Bungled ransomware raid targeting WS_FTP servers demanded just 0.018 BTC

October 13, 2023 at 02:22PM Security researchers have discovered the first ransomware campaign targeting organizations using a vulnerability in Progress Software’s WS_FTP Server. The campaign, carried out by the “Reichsadler Cybercrime Group,” demanded a ransom of 0.018 Bitcoin (approximately $500) to recover encrypted files. Sophos’s product prevented the download of the ransomware payload, and patches … Read more

Kwik Trip IT systems outage caused by mysterious ‘network incident’

October 13, 2023 at 02:15PM Summary: Kwik Trip, a US chain of convenience stores and gas stations, has experienced a series of disruptive IT outages since the weekend, potentially due to a ransomware attack. Employees have been unable to receive orders, accept payments, or access support systems, while customers have been frustrated by the inability … Read more

ShellBot Cracks Linux SSH Servers, Debuts New Evasion Tactic

October 13, 2023 at 01:47PM Cyberattackers are using the ShellBot malware to target Linux SSH servers. They are now using hexadecimal IP addresses to evade detection. This new method allows them to hide their activity from behavior-based detection systems. ShellBot is a well-known botnet that compromises servers with weak SSH credentials and can be used … Read more

Microsoft Debuts AI Bug-Bounty Program, Offers $15K

October 13, 2023 at 01:26PM Microsoft has introduced an AI bug-bounty program for researchers to identify vulnerabilities in its Bing generative AI chatbot and AI integrations. Rewards for eligible submissions range from $2,000 to $15,000. The program covers AI-powered Bing on bing.com, as well as integrations in Microsoft Edge, the Microsoft Start app, and Skype … Read more

Microsoft plans to kill off NTLM authentication in Windows 11

October 13, 2023 at 12:50PM Microsoft has announced that the NTLM authentication protocol will be phased out in Windows 11. Kerberos has replaced NTLM as the default authentication protocol since Windows 2000. Despite being used in older versions, NTLM is still vulnerable to attacks such as relay attacks and pass-the-hash attacks. Microsoft is working on … Read more

Gaza Conflict Paves Way for Pro-Hamas Information Operations

October 13, 2023 at 12:29PM Researchers are currently monitoring state-sponsored information operations connected to the Israel-Hamas conflict, but no significant cyber activities have been observed yet. However, experts predict an increase in cyber attacks over time. There have been two notable information operations campaigns identified, one related to Iran and the other to China. The … Read more

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit

October 13, 2023 at 11:38AM A single-click exploit has raised concerns about the security of Microsoft’s Visual Studio IDE once again. Developed by security researcher Zhiniang Peng, the exploit takes advantage of the default implementation of the IDE’s “trusted locations” feature. Peng argues that enabling this feature by default would protect users from potential attacks, … Read more

New PEAPOD Cyberattack Campaign Targeting Women Political Leaders

October 13, 2023 at 11:24AM A new cyber attack campaign called PEAPOD has targeted EU military personnel and political leaders working on gender equality. Cybersecurity firm Trend Micro has attributed the attacks to a threat actor known as Void Rabisu, which is associated with Cuba ransomware. The group conducts both financial motivated and espionage attacks, … Read more

CISA shares vulnerabilities, misconfigs used by ransomware gangs

October 13, 2023 at 10:57AM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has shared new details about vulnerabilities exploited by ransomware groups in order to help critical infrastructure organizations defend against attacks. Through its Ransomware Vulnerability Warning Pilot program, CISA has identified over 800 vulnerable systems frequently targeted by ransomware operations. CISA has also … Read more

Can open source be saved from the EU’s Cyber Resilience Act?

October 13, 2023 at 10:49AM The European Union’s Cyber Resilience Act (CRA) is causing concern among the open source community. The Act, aimed at addressing cybersecurity issues, imposes strict regulations on software publishers, potentially hindering open source development. The open source community is advocating for more flexibility in the regulations and better understanding of how … Read more