Microsoft Fixes Exchange Server Zero-Day in May Patch Tuesday

Microsoft Fixes Exchange Server Zero-Day in May Patch Tuesday

Microsoft fixed 55 vulnerabilities yesterday including three zero-days not thought to have been exploited in the wild, one of which affected the under-fire Exchange Server. This month’s Patch Tuesday is lighter than many have been in recent months, but there were four critical CVEs for admins to address, alongside the three publicly disclosed bugs. Top…

Ransom group DarkSide linked to Colonial Pipeline

Ransom group DarkSide linked to Colonial Pipeline

Ransom software works by encrypting victims’ data; typically hackers will offer the victim a key in return for cryptocurrency payments that can run into the hundreds of thousands or even millions of dollars. If the victim resists, hackers are increasingly threatening to leak confidential data in a bid to pile on the pressure. Loading DarkSide’s…

DarkSide’s Pipeline Ransomware Hit: Strictly Business?

DarkSide’s Pipeline Ransomware Hit: Strictly Business?

Cybercrime , Fraud Management & Cybercrime , Fraud Risk Management Affiliate-Driven Ransomware-as-a-Service Operations Keep Generating Big Profits Mathew J. Schwartz (euroinfosec) • May 11, 2021     Statements posted to DarkSide’s data leak site “It’s not personal, Sonny. It’s strictly business.” See Also: Live Webinar | Software Security: Prescriptive vs. Descriptive That immortal…

Colonial Pipeline Attack: ‘All Monsters Are Human’

Colonial Pipeline Attack: ‘All Monsters Are Human’

Critical Infrastructure Security , Cybercrime as-a-service , Cyberwarfare / Nation-State Attacks Cybereason’s Sam Curry on DarkSide and New Breed of Ransomware Attack Tom Field (SecurityEditor) • May 12, 2021     Sam Curry, CSO, Cybereason In April, Cybereason published a blog describing its research into the DarkSide ransomware strain that infected…