Officials crack down on Southeast Asia cybercrime networks, seize $15B

The cryptocurrency seizure and sanctions targeting the Prince Group, associates and affiliated businesses mark the most extensive action taken against cybercrime operations in the region to date.

The post Officials crack down on Southeast Asia cybercrime networks, seize $15B appeared first on CyberScoop.

Continue reading Officials crack down on Southeast Asia cybercrime networks, seize $15B

Fortra cops to exploitation of GoAnywhere file-transfer service defect

The vendor belatedly admitted the max-severity vulnerability was actively exploited weeks after researchers and officials confirmed as much independently.

The post Fortra cops to exploitation of GoAnywhere file-transfer service defect appeared first on CyberScoop.

Continue reading Fortra cops to exploitation of GoAnywhere file-transfer service defect

SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal

The security vendor’s customers have confronted a barrage of actively exploited defects since 2021. The brute-force attack on a company-controlled system underscores broader security pitfalls are afoot.

The post SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal appeared first on CyberScoop.

Continue reading SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal

Dozens of Oracle customers impacted by Clop data theft for extortion campaign

Researchers said malicious activity dates back to early July and active exploitation was observed two months ago.

The post Dozens of Oracle customers impacted by Clop data theft for extortion campaign appeared first on CyberScoop.

Continue reading Dozens of Oracle customers impacted by Clop data theft for extortion campaign

Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175

Multiple researchers and CISA have confirmed active exploitation of the maximum-severity defect. Fortra, the company behind the file-transfer service, remains silent.

The post Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175 appeared first on CyberScoop.

Continue reading Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175

Oracle zero-day defect amplifies panic over Clop’s data theft attack spree

The notorious ransomware group exploited multiple vulnerabilities, including a zero-day, for at least eight weeks before alleged victims received extortion demands.

The post Oracle zero-day defect amplifies panic over Clop’s data theft attack spree appeared first on CyberScoop.

Continue reading Oracle zero-day defect amplifies panic over Clop’s data theft attack spree

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

Okta thwarted the supply-chain attack with security controls it had in place. Zscaler did not. Their experiences provide insights into the root of a much broader problem.

The post Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks appeared first on CyberScoop.

Continue reading Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

Red Hat confirms breach of GitLab instance, which stored company’s consulting data

The open-source software company said exposure is limited to consulting engagements, adding that it hasn’t found evidence of personal or sensitive data theft.

The post Red Hat confirms breach of GitLab instance, which stored company’s consulting data appeared first on CyberScoop.

Continue reading Red Hat confirms breach of GitLab instance, which stored company’s consulting data

Here is the email Clop attackers sent to Oracle customers

The emails, which are littered with broken English, aim to instill fear, apply pressure, threaten public exposure and seek negotiation for a ransom payment.

The post Here is the email Clop attackers sent to Oracle customers appeared first on CyberScoop.

Continue reading Here is the email Clop attackers sent to Oracle customers

North Korea IT worker scheme swells beyond US companies

Okta Threat Intelligence uncovered a large-scale and sustained operation, reflecting the North Korean regime’s pursuit of any opportunity that allows for remote employment.

The post North Korea IT worker scheme swells beyond US companies appeared first on CyberScoop.

Continue reading North Korea IT worker scheme swells beyond US companies