Ransomware Hits Hundreds of US Companies, Security Firm Says | Voice of America

Ransomware Hits Hundreds of US Companies, Security Firm Says | Voice of America

A ransomware attack paralyzed the networks of at least 200 U.S. companies Friday, according to a cybersecurity researcher whose company was responding to the incident.   The REvil gang, a major Russian-speaking ransomware syndicate, appears to be behind the attack, said John Hammond of the security firm Huntress Labs. He said the criminals targeted a…

PrintNightmare 0-day can be used to take over Windows domain controllers – Malwarebytes Labs

PrintNightmare 0-day can be used to take over Windows domain controllers – Malwarebytes Labs

PrintNightmare is a 0-day vulbnerability in the widely used Windows Print Spooler service. And working exploits are out there. In a rush to be the first to publish a proof-of-concept (PoC), researchers have published a write-up and a demo exploit to demonstrate a vulnerability that has been dubbed PrintNightmare. Only to find out they had…

CISA Provides Bad Practices List To Reinforce Cyber Infrastructure

CISA Provides Bad Practices List To Reinforce Cyber Infrastructure

The federal Cybersecurity and Infrastructure Security Agency (CISA) released a few cybersecurity “bad practices” this week to assist in decreasing the volume of knowable and preventable cyber mistakes. These bad practices are aimed at educating critical infrastructure owners and operators, as well as the defense industry and the organizations that support the supply chain for…

Kaspersky Comment: Critical Microsoft vulnerability is failed to be patched – leaves devices at significant risk

Kaspersky Comment: Critical Microsoft vulnerability is failed to be patched – leaves devices at significant risk

Kaspersky Comment: Critical Microsoft vulnerability is failed to be patched – leaves devices at significant risk Security researchers have found that, despite recent efforts by Microsoft, a critical windows vulnerability has failed to be patched, allowing hackers to take full control of computers and servers. In early June, Microsoft patched a Windows vulnerability that it…

Microsoft shares mitigations for Windows PrintNightmare zero-day bug

Microsoft shares mitigations for Windows PrintNightmare zero-day bug

Microsoft has provided mitigation guidance to block attacks on systems vulnerable to exploits targeting the Windows Print Spooler zero-day vulnerability known as PrintNightmare. This remote code execution (RCE) bug—now tracked as CVE-2021-34527—impacts all versions of Windows per Microsoft, with the company still investigating if the vulnerability is exploitable on all of them. CVE-2021-34527 allows attackers to take over affected…

Ransomware Breach at Florida IT Firm Kaseya Hits 200 Businesses

Ransomware Breach at Florida IT Firm Kaseya Hits 200 Businesses

Hundreds of American businesses were hit Friday by an unusually sophisticated ransomware attack that hijacked widely used technology management software from a Miami-based supplier called Kaseya. The attackers changed a Kaseya tool called VSA, used by companies that manage technology at smaller businesses. They then encrypted the files of those providers’ customers simultaneously. Security firm…

Kaseya is Focus of New Supply Chain Ransomware Attack

Kaseya is Focus of New Supply Chain Ransomware Attack

3rd Party Risk Management , Breach Notification , Critical Infrastructure Security REvil Malware Suspected of Infecting Scores of IT Management Companies, Clients Akshaya Asokan (asokan_akshaya) • July 3, 2021     UPDATED July 3, 11:30 a.m. EDT See Also: Rapid Digitization and Risk: A Roundtable Preview IT management software vendor Kaseya sustained a suspected…