Cybersecurity News
US Unseals Indictments Against North Korean Cyberattackers for Thefts Totaling $1.3B
FBI, CISA, and Treasury Department also release details about North Korean malware used in cryptocurrency thefts since 2018.17 February 2021
White House Says 100 Private Sector Orgs Hit in SolarWinds Campaign
Anne Neuberger, a top Biden cybersecurity official, provided an update on the government's investigation into the massive breach.17 February 2021
Microsoft starts removing Flash from Windows devices via new KB4577586 update
Windows 10 users are reporting seeing a new update this week that permanently removes Flash from their systems.17 February 2021
Stolen Jones Day Law Firm Files Posted on Dark Web
Jones Day, which represented Trump, said the breach is part of the Accellion attack from December.17 February 2021
Windows, Linux Devices Hijacked In Two-Year Cryptojacking Campaign
The WatchDog malware has flown under the radar for two years in what researchers call one of the 'largest' Monero cryptojacking attacks ever.17 February 2021
U.S. Indicts North Korean Hackers in Theft of $200 Million
The U.S. Justice Department today unsealed indictments against three men accused of working with the North Korean regime to carry out some of the most damaging cybercrime attacks over the past decade, including the 2014 hack of Sony Pictures, the global WannaCry ransomware contagion of 2017, and the theft of roughly $200 million and attempted theft of more than $1.2 billion from banks and other victims worldwide.17 February 2021
Kia Faces $20M DoppelPaymer Ransomware Attack
Kia Motors America this week experienced a nationwide IT outage; now, reports indicate the company was hit with ransomware.17 February 2021
Ninja Forms WordPress Plugin Bug Opens Websites to Hacks
The popular plugin is installed on more than 1 million websites, and has four flaws that allow various kinds of serious attacks, including site takeover and email hijacking.17 February 2021
U.S. Accuses North Korean Hackers of Stealing Millions
The feds have expanded the list of financial and political hacking crimes they allege are linked to Lazarus Group and North Korea.17 February 2021
Ransomware? Let's Call It What It Really Is: Extortionware
Just as the targets of these attacks have shifted from individuals to corporations, so too has the narrow focus given way to applying force and pressure to pay.17 February 2021
Breach Etiquette: How to Mind Your Manners When It Matters
Panic-stricken as you may be in the face of a cyberattack, keeping calm and, perhaps most importantly, responding appropriately are critical to limiting the damage.17 February 2021
US charges two more members of the 'Lazarus' North Korean hacking group
The US DOJ described the North Korean hackers as "the world's leading bank robbers" and "a criminal syndicate with a flag."17 February 2021
Enterprise Windows Threats Drop as Mac Attacks Rise: Report
An analysis of 2020 malware activity indicates businesses should be worried about internal hack tools, ransomware, and spyware in the year ahead.17 February 2021
Masslogger Swipes Microsoft Outlook, Google Chrome Credentials
A new version of the Masslogger trojan has been targeting Windows users - now using a compiled HTML (CHM) file format to start the infection chain.17 February 2021
Details Tied to Safari Browser-based ‘ScamClub’ Campaign Revealed
Public disclosure of a privilege escalation attack details how a cybergang bypassed browser iframe sandboxing with malicious PostMessage popups.17 February 2021
4 Predictions for the Future of Privacy
Use these predictions to avoid pushback, find opportunity, and create value for your organization.17 February 2021
Dutch police post 'friendly' warnings on hacking forums
Dutch police: "Hosting criminal infrastructure in The Netherlands is a lost cause."17 February 2021
Bug in shared SDK can let attackers join calls undetected across multiple apps
Apps that use the SDK include MeetMe, Skout, Nimo TV, temi, and Talkspace.17 February 2021
Owner of app that hijacked millions of devices with one update exposes buy-to-infect scam
The owners of the once-legitimate Android app insist that a buyer was responsible for a malicious update with far-reaching consequences.17 February 2021
Tracker pixels in emails are now an ‘endemic’ privacy concern
Critics suggest the practice is marketing gone too far.17 February 2021