Ransomware Group Claims Attack on Virginia Attorney General’s Office

The Cloak ransomware group has claimed responsibility for a February cyberattack on Virginia Attorney General’s Office.

The post Ransomware Group Claims Attack on Virginia Attorney General’s Office appeared first on SecurityWeek.

SecurityWeek – ​Read More

Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates

The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER as part of a bring your own vulnerable driver (BYOVD) attack designed to disable anti-malware tools.
Elastic Security Labs said it observed a Medusa ransomware attack that delivered the encryptor by means of a loader packed using a packer-as-a-service (PaaS

The Hacker News – ​Read More

Why Cyber Quality Is the Key to Security

The time to secure foundations, empower teams, and make cyber resilience the standard is now — because the cost of waiting is far greater than the investment in proactive security.

darkreading – ​Read More

New Attacks Exploit Year-Old ServiceNow Flaws – Israel Hit Hardest

ServiceNow vulnerability alert: Hackers are actively exploiting year-old flaws (CVE-2024-4879, CVE-2024-5217, CVE-2024-5178) for database access. Learn how to…

Hackread – Latest Cybersecurity, Tech, AI, Crypto & Hacking News – ​Read More

Russian zero-day seller is offering up to $4 million for Telegram exploits

Two sources in the zero-day industry say Operation Zero’s prices for exploits against the popular messaging app Telegram will depend on different factors.

Security News | TechCrunch – ​Read More

Industry Reactions to Google Buying Wiz: Feedback Friday

Industry professionals comment on Google acquiring cloud security giant Wiz for $32 billion in cash.

The post Industry Reactions to Google Buying Wiz: Feedback Friday appeared first on SecurityWeek.

SecurityWeek – ​Read More

China-Linked APT Aquatic Panda: 10-Month Campaign, 7 Global Targets, 5 Malware Families

The China-linked advanced persistent threat (APT) group. known as Aquatic Panda has been linked to a “global espionage campaign” that took place in 2022 targeting seven organizations.
These entities include governments, catholic charities, non-governmental organizations (NGOs), and think tanks across Taiwan, Hungary, Turkey, Thailand, France, and the United States. The activity, which took place

The Hacker News – ​Read More

Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley

The FishMonger APT group, a subdivision of Chinese cybersecurity firm I-Soon, compromised seven organizations in a 2022 campaign.

The post Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley appeared first on SecurityWeek.

SecurityWeek – ​Read More

Former NFL, Michigan Assistant Coach Matt Weiss Charged With Hacking for Athletes’ Intimate Photos

Former NFL and University of Michigan assistant football coach Matt Weiss hacked into the computer accounts of thousands of college athletes seeking intimate photos and videos.

The post Former NFL, Michigan Assistant Coach Matt Weiss Charged With Hacking for Athletes’ Intimate Photos appeared first on SecurityWeek.

SecurityWeek – ​Read More

How to Avoid US-Based Digital Services—and Why You Might Want To

Amid growing concerns over Big Tech firms aligning with Trump administration policies, people are starting to move their digital lives to services based overseas. Here’s what you need to know.

Security Latest – ​Read More