Pressure mounts on Canvas as data leak extortion deadline looms

Attackers affiliated with The Com are threatening to leak data from more than 8,800 school systems if Instructure doesn’t pay a ransom.

The post Pressure mounts on Canvas as data leak extortion deadline looms appeared first on CyberScoop.

Continue reading Pressure mounts on Canvas as data leak extortion deadline looms

Google spotted an AI-developed zero-day before attackers could use it

Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain.

The post Google spotted an AI-developed zero-day before attackers could use it appeared first on CyberScoop.

Continue reading Google spotted an AI-developed zero-day before attackers could use it

Ivanti customers confront yet another actively exploited zero-day

Attackers are hitting a frequent target in the network edge space, intruding victim networks through a defect in a widely used mobile endpoint security product.

The post Ivanti customers confront yet another actively exploited zero-day appeared first on CyberScoop.

Continue reading Ivanti customers confront yet another actively exploited zero-day

A critical Palo Alto PAN-OS zero-day is being exploited in the wild

The vendor hasn’t released a patch for the vulnerability or described the scope and objective of confirmed attacks.

The post A critical Palo Alto PAN-OS zero-day is being exploited in the wild appeared first on CyberScoop.

Continue reading A critical Palo Alto PAN-OS zero-day is being exploited in the wild

Latvian national sentenced for ransomware attacks run by former Conti leaders

Deniss Zolotarjovs was mostly tasked with putting pressure on the Russia-based crew’s victims, in one case leaking hundreds of children’s health records.

The post Latvian national sentenced for ransomware attacks run by former Conti leaders appeared first on CyberScoop.

Continue reading Latvian national sentenced for ransomware attacks run by former Conti leaders

‘Copy Fail’ is a real Linux security crisis wrapped in AI slop

The actively exploited defect could affect every mainstream Linux distribution built since 2017, but some researchers found Theori’s AI-generated disclosure unhelpful and lacking.

The post ‘Copy Fail’ is a real Linux security crisis wrapped in AI slop appeared first on CyberScoop.

Continue reading ‘Copy Fail’ is a real Linux security crisis wrapped in AI slop

Former incident responders sentenced to 4 years in prison for committing ransomware attacks

Ryan Goldberg and Kevin Martin attacked five companies in 2023 and extorted nearly $1.3 million from one of their victims.

The post Former incident responders sentenced to 4 years in prison for committing ransomware attacks appeared first on CyberScoop.

Continue reading Former incident responders sentenced to 4 years in prison for committing ransomware attacks

Two new extortion crews are speedrunning the Scattered Spider playbook

CrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion.

The post Two new extortion crews are speedrunning the Scattered Spider playbook appeared first on CyberScoop.

Continue reading Two new extortion crews are speedrunning the Scattered Spider playbook

Chinese national extradited to US for pandemic-era Silk Typhoon attacks

Xu Zewei was allegedly directed by China’s intelligence services to conduct a sweeping espionage campaign to steal data on COVID-19 research and other U.S. policy interests.

The post Chinese national extradited to US for pandemic-era Silk Typhoon attacks appeared first on CyberScoop.

Continue reading Chinese national extradited to US for pandemic-era Silk Typhoon attacks

BlackFile actively extorting data-theft victims in retail and hospitality sector

Some attackers, which researchers link to The Com, have swatted company executives to increase leverage and pressure victims to pay their ransom demands.

The post BlackFile actively extorting data-theft victims in retail and hospitality sector appeared first on CyberScoop.

Continue reading BlackFile actively extorting data-theft victims in retail and hospitality sector