Cyberattacks: Page


  • DearCry ransomware latching onto Exchange hack, Microsoft says

    Patching is the only answer — for now.

    By Samantha Schwartz • March 12, 2021
  • Image attribution tooltip
    Kendall Davis/Cybersecurity Dive
    Image attribution tooltip

    Enterprises scramble to secure Microsoft Exchange as cybercriminals rush in

    Researchers fear, more than two months after the threat was discovered, criminal hackers have had plenty of time to loot data or plant undetected seeds of compromise.

    By March 10, 2021
  • Trendline

    CISO Strategy

    AI is rapidly transforming the cybersecurity landscape, and CISOs must keep pace.

    By Cybersecurity Dive staff
  • Image attribution tooltip
    Getty Images
    Image attribution tooltip

    55% of healthcare breaches feature ransomware: report

    The healthcare industry is a favored target by cybercriminals: Hospitals cannot tolerate downtime or put off emergency patient care.

    By Samantha Schwartz • March 10, 2021
  • SolarWinds
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    63% of security professionals, execs concerned with SolarWinds hack, survey finds

    Before companies overhaul the typical process for building and securing software, SOCs have to figure out if they were a collateral victim of a supply chain hack.

    By Samantha Schwartz • March 9, 2021
  • Microsoft Exchange server compromise escalates as mitigation efforts fall short

    Officials warn that patching may not fix compromised systems, while tens of thousands of customers are potentially at risk.

    By March 8, 2021
  • Image attribution tooltip
    Getty
    Image attribution tooltip

    3 new malware strains show persistence, sophistication of SolarWinds actor

    The malware strains, identified by Microsoft, were used in targeted, late-stage attacks to compromise a select number of companies last year. 

    By March 5, 2021
  • Qualys confirms data breach related to Accellion after documents leak

    The cloud security firm retained FireEye and insists the breach had no impact on production environments or its code base.

    By March 4, 2021
  • Illustration of locks layered above circuity.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Malicious email campaigns target business platforms following remote work surge

    Phishing attacks are more becoming targeted, less frequent and use PII to harvest credentials.

    By March 4, 2021
  • 4 questions to ask after discovering a cyberattack

    Identifying signs of an ongoing attack or backdoor deployment is nearly impossible for digital laggards.

    By Samantha Schwartz • March 4, 2021
  • UHS
    Image attribution tooltip

    UHS

    Image attribution tooltip

    UHS estimates Ryuk ransomware damage cost at $67M

    Coding and billing functions were delayed into December, impacting the operating cash flows in Q4, the healthcare organization said.

    By Samantha Schwartz • March 2, 2021
  • Image attribution tooltip
    "Google Bike" by R Boed is licensed under CC BY 2.0
    Image attribution tooltip

    Google Cloud enters cyber insurance collaboration with Allianz, Munich Re

    The agreement comes amid increased financial pressure on the cyber insurance industry due to a rise in ransomware and the historic nation-state attack against SolarWinds.

    By March 2, 2021
  • Capitol Hill
    Image attribution tooltip
    The image by Андрей Бобровский is licensed under CC BY 3.0
    Image attribution tooltip

    SolarWinds missed early security warnings

    Lawmakers scrutinized SolarWinds' security practices, including its use of "solarwinds123" as a password, a lapse blamed on a former intern. 

    By March 1, 2021
  • SolarWinds
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    SolarWinds execs warn of short-term impacts from cyberattack, as renewal rates slow

    The company will incur up to $25 million in security-related expenses and declined to provide a full-year earnings outlook.

    By Feb. 26, 2021
  • Image attribution tooltip
    Getty Images
    Image attribution tooltip

    FireEye identifies 2 threat activity clusters behind Accellion hack

    The security firm has labeled one activity cluster for exploiting the FTA vulnerabilities and the other for extortion.

    By Samantha Schwartz • Feb. 23, 2021
  • Water system hack reveals thousands of organizations vulnerable to Window 7 exposure

    Critical infrastructure providers and SMBs continue to operate the outdated Microsoft OS without security updates and patches.

    By Feb. 19, 2021
  • Image attribution tooltip
    Kendall Davis/Cybersecurity Dive
    Image attribution tooltip

    Microsoft says it was not a SolarWinds attack vector, after completing internal probe

    The company confirmed limited amounts of source code for Azure, Exchange and Intune were downloaded.

    By Feb. 19, 2021
  • Sponsored
    Image attribution tooltip
    Permission granted by Jacob Erling
    Image attribution tooltip
    Sponsored by Avanan

    The next generation of email security

    Now, with a single approval of an API, every line of cloud business communication can be secured.

    Feb. 16, 2021
  • Sponsored
    Image attribution tooltip

    dragana991​/iStock

    Image attribution tooltip
    Sponsored by Code42

    The downside of the remote work shift: 85% increase in Insider Risk

    The Code42 2021 Data Exposure Report reveals a perfect storm for Insider Risk.

    Feb. 16, 2021
  • Image attribution tooltip
    Getty
    Image attribution tooltip

    Organizations running SolarWinds Orion online drops 25% since December: report

    A report by RiskRecon shows only 8% of entities operating on the internet actually upgraded to later versions based on SolarWinds security recommendations.

    By Feb. 12, 2021
  • White House taps Neuberger to lead SolarWinds government response

    The SolarWinds attack has opened a deeper conversation about the role of the federal government in coordinating cybersecurity policy and sharing intelligence with the private sector.

    By Feb. 11, 2021
  • Security flaws enabled Florida city water utility hack

    Authorities found poor security hygiene — weak passwords and an outdated operating system — played a role in the hack.

    By Samantha Schwartz • Updated Feb. 12, 2021
  • SolarWinds fallout could last for years, as power industry secures vulnerable equipment: Dragos CEO

    The energy sector is experiencing a "digital transformation with a threat convergence," the CEO of security company Dragos told the U.S. Department of Energy.

    By Robert Walton • Feb. 5, 2021
  • SolarWinds
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Long-term SolarWinds consequences

    SolarWinds security to-do list post hack

    One of the first changes security teams need to make is in how they consider adversaries' capabilities: Always assume the perimeter has been breached.

    By Samantha Schwartz • Feb. 5, 2021
  • Mimecast to cut 4% of workforce in restructuring as breach probe continues

    More than half of Mimecast's business stems from protecting Office 365, which has become a significant target for cyberattacks, Mimecast CEO Peter Bauer said.

    By Feb. 4, 2021
  • Image attribution tooltip
    Naomi Eide
    Image attribution tooltip

    FireEye reports record revenue in first report since Red Team hack

    The company's discovery of the SolarWinds attack has fueled additional customer demand, which should be reflected in deferred revenue during 2021.

    By Feb. 3, 2021