Study - Technical - LMS-SFC (EN) - Cyber Security - News Archive August 2021


Cyber Security - News Archive

August 2021


- FBI, CISA: Ransomware attack risk increases on holidays, weekends. (to the original material)

- Coinbase seeds panic among users with erroneous 2FA change alerts. (to the original material)

- Cybercriminal sells tool to hide malware in AMD, NVIDIA GPUs. (to the original material)

- Canada accepted 7,300 more immigration applications due to technical bug. (to the original material)

- Microsoft 365 Usage Analytics now anonymizes user info by default. (to the original material)

- CISA and FBI urge organizations to remain vigilant to ransomware threats on holidays, including this Labor Day. (to the original material)


- 30th August – Threat Intelligence Report. (to the original material)

- Beyond the pandemic: Why are the costs of data breaches at an all-time high? (to the original material)

- QNAP works on patches for OpenSSL bugs impacting its NAS devices. (to the original material)

- CISA: Don’t use single-factor auth on Internet-exposed systems. (to the original material)

- CISA Adds Single-Factor Authentication to list of Bad Practices. (to the original material)

- Brute Force Email Attacks and Account Takeover Attempts Rise 671%, Reaching Unprecedented Levels, According to Abnormal Security Research. (to the original material)

- Property-related business email compromise scams rising in Australia. (to the original material)

- Microsoft Exchange ProxyToken bug can let hackers steal user email. (to the original material)

- The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers. (to the original material).

- Vulnerability Summary for the Week of August 30, 2021. (to the original material)

- How to Maintain PCI-DSS Compliance for E-commerce Applications. (to the original material)


- LockFile ransomware’s box of tricks: intermittent encryption and evasion. (to the original material)


- Record numbers of young people signed up this summer to develop security skills. (to the original material)


- 5 Marketing Metrics That Every Cybersecurity CMO (Chief Marketing Officer) Should Track. (to the original material)

- Malicious actors deploying Gootkit Loader on Australian Networks. (to the original material)

- Microsoft Azure Cosmos DB Guidance. (to the original material)

- FBI Releases Indicators of Compromise Associated with Hive Ransomware. (to the original material)

- ICSJWG (Industrial Control Systems Joint Working Group) 2021 Fall Virtual Meeting. (to the original material)

- Microsoft, Google to Invest $30 Billion in Cybersecurity Over Next 5 Years. (to the original material)

- Kaseya Issues Patches for Two New 0-Day Flaws Affecting Unitrends Servers. (to the original material)

- Critical Cosmos Database Flaw Affected Thousands of Microsoft Azure Customers. (to the original material)

- Experts: WH Cybersecurity Summit Should Be Followed by Regulation, Enforcement. (to the original material)

- Ragnarok Ransomware Gang Bites the Dust, Releases Decryptor. (to the original material)

- Parallels Offers ‘Inconvenient’ Fix for High-Severity Bug. (to the original material)

- Critical Azure Cosmos DB Bug Allows Full Cloud Account Takeover. (to the original material)

- Winning the Cyber-Defense Race: Understand the Finish Line. (to the original material)

- FIN8 Targets US Bank With New ‘Sardonic’ Backdoor. (to the original material)

- T-Mobile CEO: Hacker brute-forced his way through our network. (to the original material)

- Boston Public Library discloses cyberattack, system-wide technical outage. (to the original material)

- Fake DMCA and DDoS complaints lead to BazaLoader malware. (to the original material)

- Microsoft warns Azure customers of critical Cosmos DB vulnerability. (to the original material)

*** - FIN8 APT Hackers Attacks Financial Institutions Using Sophisticated Backdoor. (to the original material)

- Top Strategies That Define the Success of a Modern Vulnerability Management Program. (to the original material)

- ‘Pay Ransom’ Screen? Too Late, Humpty Dumpty – Podcast. (to the original material)

- FBI issues alert on Hive ransomware group, said to have impacted 28 organizations worldwide. (to the original material)

- Disrupt lateral movement by eliminating the utility of a stolen password. (to the original material)

- Microsoft warns thousands of cloud customers of exposed databases. (to the original material)


- Updates on our continued collaboration with NIST to secure the Software Supply Chain. (to the original material)

- Cybersecurity news of the week (26.08.2021). (to the original material)

*** - Risk management strategies for cyber resilience in the cloud. (to the original material)

*** - How to Spot Fake Login Pages. (to the original material)

- Cisco Releases Security Updates for Multiple Products. (to the original material)

- The Increased Liability of Local In-home Propagation. (to the original material)

- F5 Bug Could Lead to Complete System Takeover. (to the original material)

- Man Sues Parents of Teens Who Hijacked Nearly $1M in Bitcoin. (to the original material)

- Microsoft Breaks Silence on Barrage of ProxyShell Attacks. (to the original material)

- F5 Releases Critical Security Patch for BIG-IP and BIG-IQ Devices. (to the original material)

- New Passwordless Verification API Uses SIM Security for Zero Trust Remote Access. (to the original material)

- Ragnarok ransomware releases master decryptor after shutdown. (to the original material)

- Synology: Multiple products impacted by OpenSSL RCE vulnerability. (to the original material)

- FBI shares technical details for Hive ransomware. (to the original material)

- Microsoft and Google to invest billions to bolster US cybersecurity. (to the original material)

- Kaseya patches Unitrends server zero-days, issues client mitigations. (to the original material)

- Cybercriminals increasingly use phishing, and no industry is spared. (to the original material)

- ULA email leak: internal emails allege smear campaign against SpaceX and Elon Musk. (to the original material)

- On the prowl for nudes, California man steals 620,000 iCloud photos. (to the original material)

*** - VMware Issues Patches to Fix New Flaws Affecting Multiple Products. (to the original material)

- Preventing Multi-Stage Attacks – Case in Point. (to the original material)


*** - Cisco Issues Critical Fixes for High-End Nexus Gear. (to the original material)

- Poor configuration of Microsoft Power Apps exposed millions of data. (to the original material)

- Microsoft: Vulnerabilitățile ProxyShell "ar putea fi exploatate", actualizați serverele Exchange acum! (to the original material)

- Microsoft will add secure preview for Office 365 quarantined emails. (to the original material)

- Critical F5 BIG-IP bug impacts customers in sensitive sectors. (to the original material)

- Gauging Threats in DDoS Landscape Becomes More Challenging. (to the original material)

- Cyberattack Trends: Critical Infrastructure Edition. (to the original material)

- New Hampshire town loses $2.3 million to overseas scammers. (to the original material)

- Ethereum urges Go devs to fix severe chain-split vulnerability. (to the original material)

- FIN8 cybercrime gang backdoors US orgs with new Sardonic malware. (to the original material)

- VMware Releases Security Updates for Multiple Products. (to the original material)

- OpenSSL Releases Security Update. (to the original material)

- FBI Releases Indicators of Compromise Associated with OnePercent Group Ransomware. (to the original material)

- F5 Releases August 2021 Security Advisory. (to the original material)


- CISA Releases Five Pulse Secure-Related MARs (MAR - Malware Analysis Report). (to the original material)

- Fake OpenSea support staff are stealing cryptowallets and NFTs. (to the original material)

- Samsung can remotely disable their TVs worldwide using TV Block. (to the original material)

- SteelSeries bug gives Windows 10 admin rights by plugging in a device. (to the original material)

- Ransomware gang's script shows exactly the files they're after. (to the original material)

- Malicious WhatsApp mod infects Android devices with malware. (to the original material)

- New zero-click iPhone exploit used to deploy NSO spyware. (to the original material)

- Researchers Warn of 4 Emerging Ransomware Groups That Can Cause Havoc. (to the original material)

- Phishing attack exposes medical information for 12,000 patients at Revere Health. (to the original material)

- The Proliferation of LockBit 2.0 Attacks. (to the original material)

- Resurgence in FluBot Malware Attacks. (to the original material)

- Phishing and Crypto Attacks Soared in First Half of 2021. (to the original material)

- A Year-Long Spear-Phishing Campaign Ensnares Office 365 Users - Identity Theft, Fraud, Scams  August 2. (to the original material)

- Hackers Could Increase Medication Doses Through Infusion Pump Flaws. (to the original material)

- DLL side-loading Attack Takes Advantage of Windows Search Order to Inject Malicious DLL. (to the original material)

- Earth Baku Returns: Uncovering the Upgraded Toolset Behind the APT Group’s New Cyberespionage Campaign. (to the original material)


- 23rd August – Threat Intelligence Report. (to the original material)

- FBI: OnePercent Group Ransomware targeted US orgs since Nov 2020. (to the original material)

- Phishing campaign uses UPS.com XSS vuln to distribute malware. (to the original material)

- Botnet targets hundreds of thousands of devices using Realtek S. (to the original material)

- Hacker gets 500K reward for returning stolen cryptocurrency. (to the original material)

- Nokia subsidiary (SAC Wireless) discloses data breach after Conti ransomware attack. (to the original material)

- CISA warns admins to urgently patch Exchange ProxyShell bugs. (to the original material)

- Hackers have stolen nearly $100 million in cryptocurrencies from a major Japanese exchange. (to the original material)

- Linux Threat Report 2021 1H - Linux threats in the cloud and security recommendations. (to the original material)

- Vulnerability Summary for the Week of August 16, 2021. (to the original material)

- Cloud Security Posture Management (CSPM - Cloud Security Posture Management): Getting It Right. (to the original material)

- Your AppSec Needs Intrusion Prevention, And Here’s Why. (to the original material)

- ABC of Cybersecurity: The Ransomware Element. (to the original material)

- ABC of Cybersecurity: Rootkits. (to the original material)

- ABC of Cybersecurity: SMS Sender. (to the original material)

- ABC of Cybersecurity: Exploit. (to the original material)

- ABC of Cybersecurity: Adware. (to the original material)

- ABC of Cybersecurity: The Trojan. (to the original material)

- ABC of Cybersecurity: The Man-in-the-Middle (MiTM) Element. (to the original material)

- ABC of Cybersecurity: The Keylogger Element. (to the original material)

- Google is completely withdrawing support for Android 2.3.7 and older versions. (to the original material)


- Razer bug lets you become a Windows 10 admin by plugging in a mouse. (to the original material)

- Microsoft shares guidance on securing Windows 365 Cloud PCs. (to the original material)

- ABC of Cybersecurity: The Spyware Element. (to the original material)

- ABC of Cybersecurity: The Virus Element. (to the original material)

- ABC of Cybersecurity: The Phishing Element. (to the original material)


- Hurricane-Related Scams. (to the original material)

- Urgent: Protect Against Active Exploitation of ProxyShell Vulnerabilities. (to the original material)

- Microsoft Exchange servers being hacked by new LockFile ransomware. (to the original material)


- The Week in Ransomware - August 20th 2021 - Exploiting Windows. (to the original material)

- LockFile ransomware uses PetitPotam attack to hijack Windows domains. (to the original material)

- SynAck ransomware decryptor lets victims recover files for free. (to the original material)

- HTTP DDoS attacks reach unprecedented 17 million requests per second. (to the original material)

- T-Mobile data breach just got worse - now at 54 million customers. (to the original material)

- Pegasus iPhone hacks used as lure in extortion scheme. (to the original material)

- AT&T denies data breach after hacker auctions 70 million user database. (to the original material)

- Social account thief goes to prison for stealing, trading nude photos. (to the original material)

- Cloudflare mitigated one of the largest DDoS attack involving 17.2 million rps. (to the original material)

- ShadowPad Malware is Becoming a Favorite Choice of Chinese Espionage Groups. (to the original material)

- Cybercrime Group Asking Insiders for Help in Planting Ransomware. (to the original material)

- Mozi IoT Botnet Now Also Targets Netgear, Huawei, and ZTE Network Gateways. (to the original material)

- Web Censorship Systems Can Facilitate Massive DDoS Attacks. (to the original material)

- Creating Cybersecurity Industry Content for Different Audiences and Learning Styles. (to the original material)


- Cybersecurity news of the week (19.08.2021). (to the original material)

- InkySquid State Actor Exploiting Known IE Bugs. (to the original material)

- Windows EoP Bug Detailed by Google Project Zero. (to the original material)

- COVID-19 Contact-Tracing Data Exposed, Fake Vax Cards Circulate. (to the original material)

- Health authorities in 40 countries targeted by fraudulent campaigns around the COVID-19 vaccine. (to the original material)

- Postmortem on U.S. Census Hack Exposes Cybersecurity Failures. (to the original material)

- How Ready Are You for a Ransomware Attack? (to the original material)

- ISC Releases Security Advisory for BIND. (to the original material)

- CEO tried funding his startup by asking insiders to deploy ransomware. (to the original material)

-  Cisco Releases Security Updates for Multiple Products. (to the original material)

- Cisco won’t fix zero-day RCE vulnerability in end-of-life VPN routers. (to the original material)

- Critical Flaw Found in Older Cisco Small Business Routers Won't Be Fixed. (to the original material)

- Hackers can bypass Cisco security products in data theft attacks. (to the original material)

- You can post LinkedIn jobs as almost ANY employer - so can attackers. (to the original material)

- Microsoft Exchange ProxyShell Targeting in Australia. (to the original material)

- New unofficial Windows patch fixes more PetitPotam attack vectors. (to the original material)

- CISA shares guidance on how to prevent ransomware data breaches. (to the original material)

- Liquid cryptocurency exchange loses over $90 million following hack. (to the original material)

- Researchers Find New Evidence Linking Diavol Ransomware to TrickBot Gang. (to the original material)

- Facebook launches VR remote work app, calling it a step to the 'metaverse'. (to the original material)


- Bogus Cryptomining Apps Infest Google Play. (to the original material)

- Kerberos Authentication Spoofing: Don’t Bypass the Spec. (to the original material)

- Mozilla Releases Security Updates. (to the original material)

- Adobe Releases Multiple Security Updates. (to the original material)

- Google Releases Security Updates for Chrome. (to the original material)

- CISA Provides Recommendations for Protecting Information from Ransomware-Caused Data Breaches. (to the original material)

- Vulnerability Affecting BlackBerry QNX RTOS. (to the original material)

- Major flaw in BlackBerry software may affect car safety, hospitals. (to the original material)

- Almost 2 million pieces of data from a terrorist watch list have been exposed online. (to the original material)

- US Census Bureau hacked in January 2020 using Citrix exploit. (to the original material)

- Bitcoin mixer owner pleads guilty to laundering over $300 million. (to the original material)

- Japanese insurer Tokio Marine discloses ransomware attack. (to the original material)

- GitHub urges users to enable 2FA after going passwordless. (to the original material)

- Diavol ransomware sample shows stronger connection to TrickBot gang. (to the original material)

- T-Mobile says hackers stole records belonging to 48.6 million individuals. (to the original material)

- 40M T-Mobile customers’ data leaked: expect social engineering and identity theft. (to the original material)

- Major flaw in BlackBerry software may affect car safety, hospitals. (to the original material)

- Critical ThroughTek SDK Bug Could Let Attackers Spy On Millions of IoT Devices. (to the original material)

- BadAlloc Flaw Affects BlackBerry QNX Used in Millions of Cars and Medical Devices. (to the original material)

- Iranian Hackers Target Several Israeli Organizations With Supply-Chain Attacks. (to the original material)

- Does a VPN Protect You from Hackers? (to the original material)

- NK Hackers Deploy Browser Exploits on South Korean Sites to Spread Malware. (to the original material)

- Check Point Research: Education sector sees 29% increase in attacks against organizations globally. (to the original material)


*** - Malicious Ads Target Cryptocurrency Users With Cinobi Banking Trojan. (to the original material)

- CISA Releases Security Advisory for ThroughTek Kalay P2P SDK. (to the original material)

- BadAlloc Vulnerability Affecting Devices Incorporating Older BlackBerry QNX Products. (to the original material)

- Apple Releases Security Update. (to the original material)

- T-Mobile says it found unauthorized access to data. (to the original material)

- Govt hackers impersonate HR employees to hit Israeli targets. (to the original material)

- Conti ransomware prioritizes revenue and cyberinsurance data theft. (to the original material)

- CISA: BadAlloc impacts critical infrastructure using BlackBerry QNX. (to the original material)

- Pharmacist faces 120 years in prison for selling vaccination cards on eBay. (to the original material)

- Malware campaign uses clever 'captcha' to bypass browser warning. (to the original material)

- Brazilian government discloses National Treasury ransomware attack. (to the original material)

- Critical bug impacting millions of IoT devices lets hackers spy on you. (to the original material)

- Fortinet delays patching zero-day allowing remote server takeover. (to the original material)

- Chase bank accidentally leaked customer info to other customers. (to the original material)


- 16th August – Threat Intelligence Report. (to the original material)

- Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets. (to the original material)

- Fraudsters target governments with a vaccine scam - Interpol. (to the original material)

- Hive ransomware attacks Memorial Health System, steals patient data. (to the original material)

- T-Mobile confirms servers were hacked, investigates data breach. (to the original material)

- Malware dev infects own PC and data ends up on intel platform. (to the original material)

- Education giant Pearson fined $1M for downplaying data breach. (to the original material)

- Secret terrorist watchlist with 2 million records exposed online. (to the original material)

- SIM swap scammer pleads guilty to Instagram account hijacks, crypto theft. (to the original material)

- Hackers behind Iranian wiper attacks linked to Syrian breaches. (to the original material)

- Colonial Pipeline reports data breach after May ransomware attack. (to the original material)

- AMD and Intel confidential data leaked online after GIGABYTE ransomware attack. (to the original material)

- Vulnerability Summary for the Week of August 9, 2021. (to the original material)


- Hacker claims to steal data of 100 million T-mobile customers. (to the original material)

- Ford bug exposed customer and employee records from internal systems. (to the original material)


- Apple employees flooded the company's internal forum with hundreds of messages drawing attention to the fact that the software that scans phones and computers to detect possible acts of pedophilia could be exploited by repressive governments. (to the original material)

- US brokers warned of ongoing phishing attacks impersonating FINRA (Financial Industry Regulatory Authority). (to the original material)

- Pysa Ransomware Attacks K-12 Schools. (to the original material)

- The Rise of Deep Learning for Detection and Classification of Malware. (to the original material)

- Russian cyberspies targeted the Slovak government for months. (to the original material)

- London court orders Binance to trace cryptocurrency hackers. (to the original material)

- Indra Group Attack on Iran Highlights the Threats to Global Critical Infrastructure. (to the original material)


- Racoon Stealer distributes malware via Google SEO. (to the original material)

- Cybercriminals Reportedly Created Blockchain Analytics Tool. (to the original material)

- Microsoft Teams will alert users of incoming spam calls. (to the original material)

- Windows 365 exposes Microsoft Azure credentials in plaintext. (to the original material)

- SynAck ransomware releases decryption keys after El_Cometa rebrand. (to the original material)

- Vice Society ransomware joins ongoing PrintNightmare attacks. (to the original material)

- Emails from Lithuanian Ministry of Foreign Affairs for sale on data-trading forum. (to the original material)

- The Week in Ransomware - August 13th 2021 - The rise of LockBit. (to the original material)

- Facebook rolls out end-to-end encryption for Messenger calls. (to the original material)

- Bugs in gym management software let hackers wipe fitness history. (to the original material)

- Brief Analysis of Device Security Threats in the Hybrid Work System. (to the original material)

- Dark web AlphaBay marketplace resurface after four years. (to the original material)

- Phishing campaign leverages legit DocuSign email notifications. (to the original material)

- The Importance of Blogs to Maximize SEO Results for Cybersecurity Vendors. (to the original material)


- Cybersecurity news of the week (12.08.2021). (to the original material)

- Zoom deal: $85 million for security investments. (to the original material)

- Drupal Releases Security Updates. (to the original material)

- Mozilla Releases Security Updates for Thunderbird. (to the original material)

- Ransomware gang uses PrintNightmare to breach Windows servers. (to the original material)

- Ukraine shuts down money laundering cryptocurrency exchanges. (to the original material)

- Notorious AlphaBay darknet market comes back to life. (to the original material)

- Microsoft: Evasive Office 365 phishing campaign active since July 2020. (to the original material)

- Microsoft Exchange servers are getting hacked via ProxyShell exploits. (to the original material)

- GitHub deprecates account passwords for authenticating Git operations. (to the original material)

- One-click Microsoft Outlook button makes it a breeze for workers to report phishing emails. (to the original material)

- Email innovation simplifies takedown of cyber scams. (to the original material)

- Britons targeted by a Flubot malware scam. (to the original material)

- University Students Targeted by Credential Phishing Campaign. (to the original material)

- July 2021’s Most Wanted Malware: Snake Keylogger Enters Top 10 for First Time. (to the original material)


- AllStar: Continuous Security Policy Enforcement for GitHub Projects. (to the original material)

- Unwanted bot traffic costs businesses $250 million a year. (to the original material)

- SAP a rezolvat 9 vulnerabilități critice și de mare severitate. (to the original material)

- Fake Brave browser website dropped malware, thanks to Google Ads. (to the original material)

- Microsoft confirms another Windows print spooler zero-day bug. (to the original material)

- Hacker behind biggest ever cryptocurrency heist returns stolen funds. (to the original material)

- Accenture confirms hack after LockBit ransomware data leak threats. (to the original material)

- New AdLoad malware variant slips through Apple's XProtect defenses. (to the original material)

- Kaseya's universal REvil decryption key leaked on a hacking forum. (to the original material)

- BlackMatter Ransomware Attack Impacting Multiple Financial Institutions. (to the original material)


- Retail became a top target for ransomware and data-theft. (to the original material)

- How do people end up working for cybercriminals? (to the original material)

- Google’s own antivirus app fails to detect 70% of spyware. (to the original material)

- Bitdefender: New scam messages claiming to be sent by the Romanian Post aim to empty people's bank accounts. (to the original material)

- Crytek confirms Egregor ransomware attack, customer data theft. (to the original material)

- Over $600 million reportedly stolen in cryptocurrency hack. (to the original material)

- Citrix Releases Security Update for ShareFile Storage Zones Controller. (to the original material)

- eCh0raix ransomware now targets both QNAP and Synology NAS devices. (to the original material)

- Microsoft Releases August 2021 Security Updates. (to the original material)

- Microsoft August 2021 Patch Tuesday fixes 3 zero-days, 44 flaws. (to the original material)

- Microsoft fixes Windows Print Spooler PrintNightmare vulnerability. (to the original material)

- Microsoft revives deprecated RDCMan (Remote Desktop Connection Manager) after fixing security flaw. (to the original material)

- Windows security update blocks PetitPotam NTLM relay attacks. (to the original material)

- Adobe Releases Security Updates for Multiple Products. (to the original material)

- Adobe fixes critical preauth vulnerabilities in Magento. (to the original material)

- Mozilla Releases Security Updates for Firefox. (to the original material)

- Firefox adds enhanced cookie clearing, HTTPS by default in private browsing. (to the original material)

- Instagram scammers figured out a way to get paid for banning people. (to the original material)

- SAP Releases August 2021 Security Updates. (to the original material)

- Intel Releases Multiple Security Updates. (to the original material)

- Tech startups join UK cyber experts to address security challenges. (to the original material)

- Black market for fake vaccine certificates reaches new peaks, while Delta variant keeps spreading globally. (to the original material)

- Who Says VoIP Configuration Has To Be Tough? (to the original material)


- 09th August – Threat Intelligence Report. (to the original material)

- One million stolen credit cards leaked to promote carding market. (to the original material)

- An engineer fell victim to a gift card scam. His colleagues discovered the whole fraud scheme. (to the original material)

- FlyTrap malware hijacks thousands of Facebook accounts. (to the original material)

- Microsoft adds Fusion ransomware attack detection to Azure Sentinel. (to the original material)

- Mozilla tests if 'Firefox/100.0' user agent breaks websites. (to the original material)

- Google drops Bluetooth Titan Security Keys in favor of NFC versions. (to the original material)

- Synology warns of malware infecting NAS devices with ransomware. (to the original material)

- Vulnerability Summary for the Week of August 2, 2021. (to the original material)

- Public can now report scam websites direct to the NCSC. (to the original material)

- Why is cloud security critical to maximizing the value of hybrid working? (to the original material)

- Vulnerability Summary for the Week of August 2, 2021. (to the original material)


- Simplifying Titan Security Key options for our users. (to the original material)

- Australian govt warns of escalating LockBit ransomware attacks. (to the original material)


- Microsoft Exchange servers scanned for ProxyShell vulnerability, Patch Now. (to the original material)

- Actively exploited bug bypasses authentication on millions of routers. (to the original material)

- Go, Rust "net" library affected by critical IP address validation vulnerability. (to the original material)


- Computer hardware giant GIGABYTE hit by RansomEXX ransomware. (to the original material)

- Ivanti Releases Security Update for Pulse Connect Secure. (to the original material)

- The Week in Ransomware - August 6th 2021 - Insider threat edition. (to the original material)

- Windows PetitPotam vulnerability gets an unofficial free patch. (to the original material)

- Cisco: Firewall manager RCE bug is a zero-day, patch incoming. (to the original material)

- NCSC lifts lid on three random words password logic. (to the original material)

- We need your help – the head of DHS addresses hackers during the Black Hat speech. (to the original material)

- New CISA director Jen Easterly: we cannot allow avoidable cyber disruption to cost human lives. (to the original material)

- It's alive! The story behind the BlackMatter ransomware strain. (to the original material)

- A Beginner’s Guide to Search Engine Optimization (SEO) for Security Vendors. (to the original material)

- Amazon Kindle Vulnerabilities could have led Threat Actors to Device Control and Information Theft. (to the original material)


- Cybersecurity news of the week (08/05/2021). (to the original material)

- Critical vulnerabilities in Las Vegas casinos with thousands at the Black Hat conference (to the original material)

- Iran threat actor Charming Kitten has exfiltrated 2TB of victims’ data since 2018. (to the original material)

- Detecting Cobalt Strike: Government-Sponsored Threat Groups. (to the original material)

- LockBit 2.0 ransomware incidents in Australia. (to the original material)

- Spam and phishing in Q2 2021. (to the original material)

- What Is Spear Phishing? (to the original material)

- Linux version of BlackMatter ransomware targets VMware ESXi servers. (to the original material)

- CISA teams up with Microsoft, Google, Amazon to fight ransomware. (to the original material)

- New DNS vulnerability allows 'nation-state level spying' on companies. (to the original material)

- CISA Releases Security Advisory for InterNiche Products. (to the original material)

- VMware Releases Security Updates for Multiple Products. (to the original material)

- Cisco Releases Security Updates (to the original material), Cisco Security Advisories (link advisories)

- LockBit 2.0 ransomware incidents in Australia (to the original material); 2021-006: ACSC Ransomware Profile - Lockbit 2.0 (to the original material)

- Angry Conti ransomware affiliate leaks gang's attack playbook. (to the original material)

- Google expects delays in enforcing 2FA for Chrome extension devs. (to the original material)

- New Windows PrintNightmare zero-days get free unofficial patch. (to the original material)

- Prometheus TDS: The $250 service behind recent malware attacks. (to the original material)

- Telegram for Mac bug lets you save self-destructing messages forever. (to the original material)

- Microsoft Edge just got a 'Super Duper Secure Mode' upgrade. (to the original material)

- Pandemic parents: Safety can turn online time into beautiful moments together. (to the original material)


- Google Releases Security Updates for Chrome. (to the original material).

- Spear phishing attacks underline how much dangerous phishing has gotten. (to the original material)

- Energy group ERG reports minor disruptions after ransomware attack. (to the original material)

- Cisco fixes critical, high severity pre-auth flaws in VPN routers. (to the original material)

- LockBit ransomware recruiting insiders to breach corporate networks. (to the original material)

- INFRA:HALT security bugs impact critical industrial control devices. (to the original material)

- New Cobalt Strike bugs allow takedown of attackers’ servers. (to the original material)

- NSA and CISA share Kubernetes security recommendations. (to the original material)

- According to a report, most Twitter users have not yet enabled two-factor authentication (2FA). (to the original material)

- Linux Kernel Security Done Right. (to the original material)

- Ethical hackers collaborate with Defence to strengthen cyber security. (to the original material), (to the original material)

- Join the Ad Hoc Working Group on EU Cybersecurity Market. (to the original material)

- CISA Releases Security Advisory for Swisslog Healthcare. (to the original material).

- SonicWall devices targeted with ransomware utilising stolen credentials. (to the original material)

- Ransomware attack hits Italy's Lazio region, affects COVID-19 site. (to the original material)

- Trash panda as a service: Raccoon Stealer in pursuit of cookies, passwords and cryptocoins. (to the original material)

- Protecting SMBs Against Kaseya Supply Chain, Zero Day, and Ransomware Attacks. (to the original material)

- 2nd August – Threat Intelligence Report. (to the original material)

- New WeTransfer phishing attack spoofs file-sharing to steal credential. (to the original material)

- CISA and NSA Release Kubernetes Hardening Guidance. (to the original material)

- Italy. The vaccination appointment platform in the Lazio region of Rome was the target of a cyber attack on Sunday. The site could not be accessed for several hours. (to the original material)

- Google Chrome to no longer show secure website indicators. (to the original material)

- Windows PetitPotam attacks can be blocked using new method. (to the original material)

- PwnedPiper critical bug set impacts major hospitals in North America . (to the original material)

- Major cyber security agencies reveal the list of the most exploited vulnerabilities of the last 2 years. (to the original material)

- Vulnerability Summary for the Week of July 26, 2021. (to the original material)

- Bot protection now generally available in Azure Web Application Firewall. (to the original material)


Archive:

Click here to access archive content.
Click here to access CMS (Content Management System) in Joomla.

Source:

Click here to access to documentation sources.

Note Dorin M.

This site has a double form, one in HTML and one in Joomla (if you are interested in the utility behind this effort you can read the "Why  a HTML and a CMS (Joomla)" page).
That's why I suggest you, depending on your desire, to use the HTML form for simple browsing / information or the Joomla form if you want in-depth studies / searches using the CMS search engine.

Dorin M - August 31, 2021