Cyberattacks: Page 16


  • SolarWinds
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by ismagilov via Getty Images
    Image attribution tooltip

    SEC charges SolarWinds, its CISO with fraud

    The company allegedly misled investors regarding its cybersecurity practices and failed to disclose known risks, according to a complaint.

    By Updated Oct. 31, 2023
  • A Five Guys restaurant is pictured in London, England on May 7, 2020. The company confirmed a data breach last September in a series of consumer notification letters issued Dec. 29, 2022.
    Image attribution tooltip
    Alex Davidson via Getty Images
    Image attribution tooltip

    Five Guys discloses hack of 2 employees’ emails

    The disclosure comes weeks after the company agreed to settle a federal class action suit stemming from a 2022 attack.

    By Oct. 30, 2023
  • Boeing Unveils Is First 737 MAX 7 Passenger Aircraft At Renton Factory
    Image attribution tooltip
    Stephen Brashear / Stringer via Getty Images
    Image attribution tooltip

    Boeing assessing ransomware group’s claim of ‘sensitive’ data theft

    A prolific Russia-affiliated group threatened to leak data if the aerospace company doesn't make contact by Nov. 2.

    By Oct. 30, 2023
  • An image of a digital lock is shown
    Image attribution tooltip
    Just_Super via Getty Images
    Image attribution tooltip

    How to protect sensitive school data during a cyberattack

    The CFO of a Texas school district recommends safer ways to request sensitive employee data and stronger password and verification policies.

    By Kara Arundel • Oct. 27, 2023
  • An octopus floats, depicted in a deep blue background
    Image attribution tooltip
    TheSP4N1SH via Getty Images
    Image attribution tooltip

    High-profile summer attacks linked to same aggressive ransomware group

    Microsoft researchers described Octo Tempest, or Oktapus, as one of the most dangerous financial criminal groups currently in operation.

    By Oct. 27, 2023
  • Skyline of Philadelphia across the water
    Image attribution tooltip
    Permission granted by Philadelphia Office of Innovation and Technology
    Image attribution tooltip

    Philadelphia discloses email compromise 5 months after initial detection

    An ongoing investigation uncovered a two-month dwell time in the city’s email system that exposed some individuals’ sensitive information.

    By Oct. 26, 2023
  • With cyberattacks becoming more frequent, now is the time for CFOs to shore up their cybersecurity programs and strategies.
    Image attribution tooltip
    Getty Images via Getty Images
    Image attribution tooltip

    Novel zero-day exploits fuel Q3 surge in DDoS attacks

    Exploits of the HTTP/2 Rapid Reset vulnerability led to record-breaking attacks as global threat activity continued into October.

    By Oct. 26, 2023
  • A photo illustration of LastPass logos on a hard drive disk held in someone's hand.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    LastPass working through ‘systemic’ security overhaul

    “We didn’t just address the issues that were the cause of the breach,” CEO Karim Toubba said. Still, nearly 1 in 10 customers are fleeing the password manager.

    By Oct. 25, 2023
  • Password input field
    Image attribution tooltip
    Getty via Getty Images
    Image attribution tooltip

    1Password caught in Okta breach, impacting employee-facing apps

    The password manager came forward after BeyondTrust and Cloudflare disclosed similar Okta environment breaches. All three victims claim no data was compromised.

    By Oct. 24, 2023
  • Businessman looking at city through office window
    Image attribution tooltip
    baona via Getty Images
    Image attribution tooltip

    Citrix urges NetScaler ADC, Gateway customers to patch

    The company warned of session hijacking and targeted attacks against a critical vulnerability.

    By Oct. 24, 2023
  • An image of a digital lock is shown
    Image attribution tooltip
    Just_Super via Getty Images
    Image attribution tooltip

    Cisco urges IOS XE customers to patch as thousands of devices remain infected

    The company released enhanced guidance after security researchers were temporarily unable to detect exploited devices.

    By Oct. 24, 2023
  • Okta booth at RSA Conference on April 27, 2023 in San Francisco.
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Okta attacked again, this time hitting its support system

    A threat actor accessed customer support tickets and files containing sensitive data. Okta declined to say how many customers are impacted.

    By Updated Oct. 23, 2023
  • Teacher Giving Computer Science Lecture to Diverse Multiethnic Group of Female and Male Students in Dark College Room.
    Image attribution tooltip
    gorodenkoff via Getty Images
    Image attribution tooltip

    Cisco releases security fix for widely-exploited IOS XE software vulnerability

    An unidentified threat actor is linked to attacks dating back to mid-September, resulting in about 42,000 exploited devices.

    By Updated Oct. 23, 2023
  • Double exposure shot of backside of a computer and red binary codes.
    Image attribution tooltip
    Suebsiri via Getty Images
    Image attribution tooltip

    Critical flaw in JetBrains TeamCity exploited weeks after patch issued

    State-linked actors are targeting the CI/CD platform, and the vendor warns backdoors are lingering undetected.

    By Oct. 20, 2023
  • Exterior of Citrix office complex.
    Image attribution tooltip
    Justin Sullivan/Getty Images via Getty Images
    Image attribution tooltip

    Citrix Netscaler patch for critical CVE bypassed by malicious hackers

    Citrix issued the patch on Oct. 10 for critical vulnerabilities in Netscaler ADC and Netscaler Gateway, but Mandiant is urging users to terminate all sessions.

    By Updated Oct. 19, 2023
  • A bicyclist rides by a sign that is posted in front of the Cisco Systems headquarters on August 10, 2011 in San Jose, California.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Cisco’s critical IOS XE software zero day is a ‘bad situation’

    Researchers from VulnCheck said they have found thousands of implanted hosts.

    By Oct. 17, 2023
  • Threat actor views data file
    Image attribution tooltip
    iStock / Getty Images Plus via Getty Images
    Image attribution tooltip

    US data compromises hit all-time high

    Supply-chain attacks and zero-day exploits, such as the widespread attacks against the MOVEit file-transfer service, are surging, according to the Identity Theft Resource Center.

    By Oct. 16, 2023
  • An image of a digital lock is shown
    Image attribution tooltip
    Just_Super via Getty Images
    Image attribution tooltip

    Critical Atlassian Confluence CVE under exploit by prolific state-linked actor

    Microsoft researchers warn a threat actor with ties to China has been exploiting the vulnerability since mid-September.

    By Oct. 13, 2023
  • Digital technology vector background depicting a cyberattack.
    Image attribution tooltip
    WhataWin via Getty Images
    Image attribution tooltip

    Microsoft tops CISA’s list of exploited CVEs used in ransomware attacks

    CISA updated its Known Exploited Vulnerabilities Catalog to alert organizations to CVEs linked to ransomware.

    By Oct. 13, 2023
  • Estes Express Lines President and COO Webb Estes provides an update on the cyberattack against the LTL carrier.
    Image attribution tooltip
    Retrieved from Estes Express Lines on Facebook on October 09, 2023
    Image attribution tooltip

    Estes cyberattack affected carrier’s phones, other communications

    The LTL carrier is moving freight and remains "open for business," President and COO Webb Estes said in a video message.

    By Colin Campbell • Oct. 12, 2023
  • Law flat icon on wooden block cube with calculator and pencil on dollar bank note money,
    Image attribution tooltip
    grapestock via Getty Images
    Image attribution tooltip

    Progress Software’s financial hit from MOVEit cuts deeper

    With insurance coverage dwindling, and class-action lawsuits and financial restitution claims piling up, more trouble could be on the way for the software company.

    By Oct. 11, 2023
  • Ransomware virus has encrypted data. Attacker is offering key to unlock encrypted data for money.
    Image attribution tooltip
    vchal via Getty Images
    Image attribution tooltip

    Most CISOs confront ransomware — and pay ransoms

    The number of ransomware attacks organizations face has a direct correlation with the frequency with which ransoms are paid.

    By Oct. 11, 2023
  • Header image for "43% of Audit Executives Rank Cybersecurity Controls as 2023's Lead Risk"
    Image attribution tooltip
    Colin Anderson Productions pty ltd
    Image attribution tooltip

    Cloud giants sound alarm on record-breaking DDoS attacks

    Google, AWS and Cloudflare warned the HTTP/2 Rapid Reset attacks are beyond anything ever recorded. 

    By Oct. 10, 2023
  • An exterior image of a hotel
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    Caesars Entertainment says social-engineering attack behind August breach

    In a filing with the Maine attorney general, the gaming company said the attack began in mid-August and impacted tens of thousands of the state's residents.

    By Oct. 9, 2023
  • cyber security graphic
    Image attribution tooltip

    iStock.com/Thapana Onphalai

    Image attribution tooltip
    Sponsored by ISN

    5 ways to help instill a cybersecurity culture within your organization

    Educate your workforce on the importance of mitigating cybersecurity threats to help prevent a cyberattack on your organization.

    Oct. 9, 2023