Category: News

Top Illicit Carding Marketplace UniCC Abruptly Shuts Down  

UniCC controlled 30 percent of the stolen payment-card data market; leaving analysts eyeing what’s next.

Real Big Phish: Mobile Phishing & Managing User Fallibility

Phishing is more successful than ever. Daniel Spicer, CSO of Ivanti, discusses emerging trends in phishing, and using zero-trust security to patch the human vulnerabilities underpinning the spike.

Critical Cisco Contact Center Bug Threatens Customer-Service Havoc

Attackers could access and modify agent resources, telephone queues and other customer-service systems – and access personal information on companies’ customers.

‘Be Afraid:’ Massive Cyberattack Downs Ukrainian Gov’t Sites

As Moscow moves troops and threatens military action, about 70 Ukrainian government sites were hit. “Be afraid” was scrawled on the Foreign Ministry site.

Russian Security Takes Down REvil Ransomware Gang

The country’s FSB said that it raided gang hideouts; seized currency, cars and personnel; and neutralized REvil’s infrastructure.

Three Plugins with Same Bug Put 84K WordPress Sites at Risk

Researchers discovered vulnerabilities that can allow for full site takeover in login and e-commerce add-ons for the popular website-building platform.

Microsoft Yanks Buggy Windows Server Updates

Since their release on Patch Tuesday, the updates have been breaking Windows, causing spontaneous boot loops on Windows domain controller servers, breaking Hyper-V and making ReFS volume systems unavailable.

North Korean APTs Stole ~$400M in Crypto in 2021

Meanwhile, EtherumMax got sued over an alleged pump-and-dump scam after using celebs like Floyd Mayweather Jr. & Kim Kardashian to promote EMAX Tokens.

US Military Ties Prolific MuddyWater Cyberespionage APT to Iran

US Cyber Command linked the group to Iranian intelligence and detailed its multi-pronged, increasingly sophisticated suite of malware tools.

New GootLoader Campaign Targets Accounting, Law Firms

GootLoader hijacks WordPress sites to lure professionals to download malicious sample contract templates.