Security News > 2024 > May

Ransomware statistics that reveal alarming rate of cyber extortion
2024-05-15 04:00

In this article, you will find excerpts from various reports that offer statistics and insights about the current ransomware landscape. In January, Corvus reported that global ransomware attacks in 2023 set a record high, surpassing 2022 by close to 70%. According to the data, 1,075 leak site ransomware victims were posted on leak sites during the first quarter of 2024, despite the disruption of two major ransomware groups, LockBit and ALPHV/BlackCat, which accounted for 22% and 8% of the activity, respectively.

Key questions to ask when tailoring defensive stacks
2024-05-15 03:30

In this Help Net Security video, Scott Small, Director of Cyber Threat Intelligence at Tidal Cyber, outlines the questions you need to ask your security team when tailoring a defense stack against your current threat landscape. Small talks about what what those questions are, where can you find answers, and how you should address them.

Cybersecurity analysis exposes high-risk assets in power and healthcare sectors
2024-05-15 03:00

To understand the scope of exposure and the associated risk facing cyber-physical systems environments, Claroty's research group Team82 analyzed data from over 20 million operational technology, connected medical devices, IoT, and IT assets in CPS environments. Researchers defined "High risk" as having a high likelihood and high impact of being exploited, based on a combination of risk factors such as end-of-life state, communication with insecure protocols, known vulnerabilities, weak or default passwords, PII or PHI data, consequence of failure, and several others.

Microsoft fixes a bug abused in QakBot attacks plus a second under exploit
2024-05-14 22:15

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers
2024-05-14 22:10

The D-Link EXO AX4800 router is vulnerable to remote unauthenticated command execution that could lead to complete device takeovers by attackers with access to the HNAP port. The D-Link DIR-X4860 router is a high-performance Wi-Fi 6 router capable of speeds of up to 4800 Mbps and advanced features like OFDMA, MU-MIMO, and BSS Coloring that enhance efficiency and reduce interference.

FCC names and shames Royal Tiger AI robocall crew
2024-05-14 21:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Microsoft fixes VPN failures caused by April Windows updates
2024-05-14 20:15

"Windows devices might face VPN connection failures after installing the April 2024 security update or the April 2024 non-security preview update," Redmond explains on the Windows health dashboard. The list of impacted Windows versions includes Windows 11, Windows 10, and Windows Server 2008 and later.

Singing River Health System: Data of 895,000 stolen in ransomware attack
2024-05-14 20:08

The Singing River Health System is warning that it is now estimating that 895,204 people are impacted by a ransomware attack it suffered in August 2023. [...]

VMware makes Workstation Pro and Fusion Pro free for personal use
2024-05-14 19:34

VMWare has made Workstation Pro and Fusion Pro free for personal use, allowing home users and students to set up their own virtualized test labs and play with another operating system at little to no cost. We have some good news for a change, with VMware announcing yesterday that VMware Workstation Pro and Fusion Pro are now free for personal use.

Microsoft fixes Windows Server bug causing crashes, NTLM auth failures
2024-05-14 19:11

Microsoft has fixed a known issue causing NTLM authentication failures and domain controller reboots after installing last month's Windows Server security updates. [...]