Meta is taking aim at private surveillance companies that it says act as "cyber mercenaries" for hire. The Facebook parent company has banned seven of these companies from the platform, citing the targeting of users in over 100 countries.
WordFence discovered over 13.7 million cyber attacks targeting four vulnerable plugins and 15 Epsilon framework themes in 36 hours hitting 1.6 million WordPress websites.
Leveraging the Hancitor malware, the ransomware gang earned $43.9 m after compromising 49 critical infrastructure entities in finance, government, healthcare, manufacturing, and IT.
Kronos, a payroll provider known to be used by several thousand companies ranging from Tesla to National Public Radio (NPR), had its Private Cloud service go offline due to a ransomware attack. There is speculation that the Log4Shell vulnerability was involved.
The latest Gone Phishin' event, finds that about 20% of the subjects were compromised by a simulated phishing email; almost 15% did not recognize a malicious download site. Larger organizations, or those that would be expected to have more robust security training programs, tended to fare the worst.
BitMart crypto exchange was victimized with a total loss of about $196 million. BitMart has said that it will compensate victims of the crypto theft, but it is using its own internal estimate of $150 million in losses as a guideline.
Pernicious botnet used for cryptojacking has taken a major blow thanks to Google. Glupteba has been operating for some months and was thought to be compromising thousands of people per day at its peak.
Many organizations affected by Log4j’s zero-day vulnerability with mass internet scanning detected, suggesting the remote code execution flaw was actively targeted in the wild.
The Tor network will no longer be officially available to residents of Russia after a government ban. Taking a path that somewhat resembles China's program of internet control, the Russian government has made a series of moves to restrict access to websites.
Apple's privacy rules will still block developers from the convenience of using each device's unique identifying number without permission, but it appears a number of anonymized device-level "signals" will now be fair game for ad tracking purposes.










