Recent Security News

  • US government tells hospitals: Meet security standards or no federal dollars for you

    January 10, 2024 at 03:37PM The White House is expected to propose rules requiring US hospitals to meet cybersecurity standards before receiving federal funding. This move aims to combat ransomware attacks on healthcare facilities. The rules, set to take effect this year, will link hospital IT security with funding. Stakeholders’ feedback will be valued, with…

    Read More

  • Bitcoin Prices Spike After SEC X Account Hack

    January 10, 2024 at 03:11PM The SEC’s Twitter account was hacked, leading to a fraudulent post about ETF approval. The SEC launched an investigation, confirming the compromise was due to an unknown individual gaining control of a phone number associated with the account. The incident caused a 5% increase in Bitcoin’s price and underscored the…

    Read More

  • Be honest. Would you pay off a ransomware crew?

    January 10, 2024 at 03:01PM The text discusses the complex issue of ransomware and the potential effectiveness of banning ransom payments to curb attacks. It also touches on criminal tactics like threatening to involve police SWAT teams. The piece mentions a colleague’s opinion piece and invites further discussion. The episode features vultures Chris Williams, Brandon…

    Read More

  • Pro-Ukraine hackers breach Russian ISP in revenge for KyivStar attack

    January 10, 2024 at 02:49PM The pro-Ukraine hacktivist group ‘Blackjack’ claimed a cyberattack on Russian ISP M9com in retaliation for an attack on Ukraine’s Kyivstar mobile operator. The attack disrupted M9com’s services and exposed confidential data. Blackjack promised more attacks as retaliation for the Kyivstar hack. The group is reportedly linked to the Security Service…

    Read More

  • Ivanti warns of Connect Secure zero-days exploited in attacks

    January 10, 2024 at 01:59PM Ivanti has disclosed two zero-day vulnerabilities in its Connect Secure (ICS) and Policy Secure products. The CVE-2023-46805 flaw bypasses authentication, while CVE-2024-21887 allows arbitrary command execution. Chaining the two enables attackers to run commands without authentication. Ivanti is working on patches, with mitigation available until then. The company reports limited…

    Read More