E-Root market admin faces 20 years for selling stolen RDP, SSH accounts

October 19, 2023 at 06:42PM Sandu Diaconu, operator of the E-Root marketplace, has been extradited to the U.S. to face a maximum imprisonment penalty of 20 years. He is accused of selling access to compromised computers. Evidence suggests over 350,000 compromised systems were listed for sale on E-Root, including government systems and those from various … Read more

BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks

October 19, 2023 at 05:46PM BlackCat/ALPHV ransomware is using a new tool called ‘Munchkin’ to deploy encryptors on network devices stealthily. The tool runs on virtual machines and allows threat actors to dump passwords, spread on the network, build encryptor payloads, and execute programs on computers. Munchkin makes the ransomware operation more attractive to cybercriminals. … Read more

AI ‘Will Have a Significant Impact on Energy Industry,’ EPRI Tells Congress

October 19, 2023 at 05:24PM EPRI Senior Technical Executive, Jeremy Renshaw, testified before a U.S. House Energy and Commerce Subcommittee on the benefits and challenges of using artificial intelligence (AI) in the energy sector. EPRI has been studying AI’s potential impacts on the energy sector for over a decade and has been involved in over … Read more

Norton Boosts Security and Privacy With Enhanced Password Manager and AntiTrack

October 19, 2023 at 05:16PM Norton, a consumer Cyber Safety brand, has announced new features for Norton Password Manager and Norton AntiTrack. Norton Password Manager now offers a premium password management experience at no cost, with improved security and convenience. Norton AntiTrack includes a new Private Email feature to protect online privacy by masking personal … Read more

Fingerprint Raises $33M in Series C Funding to Accelerate Enterprise Device Intelligence and Fraud Prevention Adoption

October 19, 2023 at 05:16PM Chicago-based device intelligence platform, Fingerprint, has raised $33 million in Series C funding led by Nexus Venture Partners. The platform offers flexible APIs that aid developers in device identification, allowing them to detect fraudsters while ensuring seamless experiences for trusted users. Fingerprint’s funding total now stands at $77 million. The … Read more

Spec Secures $15M Series A Funding, Accelerating Innovation in Fraud Defense

October 19, 2023 at 05:09PM Leading cybersecurity firm, Spec, has successfully closed a $15M Series A funding round led by SignalFire, with participation from Legion Capital and Rally Ventures. The funding will support Spec’s continued growth and innovation, including advancing their platform, expanding their threat labs, and co-developing specialized products. Spec is dedicated to providing … Read more

SailPoint Unveils Annual ‘Horizons of Identity Security’ Report

October 19, 2023 at 05:09PM SailPoint Technologies, in collaboration with Accenture, released the findings from their annual research report, ‘The Horizons of Identity Security.’ The report revealed that 44% of companies are still in the early stages of their identity security journeys, and only 70% of identities in mature companies are covered by foundational governance … Read more

23AndMe Hacker Leaks New Tranche of Stolen Data

October 19, 2023 at 04:47PM A threat actor known as Golem has released a new dataset containing the records of over 4 million people’s genetic ancestry, including information on wealthy individuals in the US and Western Europe, after compromising the 23AndMe site. 23andMe is still verifying the authenticity of the leaked data. The breach was … Read more

North Korean State Actors Attack Critical Bug in TeamCity Server

October 19, 2023 at 04:33PM North Korean state-backed threat groups, Diamond Sleet and Onyx Sleet, are exploiting a critical vulnerability in JetBrains TeamCity server to carry out cyber espionage, data theft, and other malicious activities. Over 30,000 organizations, including Citibank, Nike, and Ferrari, use TeamCity. The vulnerability allows attackers to gain administrative privileges and execute … Read more

Microsoft extends Purview Audit log retention after July breach

October 19, 2023 at 04:27PM Microsoft is extending Purview Audit log retention following the breach of Exchange and Microsoft 365 accounts by the Chinese hacking group Storm-0558. The affected organizations included government agencies, with the US State and Commerce Departments among them. The changes will roll out to customers with Standard licenses, providing longer retention … Read more