Wed.Mar 15, 2023

article thumbnail

Long-Term Care Services Firm Says Breach Affects 4.2 Million

Data Breach Today

Inaccessible Computers' Incident Initially Reported as Affecting 501 People A vendor of clinical and third-party administrative services to managed care organizations and healthcare providers serving elderly and disabled patients said a cybersecurity incident last summer has affected more than 4.2

article thumbnail

Microsoft Patch Tuesday, March 2023 Edition

Krebs on Security

Microsoft on Tuesday released updates to quash at least 74 security bugs in its Windows operating systems and software. Two of those flaws are already being actively attacked, including an especially severe weakness in Microsoft Outlook that can be exploited without any user interaction.

Passwords 225
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

MKS Instruments Ransomware Attack Results in $200M Sales Hit

Data Breach Today

Attack Removed MKS' Ability to Process Orders, Ship Products or Provide Services MKS Instruments expects a $200 million revenue hit from February's ransomware attack after the hack removed the company's ability to process orders or ship products. The Feb.

Sales 246
article thumbnail

Analysts Spot a Wave of SVB-Related Cyber Fraud Striking the Business Sector

Dark Reading

Over the weekend, cybercriminals laid the groundwork for Silicon Valley Bank-related fraud attacks that they're now starting to cash in on. Businesses are the targets and, sometimes, the enablers

142
142
article thumbnail

Everything You Need to Know About Crypto

Speaker: Ryan McInerny, CAMS, FRM, MSBA - Principal, Product Strategy

This exclusive webinar with Ryan McInerny will teach you all about cryptocurrency and NFTs! Register to learn more about identifying crypto transactions, crypto asset market trends, managing risk and compliance, and supporting customers and partners using crypto-based payments.

article thumbnail

Rubrik Breached Via Zero-Day Attack Exploiting GoAnywhere

Data Breach Today

Company Says Data Breach Ties to Fortra Software Exploit; Nothing Sensitive Stolen Cybersecurity software giant Rubrik has joined the ranks of organizations that fell victim to attackers who have been exploiting a zero-day vulnerability in Fortra's widely used managed file transfer software, GoAnywhere MFT.

More Trending

article thumbnail

Proof of Concept: Is New US Cyber Strategy Really Viable?

Data Breach Today

Panel Discusses Political and Policy Realities of Mandates, Vendor Liability, Costs In the latest "Proof of Concept" panel discussion, two Capitol Hill observers at Venable, Grant Schneider and Jeremy Grant, join Information Security Media Group editors to break down the Biden administration's new U.S.

article thumbnail

SMBs Orgs Want Help, but Cybersecurity Expertise Is Scarce

Dark Reading

Smaller firms are boosting cybersecurity budgets, but there's a long way to go to address a deep lack of cyber preparedness among SMBs

article thumbnail

CISA Alert: 4-Year-Old Software Bug Exploited at US Agency

Data Breach Today

Progress Telerik UI's.NET NET Vulnerability Could Lead to Remote Code Execution U.S. cybersecurity officials on Thursday issued an alert about a 4-year-old software vulnerability that has been exploited by hackers, including one APT group, in a federal civilian agency.

article thumbnail

GoatRAT Android Banking Trojan Targets Mobile Automated Payment System

Dark Reading

The new malware was discovered targeting three banks in Brazil

111
111
article thumbnail

Contact vs. Company Intent Signal Data

Intent signal data comes in two types: either companies or individuals signaling interest in products like yours. Which kind of data delivers more advantages to B2B marketers? It depends. Get this infographic to learn about the advantages of intent-based leads and how you can most effectively use both types of data.

article thumbnail

Microsoft Fixes Russia-Exploited Zero Day

Data Breach Today

Patch Tuesday Fixes Address 80 Vulnerabilities, Including 8 Critical Ones Microsoft's March dump of patches fixes two actively exploited zero-day vulnerabilities, including a critical issue in Outlook that Russian threat actor APT28 has used to target European companies.

article thumbnail

Cyberattackers Continue Assault Against Fortinet Devices

Dark Reading

Patched earlier this month, a code-execution vulnerability is the latest FortiOS weakness to be exploited by attackers, who see the devices as well-placed targets for initial access operations

Access 105
article thumbnail

Rapid7 Buys Ransomware Prevention Firm Minerva Labs for $38M

Data Breach Today

Deal Will Help Rapid7 Neutralize and Prevent Malicious Activity Prior to Execution Rapid7 has purchased a ransomware prevention vendor founded by a former Israel Defense Forces captain to strengthen its managed detection and response muscle.

article thumbnail

How Do Attackers Hijack Old Domains and Subdomains?

Dark Reading

Here is a cautionary tale of what happens if side-projects or sections of the website becomes obsolete. If you don't remove them, someone might hijack your subdomain

104
104
article thumbnail

Exploring the Overlap: Cost Optimization and Digital Transformation

Speaker: Alex Jiménez, Managing Principal, Financial Service Consulting for EPAM

The largest banks have increased reserves for protection against deteriorating economic conditions. Should banks delay their digital transformation investments and focus on cost reductions? In this webinar, Alex Jiménez will walk us through that question and examine the prudent course of action.

article thumbnail

US SEC Amps Up Regulatory Proposals for Market Cybersecurity

Data Breach Today

Biden Administration Officials Show Impatience With Hacking Risk The Securities and Exchange Commission proposed a slew of new cybersecurity rules for the companies underpinning the U.S.

Marketing 130
article thumbnail

Telerik Bug Exploited to Steal Federal Agency Data, CISA Warns

Dark Reading

An unpatched Microsoft Web server allowed multiple cybersecurity threat groups to steal data from a federal civilian executive branch

article thumbnail

Illicit Crypto Miners Find a New Fav in Privacy Coin Dero

Data Breach Today

CrowdStrike Finds Dero Cryptojacking Operations on Kubernetes Cluster Threat actors who mine digital assets using other people's infrastructure have found a lucrative new cryptocurrency to motivate their hacking: the privacy focused currency named Dero.

Mining 130
article thumbnail

Why Security Practitioners Should Understand Their Business

Dark Reading

The sooner CISOs become proactive in understanding the flip side of the organizations they protect, the better they'll be at their jobs

article thumbnail

Intent Signal Data 101

Intent signal data helps B2B marketers engage with buyers sooner in the sales cycle. But there are many confusing terms used to describe intent data. Read this infographic to better understand three common areas of confusion.

article thumbnail

This Is the New Leader of Russia's Infamous Sandworm Hacking Unit

WIRED Threat Level

Evgenii Serebriakov now runs the most aggressive hacking team of Russia’s GRU military spy agency. To Western intelligence, he’s a familiar face. Security Security / Cyberattacks and Hacks Security / National Security

article thumbnail

Hornetsecurity Launches VM Backup V9

Dark Reading

Hornetsecurity research highlights that more than 1 in 4 companies have fallen victim to ransomware attacks, with 14.1% losing data and 6.6% paying a ransom

article thumbnail

79% of Employee-Reported Phishing Emails Go Completely Undetected by Cybersecurity Solutions

KnowBe4

As cybercriminals increasingly turn to malwareless phishing attacks, the ability for security solutions to correctly identify a malicious email is becoming more and more difficult. Phishing

article thumbnail

Are We Doing Enough to Protect Our Unstructured Data?

Dark Reading

Organizations are coming under pressure to protect their data, but does all data need the same security? To secure it, you first need to know what and where it is

article thumbnail

The Anti-Money Laundering Act of 2020: Initial Catalysts, Current Implications, and Future Impacts

Speaker: Elizabeth "Paige" Baumann, Founder and CEO of Paige Baumann Advisory, LLC

In this session, Elizabeth “Paige” Baumann will cover the Anti-Money Laundering Act of 2020, which also includes the Corporate Transparency Act. She'll take a deep dive into the catalysts that brought on the act, the current implications of the act, and what impacts the act has on the future of banking and finance.

article thumbnail

A Spy Wants to Connect With You on LinkedIn

WIRED Threat Level

Russia, North Korea, Iran, and China have been caught using fake profiles to gather information. But the platform’s tools to weed them out only go so far. Security Security / Cyberattacks and Hacks Security / National Security

article thumbnail

'Vile' Gang Duo Breaches Police Database, Impersonates Officers in Extortion Gambit

Dark Reading

Two gang members are being charged for allegedly threatening to release personal information and impersonating law enforcement in an effort to dox victims

92
article thumbnail

University of Sydney Gives Students and Staff Advice on Avoiding Social Engineering Scams

KnowBe4

The University of Sydney has issued advice to help students and staff avoid falling for social engineering attacks. Social Engineering

79
article thumbnail

Key aerospace player Safran Group leaks sensitive data

Security Affairs

Top aviation company Safran Group left itself vulnerable to cyberattacks, likely for well over a year, underlining how vulnerable big aviation firms are to threat actors, according to research by Cybernews.

article thumbnail

Aggregage Intent Signal Service

Aggregage Intent Signal Service helps your sales team reach more active buyers sooner. You’ll get names and contact information of specific in-market buyers plus all companies and job titles signaling intent for your product or service. Get the overview to learn more!

article thumbnail

DirectDefense Reports the Top Threats From 2022 and What's Trending for 2023

Dark Reading

Research found that phishing threats were low in 2022, while foreign login activity and application process analysis accounted for nearly 50% of incident alerts

article thumbnail

Security Firm Rubrik breached by Clop gang through GoAnywhere Zero-Day exploitation

Security Affairs

Data security firm Rubrik discloses a data breach, attackers exploited recent GoAnywhere zero-day to steal its data.

Sales 76
article thumbnail

SecurityScorecard Appoints Former US Congressman John Katko As Senior Advisor

Dark Reading

Capitol Hill cybersecurity leader joins the company’s Cybersecurity Advisory Board to drive further adoption of security ratings in the public and private sectors