Cyberattacks: Page 23


  • Threat actor views data file
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    The MOVEit spree is as bad as — or worse than — you think it is

    The mass exploit has compromised more than 600 organizations, but that only scratches the surface of the potential number of downstream victims. Security experts project years of fallout.

    By Aug. 9, 2023
  • CrowdStrike booth at RSA Conference in San Francisco.
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Threat actors abuse valid accounts using manual tactics, CrowdStrike says

    The research underscores the outsized role and prevalence of legitimate credentials as an entry point for cyberattacks.

    By Aug. 8, 2023
  • Trendline

    Top 5 stories from Cybersecurity Dive

    tk

    By Cybersecurity Dive staff
  • exclamation point depicted hovering above network infrastructure
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ransomware attack on Prospect Medical Holdings impacts hospitals across 4 states

    Multiple hospitals in the system are still experiencing complications or closures as of Monday.

    By Aug. 7, 2023
  • Teenage students are walking up and down a staircase in a school hallway.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    White House rolls out millions in funding to combat K-12 cyberattacks

    Federal officials are meeting with key administrators and technology providers to address a surge in ransomware and other malicious activity facing K-12 schools.

    By Aug. 7, 2023
  • A large hallway with supercomputers inside a server room data center.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Poor access management besets most cloud compromises, Google says

    The prevalence of systems with weak access controls underscores a chronic security problem for organizations storing data in the cloud.

    By Aug. 3, 2023
  • Hot Topic hit by automated credential stuffing attack spree

    The U.S. retail chain doesn’t yet know what personal information was compromised or accessed by the threat actor.

    By Aug. 2, 2023
  • Tempur Sealy responding to cyberattack that disrupted operations

    The attack occurred almost two months after the company signed an agreement to acquire Mattress Firm, which will position it as one of the world's largest mattress manufacturers.

    By Aug. 1, 2023
  • Fredrick Lee, CISO at Reddit.
    Image attribution tooltip
    Permission granted by Reddit
    Image attribution tooltip

    Reddit names seasoned IT security leader as new CISO

    The hire of Fredrick “Flee” Lee comes about six months after hackers obtained company data and source code via a sophisticated phishing attack.

    By July 31, 2023
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Valid account credentials are behind most cyber intrusions, CISA finds

    The success rate of these techniques underscores the staying power of the most common methods threat actors use to gain initial access to targeted systems.

    By July 28, 2023
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Mandiant finds no evidence of data or cryptocurrency theft in JumpCloud attack

    The incident response firm only has insights into one of a handful of downstream victims, but the research suggests the damage may be limited.

    By July 26, 2023
  • A picture of a doctor's chest with a stethoscope around the neck.
    Image attribution tooltip
    Joe Raedle/Getty Images via Getty Images
    Image attribution tooltip

    Average cost of healthcare data breach reaches $11M, report finds

    The sector continues to be the most expensive industry for data breaches, with costs increasing 53% since 2020.

    By Emily Olsen • July 25, 2023
  • Money moving through cyberspace.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Investigations are causing data breach costs to skyrocket, IBM finds

    Organizations are under mounting pressure to conduct more thorough investigations as the complexity of data breaches grow.

    By July 24, 2023
  • Digital code data numbers and secure lock icons on hacker's hands working with keyboard computer on dark blue tone background.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Citrix zero day exposes critical infrastructure, one provider hit

    Researchers warn thousands of the Citrix NetScaler devices remain vulnerable to attack.

    By July 24, 2023
  • Activision
    Image attribution tooltip
    jeenah Moon via Getty Images
    Image attribution tooltip

    Microsoft attackers may have data access beyond Outlook, researchers warn

    Microsoft is pushing back on claims by Wiz that compromised private encryption keys may have exposed SharePoint, Teams and OneDrive data to an APT actor.

    By July 21, 2023
  • Rendered image depicting global networks.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    JumpCloud cyberattack hits up to 5 customers, 10 devices

    Security researchers attributed the highly targeted attack to a cryptocurrency-seeking APT actor linked to the North Korean government.

    By July 20, 2023
  • cybersecurity cfos evaluate and prioritize data protection
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    DDoS attacks, growing more sophisticated, surged in Q2

    One of the more serious incidents used a Mirai-variant botnet to unleash an ACK flood DDoS attack that peaked at 1.4 terabits per second, Cloudflare found.

    By July 19, 2023
  • Estee Lauder Lipsticks on display.
    Image attribution tooltip
    Mike Coppola/Getty Images via Getty Images
    Image attribution tooltip

    Estée Lauder takes down some systems following cyberattack

    ALPHV, the ransomware threat actor taking credit for the attack, threatened to reveal more information about the data it claims to have stolen.

    By July 19, 2023
  • Business man looks out of an office window
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    GoTo, parent company to LastPass, names new CISO

    The change in security leadership comes months after the third-party cloud storage service GoTo shares with LastPass was breached.

    By July 19, 2023
  • A building is seen from a parking lot with a sign that reads "UKG."
    Image attribution tooltip

    Photo: Obtained by Industry Dive

    Image attribution tooltip

    UKG agrees to pay up to $6M in lawsuit tied to 2021 breach

    The payroll services provider reached an agreement to settle a class action lawsuit tied to a ransomware attack that targeted its Kronos Private Cloud service.

    By July 18, 2023
  • Digital technology vector background depicting a cyberattack.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Cyberattack compromised JumpCloud customer environments

    The gap between the intrusion and confirmed customer impact suggests the threat actor had access to JumpCloud’s systems for almost two weeks.

    By Updated July 17, 2023
  • A logo sits illuminated outside the Microsoft pavilion on the opening day of the World Mobile Congress at the Fira Gran Via Complex on February 22, 2016 in Barcelona, Spain.
    Image attribution tooltip
    David Ramos via Getty Images
    Image attribution tooltip

    Microsoft hardens key issuance systems after state-backed hackers breach Outlook accounts

    The China-linked group, which Microsoft calls Storm-1558, has adopted new techniques after it took steps to disrupt their recent hacking activity.

    By July 17, 2023
  • Sponsored by Specops Software

    Block known breached passwords from your active directory

    99% of users reuse passwords, here's how to keep the breached ones out of your Active Directory

    July 17, 2023
  • 3D digital circular dynamic wave.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Deep Dive

    MOVEit mass exploit timeline: How the file-transfer service attacks entangled victims

    The slow-moving disaster has ensnared some of the world's largest enterprises. Cybersecurity experts expect further damage to come.

    By July 14, 2023
  • A building showing in the sun with a sign out front that says U.S. State Department.
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    Microsoft warns China-linked APT actor hacked US agency, other email accounts

    U.S. officials alerted Microsoft about what emerged as a targeted, monthlong hacking campaign.

    By July 12, 2023
  • Image attribution tooltip
    Anastasia Vlasova via Getty Images
    Image attribution tooltip

    RomCom uses Word documents in new phishing campaign, Microsoft warns

    The hackers are known to use trojanized versions of legitimate software from Adobe, SolarWinds, KeePass and others.

    By July 12, 2023