Security News > 2021

Hackers hit CD Projekt Red, steal data, ask for ransom
2021-02-09 13:59

Polish game developer CD Projekt Red has been hit by hackers, who breached its internal network, stole data, encrypted some devices, and asked for a ransom to not sell of leak online sensitive company documents and the source code of some of their more popular games. The company categorized the attack as targeted, and admitted that the attacker managed to access the company's internal network and "Collected certain data belonging to CD PROJEKT capital group."

Microsoft: Recent Windows 10 gaming issues caused by Discord bug
2021-02-09 13:37

Microsoft has acknowledged a known issue that was causing Direct3D 12 games to fail to launch or crash with an error on some Windows 10 devices. "Microsoft and Discord have found incompatibility issues with some games using Direct3D 12 when the in-game overlay feature of Discord is enabled," Microsoft said.

Ransomware can be installed via ghost accounts
2021-02-09 12:58

Active accounts for people who have left your organization can make exploitation easy, according to Sophos.

Hacker Tries to Poison Water Supply of Florida Town
2021-02-09 12:54

A threat actor hacked into the computer system of the water treatment facility in Oldsmar, Fla., and tried to poison the town's water supply by raising the levels of sodium hydroxide, or lye, in the water supply. Someone remotely accessed the computer system the operator was monitoring that controls chemical levels in the water as well as other operations, he said.

CD Projekt Red 'EPICALLY pwned': Cyberpunk 2077 dev publishes ransom note after company systems encrypted
2021-02-09 12:28

CD Projekt Red, the Polish developer of Cyberpunk 2077 and The Witcher 3, has disclosed a major security incident in which several company systems were encrypted and confidential data stolen. "If we will not come to an agreement, then your source codes will be sold or leaked online and your documents will be sent to our contacts in gaming journalism," wrote the attackers, who added CD Projekt Red had a 48-hour deadline to respond to their demands.

U.S. Agencies Publish Ransomware Factsheet
2021-02-09 12:15

The National Cyber Investigative Joint Task Force on Friday released a joint-sealed ransomware factsheet detailing common attack techniques and means to ensure prevention and mitigation. The factsheet has been developed by an interagency group of experts in ransomware, from more than 15 government agencies, and is meant to help increase awareness on the threat that ransomware poses to critical infrastructure.

Web Credit Card Skimmer Steals Data from Another Credit Card Skimmer
2021-02-09 12:01

MalwareBytes is reporting a weird software credit card skimmer. Even though spotting multiple card skimmer scripts on the same online shop is not unheard of, this one stood out due to its highly specialized nature.

Microsoft to alert enterprise security teams when nation-state attackers target their employees
2021-02-09 11:45

Microsoft will introduce this month a new security alert that will notify enterprise security teams when an employee is being targeted by suspected nation-state attackers. " attacks represent some of the most advanced and persistent threat activity Microsoft tracks.

CD PROJEKT RED gaming studio hit by ransomware attack
2021-02-09 10:33

CD PROJEKT RED, the video game development studio behind Cyberpunk 2077 and The Witcher trilogy, has disclosed a ransomware attack that impacted its network. The Polish gaming studio said in an official statement that the attackers breached the internal network and were able to collect CD PROJEKT capital group data before encrypting systems and leaving behind a ransom note.

Top 5 Bug Bounty Platforms to Watch in 2021
2021-02-09 09:07

The skyrocketing OpenBugBounty project is the only non-for-profit vulnerability disclosure and Bug Bounty platform on our list. With over 1,200 active Bug Bounty programs, OpenBugBounty also permits coordinated disclosure of security issues on any website if the issue was detected by non-intrusive means.