Ransomware is never far from the news

Threat actors have been taking advantage of an exploited set of Microsoft credentials to embed ransomware attacks into signed drivers: Microsoft-signed malicious Windows drivers used in ransomware attacks (bleepingcomputer.com) And LockBit got through the cyber security defences of California’s Department of Finance: LockBit claims attack on California’s Department of Finance …

CISA adds five vulnerabilities to the Known Exploited Vulnerabilities Catalog

This is another good resource from the US government Cybersecurity and Infrastructure Security Agency (CISA). Vulnerabilities for Fortinet, Citrix have been added but also for Microsoft Defender and Veeam Backup both of which are vital tools in the fight against threat actors: CISA Adds Five Known Exploited Vulnerabilities to Catalog …

Hosted Exchange supplier hit by cyber incident. Do you have a plan if your email service goes down? UPDATED

email

It is ransomware: Rackspace confirms outage was caused by ransomware attack (bleepingcomputer.com) Rackspace has now confirmed that the outage of Exchange email services for its clients is being caused by a ransomware infection inside their systems – but they refer to this as “isolated disruption”. Which I think is a …

CISA adds a Google vulnerability to the Known Exploited Vulnerabilities Catalog and Cuba Ransomware

The US government Cybersecurity and Infrastructure Security Agency (CISA) has added a Google vulnerability to its Known Exploited Vulnerabilities Catalog. CISA Adds One Known Exploited Vulnerability to Catalog | CISA CISA also published a detailed advisory last week examining all aspects of the Cuba Ransomware as part of its #StopRansomware …