BleepingComputer.com

"Google Chrome emergency update fixes 6th zero-day exploited in 2024."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 14 May 2024, 1351 UTC.

Content and Source:  https://www.bleepingcomputer.com/BleepingComputer.com.

Please scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Get up to date on Microsoft Azure with $77 off this training bundle

  • Cloud technology is changing how IT departments function, and getting certified in it can help advance your career. These nine Microsoft Azure exam prep courses put you on the path for $39.99, $77 off the $117 MSRP.

    • BLEEPINGCOMPUTER DEALS
    •  
    • MAY 14, 2024
    •  
    • 07:19 AM
    •  
    • Comment Count 0
  • Google Chrome
     

Google Chrome emergency update fixes 6th zero-day exploited in 2024

  • Google has released emergency security updates for the Chrome browser to address a high-severity zero-day vulnerability tagged as exploited in attacks.

  • Sliver Framework
     

PyPi package backdoors Macs using the Sliver pen-testing suite

  • A new package mimicked the popular 'requests' library on the Python Package Index (PyPI) to target macOS devices with the Sliver C2 adversary framework, used for gaining initial access to corporate networks.

  • Apple
     

Apple backports fix for RTKit iOS zero-day to older iPhones

  • Apple has backported security patches released in March to older iPhones and iPads, fixing an iOS Kernel zero-day tagged as exploited in attacks.

  • FCC
     

FCC reveals Royal Tiger, its first tagged robocall threat actor

  • The Federal Communications Commission (FCC) has named its first officially designated robocall threat actor 'Royal Tiger,' a move aiming to help international partners and law enforcement more easily track individuals and entities behind repeat robocall campaigns.

  • BlackSuit Black Suit
     

INC ransomware source code selling on hacking forums for $300,000

  • A cybercriminal using the name "salfetka" claims to be selling the source code of INC Ransom, a ransomware-as-a-service (RaaS) operation launched in August 2023.

  • Phishing
     

Botnet sent millions of emails in LockBit Black ransomware campaign

  • Since April, millions of phishing emails have been sent through the Phorpiex botnet to conduct a large-scale LockBit Black ransomware campaign.

  • Hacker Tunnel
     

Hackers use DNS tunneling for network scanning, tracking victims

  • Threat actors are using Domain Name System (DNS) tunneling to track when their targets open phishing emails and click on malicious links, and to scan networks for potential vulnerabilities.

  • Helsinki
     

Helsinki suffers data breach after hackers exploit unpatched flaw

  • The City of Helsinki is investigating a data breach in its education division, which it discovered in late April 2024, impacting tens of thousands of students, guardians, and personnel.

  • Criminal IP Teams with Quad9 for Advanced Threat Intelligence Sharing
     
    SPONSORED CONTENT

Criminal IP Teams with Quad9 for Advanced Threat Intelligence Sharing

  • The Criminal IP Threat Intelligence (CTI) search engine to integrate with Quad9's threat-blocking service. Learn more from Criminal IP about how this integration can help you.

  • Security Cybersecurity
     

Get started in penetration testing with $300 off this course bundle

  • White-hat hacking is one of the best skills you can learn to advance your cybersecurity career. These nine cybersecurity courses teach you how for $49.99, $301 off the $351 MSRP.

    • BLEEPINGCOMPUTER DEALS
    •  
    • MAY 13, 2024
    •  
    • 07:19 AM
    •  
    • Comment Count 0
  • Largest non-bank lender in Australia warns of a data breach
     

Largest non-bank lender in Australia warns of a data breach

  • Firstmac Limited is warning customers that it suffered a data breach a day after the new Embargo cyber-extortion group leaked over 500GB of data allegedly stolen from the firm.

  • Cybersecurity ethical hacking penetration testing
     

Learn ethical hacking from A to Z with $326 off this training bundle

  • Ethical hacking helps you find issues and repair them before they become a threat. This 12-course cybersecurity training bundle shows you how for $45.99, $326 off the $372 MSRP.

    • BLEEPINGCOMPUTER DEALS
    •  
    • MAY 12, 2024
    •  
    • 08:21 AM
    •  
    • Comment Count 0
  • Hand data data leak hacker
     

The Post Millennial hack leaked data impacting 26 million people

  • Have I Been Pwned has added the information for 26,818,266 people whose data was leaked in a recent hack of The Post Millennial conservative news website.

  • CISA
     

CISA: Black Basta ransomware breached over 500 orgs worldwide

  • ​CISA and the FBI said today that Black Basta ransomware affiliates breached over 500 organizations between April 2022 and May 2024.

  • Europol
     

Europol confirms web portal breach, says no operational data stolen

  • ​Europol, the European Union's law enforcement agency, confirmed that its Europol Platform for Experts (EPE) portal was breached and is now investigating the incident after a threat actor claimed they stole For Official Use Only (FOUO) documents containing classified data.

  • Microsoft Project
     

Keep the team on task with $10 off Microsoft Project through May 22

  • Through May 22 only, new users can get a lifetime license to Microsoft Project Pro 2021 on a single PC for $19.97 (reg. $29.99).

    • BLEEPINGCOMPUTER DEALS
    •  
    • MAY 11, 2024
    •  
    • 08:14 AM
    •  
    • Comment Count 0
  • LockBit
     

The Week in Ransomware - May 10th 2024 - Chipping away at LockBit

  • After many months of taunting law enforcement and offering a million-dollar reward to anyone who could reveal his identity, the FBI and NCA have done just that, revealing the name of LockBitSupp, the operator of the LockBit ransomware operation.

  • Dell
     

Dell API abused to steal 49 million customer records in data breach

  • The threat actor behind the recent Dell data breach revealed they scraped information of 49 million customer records using an partner portal API they accessed as a fake company.

  • Ascension
     

Ascension redirects ambulances after suspected ransomware attack

  • Ascension, a major U.S. healthcare network, is diverting ambulances from several hospitals due to a suspected ransomware attack that has been causing clinical operation disruptions and system outages since Wednesday.

VIEW MORE

Comments

Popular posts from this blog

SecurityWeek Briefing.

Cyber War Newswire

SecurityWeek Briefing.