Cyberattacks: Page 13
-
Wealthy countries boast superior cyber defenses
A nation’s economic prosperity is directly linked to greater defense capabilities, but no country is overachieving in cyber defense, according to SecurityScorecard.
By Matt Kapko • Jan. 17, 2024 -
Retrieved from Colorado State University on January 09, 2024Deep Dive
Progress Software’s MOVEit meltdown: uncovering the fallout
Businesses use the file-transfer service because it checks the compliance boxes for keeping data safe. Though initial attacks were targeted, thousands of bystanding businesses were hit indiscriminately.
By Matt Kapko , Julia Himmel • Jan. 16, 2024 -
Elevated ransomware activity hit nearly 5,200 organizations in 2023
While ransomware activity remains high, the number of unique ransomware families used for these attacks decreased by more than half, Rapid7 researchers found.
By Matt Kapko • Jan. 12, 2024 -
Ivanti Connect Secure attacks part of deliberate espionage operation
Researchers warn the previously unknown actor has developed custom malware designed to maintain persistent access on targeted networks and evade detection.
By David Jones • Jan. 12, 2024 -
Ivanti Connect Secure devices face active exploitation, patch schedule staggered
Unauthenticated attackers can take control of systems by exploiting the zero days, which a suspected state-linked threat actor is chaining together.
By David Jones • Jan. 11, 2024 -
5 cybersecurity trends to watch in 2024
Preventative measures remain woefully unmet, the scourge of ransomware is as bad as its ever been, and a wave of new incident reporting and compliance regulations are taking hold. Buckle up, 2024 is here.
By David Jones , Matt Kapko • Jan. 10, 2024 -
Fidelity National Financial cyberattack impacts up to 1.3M customers
While data was stolen and the company faces lawsuits, it does not consider the attack material to the business.
By David Jones • Jan. 10, 2024 -
DDoS attack traffic surged in 2023, Cloudflare finds
Elevated malicious DDoS activity coincided with mass exploits of the novel zero-day vulnerability HTTP/2 Rapid Reset, which threat actors used to launch DDoS attacks last year.
By Matt Kapko • Jan. 9, 2024 -
LoanDepot caught in mortgage industry cyberattack spree
The non-bank mortgage lender is the fourth major real estate industry organization hit by a cyberattack since late October.
By Matt Kapko • Jan. 8, 2024 -
Merck reaches settlement in closely watched NotPetya insurance case
The pharmaceutical giant previously won a New Jersey court decision involving $700 million of a $1.4 billion dispute over war-exclusions language related to the attack.
By David Jones • Jan. 8, 2024 -
Extent of a cyber specialist law firm’s data breach grows
A two-week long breach exposed a trove of highly sensitive information on Orrick’s clients. The pool of victims quadrupled between its July and December disclosures.
By Matt Kapko • Jan. 5, 2024 -
Xerox discloses a subsidiary’s breach following ransomware claim of data theft
Inc, a relatively new threat group, previously claimed to have stolen company data.
By David Jones • Jan. 3, 2024 -
First American Financial confirms threat actors stole and encrypted data
The title insurance giant said the cyberattack is contained, but it is still working to determine whether the incident will have a material impact.
By David Jones • Updated Jan. 4, 2024 -
Fleeting fake delivery phishing campaign targets last-minute shoppers
Text messages disguised as urgent or failed delivery notifications can create tension between impersonated delivery service companies and legitimate customers.
By Matt Kapko • Dec. 22, 2023 -
First American Financial takes systems offline after cyber incident
The incident comes just weeks after the title insurance firm reached a $1 million settlement with New York state financial regulators for a massive 2019 data breach that impacted 885 million customer records.
By David Jones • Updated Dec. 27, 2023 -
Notorious ransomware group tussles with law enforcement, regenerates after takedown
The on-again, off-again appearance of AlphV’s threats on the dark web underscore the difficulties law enforcement agencies confront in their disruption efforts.
By Matt Kapko • Dec. 20, 2023 -
US leads AlphV ransomware infrastructure takedown
Law enforcement released a decryptor for the prolific threat group and ransomware affiliate service behind some of 2023’s most high-profile attacks.
By Matt Kapko • Dec. 19, 2023 -
Comcast’s Xfinity discloses massive data breach linked to CitrixBleed vulnerability
The breach, involving 35.9 million customers, took place just a week after Citrix released a patch for a critical flaw.
By David Jones • Dec. 19, 2023 -
Cyberattack on VF Corp. disrupts order fulfillment
The attack on the company last week, which owns Vans and The North Face, also resulted in data theft.
By Laurel Deppen • Dec. 18, 2023 -
Mr. Cooper cyberattack hits every current — and former — customer
The mortgage servicer expects vendor expenses related to its response and recovery to reach $25 million this quarter. Almost 14.7 million people were impacted.
By Matt Kapko • Dec. 18, 2023 -
State-linked cyber actors behind SolarWinds plant seeds for new malicious campaign
U.S. authorities are raising alarms that the 2020 Sunburst attack threat actors are exploiting a CVE in JetBrains TeamCity in preparation for future supply chain compromises.
By David Jones • Dec. 15, 2023 -
Kraft Heinz probes ransomware attack claim
The food and beverage company attributed the potential attack to a decommissioned marketing site and said internal systems are operating normally.
By Matt Kapko • Dec. 15, 2023 -
Credit unions recover from outages caused by third-party ransomware attack
While Ongoing Operations said some of its data was compromised and notified impacted customers, credit unions have yet to disclose damages downstream.
By Matt Kapko • Dec. 14, 2023 -
Check Point Software in SEC settlement talks in connection with SolarWinds probe
The cybersecurity firm provided documents and other information related to the 2020 supply chain hack of the SolarWinds Orion platform.
By David Jones • Dec. 13, 2023 -
Henry Schein says 29K people affected in September cyberattack
The ransomware group AlphV/BlackCat claimed responsibility for the data breach and a second incident involving the company.
By Susan Kelly • Dec. 11, 2023