Security News

ConnectWise urges ScreenConnect admins to patch critical RCE flaw
2024-02-20 16:48

ConnectWise warned customers to patch their ScreenConnect servers immediately against a maximum severity flaw that can be used in remote code execution attacks. ConnectWise has yet to assign CVE IDs to the two security flaws that impact all servers running ScreenConnect 23.9.7 and prior.

Knight ransomware source code for sale after leak site shuts down
2024-02-20 16:28

The alleged source code for the third iteration of the Knight ransomware is being offered for sale to a single buyer on a hacker forum by a representative of the operation. Knight ransomware launched at the end of July 2023 as a re-brand of the Cyclops operation, targeting Windows, macOS, and Linux/ESXi systems.

Cops turn LockBit ransomware gang's countdown timers against them
2024-02-20 16:00

After the infosec world was invigorated by the announcement of LockBit's site being seized yesterday, the authorities involved in the takedown operation - dubbed "Operation Cronos" - have now completely taken over the group's leak site and turned it into an exposé hub. In typical LockBit style, its countdown timers have been hijacked to reveal the times at which various pieces of information will be revealed, including what appears to be the identity of LockBit's leader.

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining
2024-02-20 15:20

A novel malware campaign has been observed targeting Redis servers for initial access with the ultimate goal of mining cryptocurrency on compromised Linux hosts. "This particular campaign involves...

Wyze admits 13,000 users could have viewed strangers' camera feeds
2024-02-20 15:15

Smart home security camera slinger Wyze is telling customers that a cybersecurity "Incident" allowed thousands of users to see other people's camera feeds. Thanks to a helpful Reg reader who sent a customer email over to us, we know that around 13,000 Wyze users had the opportunity to view events captured by other users' cameras.

Ransomware Groups, Targeting Preferences, and the Access Economy
2024-02-20 15:01

Ransomware attackers are opportunistic criminals that exploit easily accessible targets, often leveraging initial access points provided by other cybercriminals, rather than creating these access points themselves. While we suspect many ransomware groups and affiliates directly leverage access gained through infostealers, many others choose the "White glove" service that initial access brokers offer.

Top 4 Ivanti Competitors and Alternatives for 2024
2024-02-20 14:41

Ivanti Secure VPN is a popular remote access VPN solution used by businesses, organizations and governments worldwide. French cyberdefense search engine ONYPHE has said that 29,664 Ivanti Secure VPN appliances are connected to the internet.

Critical infrastructure software maker confirms ransomware attack
2024-02-20 14:36

PSI Software SE, a German software developer for complex production and logistics processes, has confirmed that the cyber incident it disclosed last week is a ransomware attack that impacted its internal infrastructure. The company operates at a global level with a staff of more than 2,000 and specializes in software solutions for major energy suppliers.

LockBit Ransomware Operation Shut Down; Criminals Arrested; Decryption Keys Released
2024-02-20 12:55

The U.K. National Crime Agency (NCA) on Tuesday confirmed that it obtained LockBit's source code as well as intelligence pertaining to its activities and their affiliates as part of a dedicated...

New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics
2024-02-20 12:30

Cybersecurity researchers have discovered two malicious packages on the Python Package Index (PyPI) repository that were found leveraging a technique called DLL side-loading to circumvent...