BleepingComputer.com

"Russian ransomware gangs account for 69% of all ransom proceeds."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 26 July 2024, 1515 UTC.

Content and Source:   https://www.bleepingcomputer.com/

Please check link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Russian ransomware gangs account for 69% of all ransom proceeds

  • Russian-speaking threat actors accounted for at least 69% of all crypto proceeds linked to ransomware throughout the previous year, exceeding $500,000,000.

  • Project Management
     

Study project management and more in this $30 course bundle deal

  • Productivity and project management are skills like any other. Learn how to use them by getting the 2024 Career Productivity Hacker Bundle on sale for $29.99.

    • BleepingComputer Deals
    •  
    • July 26, 2024
    •  
    • 07:19 AM
    •  
    • Comment Count 0
  • PKFail
     

PKfail Secure Boot bypass lets attackers install UEFI malware

  • Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows attackers to bypass Secure Boot and install malware.

  • Hacker
     

Critical ServiceNow RCE flaws actively exploited to steal credentials

  • Threat actors are chaining together ServiceNow flaws using publicly available exploits to breach government agencies and private firms in data theft attacks.

  • Windows 11
     

Windows 11 KB5040527 update fixes Windows Backup failures

  • Microsoft has released the optional KB5040527 preview cumulative update for Windows 11 23H2 and 22H2, which includes fixes for Windows Backup and upgrade failures.

  • Cybersecurity ethical hacking penetration testing
     

Study PenTesting and hacking in this $45 course bundle

  • Start studying ethical hacking and penetration testing on your own schedule. For a limited time, you can get the Complete 2024 Penetration Testing and Ethical Hacking Certification Training Bundle on sale for $44.97.

    • BleepingComputer Deals
    •  
    • July 25, 2024
    •  
    • 02:06 PM
    •  
    • Comment Count 0
  • North Korean hackers
     

US offers $10M for tips on DPRK hacker linked to Maui ransomware attacks

  • The U.S. State Department is offering a reward of up to $10 million for information that could help capture a North Korean military hacker.

  • Instagram
     

Meta nukes massive Instagram sextortion network of 63,000 accounts

  • Meta has removed 63,000 Instagram accounts from Nigeria that were involved in sextortion scams, including a coordinated network of 2,500 accounts linked to 20 individuals targeting primarily adult men in the United States.

  • Progress
     

Progress warns of critical RCE bug in Telerik Report Server

  • Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compromise vulnerable devices.

  • Kill Switch
     

French police push PlugX malware self-destruct payload to clean PCs

  • The French police and Europol are pushing out a "disinfection solution" that automatically removes the PlugX malware from infected devices in France.

  • Why Multivendor Cybersecurity Stacks Are Increasingly Obsolete
     
    Sponsored Content

Why Multivendor Cybersecurity Stacks Are Increasingly Obsolete

  • Multivendor tech stacks are costly and complex to integrate and manage. Learn more from Cynet about how an All-in-One approach reduces costs for MSPs and SMEs, while offering increased security.

    • Sponsored by Cynet
    •  
    • July 25, 2024
    •  
    • 09:37 AM
    •  
    • Comment Count 0
  • This $90 Netgear open-box router would normally cost $269
     

This $90 Netgear open-box router would normally cost $269

  • The NETGEAR Nighthawk RAX43 (AX4200) is a Wi-Fi 6 router with up to 4.2Gbps speed and coverage for up to 2,000 square feet. Normally, this advanced router would cost $269, but you can get it for $89.99.

    • BleepingComputer Deals
    •  
    • July 25, 2024
    •  
    • 07:09 AM
    •  
    • Comment Count 0
  • GitHub
     

Over 3,000 GitHub accounts used by malware distribution service

  • Threat actors known as 'Stargazer Goblin' have created a malware Distribution-as-a-Service (DaaS) from over 3,000 fake accounts on GitHub that push information-stealing malware.

  • Docker
     

Docker fixes critical 5-year old authentication bypass flaw

  • Docker has issued security updates to address a critical vulnerability impacting certain versions of Docker Engine that could allow an attacker to bypass authorization plugins (AuthZ) under certain circumstances.

  • AdGuard Home
     

Get a VPN, DNS, and ad blocker for 5 years for $59.99 in this AdGuard deal

  • Instead of paying the high subscription fees associated with most VPNs, you can get the same service plus an ad blocker and DNS filter all in one. Get the All-in-One AdGuard Bundle five-year subscription while it's on sale for $59.99. 

    • BleepingComputer Deals
    •  
    • July 24, 2024
    •  
    • 02:09 PM
    •  
    • Comment Count 0
  • Windows
     

Microsoft fixes bug behind Windows 10 Connected Cache delivery issues

  • Microsoft has fixed a known Windows 10 update issue that broke Microsoft Connected Cache (MCC) node discovery on enterprise networks.

  • North Korean hackers
     

KnowBe4 mistakenly hires North Korean hacker, faces infostealer attack

  • American cybersecurity company KnowBe4 says a person it recently hired as a Principal Software Engineer turned out to be a North Korean state actor who attempted to install information-stealing on its devices.

  • Google Chrome
     

Google Chrome now asks for passwords to scan protected archives

  • Google Chrome now warns when downloading risky password-protected files and provides improved alerts with more information about potentially malicious downloaded files.

  • CrowdStrike
     

CrowdStrike: 'Content Validator' bug let faulty update pass checks

  • CrowdStrike released a Preliminary Post Incident Review (PIR) on the faulty Falcon update explaining that a bug allowed bad data to pass its Content Validator and cause millions of Windows systems to crash on July 19, 2024.

  • Hot topics: Can’t-miss sessions at Mandiant’s 2024 mWISE event
     
    Sponsored Content

Hot topics: Can’t-miss sessions at Mandiant’s 2024 mWISE event

  • Now that the mWISE 2024 session catalog is out, it's time to take a closer look at the topics. Learn more from @mWISEConference about the three hottest tracks in this year's conference.

Comments

Popular posts from this blog

SecurityWeek Briefing.

SecurityWeek Briefing.

The Hacker News