Do you operate an Exchange Server? Is it patched and up to date?

There is an actively exploited zero-day flaw being reported, that Microsoft has not yet patched – so have a look at GTSC’s blog post: Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | GTSC (gteltsc.vn) The post also includes some temporary mitigation whilst waiting …

Here is some of the open-source software I use – and it has all been targeted!

antivirus

PuTTY, KiTTY and Sumatra PDF Reader – I did my due diligence before installing these – and now they have been targeted by ZINC, a state-sponsored group operating out of North Korea. ZINC weaponizing open-source software – Microsoft Security Blog Before writing this blog post I had checked my system …

Hacking is not just data theft and ransomware – it can be reputation damage. Some advice about your WordPress website and your reputation.

wordpress

Fast Company an American magazine was hacked and abusive articles added to its news feeds, resulting in this material getting a wider audience through syndication on the Apple News app. The Apple News channel was quickly disabled and Fast Company took its site down pending a fix but the damage was …

Chaos

Black Lotus Labs has discovered a new strain a malware, they are calling it Chaos. The new is very telling – the malware is infecting a wide range of devices and servers, Linux, Windows, small office routers etc. One of the servers infected was hosting an instance of GitHub, bringing …

New ransomwareattacks following the leak of LockBit software by a hacker insider

I reported on the information leak that LockBit suffered when one of the hacker developers has a spat and leaked the software code. Security software vendors would have been checking out this code to improve their defences but there was also the opportunity for less experienced hackers to improve their …