Security News

North Korean Hackers Turn to Credential Harvesting in Latest Wave of Cyberattacks
2023-01-25 10:41

A North Korean nation-state group notorious for crypto heists has been attributed to a new wave of malicious email attacks as part of a "Sprawling" credential harvesting activity targeting a number of industry verticals, marking a significant shift in its strategy. The state-aligned threat actor is being tracked by Proofpoint under the name TA444, and by the larger cybersecurity community as APT38, BlueNoroff, Copernicium, and Stardust Chollima.

Gamaredon Group Launches Cyberattacks Against Ukraine Using Telegram
2023-01-20 13:35

The Russian state-sponsored cyber espionage group known as Gamaredon has continued its digital onslaught against Ukraine, with recent attacks leveraging the popular messaging app Telegram to strike military and law enforcement sectors in the country. "The Gamaredon group's network infrastructure relies on multi-stage Telegram accounts for victim profiling and confirmation of geographic location, and then finally leads the victim to the next stage server for the final payload," the BlackBerry Research and Intelligence Team said in a report shared with The Hacker News.

Royal Mail cyberattack linked to LockBit ransomware operation
2023-01-12 23:43

A cyberattack on Royal Mail, UK's largest mail delivery service, has been linked to the LockBit ransomware operation. "Royal Mail is experiencing severe service disruption to our international export services following a cyber incident," disclosed Royal Mail in a service update.

Royal Mail halts international services after cyberattack
2023-01-11 17:13

The Royal Mail, UK's leading mail delivery service, has stopped its international shipping services due to "Severe service disruption" caused by what it described as a "Cyber incident." "Incident was detected yesterday, UK/ domestic mail remains unaffected," a Royal Mail spokesperson told BleepingComputer when we reached out for more details earlier today.

Iowa’s largest school district cancels classes after cyberattack
2023-01-10 18:10

Des Moines Public Schools, the largest school district in Iowa, canceled all classes on Tuesday after taking all networked systems offline in response to "Unusual activity" detected on its network one day before. "Because many technology tools that support both classroom learning as well as the management and operation of the school district are not available at this time, the prudent decision is to close the district for the day."

Recent 2022 cyberattacks presage a rocky 2023
2023-01-06 19:22

This week rang in 2023 with a chorus of news on ransomware, DDoS, mass exfiltration, phishing attacks, revelations of attacks past, and threats of attacks to come. The exfiltration of a reputed 230 million Twitter users' private-date records was due to a zero-day application programming interface flaw by an attacker who may or may not be known as Ryushi.

Rackspace confirms Play ransomware was behind recent cyberattack
2023-01-04 22:21

Texas-based cloud computing provider Rackspace has confirmed that the Play ransomware operation was behind a recent cyberattack that took down the company's hosted Microsoft Exchange environments. While Crowdstrike didn't name the victim in their report, Rackspace officials have revealed in recent local media interviews and emails to BleepingComputer that the OWASSRF exploit was found on its network and Play ransomware was behind last month's ransomware attack.

Trojanized Windows 10 Installer Used in Cyberattacks Against Ukrainian Government Entities
2022-12-16 14:00

Government entities in Ukraine have been breached as part of a new campaign that leveraged trojanized versions of Windows 10 installer files to conduct post-exploitation activities. Mandiant, which discovered the supply chain attack around mid-July 2022, said the malicious ISO files were distributed via Ukrainian- and Russian-language Torrent websites.

FuboTV says World Cup streaming outage caused by a cyberattack
2022-12-15 23:40

FuboTV has confirmed that a streaming outage preventing subscribers from watching the World Cup Qatar 2022 semifinal match between France and Morocco was caused by a cyberattack. Subscribers could not contact support to report the problem, as it requires a user to first log in to the FuboTV site, which could no longer be done.

Malicious Microsoft-signed Windows drivers wielded in cyberattacks
2022-12-14 23:24

Microsoft says it has suspended several third-party developer accounts that submitted malicious Windows drivers for the IT giant to digitally sign so that the code could be used in cyberattacks. These moves come after eggheads at Google-owned Mandiant, SentinelOne, and Sophos told Microsoft in October that multiple cybercrime gangs were using malicious third-party-developed Microsoft-signed kernel-mode hardware drivers to help spread ransomware.