New ScreenConnect RCE flaw exploited in ransomware attacks

February 23, 2024 at 07:15AM Sophos reported that recent ransomware attacks used the leaked LockBit ransomware builder, dropped on 30 customer networks and created by a different threat actor. The attacks exploit an authentication bypass vulnerability in unpatched ScreenConnect servers, prompting CISA to issue a security directive. Despite a law enforcement operation, LockBit attacks continue … Read more

UnitedHealth confirms Optum hack behind US healthcare billing outage

February 23, 2024 at 04:42AM US healthcare giant UnitedHealth Group’s subsidiary Optum experienced a cyberattack by suspected “nation-state” hackers, leading to IT system shutdowns and service disruptions. The incident impacts 119 Change Healthcare and Optum services, affecting payment processing in pharmacies and leading to widespread disconnection from UHG services. The exact nature and extent of … Read more

Hubris May Have Contributed to Downfall of Ransomware Kingpin LockBit

February 22, 2024 at 06:47PM The LockBit ransomware group faced issues and was shut down by an international law enforcement effort led by the UK’s National Crime Agency due to dissent among members and affiliates. The takedown disrupted its infrastructure and led to several arrests. The group’s viability and reputation have been severely affected, and … Read more

Authorities dismantled LockBit before it could unleash revamped variant

February 22, 2024 at 02:56PM Law enforcement’s disruption of the LockBit ransomware crew revealed they were developing a new variant. Unlike competitors, LockBit chose .NET and CoreRT instead of Rust for its latest locker. The in-development variant aimed to counter code leaks with a new expiry date but lacked some capabilities of previous versions. The … Read more

ScreenConnect servers hacked in LockBit ransomware attacks

February 22, 2024 at 01:35PM Attackers exploit a severe authentication bypass vulnerability to breach unpatched ScreenConnect servers, deploying LockBit ransomware. ConnectWise released security updates, including a patch for a high-severity path traversal flaw. Both bugs impact all ScreenConnect versions. CISA ordered U.S. federal agencies to secure servers within a week. Threat actors have deployed LockBit … Read more

Ukrainian police arrest father and son in suspected LockBit affiliate double act

February 22, 2024 at 10:35AM Father-son duo apprehended in Ukraine as part of LockBit leaks takedown. National Police of Ukraine confirms their identity and involvement in attacks on individuals, businesses, and public institutions in France. LockBit’s total attacks exceed 3,000. Five LockBit affiliates arrested this week. US offers $10 million reward for information on LockBit’s … Read more

4 Key Steps to Reevaluate Your Cybersecurity Priorities

February 22, 2024 at 10:28AM Cyber extortion reached a new peak in early 2023. Businesses face rising cyberattacks, especially targeting sensitive data holders like banks and hospitals. Financially motivated cybercriminals exploit victims’ willingness to pay. Brands must respond transparently to incidents. It is critical for boards to elevate cybersecurity, audit sensitive information, update incident response … Read more

LockBit ransomware secretly building next-gen encryptor before takedown

February 22, 2024 at 08:52AM LockBit ransomware developers were working on a new version, LockBit-NG-Dev, likely to become LockBit 4.0, before law enforcement dismantled their infrastructure. Trend Micro’s analysis revealed this new version’s capabilities, including support for multiple operating systems and encryption modes, though lacking some features from previous iterations. The discovery poses a challenge … Read more

US Offering $10M for LockBit Leaders as Law Enforcement Taunts Cybercriminals

February 22, 2024 at 07:51AM The United States is offering significant rewards for information about cybercriminals involved in the disrupted LockBit ransomware operation. Law enforcement agencies have made seizures and implemented disruptions to the cybercrime operation, even mocking cybercriminals and taking down associated servers. Rewards, charges, sanctions, and crackdowns on individuals continue amidst skepticism about … Read more

LockBit Attempts to Stay Afloat With a New Version

February 22, 2024 at 03:04AM Summary: LockBit, a Ransomware-as-a-Service, faced internal and external challenges resulting in a decline. The leaked LockBit builder led to confusion and loss of confidence. Technical issues and dissatisfaction among affiliates further aggravated the situation. The recent development of LockBit-NG-Dev suggests an upcoming version, indicating efforts to revive the group’s deteriorating … Read more