December 16, 2021
Tornado outbreak in Midwest U.S. emphasizes the need for cyber protection
A storm supercell turned disastrous on December 10–11, with more than 50 tornadoes spawning across eight U.S. states. One tornado alone left a path of destruction more than 225 miles (402 km) long, affecting four states.
December 15, 2021
HR management provider Kronos hit by ransomware
Kronos, the provider of workforce management and human capital management solutions, has suffered a significant ransomware attack that threatens to disrupt payroll and timesheet processing services for its customer organizations.
December 15, 2021
NIST records fifth straight year of record-breaking vulnerability counts
A graph recently released by the National Institute of Standards and Technology (NIST) shows that for the fifth year in a row, there have been a record-breaking number of reported vulnerabilities.
December 15, 2021
Malicious Notepad++ installers drop StrongPity malware
Notepad++, one of the most popular, and free, text and source code editors for Windows systems, is being used by attackers to distribute malware.
December 15, 2021
Emotet, in new tactic, deploys Cobalt Strike directly
The notorious Emotet malware, which recently returned from a hiatus after its botnet was dismantled by a joint task force early this year, has begun installing Cobalt Strike directly — a deviation from its typical tactic of installing a trojan like TrickBot or Qbot and then delivering Cobalt Strike through it.
December 13, 2021
Critical Apache Log4j vulnerability discovered — here's what you need to know
Late last week, a critical zero-day vulnerability in the popular Java logging library Log4j surfaced when attackers were observed exploiting Minecraft servers via the game’s chat box. It has since become clear that the vulnerability in question poses perhaps the largest security threat we’ve seen in years.Details are still unfolding, but here’s what we know now.
December 13, 2021
Log4j zero-day poses an internet-wide threat
A critical remote code execution (RCE) vulnerability (CVE-2021-44228) in the Log4j Java library is affecting most Java applications, including VMWare vCenter, Minecraft, Twitter, iCloud, and ElasticSearch.
December 09, 2021
FBI: Cuba operators receive $44 million in ransomware payments
A recent report from the FBI shows that Cuba ransomware has scored at least $43.9 million in total ransom payments after successful attacks on 49 different targets in five critical infrastructure sectors.
December 08, 2021
Coronavirus-related phishing lures rise amid Omicron fears
Fear of the recent Omicron COVID-19 variant is providing fuel for phishing threats — like one U.K.-based campaign that makes use of a fake NHS website.
December 05, 2021
Windows Defender generates numerous Emotet-related false positives
Shortly after Trickbot was observed dropping an updated version of the Emotet botnet malware, Windows Defender began incorrectly reporting certain executables and Microsoft Office documents as Emotet payloads.
December 04, 2021
Japanese hospital will rebuild computer systems after ransomware strike
Handa Hospital, in the Japanese town of Tsurugi, has announced that following a ransomware attack this past October, they will be spending around ¥200 million to build a new computer system instead of paying the demanded ransom.
December 03, 2021
IKEA email systems targeted in cyberattack
IKEA, the world's largest furniture retailer, is experiencing internal phishing attacks which target employees using reply-chain email threats.