
- Details
- Written by: Merticaru Dorin Nicolae
- Category: Cyber Security News
- Hits: 118
- Samba addressed multiple high-severity vulnerabilities. (to the original material)
- Co-Founder of OneCoin Cryptocurrency Scam Pleads Guilty. (to the original material)
- Glupteba malware is back in action after Google disruption. (to the original material)
- Google introduces end-to-end encryption for Gmail on the web. (to the original material)

- Details
- Written by: Merticaru Dorin Nicolae
- Category: Cyber Security News
- Hits: 115
- Samba Releases Security Updates. (to the original material)
- FBI, FDA OCI, and USDA Release Joint Cybersecurity Advisory Regarding Business Email Compromise (BEC) Schemes Used to Steal Food. (to the original material)
- In Search for the Best Security Architecture. (to the original material)
- MirrorFace aims for high‑value targets in Japan – Week in security with Tony Anscombe. (to the original material)
- Help! My kid has asked Santa for a smartphone. (to he original material)
- Agenda Ransomware Switches to Rust to Attack Critical Infrastructure. (to the original material)
- Meta's Bug Bounty Program Shows $2m Awarded in 2022. (to the original material)
- Social Blade Confirms Data Breach Exposing PII on the Dark Web. (to the original material)
- Two-Thirds of Security Pros Have Burnt Out in Past Year. (to the original material)
- Former Twitter Employee Gets 42 Months for Saudi Scheme. (to the original material)
- OECD Signs "Landmark" Privacy Agreement. (to the original material)
- Former Twitter employee sentenced to 3.5 years in jail for spying on behalf of Saudi Arabia. (to the original material)
- Social Blade discloses security breach. (to the original material)
- Data of 5.7M Gemini users available for sale on hacking forums. (to the original material)
- CISA adds Veeam Backup and Replication bugs to Known Exploited Vulnerabilities Catalog. (to the original material)
- MCCrash botnet targets private Minecraft servers, Microsoft warns. (to the original material)
- Microsoft revised CVE-2022-37958 severity due to its broader scope. (to the original material)
- Looking Forward and Back at the California State Legislature. (to the original material)
- Federal Agencies Keep Rejecting FOIA (Freedom of Information Act) Requests for Their Procedures for Handling FOIA Requests. (to the original material)
- All public GitHub repositories will have free secret scanning by February 2023. (to the original material)
- DarkTortilla malware spreads on phishing sites masquerading as legitimate domains. (to the original material)
- Meta has removed over 200 influence operations, raises bug bounty payouts. (to the original material)
- Three principles ethical hackers can adopt as a code of conduct. (to the original material)
- IronNet Nearly Insolvent; Board to Probe Claims of Deception. (to the original material)
- Subcontractor Breach Affects 245K Medicare Beneficiaries. (to the original material)
- How CISOs Can Guard Against Their Own Liability. (to the original material)
- Synack CEO Jay Kaplan on Doing Adversarial Pen Tests of APIs. (to the original material)
- ISMG Editors: Payments Special. (to the original material)
- 2023: Addressing the CISO's Many Challenges. (to the original material)
- Rising Above the Cybersecurity Poverty Line. (to the original material)
- New infosec products of the week: December 16, 2022. (to the original material)
- Executives take more cybersecurity risks than office workers. (to the original material)
- The Week in Ransomware - December 16th 2022 - Losing Trust. (to the original material)
- Colombian energy supplier EPM hit by BlackCat ransomware attack. (to the original material)
- FBI warns that BEC attacks now also target food shipments. (to the original material)
- Woman gets 66 months in prison for role in $3.3 million ID fraud op. (to the original material)
- Microsoft warns of new Minecraft DDoS malware infecting Windows, Linux. (to the original material)

- Details
- Written by: Merticaru Dorin Nicolae
- Category: Cyber Security News
- Hits: 110
- Cybersecurity news of the week (15.12.2022). (to the original material)
- CISA Releases Forty-One Industrial Control Systems Advisories. (to the original material)
- Drupal Releases Security Updates to Address Vulnerabilities in H5P and File (Field) Paths. (to th original material)
- CISA Consolidates Twitter Accounts. (to the original material)
- Traveling for the holidays? Stay cyber‑safe with these tips. (to the original material)
- Senate Approves Bill Banning TikTok From US Government Devices. (to the original material)
- NSA, CISA Warn Against Threats to 5G Network Slicing. (to the original material)
- Loan Scam Campaign 'MoneyMonger' Exploits Flutter to Hide Malware. (to the original material)
- Feds Hit DDoS-for-Hire Services with 48 Domain Seizures. (to the original material)
- Over 85% of Attacks Hide in Encrypted Channels. (to the original material)
- Platforms Flooded with 144,000 Phishing Packages. (to the original material)
- Chinese MirrorFace APT group targets Japanese political entities. (to the original material)
- Database of the FBI’s InfraGard US Critical Infrastructure Intelligence portal available for sale. (to the original material)
- FBI seized 48 domains linked to DDoS-for-Hire service platforms. (to the original material)
- Crooks use HTML smuggling to spread QBot malware via SVG files. (to the original material)
- Dangerous "Kids Online Safety Act" Does Not Belong in Must-Pass Legislation. (to the original material)
- Only A Few More Weeks Left to Support EFF Through The CFC (Combined Federal Campaign)! (to the original material)
- IBM to work with nonprofit on cloud security framework for financial services. (to the original material)
- Strata Identity and HYPR push closer to a passwordless future. (to the original material)
- MDR (Managed Detection and Response) and the importance of shared responsibility: An SC eBook preview. (to the original material)
- Think of cyber insurance as a strategic business decision. (to the original material)
- Australian Telecom Giant TPG Discloses Email Hack. (to the original material)
- Medical Practice Pays $20K to Settle 'Right of Access' Case. (to the original material)
- US Prosecutors Charge 6 With Offering DDoS for Sale. (to the original material)
- New AI Bot Could Take Phishing, Malware to a Whole New Level. (to the original material)
- Will Third-Party App Stores Play With Apple's Walled Garden? (to the original material)
- X5 Firewall Practices to Prevent a Data Breach. (to the original material)
- Palo Alto's Biggest Bets Around AppSec, SecOps, SASE & Cloud. (to the original material)
- Next-Gen Cyber Targets: Satellites and Communication. (to the original material)
- Top 5 Tips for Choosing Endpoint Security. (to the original material)
- Planning for Prolonged Regional Medical Device Outages. (to the original material)
- Prosecutors Accuse FTX's Founder of Crypto-Based 'Deception'. (to the original material)
- Palo Alto Founder Nir Zuk on Making the SOC More Autonomous. (to the original material)
- Palo Alto's BJ Jenkins on Changing Cloud Needs for Customers. (to the original material)
- Product showcase: Searchable encryption in Elasticsearch and OpenSearch with IronCore Labs. (to the original material)
- Distractions at work can have serious cybersecurity implications. (to the original material)
- As legislation evolves, businesses need a firm understanding of secure payment options. (to the original material)
- FuboTV says World Cup streaming outage caused by a cyberattack. (to the original material)
- Hackers leak personal info allegedly stolen from 5.7M Gemini users. (to the original material)
- GitHub to require all users to enable 2FA by the end of 2023. (to the original material)
- Phishing attack uses Facebook posts to evade email security. (to the original material)
- Ukrainian govt networks breached via trojanized Windows 10 installers. (to the original material)
- Social Blade confirms breach after hacker posts stolen user data. (to the original material)
- How Gcore uses regular expressions to block DDoS attacks. (to the original material)
- LEGO BrickLink bugs let hackers hijack accounts, breach servers. (to the original material)
- Hackers target Japanese politicians with new MirrorStealer malware. (to the original material)

- Details
- Written by: Merticaru Dorin Nicolae
- Category: Cyber Security News
- Hits: 109
- Romania has adopted a law prohibiting the purchase and use, by public authorities, of cyber security software products and services from the Russian Federation. (to the original material)
- CISA Adds One Known Exploited Vulnerability to Catalog. (to the original material)
- Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. (to the original material)
- Signed Microsoft Drivers Used in Attacks Against Businesses. (to the original material)
- AgentTesla Remains Most Prolific Malware in November, Emotet and Qbot Grow. (to the original material)
- Apple Fixes Actively Exploited iPhone Zero-Day Vulnerability. (to the original material)
- New Google Tool Helps Devs Root Out Open Source Bugs. (to the original material)
- Loan Fee Fraud Surges by a Fifth as Christmas Approaches. (to the original material)
- Two Zero-Days Fixed in December Patch Tuesday. (to the original material)
- GoTrim botnet actively brute forces WordPress and OpenCart sites. (to the original material)
- December 2022 Patch Tuesday fixed 2 zero-day flaws. (to the original material)
- Apple fixed the tenth actively exploited zero-day this year. (to the original material)
- 3.5m IP cameras exposed, with US in the lead. (to the original material)
- VMware fixed critical VM Escape bug demonstrated at Geekpwn hacking contest. (to the original material)
- Citrix and NSA urge admins to fix actively exploited zero-day in Citrix ADC and Gateway. (to the original material)
- EFF Agrees With the NLRB (National Labor Relations Board): Workers Need Protection Against Bossware. (to the original material)
- Digital Rights Updates with EFFector 34.6. (to the original material)
- Stellar Cyber integrates with Deep Instinct’s deep learning technology. (to the original material)
- Microsoft blocks threat actors that obtained signed drivers to deploy ransomware. (to the original material)
- CloudBolt says survey of IT leaders show a need for greater maturity, security in cloud environments. (to the original material)
- Netskope to offer Cloud Exchange platform as a managed service. (to the original material)
- Scanning assets in the cloud: Challenges and improvements to make. (to the original material)
- Counter insider risks by taking security out to the edge. (to the original material)
- Hacker Reportedly Breaches US FBI Cybersecurity Forum. (to the original material)
- Dental Practice Hit With HIPAA Fine for Posting PHI on Yelp. (to the original material)
- Microsoft Patches Zero-Day Magniber Ransomware Hackers Used. (to the original material)
- How Criminals Extort Healthcare Victims With Ransomware. (to the original material)
- Zero Trust: How to Know What Your Crown Jewels Are. (to the original material)
- Palo Alto CEO: 'SIEM (Security Intelligence and Extended Management) Needs to Be Eliminated and Replaced'. (to the original material)
- Nikesh Arora on Palo Alto's Approach to Supply Chain Defense. (to the original material)
- Assessing Cyber Risk, Maturity in Healthcare M&As. (to the original material)
- Combating Ransomware Attacks: Which Strategies Hold Promise? (to the original material)
- OSV-Scanner: A free vulnerability scanner for open-source software. (to the original material)
- Nosey Parker: Find sensitive information in textual data and Git history. (to the original material)
- What CISOs consider when building up security resilience. (to the original material)
- FBI seized domains linked to 48 DDoS-for-hire service platforms. (to the original material)
- Attackers use SVG files to smuggle QBot malware onto Windows systems. (to the original material)
- Microsoft patches Windows zero-day used to drop ransomware. (to the original material)
- VMware fixes critical ESXi and vRealize security flaws. (to the original material)
- NSA shares tips on mitigating 5G network slicing threats. (to the original material)
- The Dark Web is Getting Darker - Ransomware Thrives on Illegal Markets. (to the original material)
- Open-source repositories flooded by 144,000 phishing packages. (to the original material)

- Details
- Written by: Merticaru Dorin Nicolae
- Category: Cyber Security News
- Hits: 113
- Is the EU Healthcare Sector Cyber Healthy? The Conclusions of Cyber Europe 2022. (to the original material)
- Apple Releases Security Updates for Multiple Products. (to the original material)
- Microsoft Releases December 2022 Security Updates. (to the original material)
- CISA Updates Advisory on #StopRansomware: Cuba Ransomware. (to the original material)
- Citrix Releases Security Updates for Citrix ADC, Citrix Gateway. (to the original material)
- Mozilla Releases Security Updates for Thunderbird and Firefox. (to the original material)
- VMware Releases Security Updates for Multiple products. (to the original material)
- CISA Adds Five Known Exploited Vulnerabilities to Catalog. (to the original material)
- NSA, CISA, and ODNI Release Guidance on Potential Threats to 5G Network Slicing. (to the original material)
- CISA Releases Three Industrial Control Systems Advisories. (to the original material)
- November 2022’s Most Wanted Malware: A Month of Comebacks for Trojans as Emotet and Qbot Make an Impact. (to the original material)
- Top tips for security‑ and privacy‑enhancing holiday gifts. (to the original material)
- Twitter Addresses November Data Leak Claims. (to the original material)
- California Hit By Cyber-Attack, LockBit Claims Responsibility. (to the original material)
- Uber Hit By New Data Breach After Attack on Third-Party Vendor. (to the original material)
- Experts Warn ChatGPT Could Democratize Cybercrime. (to the original material)
- Aussie Data Breaches Surge 489% in Q4 2022. (to the original material)
- Security Overlooked in Rush to Hybrid Working. (to the original material)
- Lockbit ransomware gang hacked California Department of Finance. (to the original material)
- Experts detailed a previously undetected VMware ESXi backdoor. (to the original material)
- Twitter says recently leaked user data are from 2021 breach. (to the original material)
- Letter to the UN Ad Hoc Committee. (to the original material)
- Executives are four times more likely to be victims of phishing than workers. (to the original material)
- Host Todd Fitzgerald reflects on 100 episodes of the CISO Stories podcast. (to the original material)
- One year after Log4Shell, trouble remains…but here are five reasons for optimism. (to the original material)
- Sam Bankman-Fried's Terrible, Horrible, Very Bad Day. (to the original material)
- DNS Is Conduit Into Air-Gapped Networks, Say Researchers. (to the original material)
- LockBit 3.0 Ransomware Threatens Health Sector, Feds Warn. (to the original material)
- Irish Healthcare Ransomware Hack Cost Over 80 Million Euros. (to the original material)
- Skyhigh Security CEO on Taking a Data-First Approach to SSE. (to the original material)
- Ngrok Raises $50M to Drive App Authentication, Observability. (to the original material)
- Embattled FTX Founder Sam Bankman-Fried Arrested in Bahamas. (to the original material)
- New Approaches to Solve the Age-Old AML Problem. (to the original material)
- Microsoft fixes exploited zero-day, revokes certificate used to sign malicious drivers (CVE-2022-44698). (to the original material)
- State-sponsored attackers actively exploiting RCE in Citrix devices, patch ASAP! (CVE-2022-27518). (to the original material)
- Critical FortiOS pre-auth RCE vulnerability exploited by attackers (CVE-2022-42475). (to the original material)
- 24% of technology applications contain high-risk security flaws. (to the original material)
- Privacy concerns are limiting data usage abilities. (to the original material)
- eBook: 4 ways to secure passwords, avoid corporate account takeover. (to the original material)
- Microsoft-signed malicious Windows drivers used in ransomware attacks. (to the original material)
- LockBit claims attack on California's Department of Finance. (to the original material)
- Apple security update fixes new iOS zero-day used to hack iPhones. (to the original material)
- Microsoft December 2022 Patch Tuesday fixes 2 zero-days, 49 flaws. (to the original material)
- Google releases dev tool to list vulnerabilities in project dependencies. (to the original material)
- New GoTrim botnet brute forces WordPress site admin accounts. (to the original material)
- Hackers exploit critical Citrix ADC and Gateway zero day, patch now. (to the original material)
- Amazon ECR Public Gallery flaw could have wiped or poisoned any image. (to the original material)