Washington Post confirms data on nearly 10,000 people stolen from its Oracle environment

The newspaper said a “bad actor” contacted the company in late September, prompting an investigation that nearly a month later confirmed the extent of compromise.

The post Washington Post confirms data on nearly 10,000 people stolen from its Oracle environment appeared first on CyberScoop.

Continue reading Washington Post confirms data on nearly 10,000 people stolen from its Oracle environment

Amazon pins Cisco, Citrix zero-day attacks to APT group

The vendors disclosed and patched the defects last summer, but not before advanced attackers exploited the vulnerabilities to likely gain prolonged access for espionage, according to Amazon.

The post Amazon pins Cisco, Citrix zero-day attacks to APT group appeared first on CyberScoop.

Continue reading Amazon pins Cisco, Citrix zero-day attacks to APT group

Maryland man faces federal charges for crimes allegedly linked to 764

Erik Lee Madison is accused of victimizing five children this fall. His alleged criminality dates back to 2020, when he was a minor.

The post Maryland man faces federal charges for crimes allegedly linked to 764 appeared first on CyberScoop.

Continue reading Maryland man faces federal charges for crimes allegedly linked to 764

Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day

Researchers warn that although exploitation of the zero-day is complex, a functional exploit exists in the wild.

The post Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day

Hitachi subsidiary GlobalLogic impacted by Clop’s attack spree on Oracle customers

The digital engineering services firm said human resources data on nearly 10,500 current and former employees was exposed.

The post Hitachi subsidiary GlobalLogic impacted by Clop’s attack spree on Oracle customers appeared first on CyberScoop.

Continue reading Hitachi subsidiary GlobalLogic impacted by Clop’s attack spree on Oracle customers

What’s left to worry (and not worry) about in the F5 breach aftermath

Researchers say the nation-state attacker could cause more serious problems with the BIG-IP source code it nabbed during the attack on F5’s systems.

The post What’s left to worry (and not worry) about in the F5 breach aftermath appeared first on CyberScoop.

Continue reading What’s left to worry (and not worry) about in the F5 breach aftermath

Russian national pleads guilty to breaking into networks for Yanluowang ransomware attacks

Aleksei Olegovich Volkov served as an initial access broker and was involved in attacks on seven U.S. businesses from July 2021 through November 2022.

The post Russian national pleads guilty to breaking into networks for Yanluowang ransomware attacks appeared first on CyberScoop.

Continue reading Russian national pleads guilty to breaking into networks for Yanluowang ransomware attacks

SonicWall pins attack on customer portal to undisclosed nation-state

The security vendor said the attack, which exposed customers’ firewall configuration files, is contained and unrelated to recent Akira ransomware attacks on its customers.

The post SonicWall pins attack on customer portal to undisclosed nation-state appeared first on CyberScoop.

Continue reading SonicWall pins attack on customer portal to undisclosed nation-state

Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads

The tech giant didn’t report active exploitation of any of the patched defects, yet details about potential impacts remain limited.

The post Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads appeared first on CyberScoop.

Continue reading Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads

Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks

The alleged cybersecurity turncoats attacked at least five U.S. companies while working for their respective employers, officials said.

The post Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks appeared first on CyberScoop.

Continue reading Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks