Security News > 2023 > June

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?
2023-06-28 18:59

The latest high-profile cybercrime exploits attributed to the Clop ransomware crew aren't your traditional sort of ransomware attacks. Conventional ransomware attacks are where your files get scrambled, your business gets totally derailed, and a message appears telling you that a decryption key for your data is available.

Linux version of Akira ransomware targets VMware ESXi servers
2023-06-28 18:51

The Akira ransomware operation uses a Linux encryptor to encrypt VMware ESXi virtual machines in double-extortion attacks against companies worldwide. BleepingComputer's analysis of the Linux encryptor shows it has a project name of 'Esxi Build Esxi6,' indicating the threat actors designed it specifically to target VMware ESXi servers.

Microsoft fixes Windows bug causing File Explorer freezes
2023-06-28 17:15

Microsoft has addressed a known issue causing File Explorer on Windows 11 and Windows Server systems after viewing a file's effective access permissions. The known issue impacts systems running the latest Windows releases, including Windows 11 21H2/22H2 and Windows Server 2022.

Hiring Kit: IT Audit Director
2023-06-28 16:00

The IT audit director develops and schedules internal audits to measure and document whether those IT controls were followed as prescribed. This hiring kit from TechRepublic Premium can give your enterprise a head start on finding your ideal candidate for the IT audit director role.

Brave Browser boosts privacy with new local resources restrictions
2023-06-28 15:44

The Brave team has announced that the privacy-centric browser will soon introduce new restriction controls allowing users to specify how long sites can access local network resources. "Surprising though it may be, most browsers allow websites to access these local resources just as easily as they can access other resources on the web," explains Brave.

Alert: New Electromagnetic Attacks on Drones Could Let Attackers Take Control
2023-06-28 15:05

Drones that don't have any known security weaknesses could be the target of electromagnetic fault injection attacks, potentially enabling a threat actor to achieve arbitrary code execution and compromise their functionality and safety. Side-channel attacks typically work by indirectly gathering information about a target system by exploiting unintended information leakages arising from variations in power consumption, electromagnetic emanations, and the time it takes to perform different mathematical operations.

NPM ecosystem at risk from “Manifest Confusion” attacks
2023-06-28 14:28

Manifest confusion occurs there is an inconsistency between a package's manifest information presented on the npm registry and the actual 'package. Json' file in the tarball of the published npm package used when the package is installed.

The Current State of Business Email Compromise Attacks
2023-06-28 14:01

Attackers use various tactics to access sensitive information, such as email account compromise and using a legitimate email address to initiate the attack. In a more insidious attack, an attacker may compromise an existing employee's email account from the inside.

CryptosLabs Scam Ring Targets French-Speaking Investors, Rakes in €480 Million
2023-06-28 13:47

Cybersecurity researchers have exposed the workings of a scam ring called CryptosLabs that's estimated to have made €480 million in illegal profits by targeting users in French-speaking individuals in France, Belgium, and Luxembourg since April 2018. The syndicate's massive fake investment schemes primarily involve impersonating 40 well-known banks, fin-techs, asset management firms, and crypto platforms, setting up a scam infrastructure spanning over 350 domains hosted on more than 80 servers, Group-IB said in a deep-dive report.

8Base ransomware group leaks data of 67 victim organizations
2023-06-28 13:32

Lockbit 3.0 is currently the most active ransomware group, NCC Group says in its most recent Threat Pulse report, but new ransomware groups like 8Base and Akira are rising in prominence. Collectively, the various ransomware groups revealed 436 victim organizations in May 2023 - 24% more than in April 2023, and 56% more that in May 2022.