92% of Exchange servers safe from ProxyLogon attacks

92% of Exchange servers safe from ProxyLogon attacks

Roughly 92% of all Internet-connected on-premises Microsoft Exchange servers affected by the ProxyLogon vulnerabilities are now patched and safe from attacks, Microsoft said on Monday. A total of 400,000 Internet-connected Exchange servers were impacted by the ProxyLogon vulnerabilities when Microsoft issued the initial security patches, on March 2, with over 100,000 of them still unpatched one…

Ransomware-Wielding Gangs Love to Phish With Trojan Loaders

Ransomware-Wielding Gangs Love to Phish With Trojan Loaders

Fraud Management & Cybercrime , Fraud Risk Management , Next-Generation Technologies & Secure Development Spearheaded by Ryuk and Vatet, Gangs Wield Commodity Downloaders, Researchers Warn Mathew J. Schwartz (euroinfosec) • March 25, 2021     Ryuk ransom note (Source: Coveware) Criminals operating online continue to tap ransomware in their pursuit of an illicit payday. See…

Chinese hackers used Facebook to spy on Uighurs abroad, firm says | Cybercrime News

Chinese hackers used Facebook to spy on Uighurs abroad, firm says | Cybercrime News

Facebook says hackers used the site to lure activists, journalists, dissidents to others containing links to malware. Facebook Inc says it has blocked a group of hackers in China who used the platform to fool Uighurs living abroad into clicking on links to malware that would infect their devices and enable surveillance. The social media…

6 Cloud Security Resources that You Should Be Using

6 Cloud Security Resources that You Should Be Using

It’s easy to get overwhelmed with the number of cloud security resources available. How do you know which sources to trust? Which ones should inform your security strategies? Which reports will actually improve your cloud security posture? Let’s first look at six cloud security guides that you should be using. These resources provide action items…

CNA Suffers “Sophisticated” Cyber-Attack – Infosecurity Magazine

CNA Suffers “Sophisticated” Cyber-Attack – Infosecurity Magazine

The website of insurance giant CNA is out of action following a cyber-attack that took place over the weekend. Visitors to the website of the Chicago-based firm are greeted with a notice explaining that threat actors have disrupted the company’s network.  In a statement released Tuesday evening, CNA described the assault as a “sophisticated cybersecurity attack.” The company said that…

Chinese hackers used Facebook to target dissidents, activists with iOS, Android malware

Chinese hackers used Facebook to target dissidents, activists with iOS, Android malware

Facebook said it has disrupted a cyberespionage operation orchestrated by China-backed hackers that has been targeting activists, journalists and dissidents predominantly among Uyghurs living abroad. The threat actor behind this campaign is believed to be a hacker group known as Earth Empusa or Evil Eye. The malicious actor used Facebook to distribute links…

Covid-19: Vaccine export ban ‘a slippery slope’, says Euro official

Covid-19: Vaccine export ban ‘a slippery slope’, says Euro official

European Parliament vice-president Nicola Beer says heads of state must turn the EU summit on boosting vaccine supplies and distribution into a global response to the coronavirus pandemic. She told BBC World News the EU should join forces with global leaders, including UK Prime Minister Boris Johnson. A vaccine export ban would result in a…

REvil Ransomware Can Now Reboot Infected Devices

REvil Ransomware Can Now Reboot Infected Devices

Business Continuity Management / Disaster Recovery , Fraud Management & Cybercrime , Governance & Risk Management MalwareHunterTeam Finds Updated Capabilities Akshaya Asokan (asokan_akshaya) • March 24, 2021     The REvil ransomware gang has added a new malware capability that enables the attackers to reboot an infected device after encryption, security researchers at MalwareHunterTeam report….