more Palo Alto Networks bugs exploited in attacks
- New Glove infostealer malware bypasses Chrome’s cookie encryption
- Fraud network uses 4,700 fake shopping sites to steal credit cards
- Microsoft just killed the Windows 10 Beta Channel again
- Palo Alto Networks warns of critical RCE zero-day exploited in attacks
- Microsoft just killed the Windows 10 Beta Channel for good
- Microsoft pulls Exchange security updates over mail delivery issues
- Bitfinex hacker gets 5 years in prison for 120,000 bitcoin heist
- Botnet exploits GeoVision zero-day to install Mirai malware
- FTC reports 50% drop in unwanted call complaints since 2021
- NSO Group used another WhatsApp zero-day after being sued, court docs say
- GitHub projects targeted with malicious commits to frame researcher
- T-Mobile confirms it was hacked in recent wave of telecom breaches
- Fake AI video generators infect Windows, macOS with infostealers
- Security plugin flaw in millions of WordPress sites gives admin access
- Phishing emails increasingly use SVG attachments to evade detection
- Microsoft 365 Admin portal abused to send sextortion emails
- Fake Bitwarden ads on Facebook push info-stealing Chrome extension
- Critical RCE bug in VMware vCenter Server now exploited in attacks
- US charges Phobos ransomware admin after South Korea extradition
- Palo Alto Networks patches two firewall zero-days used in attacks
- US space tech giant Maxar discloses employee data breach
- Brave on iOS adds new "Shred" button to wipe site-specific data
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials
- Spotify abused to promote pirated software and game cheats
- Microsoft shares more details on Windows 11 admin protection
- Microsoft launches Zero Day Quest hacking event with $4 million in rewards
- New Windows 11 recovery tool to let admins remotely fix unbootable devices
- Botnet fueling residential proxies disrupted in cybercrime crackdown
- Helldown ransomware exploits Zyxel VPN flaw to breach networks
- D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
- Microsoft now testing hotpatch on Windows 11 24H2 and Windows 365
- Oracle warns of Agile PLM file disclosure flaw exploited in attacks
- CISA tags Progress Kemp LoadMaster flaw as exploited in attacks
- Ford investgates alleged breach following customer data leak
- Apple fixes two zero-days used in attacks on Intel-based Macs
- Ford investigates alleged breach following customer data leak
- Amazon and Audible flooded with 'forex trading' and warez listings
- Microsoft confirms game audio issues on Windows 11 24H2 PCs
- New Ghost Tap attack abuses NFC mobile payments to steal money
- US charges five linked to Scattered Spider cybercrime gang
- Ubuntu Linux impacted by decade-old 'needrestart' flaw that gives root
- MITRE shares 2024's top 25 most dangerous software weaknesses
- Fintech giant Finastra investigates data breach after SFTP hack
- Cyberattack at French hospital exposes health data of 750,000 patients
- Ford rejects breach allegations, says customer data not impacted
- Now BlueSky hit with crypto scams as it crosses 20 million users
- Fortinet VPN design flaw hides successful brute-force attacks
- US seizes PopeyeTools cybercrime marketplace, charges administrators
- Microsoft disrupts ONNX phishing-as-a-service infrastructure
- Microsoft pulls WinAppSDK update breaking Windows 10 app uninstalls
- CISA says BianLian ransomware now focuses only on data theft
- Over 2,000 Palo Alto firewalls hacked using recently patched bugs
- Chinese hackers target Linux with new WolfsBane malware
- Windows 11 KB5046740 update released with 14 changes and fixes
- Microsoft rolls out Recall to Windows Insiders with Copilot+ PCs
- Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
- QNAP pulls buggy QTS firmware causing widespread NAS issues
- Windows 10 KB5046714 update fixes bug preventing app uninstalls
- Hackers abuse Avast anti-rootkit driver to disable defenses
- Microsoft testing Windows 11 support for third-party passkeys
- Windows 11 24H2 update blocked on PCs with Assassin's Creed, Star Wars Outl
- Salt Typhoon hackers backdoor telcos with new GhostSpider malware
- Microsoft 365 outage impacts Exchange Online, Teams, Sharepoint
- Meta removes over 2 million accounts pushing pig butchering scams
- Bangkok busts SMS Blaster sending 1 million scam texts from a van
- Microsoft blocks Windows 11 24H2 on some PCs with USB scanners
- DOJ: Man hacked networks to pitch cybersecurity services
- Blue Yonder ransomware attack disrupts grocery store supply chain
- New Windows 10 0x80073CFA fix requires installing WinAppSDK 3 times
- QNAP addresses critical flaws across NAS, router software
- Firefox and Windows zero-days exploited by Russian RomCom hackers
- Hackers exploit critical bug in Array Networks SSL VPN products
- Why Cybersecurity Leaders Trust the MITRE ATT&CK Evaluations
- Get 50% off Malwarebytes during Black Friday 2024
- Over 1,000 arrested in massive ‘Serengeti’ anti-cybercrime operation
- NordVPN Black Friday Deal: Save up to 74% on yearly subscriptions
- New NachoVPN attack uses rogue VPN servers to install malicious updates
- Police bust pirate streaming service making €250 million per month
- The Black Friday 2024 Cybersecurity, IT, VPN, & Antivirus Deals
- Cloudflare says it lost 55% of logs pushed to customers for 3.5 hours
- Chinese hackers breached T-Mobile's routers to scope out network
AMJ Bulletin Powered By phillyfinestserverstat Copyright 2000 - 2024, Jelsoft Enterprises Ltd