Security News > 2023 > April

Fake ransomware gang targets U.S. orgs with empty data leak threats
2023-04-01 15:59

Fake extortionists are piggybacking on data breaches and ransomware incidents, threatening U.S. companies with publishing or selling allegedly stolen data unless they get paid. They have also impersonated some ransomware and data extortion gangs in emails and claimed to be the authors of the intrusion, stealing hundreds of gigabytes of important data.

DISH slapped with multiple lawsuits after ransomware cyber attack
2023-04-01 10:39

Dish Network has been slapped with multiple class action lawsuits after it suffered a ransomware incident that was behind the company's multi-day "Network outage." DISH is facing at least five lawsuits seeking to recover losses for Dish shareholders who were adversely affected by the alleged "Securities fraud" from February 22, 2021 to February 27, 2023.

Microsoft Fixes New Azure AD Vulnerability Impacting Bing Search and Major Apps
2023-04-01 08:33

Microsoft has patched a misconfiguration issue impacting the Azure Active Directory identity and access management service that exposed several "High-impact" applications to unauthorized access. "One of these apps is a content management system that powers Bing.com and allowed us to not only modify search results, but also launch high-impact XSS attacks on Bing users," cloud security firm Wiz said in a report.

Ukrainian cops nab suspects accused of stealing $4.3m from victims across Europe
2023-04-01 07:25

Ukrainian cops have arrested two suspects and detained 10 others for their alleged roles in a cybercrime gang that used phishing scams and phony online marketplaces to steal more than $4.3 million from over 1,000 victims across Europe. Police say the victims come from several European countries including the Czech Republic, Poland, France, Spain, Portugal.

Cacti, Realtek, and IBM Aspera Faspex Vulnerabilities Under Active Exploitation
2023-04-01 04:51

Critical security flaws in Cacti, Realtek, and IBM Aspera Faspex are being exploited by various threat actors in hacks targeting unpatched systems. CVE-2022-46169 relates to a critical authentication bypass and command injection flaw in Cacti servers that allows an unauthenticated user to execute arbitrary code.

Hackers Exploiting WordPress Elementor Pro Vulnerability: Millions of Sites at Risk!
2023-04-01 04:36

Unknown threat actors are actively exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress. The premium plugin is estimated to be used on over 12 million sites.