Cyberattacks: Page 19
-
DDoS attacks, growing more sophisticated, surged in Q2
One of the more serious incidents used a Mirai-variant botnet to unleash an ACK flood DDoS attack that peaked at 1.4 terabits per second, Cloudflare found.
By David Jones • July 19, 2023 -
Estée Lauder takes down some systems following cyberattack
ALPHV, the ransomware threat actor taking credit for the attack, threatened to reveal more information about the data it claims to have stolen.
By Matt Kapko • July 19, 2023 -
GoTo, parent company to LastPass, names new CISO
The change in security leadership comes months after the third-party cloud storage service GoTo shares with LastPass was breached.
By Matt Kapko • July 19, 2023 -
UKG agrees to pay up to $6M in lawsuit tied to 2021 breach
The payroll services provider reached an agreement to settle a class action lawsuit tied to a ransomware attack that targeted its Kronos Private Cloud service.
By Matt Kapko • July 18, 2023 -
Cyberattack compromised JumpCloud customer environments
The gap between the intrusion and confirmed customer impact suggests the threat actor had access to JumpCloud’s systems for almost two weeks.
By Matt Kapko • Updated July 17, 2023 -
Microsoft hardens key issuance systems after state-backed hackers breach Outlook accounts
The China-linked group, which Microsoft calls Storm-1558, has adopted new techniques after it took steps to disrupt their recent hacking activity.
By David Jones • July 17, 2023 -
Sponsored by Specops Software
Block known breached passwords from your active directory
99% of users reuse passwords, here's how to keep the breached ones out of your Active Directory
July 17, 2023 -
Deep Dive
MOVEit mass exploit timeline: How the file-transfer service attacks entangled victims
The slow-moving disaster has ensnared some of the world's largest enterprises. Cybersecurity experts expect further damage to come.
By Matt Kapko • July 14, 2023 -
Microsoft warns China-linked APT actor hacked US agency, other email accounts
U.S. officials alerted Microsoft about what emerged as a targeted, monthlong hacking campaign.
By David Jones • July 12, 2023 -
RomCom uses Word documents in new phishing campaign, Microsoft warns
The hackers are known to use trojanized versions of legitimate software from Adobe, SolarWinds, KeePass and others.
By David Jones • July 12, 2023 -
Johns Hopkins hit with class action suit following MOVEit data breach
The suit alleges that the health system failed to implement safeguards to secure patients’ health information and provided insufficient details about the stolen data.
By Sydney Halleman • July 12, 2023 -
Threat group testing more sophisticated DDoS hacks, authorities warn
Hacktivists behind the attacks on Microsoft OneDrive and Azure are claiming recent test disruptions at Stripe, Reddit and EFTPS.
By David Jones • July 10, 2023 -
Hackers using TrueBot malware for phishing attacks in US, Canada, officials warn
Threat actors have been leveraging a known vulnerability in Netwrix Auditor to exfiltrate data from targeted entities since May.
By David Jones • July 7, 2023 -
Suncor Energy confirms hackers breached Petro-Canada gas stations’ customer rewards data
The company, the largest integrated energy firm in Canada, said field operations were not impacted.
By David Jones • July 6, 2023 -
MOVEit vulnerability snags almost 200 victims, more expected
The education sector has been hit particularly hard as many widely used vendors in the space confirm impacts linked to the mass exploited vulnerability.
By Matt Kapko • July 5, 2023 -
Petro-Canada reports service restoration after suspected Suncor breach
The gas station chain restored card payments, but hasn’t shared specific details about the disruption. The industry has been under threat from state-linked actors.
By David Jones • June 29, 2023 -
Suncor Energy continues probe of cyber incident disrupting gas station payments
The incident came just days after authorities warned of possible attacks against the Canadian oil and gas sector.
By David Jones • June 28, 2023 -
Cyberattack exposes data on nearly 9K American and Southwest Airlines pilot applicants
Two of the world’s largest airlines no longer use recruitment portal Pilot Credentials after a cyberattack at the end of April.
By Matt Kapko • June 27, 2023 -
MOVEit vulnerability ensnares more victims
Some organizations have been impacted due to their direct use of MOVEit while others have been exposed by third-party vendors.
By Matt Kapko • June 27, 2023 -
Cybercriminals target high-profit companies: AEI
Investors in recent years have responded faster to news about a cyberattack, the study, which encompasses more than two decades of cyber events, found.
By Jim Tyson • June 26, 2023 -
Big names disclose MOVEit-related breaches, including PwC, EY and Genworth Financial
More than 100 organizations have been hit as part of the MOVEit attack campaign, including PBI Research Services, which exposed millions of customer data files to theft.
By David Jones • June 23, 2023 -
Retrieved from Dole.
Dole says February ransomware attack breached data of almost 3,900 US workers
The fresh produce giant disclosed the data security impact in a filing with the Maine Attorney General.
By David Jones • June 22, 2023 -
Mondelēz retirement data breached after hacker targets law firm Bryan Cave
The company said a third-party actor stole sensitive customer data from the firm, impacting more than 51,000 current and former Mondelēz employees.
By David Jones • June 21, 2023 -
Progress Software faces federal class action lawsuits as MOVEit breach exposure widens
Louisiana residents allege their personal financial information was put at risk after the state's motor vehicles department had data exposed in the MOVEit data breach.
By David Jones • June 21, 2023 -
US puts $10M bounty on Clop as federal agencies confirm data compromises
Additional private sector companies have disclosed attacks after multiple vulnerabilities were found in MOVEit Transfer software.
By David Jones • June 20, 2023