Security News > 2022

Red Cross cyberattack exposes data of 515,000 people seeking missing family
2022-01-19 23:26

A cyberattack on a Red Cross contactor has led to the theft of personal data for more than 515,000 people in 'Restoring Family Links,' a program that helps reunite families separated by war, disaster, and migration. The announcement comes from the International Committee of the Red Cross, which states that the data was compiled by at least 60 different Red Cross and Red Crescent National Societies worldwide.

Microsoft: SolarWinds fixes Serv-U bug exploited for Log4j attacks
2022-01-19 22:32

SolarWinds has patched a Serv-U vulnerability discovered by Microsoft that threat actors actively used to propagate Log4j attacks to internal devices on a network. Microsoft says they discovered the vulnerability during their monitoring of the Log4j attacks.

Marketing giant RRD confirms data theft in Conti ransomware attack
2022-01-19 21:25

RR Donnelly has confirmed that threat actors stole data in a December cyberattack, confirmed by BleepingComputer to be a Conti ransomware attack. While RRD initially said they were not aware of any client data stolen during the attack, on January 15th, the Conti ransomware gang claimed responsibility and began leaking 2.5GB of data allegedly stolen from RRD. However, a source told BleepingComputer that Conti soon removed the data from public view after RRD began further negotiations to prevent the release of data.

Need to prioritize security bug patches? Don't forget to scan Twitter as well as use CVSS scores
2022-01-19 21:22

Organizations looking to minimize exposure to exploitable software should scan Twitter for mentions of security bugs as well as use the Common Vulnerability Scoring System or CVSS, Kenna Security argues. The initial Log4j vulnerability received a base CVSS score of 10.0.

Destructive Wiper Targeting Ukraine Aimed at Eroding Trust, Experts Say
2022-01-19 20:55

Russia is positioned for a hot-war attack on Ukraine that the Biden administration warned could come "At any point" - but the country is already suffering an attack of a different kind. The perpetrators are taking pains to make the attacks look like a ransomware attack, even providing a ransom note.

DDoS IRC Bot Malware Spreading Through Korean WebHard Platforms
2022-01-19 20:23

An IRC bot strain programmed in GoLang is being used to launch distributed denial-of-service attacks targeting users in Korea. "Additionally, the DDoS malware was installed via downloader and UDP RAT was used."

FIN8 Hackers Spotted Using New 'White Rabbit' Ransomware in Recent Attacks
2022-01-19 20:22

The financially motivated FIN8 actor, in all likelihood, has resurfaced with a never-before-seen ransomware strain called "White Rabbit" that was recently deployed against a local bank in the U.S. in December 2021. "One of the most notable aspects of White Rabbit's attack is how its payload binary requires a specific command-line password to decrypt its internal configuration and proceed with its ransomware routine," the researchers noted.

Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism
2022-01-19 20:01

US companies should be on the lookout for security nasties from Ukrainian partners following the digital graffiti and malware attack launched against Ukraine by Belarus, the CISA has warned. "If working with Ukrainian organizations, take extra care to monitor, inspect, and isolate traffic from those organizations; closely review access controls for that traffic," added CISA, which also advised reviewing backups and disaster recovery drills.

CISA urges US orgs to prepare for data-wiping cyberattacks
2022-01-19 18:33

The Cybersecurity and Infrastructure Security Agency urges U.S. organizations to strengthen their cybersecurity defenses against data-wiping attacks recently seen targeting Ukrainian government agencies and businesses.CISA is now urging business leaders and U.S. organizations to take the following steps to prevent similar destructive attacks on their networks.

Box 2FA Bypass Opens User Accounts to Attack
2022-01-19 18:30

Clearly, the stakes are high - gaining access to a Box account could give cyberattackers access to a vast array of sensitive documents and data for both individuals and organizations. When a user goes to log on with his or her credentials, Box generates the cookies and the user is asked to navigate to an SMS verification page, where the person is instructed to enter a one-time passcode sent to an enrolled mobile phone.