Breaking News

Security Affairs newsletter Round 256

A new round of the weekly newsletter arrived! The best news of the week with Security Affairs

BlackWater, a malware that uses Cloudflare Workers for C2 Communication
Coronavirus-themed attacks February 1 – March 15, 2020
Massive cyber attack hit the town hall of Marseille ahead local election
Noooo, now Ancient Tortoise BEC scammers are launching Coronavirus-Themed attacks
A cyberattack hits the US Department of Health and Human Services
Aerial Direct, the O2s largest UK partner suffered a data breach
Experts warn of a new strain of ransomware, the PXJ Ransomware
MonitorMinor, the outstanding stalkerware can track Gmail, WhatsApp, Instagram, and Facebook
Most organizations have yet to fix CVE-2020-0688 Microsoft Exchange flaw
Open Exchange Rates discloses a security breach
Attackers use a new CoronaVirus Ransomware to cover Kpot Infostealer infections
Corporate Finance firms leak 500K+ legal and financial documents online
Most ransomware attacks take place outside the working hours
Operators behind Nefilim Ransomware threaten to release stolen data
The parabola of a prolific cyber-criminal known as Dton
Ursnif campaign targets Italy with a new infection Chain
Adobe releases out-of-band patches for critical issues in Acrobat Reader, Photoshop, Bridge, ColdFusion
Cisco addresses multiple issues in its SD-WAN product
Thousands of Coronavirus-related malicious domains are being created every day
Trend Micro addresses two issues exploited by hackers in the wild
TrueFire Guitar tutoring website was hacked, financial data might have been exposed
VMware fixes high severity privilege escalation and DoS in its products
CERT France – Pysa ransomware is targeting local governments
Coronavirus news used by Emotet and Trickbot to evade detection
Experts found a new TrickBot module (rdpScanDll) built for RDP bruteforcing operations
Is APT27 Abusing COVID-19 To Attack People ?!
Pwn2Own 2020 Day1 -researchers earned $180K for hacking Windows, Ubuntu, and macOS
Drupal addresses two XSS flaws by updating the CKEditor
Pwn2Own 2020 – Participants hacked Adobe Reader, Oracle VirtualBox, and Windows
Russia-linked APT28 has been scanning vulnerable email servers in the last year
UK printing company Doxzoo exposed US and UK military docs
Healthcare sector targeted : what you need to know about the hackers very unusual strategy
Mukashi, the new Mirai variant that targets Zyxel NAS
New Coronavirus-themed attack uses fake WHO chief emails
UK Fintech company Finastra hit by a cyber attack
[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Two Linux flaws can lead to the disclosure of sensitive data

Qualys warns of two information disclosure flaws in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise…

9 hours ago

Meta stopped covert operations from Iran, China, and Romania spreading propaganda

Meta stopped three covert operations from Iran, China, and Romania using fake accounts to spread…

1 day ago

US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator

The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major…

2 days ago

ConnectWise suffered a cyberattack carried out by a sophisticated nation state actor<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

ConnectWise detected suspicious activity linked to a nation-state actor, impacting a small number of its…

2 days ago

Victoria’s Secret ‘s website offline following a cyberattack

Victoria’s Secret took its website offline after a cyberattack, with experts warning of rising threats…

2 days ago

China-linked APT41 used Google Calendar as C2 to control its TOUGHPROGRESS malware

Google says China-linked group APT41 controlled malware via Google Calendar to target governments through a…

3 days ago