Sun.Jan 02, 2022

article thumbnail

Lapsus$ ransomware gang hits Impresa, Portugal’s largest media conglomerate

Security Affairs

The Lapsus$ ransomware hit Impresa, the largest media conglomerate in Portugal and the owner of SIC and Expresso. The Lapsus$ ransomware gang has compromised the infrastructure of Impresa, the largest media conglomerate in Portugal. Impresa owns SIC TV channel, and Expresso newspaper, among other leading media, like several magazine publications. The attack took place during the New Year holiday, the websites of the Impresa group, the SIC TV channels, and the Expresso were forced offline.

Media 142
article thumbnail

Security Pro Burnout Signals IT Security Shift

Security Boulevard

Major changes to our world, ushered in by the global pandemic, have put a huge strain on IT security professionals’ mental health. Increased demands by organizations to adapt to a remote-first way of working meant that these individuals had to work overtime to ensure not only quick but secure digital transformations. A survey by 1Password. The post Security Pro Burnout Signals IT Security Shift appeared first on Security Boulevard.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Uber ignores vulnerability that lets you send any email from Uber.com

Bleeping Computer

A vulnerability in Uber's email system allows just about anyone to send emails on behalf of Uber. Uber is aware of the flaw but has decided not to fix it for now. [.].

145
145
article thumbnail

Exclusive: NASA Director Twitter account hacked by Powerful Greek Army

Security Affairs

The Twitter account of NASA Director Parimal Kopardekar (@nasapk) was hacked by the Powerful Greek Army group. The Twitter account of the NASA Director and Sr Technologist for Air Transporation Sytem Mr. Parimal Kopardekar ( @nasapk ) was hacked by the Powerful Greek Army group. NASA Director account hacked by PGA! — Powerful Greek Army (@PowerfulGRArmy) January 2, 2022.

article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

Microsoft releases emergency fix for Exchange year 2022 bug

Bleeping Computer

Microsoft has released an emergency fix for a year 2022 bug that is breaking email delivery on on-premise Microsoft Exchange servers. [.].

145
145
article thumbnail

Microsoft rolled out emergency fix for Y2k22 bug in Exchange servers

Security Affairs

Microsoft released an emergency patch to fix the Y2k22 bug that is breaking email delivery on on-premise Microsoft Exchange servers. Microsoft has rolled out an emergency fix that addresses the Y2k22 bug that is breaking email delivery on on-premise Microsoft Exchange servers since January 1st, 2022. “We have addressed the issue causing messages to be stuck in transport queues of on-premises Exchange Server 2016 and Exchange Server 2019.

More Trending

article thumbnail

North Korea-linked threat actors stole $1.7 billion from cryptocurrency exchanges

Security Affairs

North Korea-linked threat actors are behind some of the largest cyberattacks against cryptocurrency exchanges. North Korea-linked APT groups are suspected to be behind some of the largest cyberattacks against cryptocurrency exchanges. According to South Korean media outlet Chosun, North Korean threat actors have stolen around $1.7 billion (2 trillion won) worth of cryptocurrency from multiple exchanges during the past five years.

article thumbnail

Microsoft Issues Fix for Exchange Y2K22 Bug That Crippled Email Delivery Service

The Hacker News

Microsoft, over the weekend, rolled out a fix to address an issue that caused email messages to get stuck on its Exchange Server platforms due to what it blamed on a date validation error at around the turn of the year. "The problem relates to a date check failure with the change of the new year and it [is] not a failure of the [antivirus] engine itself," the company said in a blog post.

Antivirus 120
article thumbnail

BleepingComputer's most popular cybersecurity and tech stories of 2021

Bleeping Computer

?2021 is over, and we can look forward to a hopefully healthier, safer, and more normal 2022. However, it was a big year for technology and cybersecurity with massive cyberattacks and data breaches, innovative phishing attacks, privacy concerns, and of course, zero-day vulnerabilities. [.].

article thumbnail

Crypto security breaches cause $4.25 billion losses worth of cryptos in 2021

Security Affairs

According to a report published by Invezz, the number of crypto security breaches increased by up 850% in the last decade. The cyberattacks against the cryptocurrency industry are a profitable business for threat actors, according to the experts, $12.1 billion worth of cryptocurrencies have been stolen in the last decade. In 2021 we observed a spike in crypto heists, $4.25 billion worth of cryptos were stolen by cybercriminals in 2021.

article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

LastPass Master Passwords, New Cars and Your Privacy, Amazon Alexa Lethal Challenge

Security Boulevard

LastPass users received emails about their master passwords being compromised, details about the privacy policies of new cars, and a story about an Amazon Echo that proposed a lethal challenge to a ten-year-old girl. ** Links mentioned on the show ** Log4j 2.17.1 out now, fixes new remote code execution bug [link] If any person […]. The post LastPass Master Passwords, New Cars and Your Privacy, Amazon Alexa Lethal Challenge appeared first on The Shared Security Show.

Passwords 104
article thumbnail

Uber dismisses vulnerability that lets you email anyone as Uber!

Bleeping Computer

A vulnerability in Uber's email system allows just about anyone to send emails on behalf of Uber. Uber is aware of the flaw but has decided not to fix it for now. [.].

98
article thumbnail

Security Affairs newsletter Round 347

Security Affairs

A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Y2k22 bug in Microsoft Exchange causes failure in email delivery Security Affairs most-read cyber stories of 2021 PulseTV discloses potential credit card breach The Have I Been Pwned service now includes 441K accounts stolen by RedLine malware Mult

Banking 93
article thumbnail

Top 5 Cloud and Cyber Security Stories of 2021

Security Boulevard

The post Top 5 Cloud and Cyber Security Stories of 2021 appeared first on PeoplActive. The post Top 5 Cloud and Cyber Security Stories of 2021 appeared first on Security Boulevard.

86
article thumbnail

Cybersecurity Predictions for 2024

Within the past few years, ransomware attacks have turned to critical infrastructure, healthcare, and government entities. Attackers have taken advantage of the rapid shift to remote work and new technologies. Add to that hacktivism due to global conflicts and U.S. elections, and an increased focus on AI, and you have the perfect recipe for a knotty and turbulent 2024.

article thumbnail

BSides Greenville / BSidesGVL 2021 – Rob Slade’s ‘Security Awareness Lessons From Dr. Bonnie Henry’

Security Boulevard

Our thanks to BSides Greenville / BSidesGVL for publishing their Track1 , Track 2 and Track 3 of their well-crafted videos from the BSides Greenville / BSidesGVL 2021 conference on the Organization’s’ YouTube channel. Permalink. The post BSides Greenville / BSidesGVL 2021 – Rob Slade’s ‘Security Awareness Lessons From Dr. Bonnie Henry’ appeared first on Security Boulevard.

article thumbnail

CommitStrip ‘A Touch Of Real Life, But Not Too Much’

Security Boulevard

via the textual amusements of Thomas Gx , along with the Illustration talents of Etienne Issartia and superb translation skillset of Mark Nightingale - the creators of CommitStrip ! Permalink. The post CommitStrip ‘A Touch Of Real Life, But Not Too Much’ appeared first on Security Boulevard.

62