Security News

Australian insurance firm Medibank confirms ransomware attack
2022-10-17 17:56

Health insurance provider Medibank has confirmed that a ransomware attack is responsible for last week's cyberattack and disruption of online services.Medibank Private Limited is one of Australia's largest private health insurance providers, covering over 3.7 million people and having 4,000 employees.

Ransomware attack halts circulation of some German newspapers
2022-10-17 14:33

German newspaper 'Heilbronn Stimme' published today's 28-page issue in e-paper form after a Friday ransomware attack crippled its printing systems. On Saturday, the newspaper issued an "Emergency" six-page edition while all planned obituaries were posted on the website.

Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devices
2022-10-16 08:30

Lack of transparency, systemic risks weaken national cybersecurity preparednessBob Kolasky, SVP for Critical Infrastructure at Exiger, previously served as Assistant Director for Cybersecurity and Infrastructure Security Agency, and in this Help Net Security interview talks about protecting critical infrastructure, the importance of information-sharing, national cybersecurity preparedness, and more. Weakness in Microsoft Office 365 Message Encryption could expose email contentsWithSecure researchers are warning organizations of a security weakness in Microsoft Office 365 Message Encryption that could be exploited by attackers to obtain sensitive information.

Indian Energy Company Tata Power's IT Infrastructure Hit By Cyber Attack
2022-10-15 04:48

Tata Power Company Limited, India's largest integrated power company, on Friday confirmed it was targeted by a cyberattack. The intrusion on IT infrastructure impacted "Some of its IT systems," the company said in a filing with the National Stock Exchange of India.

Mirai Botnet Hits Wynncraft Minecraft Server with 2.5 Tbps DDoS Attack
2022-10-14 07:14

Web infrastructure and security company Cloudflare disclosed this week that it halted a 2.5 Tbps distributed denial-of-service attack launched by a Mirai botnet. Characterizing it as a "Multi-vector attack consisting of UDP and TCP floods," researcher Omer Yoachimik said the DDoS attack targeted the Minecraft server Wynncraft in Q3 2022.

PoC Exploit Released for Critical Fortinet Auth Bypass Bug Under Active Attacks
2022-10-14 03:35

A proof-of-concept exploit code has been made available for the recently disclosed critical security flaw affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager, making it imperative that users move quickly to apply the patches. "FortiOS exposes a management web portal that allows a user to configure the system," Horizon3.

Fast Company says Executive Board member info was not stolen in attack
2022-10-13 20:48

American business magazine Fast Company reached out to its Executive Board members this week to let them know their personal information was not stolen in a September 27 cyberattack that forced it to shut down its website. "The hacked downloaded Fast Company contributor user names and passwords and made the obtained information available for purchase on the web site called Breach Forums," Fast Company said in a notification shared with us by a reader.

Russian DDoS attack project pays contributors for more firepower
2022-10-13 17:23

A pro-Russian group created a crowdsourced project called 'DDOSIA' that pays volunteers launching distributed denial-of-service attacks against western entities. In hacktivist DDoS attacks, volunteers don't get a monetary reward.

New Alchimist attack framework hits Windows, Linux and Mac
2022-10-13 15:24

New Alchimist attack framework hits Windows, Linux and Mac. During initialization, all its content is placed in hard coded folders, namely /tmp/Res for the web interface, HTML files and more folders, and /tmp/Res/Payload for its payloads for Windows and Linux operating systems.

Cloudflare mitigated record DDoS attack against Minecraft server
2022-10-13 13:01

Wynncraft, one of the largest Minecraft servers, was recently hit by a 2.5 Tbps distributed denial-of-service attack. It was a multi-vector attack that lasted for about two minutes and consisted of UDP and TCP floods packets attempting to overwhelm the server and keep out hundreds of thousands of players, DDoS mitigation company Cloudflare says.