Security News

Behind the Scenes of Matveev's Ransomware Empire: Tactics and Team
2023-12-19 15:16

Cybersecurity researchers have shed light on the inner workings of the ransomware operation led by Mikhail Pavlovich Matveev, a Russian national who was indicted by the U.S. government earlier...

FBI develops decryptor for BlackCat ransomware, seizes gang's website
2023-12-19 14:59

"As a result of our office's tireless efforts, alongside FBI Miami, US Secret Service, and our foreign law enforcement partners, we have provided BlackCat's victims, in the Southern District of Florida and around the world, the opportunity to get back on their feet and to fortify their digital defenses. We will continue to focus on holding the people behind the BlackCat ransomware group accountable for their crimes." An AlphV admin said the law enforcement agencies only had access to a "Stupid old key" for the old blog site which was deleted by the group a long time ago and has since not been used.

FBI disrupts Blackcat ransomware operation, creates decryption tool
2023-12-19 14:16

The Department of Justice announced today that the FBI successfully breached the ALPHV ransomware operation's servers to monitor their activities and obtain decryption keys. With this access, the FBI silently monitored the ransomware operation for months, siphoning decryption keys and sharing them with over 500 victims so that they did not have to pay a ransom for a decryptor.

Wiz and Apiiro partner to provide context-driven security from code to cloud
2023-12-19 14:00

Apiiro, a leading application security posture management solution, today announced its partnership with Wiz, the leading cloud security company and Cloud Native Application Protection Platform provider. By joining Wiz Integrations, Apiiro brings the power of deep ASPM to the partner ecosystem, providing unified and contextual code-to-cloud application security.

Hackers Abusing GitHub to Evade Detection and Control Compromised Hosts
2023-12-19 13:30

Threat actors are increasingly making use of GitHub for malicious purposes through novel methods, including abusing secret Gists and issuing malicious commands via git commit messages. "Malware...

OpenAI Is Not Training on Your Dropbox Documents—Today
2023-12-19 12:09

There's a rumor flying around the Internet that OpenAI is training foundation models on your Dropbox documents. Dropbox isn't sharing all of your documents with OpenAI. But here's the problem: we don't trust OpenAI. We don't trust tech corporations.

Are We Ready to Give Up on Security Awareness Training?
2023-12-19 11:53

Some of you have already started budgeting for 2024 and allocating funds to security areas within your organization. It is safe to say that employee security awareness training is one of the...

Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa
2023-12-19 11:41

The Iranian nation-state actor known as MuddyWater has leveraged a newly discovered command-and-control (C2) framework called MuddyC2Go in its attacks on the telecommunications sector in Egypt,...

New Malvertising Campaign Distributing PikaBot Disguised as Popular Software
2023-12-19 11:02

The malware loader known as PikaBot is being distributed as part of a malvertising campaign targeting users searching for legitimate software like AnyDesk. "PikaBot was previously only distributed...

Mr. Cooper breach exposes sensitive info of over 14 million customers
2023-12-19 10:33

Mortgage company Mr. Cooper has confirmed that personal information of over 14.6 million customers has been exposed in its October 2023 data breach. "On October 31, 2023, Mr. Cooper detected suspicious activity in certain network systems," the company stated in the data breach notice sent out to affected customers.