BleepingComputer.com

"QNAP VioStor NVR vulnerability actively exploited by malware bot net."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 16 December 2023, 1701 UTC.

Content and Source:  https://www.bleepingcomputer.com/ ("BleepingComputer.com").

Please click link or scroll down to read your selections. Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

QNAP VioStor NVR vulnerability actively exploited by malware botnet

  • A Mirai-based botnet named 'InfectedSlurs' is exploiting a remote code execution (RCE) vulnerability in QNAP VioStor NVR (Network Video Recorder) devices to hijack and make them part of its DDoS (distributed denial of service) swarm.

  • Printer Windows
     

Microsoft unveils new, more secure Windows Protected Print Mode

  • Microsoft announced a new Windows Protected Print Mode (WPP), introducing significant security enhancements to the Windows print system.

  • Cryptocurrency Bitcoin Chains Lock
     

The Week in Ransomware - December 15th 2023 - Ransomware Drama

  • The big news over the past two weeks is the continued drama plaguing BlackCat/ALPHV after their infrastructure suddenly stopped working for almost five days. Multiple sources told BleepingComputer that this outage was related to a law enforcement operation, but BlackCat claims the outages were caused by a hardware/hosting issue.

  • Hacker crypto bitcoin
     

Ex-Amazon engineer pleads guilty to hacking crypto exchanges

  • Former Amazon security engineer Shakeeb Ahmed pleaded guilty this week to hacking and stealing over $12.3 million from two cryptocurrency exchanges in July 2022.

  • CISA
     

CISA urges tech manufacturers to stop using default passwords

  • Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged technology manufacturers to stop providing software and devices with default passwords.

  • 3CX
     

3CX warns customers to disable SQL database integrations

  • VoIP communications company 3CX warned customers today to disable SQL database integrations due to potential risks associated with what it describes as a potential vulnerability.

  • Fred Hutchinson Hospital
     

Ransomware gang behind threats to Fred Hutch cancer patients

  • The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats.

  • Box
     

Box cloud storage down amid 'critical' outage

Delta Dental of California data breach exposed info of 7 million people

  • Delta Dental of California and its affiliates are warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach.

  • Heinz Ketchup
     

Kraft Heinz investigates hack claims, says systems ‘operating normally’

  • Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site.

  • Hacker Globe
     

New NKAbuse malware abuses NKN blockchain for stealthy comms

  • A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat.

  • Ubiquiti
     

Ubiquiti users report having access to others’ UniFi routers, cameras

  • Since yesterday, customers of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's cloud services.

  • Police arrest
     

US detains suspects behind $80 million 'pig butchering' scheme

  • The U.S. Department of Justice charged four suspects (two of them already detained) for their alleged involvement in a pig butchering fraud scheme that resulted in more than $80 million in victim losses.

  • Android malware
     

Ten new Android banking trojans targeted 985 bank apps in 2023

  • This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries.

  • Discord
     

Discord adds Security Key support for all users to enhance security

  • Discord has made security key multi-factor authentication (MFA) available for all accounts on the platform, bringing significant security and anti-phishing benefits to its 500+ million registered users.

  • INL
     

U.S. nuclear research lab data breach impacts 45,000 people

  • The Idaho National Laboratory (INL) confirmed that attackers stole the personal information of more than 45,000 individuals after breaching its cloud-based Oracle HCM HR management platform last month.

  • Ledger
     

Ledger dApp supply chain attack steals $600K from crypto wallets

  • Ledger is warnings users not to use web3 dApps after a supply chain attack on the 'Ledger dApp Connect Kit' library was found pushing a JavaScript wallet drainer that stole $600,000 in crypto and NFTs.

VIEW MORE

Comments

Popular posts from this blog

The Cyberwire Daily Briefing

BleepingComputer.com

SecurityWeek Briefing