Breaking News

Security Affairs newsletter Round 344

A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.

If you want to also receive for free the newsletter with the international press subscribe here.

Western Digital SanDisk SecureAccess flaws allow brute force and dictionary attacks
New ‘Karakurt’ cybercrime gang focuses on data theft and extortion
Cybereason released Logout4Shell, a vaccine for Log4Shell Apache Log4j RCE
Volvo Cars suffers a data breach. Is it a ransomware attack?
Australian ACSC warns of Conti ransomware attacks against local orgs
A zero-day exploit for Log4j Java library could have a tsunami impact on IT giants
1.6 million WordPress sites targeted in the last couple of days
Dark Mirai botnet spreads targeting RCE on TP-Link routers
Mozilla fixed high-severity bugs in Firefox and Thunderbird mail client
Crooks injects e-skimmers in random WordPress plugins of e-stores
Tens of malicious NPM packages caught hijacking Discord servers
Moobot botnet spreads by exploiting CVE-2021-36260 flaw in Hikvision products
Microsoft Vancouver leaking website credentials via overlooked DS_STORE file
SonicWall strongly urges customers to apply patches to SMA 100 devices
CS Energy foiled a ransomware attack
Emotet directly drops Cobalt Strike beacons without intermediate Trojans
Google disrupts the Glupteba botnet
Bitcoin Miner [oom_reaper] targets QNAP NAS devices
Microsoft seized 42 domains used by the China-linked APT15 cyberespionage group
Nobelium continues to target organizations worldwide with custom malware
Nobelium APT targets French orgs, French ANSSI agency warns
330 SPAR stores close or switch to cash-only payments after a cyberattack
DMEA Colorado electric utility hit by a disruptive cyberattack
Threat actors stole more than $150 million worth of cryptocurrency tokens from BitMart platform
Hackers are sending receipts with anti-work messages to businesses’ printers
Magnat malvertising campaigns spreads malicious Chrome extensions, backdoors and info stealers
Hundreds of vulnerabilities in common Wi-Fi routers affect millions of users
German BSI agency warns of ransomware attacks over Christmas holidays

If you want to also receive for free the newsletter with the international press subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

DragonForce operator chained SimpleHelp flaws to target an MSP and its customers

Sophos warns that a DragonForce ransomware operator chained three vulnerabilities in SimpleHelp to target a…

10 hours ago

Russia-linked APT Laundry Bear linked to 2024 Dutch Police attack

A new Russia-linked APT group, tracked as Laundry Bear, has been linked to a Dutch…

17 hours ago

Nova Scotia Power confirms it was hit by ransomware attack but hasn’t paid the ransom

Nova Scotia Power confirms it was hit by a ransomware attack but hasn't paid the…

1 day ago

Crooks stole over $200 million from crypto exchange Cetus Protocol

Cetus Protocol reported a $223 million crypto theft and is offering to drop legal action…

1 day ago

Marlboro-Chesterfield Pathology data breach impacted 235,911 individuals

SafePay ransomware hit Marlboro-Chesterfield Pathology, stealing personal data of 235,000 people in a major breach.…

2 days ago

China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosure

China-linked APT exploit Ivanti EPMM flaws to target critical sectors across Europe, North America, and…

2 days ago