Network SecurityCencora reports data exfiltration in cyberattack on pharmaceutical giantSteve ZurierFebruary 28, 2024Cencora maintains there’s no connection between its recent incident and the attack on Change Healthcare.
Network SecurityUbiquiti router users urged to secure devices targeted by Russian hackersSimon HenderyFebruary 28, 2024The routers’ utility makes them “popular for both consumers and malicious cyber actors,” security agencies warn.
Governance, Risk and ComplianceTop 3 NIST Cybersecurity Framework 2.0 takeawaysLaura FrenchFebruary 27, 2024CSF 2.0 features a larger scope, new “Govern” pillar and catalog of resources to aid implementation.
RansomwareConnectWise link to Change Healthcare breach corroboratedSteve ZurierFebruary 27, 2024Initial reports said that the malware strain involved a LockBit affiliate, but recent data suggests an ALPHV/BlackCat link.
Network SecurityRussian cyberespionage group APT29 targeting cloud vulnerabilitiesSimon HenderyFebruary 27, 2024The Russian hacking group switched to attacking cloud-hosted networks to gain initial access.
Network Security‘SubdoMailing’ manipulates subdomains to send spam, malicious emailsSteve ZurierFebruary 26, 2024Guardio Labs researchers say popular tech brands exploited include MSN, VMware, McAfee and eBay.
RansomwareLoanDepot confirms SSNs leaked in breach claimed by ALPHV/BlackCatLaura FrenchFebruary 26, 2024Nearly 17 million loanDepot customers were impacted by the January cyberattack.
RansomwareLockBit returns after takedown with new extortion threatsSimon HenderyFebruary 26, 2024The gang’s purported boss is vowing revenge on government agencies and political disruption after an international taskforce dismantled its ransomware network.
RansomwareExclusive: Cyberattack on Change Healthcare was an exploit of the ConnectWise flawSteve ZurierFebruary 23, 2024First Health Advisory says the “nation-state” attackers used a LockBit strain to exploit the recent flaws reported in ConnectWise’s ScreenConnect app.
Application securityMalicious Apple Shortcuts could bypass security features to steal dataLaura FrenchFebruary 23, 2024A vulnerability enabled Shortcuts to transmit data to websites without user permission.