View Full Version : Web Host News
- Critical Exim bug bypasses security filters on 1.5 million mail servers
- Microsoft 365, Office users hit by wave of ‘30088-27’ update errors
- Advance Auto Parts data breach impacts 2.3 million people
- CRYSTALRAY hacker expands to 1,500 breached systems using SSH-Snake tool
- Dallas County: Data of 200,000 exposed in 2023 ransomware attack
- Google increases bug bounty rewards five times, up to $151K
- Signal downplays encryption key flaw, fixes it after X drama
- ARRL finally confirms ransomware gang stole data in cyberattack
- Massive AT&T data breach exposes call logs of 109 million customers
- Netgear warns users to patch auth bypass, XSS router flaws
- DNS hijacks target crypto platforms registered with Squarespace
- Rite Aid confirms data breach after June ransomware attack
- Banks in Singapore to phase out one-time passwords in 3 months
- Hackers use PoC exploits in attacks 22 minutes after release
- Microsoft fixes bug causing Windows Update automation issues
- Detecting Living Off The Land attacks with Wazuh
- June Windows Server updates break Microsoft 365 Defender features
- Facebook ads for Windows desktop themes push info-stealing malware
- Microsoft shares temp fix for Windows 11 Photos not launching
- SEXi ransomware rebrands to APT INC, continues VMware ESXi attacks
- MuddyWater hackers deploy new BugSleep backdoor malware in attacks
- New BugSleep malware implant deployed in MuddyWater attacks
- Kaspersky is shutting down its business in the United States
- Microsoft finally fixes Outlook alerts bug caused by December updates
- Microsoft links Scattered Spider hackers to Qilin ransomware attacks
- Microsoft announces new Windows 'checkpoint' cumulative updates
- Rite Aid says June data breach impacts 2.2 million people
- Email addresses of 15 million Trello users leaked on hacking forum
- CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks
- Kaspersky offers free security software for six months in U.S. goodbye
- 5 steps to automate user access reviews and simplify IT compliance
- Yacht giant MarineMax data breach impacts over 123,000 people
- Exchange Online adds Inbound DANE with DNSSEC for security boost
- Cisco SSM On-Prem bug lets hackers change any user's password
- Over 400,000 Life360 user phone numbers leaked via unsecured API
- Notorious FIN7 hackers sell EDR killer to other threat actors
- Microsoft: Windows 11 23H2 now available for all eligible devices
- Critical Cisco bug lets hackers add root users on SEG devices
- Microsoft fixes bug blocking Windows 11 Photos from starting
- SolarWinds fixes 8 critical bugs in access rights audit software
- Revolver Rabbit gang registers 500,000 domains for malware campaigns
- Hacker trap: Fake OnlyFans tool backstabs cybercriminals, steals passwords
- Veeam warns of critical RCE flaw in Backup & Replication software
- Musician charged with $10M streaming royalties fraud using AI and bots
- LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks
- Russian military hackers linked to critical infrastructure attacks
- Microsoft removes revenge porn from Bing search using new tool
- Apache fixes critical OFBiz remote code execution vulnerability
- SonicWall SSLVPN access control flaw is now exploited in attacks
- SpyAgent Android malware steals your crypto recovery phrases from images
- Microsoft Office 2024 to disable ActiveX controls by default
- Car rental giant Avis discloses data breach impacting customers
- Transport for London staff faces systems disruptions after cyberattack
- New RAMBO attack steals data using RAM in air-gapped computers
- Sextortion scam now use your "cheating" spouse’s name as a lure
- Car rental giant Avis data breach impacts over 299,000 customers
- Sextortion scams now use your "cheating" spouse’s name as a lure
- Progress LoadMaster vulnerable to 10/10 severity RCE flaw
- How to defend against brute force and password spray attacks
- Payment gateway data breach affects 1.7 million credit card owners
- Meta fixes easily bypassed WhatsApp ‘View Once’ privacy feature
- Highline Public Schools closes schools following cyberattack
- Chinese hackers use new data theft malware in govt attacks
- Quad7 botnet targets more SOHO and VPN routers, media servers
- Critical SonicWall SSLVPN bug exploited in ransomware attacks
- Fake password manager coding test used to hack Python developers
- Adobe fixes Acrobat Reader zero-day with public PoC exploit
- WordPress.org to require 2FA for plugin developers by October
- Criminal IP and IPLocation.io Join Forces for Enhanced IP Analysis
- Chinese hackers linked to cybercrime syndicate arrested in Singapore
- GitLab warns of critical pipeline execution vulnerability
- Transport for London confirms customer data stolen in cyberattack
- Hackers targeting WhatsUp Gold with public exploit since August
- UK arrests teen linked to Transport for London cyber attack
- Fortinet confirms data breach after hacker claims to steal 440GB of files
- FBI: Reported cryptocurrency losses reached $5.6 billion in 2023
- New Vo1d malware infects 1.3 million Android streaming boxes
- RansomHub claims Kawasaki cyberattack, threatens to leak stolen data
- New Linux malware Hadooken targets Oracle WebLogic servers
- Ivanti warns high severity CSA flaw is now exploited in attacks
- 23andMe to pay $30 million in genetics data breach settlement
- TfL requires in-person password resets for 30,000 employees after hack
- Port of Seattle hit by Rhysida ransomware in August attack
- Microsoft rolls out Office LTSC 2024 for Windows and Mac
- Exploit code released for critical Ivanti RCE flaw, patch now
- CISA warns of Windows flaw used in infostealer malware attacks
- Microsoft fixes bug crashing Microsoft 365 apps when typing
- Over 1,000 ServiceNow instances found leaking corporate KB data
- PKfail Secure Boot bypass remains a significant risk two months later
- Ransomware gangs now abuse Microsoft Azure tool for data theft
- CISA urges software devs to weed out XSS vulnerabilities
- AT&T pays $13 million FCC settlement over 2023 data breach
- Cloudflare outage cuts off access to websites in some regions
- Construction firms breached in brute force attacks on accounting software
- Broadcom fixes critical RCE bug in VMware vCenter Server
- Temu denies breach after hacker claims theft of 87 million data records
- CISA warns of actively exploited Apache HugeGraph-Server bug
- Microsoft Edge will flag extensions causing performance issues
- Tor says it’s "still safe" amid reports of police deanonymizing users
- Ivanti warns of another critical CSA flaw exploited in attacks
- FTC exposes massive surveillance of kids, teens by social media giants
- Suspects behind $230 million cryptocurrency theft arrested in Miami
- Clickbaity or genius? 'BF cheated on you' QR codes pop up across UK
- macOS Sequoia change breaks networking for VPN, antivirus software
- Microsoft ends development of Windows Server Update Services (WSUS)
- Windows Server 2025 previews security updates without restarts
- Disney ditching Slack after massive July data breach
- Ukraine bans Telegram on military, govt devices over security risks
- Dell investigates data breach claims after hacker leaks employee info
- Global infostealer malware operation targets crypto users, gamers
- New Google Chrome feature will translate complex pages in real time
- How to manage shadow IT and reduce your attack surface
- Android malware 'Necro' infects 11 million devices via Google Play
- Kaspersky deletes itself, installs UltraAV antivirus without warning
- New Mallox ransomware Linux variant based on leaked Kryptina code
- Telegram now shares users’ IP and phone number on legal requests
- US proposes ban on connected vehicle tech from China, Russia
- MoneyGram confirms a cyberattack is behind dayslong outage
- New Octo Android malware version impersonates NordVPN, Google Chrome
- Generative AI Security: Getting ready for Salesforce Einstein Copilot
- Infostealer malware bypasses Chrome’s new cookie-theft defenses
- Critical Ivanti vTM auth bypass bug now exploited in attacks
- Hackers deploy AI-written malware in targeted attacks
- U.S. govt agency CMS says data breach impacted 3.1 million people
- Kansas water plant cyberattack forces switch to manual operations
- AutoCanada says ransomware attack "may" impact employee data
- CISA: Hackers target industrial systems using “unsophisticated methods”
- Winamp releases source code, asks for help modernizing the player
- Windows 10 KB5043131 update released with 9 changes and fixes
- Mozilla accused of tracking users in Firefox without consent
- Meta halts routing via Deutsche Telekom over €20M peering fee
- Google sees 68% drop in Android memory safety flaws over 5 years
- HPE Aruba Networking fixes critical flaws impacting Access Points
- Fake WalletConnect app on Google Play steals Android users’ crypto
- Automattic blocks WP Engine’s access to WordPress resources
- US sanctions crypto exchanges used by Russian ransomware gangs
- Tails OS merges with Tor Project for better privacy, security
- Kia dealer portal flaw could let attackers hack millions of cars
- CUPS flaws enable Linux remote code execution, but there’s a catch
- New RomCom malware variant 'SnipBot' spotted in data theft attacks
- Windows 11 KB5043145 update released with 13 changes and fixes
- Progress urges admins to patch critical WhatsUp Gold bugs ASAP
- Embargo ransomware escalates attacks to cloud environments
- U.S. charges Joker's Stash and Rescator money launderers
- Microsoft: Windows Recall now can be removed, is more secure
- Iranian hackers charged for ‘hack-and-leak’ plot to influence election
- Ireland fines Meta €91 million for storing passwords in plaintext
- Critical flaw in NVIDIA Container Toolkit allows full host takeover
- Windows 11 KB5043145 update causes reboot loops, blue screens
- Media giant AFP hit by cyberattack impacting news delivery services
- Verizon outage: iPhones, Android devices stuck in SOS mode
- Man charged for selling forged license keys for network switches
- T-Mobile pays $31.5 million FCC settlement over 4 data breaches
- JPCERT shares Windows Event Log tips to detect ransomware attacks
- Microsoft Defender adds detection of unsecure Wi-Fi networks
- Microsoft overhauls security for publishing Edge extensions
- Hacker charged for breaching 5 companies for insider trading
- The Playstation Network is down in a global outage
- Microsoft fixes Windows KB5043145 reboot loops, USB and Bluetooth issues
- Windows 11 24H2 now rolling out, here are the new features
- Police arrest four suspects linked to LockBit ransomware gang
- Ransomware attack forces UMC Health System to divert some patients
- Evil Corp hit with new sanctions, BitPaymer ransomware charges
- Rackspace monitoring data stolen in ScienceLogic zero-day attack
- Microsoft fixes Outlook email sending issue for users with many folders
- Arc browser launches bug bounty program after fixing RCE bug
- Microsoft blocks Windows 11 24H2 on some Intel PCs over BSOD issues
- Microsoft warns of Windows 11 24H2 gaming performance issues
- Critical Zimbra RCE flaw exploited to backdoor servers using emails
- DrayTek fixed critical flaws in over 700,000 exposed routers
- CISA: Network switch RCE flaw impacts critical infrastructure
- Microsoft Office 2024 now available for Windows and macOS users
- Fake browser updates spread updated WarmCookie malware
- Critical Ivanti RCE flaw with public exploit now used in attacks
- FIN7 hackers launch deepfake nude “generator” sites to spread malware
- Linux malware “perfctl” behind years-long cryptomining campaign
- Why your password policy should include a custom dictionary
- Fraudsters imprisoned for scamming Apple out of 6,000 iPhones
- Cloudflare blocks largest recorded DDoS attack peaking at 3.8Tbps
- Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
- Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure
- Dutch Police: ‘State actor’ likely behind recent data breach
- ‘Pig butchering’ trading apps found on Google Play, App Store
- Recently patched CUPS flaw can be used to amplify DDoS attacks
- Why your password policy should include a custom dictionary wordlist
- UK nuclear site Sellafield fined $440,000 for cybersecurity shortfalls
- Google removes Kaspersky's antivirus software from Play Store
- Outlast game development delayed after Red Barrels cyberattack
- Russia arrests US-sanctioned Cryptex founder, 95 other linked suspects
- Highline Public Schools confirms ransomware behind shutdown
- Comcast and Truist Bank customers caught up in FBCS data breach
- Man pleads guilty to stealing $37 million in crypto from 571 victims
- Google Pay alarms users with accidental ‘new card’ added emails
- MoneyGram: No evidence ransomware is behind recent cyberattack
- AT&T, Verizon reportedly hacked to target US govt wiretapping platform
- Hybrid Analysis Bolstered by Criminal IP’s Comprehensive Domain Intelligenc
- American Water shuts down online services after cyberattack
- Qualcomm patches high-severity zero-day exploited in attacks
- Microsoft: Word deletes some documents instead of saving them
- LEGO's website hacked to push cryptocurrency scam
- Ukrainian pleads guilty to operating Raccoon Stealer malware
- MoneyGram confirms hackers stole customer data in cyberattack
- ADT discloses second breach in 2 months, hacked via stolen credentials
- Microsoft Edge begins testing Copilot Vision
- Casio reports IT systems failure after weekend network breach
- Ivanti warns of three more CSA zero-days exploited in attacks
- European govt air-gapped systems breached using custom malware
- Windows 10 KB5044273 update released with 9 fixes, security updates
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
- Windows 11 KB5044284 and KB5044285 cumulative updates released
- Microsoft fixes Remote Desktop issues caused by Windows Server update
- New Mamba 2FA bypass service targets Microsoft 365 accounts
- Microsoft: Windows 11 22H2 Home and Pro reached end of servicing
- New scanner finds Linux, UNIX servers exposed to CUPS RCE attacks
- Discord blocked in Russia and Turkey for spreading illegal content
- Dutch police arrest admin of 'Bohemia/Cannabia' dark web market
- How open source SIEM and XDR tackle evolving threats
- Recent Dr.Web cyberattack claimed by pro-Ukrainian hacktivists
- Mozilla fixes Firefox zero-day actively exploited in attacks
- Microsoft fixes Word bug that deleted documents when saving
- Palo Alto Networks warns of firewall hijack bugs with public exploit
- Internet Archive hacked, data breach impacts 31 million users
- CISA says critical Fortinet RCE flaw now exploited in attacks
- Crypto-stealing malware campaign infects 28,000 people
- Microsoft Outlook bug blocks email logins, causes app crashes
- GitLab warns of critical arbitrary branch pipeline execution flaw
- Underground ransomware claims attack on Casio, leaks stolen data
- Fidelity Investments says data breach affects over 77,000 people
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers
- Marriott settles with FTC, to pay $52 million over data breaches
- Ukraine arrests rogue VPN operator providing access to Runet
- Akira and Fog ransomware now exploit critical Veeam RCE flaw
- Casio confirms customer data stolen in a ransomware attack
- CISA: Hackers abuse F5 BIG-IP cookies to map internal servers
- Microsoft deprecates PPTP and L2TP VPN protocols in Windows Server
- OpenAI confirms threat actors use ChatGPT to write malware
- Iranian hackers now exploit Windows flaw to elevate privileges
- Google warns uBlock Origin and other extensions may be disabled soon
- Pokemon dev Game Freak confirms breach after stolen data leaks online
- TrickMo malware steals Android PINs using fake lock screen
- Jetpack fixes critical information disclosure flaw existing since 2016
- New FASTCash malware Linux variant helps steal money from ATMs
- Cisco investigates breach after stolen data for sale on hacking forum
- Over 200 malicious apps on Google Play downloaded millions of times
- New FIDO proposal lets you securely move passkeys across platforms
- EDRSilencer red team tool used in attacks to bypass security
- Amazon says 175 million customer now use passkeys to log in
- Finland seizes servers of 'Sipultie' dark web drugs market
- Amazon says 175 million customers now use passkeys to log in
- Malicious ads exploited Internet Explorer zero day to drop malware
AMJ Bulletin Powered By phillyfinestserverstat Copyright 2000 - 2024, Jelsoft Enterprises Ltd