Cybersecurity

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks

Dec 29, 2023NewsroomMalware / Endpoint Security Microsoft on Thursday said it’s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware. “The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware […]

Cybersecurity

October cyberattack leaked data of 14.7 million people, mortgage giant Mr. Cooper says

One of the largest mortgage loan servicers in the U.S. said the information of nearly 14.7 million people was leaked during a previously reported cyberattack in October. Mr. Cooper — which says it has more than 4.3 million customers and manages a servicing portfolio of $937 billion — filed breach notification documents with regulators in […]

Cybersecurity

Credit union operations restored after tech supplier ransomware attack

The federal agency that oversees credit unions said operations at about 60 of the organizations have been restored following a ransomware attack last month. The National Credit Union Administration (NCUA) told Recorded Future News that it has been in regular contact with all of the affected financial institutions, helping them get their systems and operations […]

Cybersecurity

Ukraine’s intelligence claims cyberattack on Russia’s state tax service

Ukraine’s defense intelligence directorate (GUR) said it infected thousands of servers belonging to Russia’s state tax service with malware, and destroyed databases and backups. During the operation, Ukraine’s military spies said they managed to break into one of the “key well-protected central servers” of Russia’s federal tax service (FNS) as well as more than 2,300 […]

Cybersecurity

CISA performance goals program trims exploited CVEs

Dive Brief: The Cybersecurity and Infrastructure Security Agency said it is making progress toward reducing security risk since the October 2022 release of its cybersecurity performance goals program, the agency said Tuesday.  Since the release of the CPG program, organizations enrolled in the agency’s vulnerability scanning service have reduced their average number of known exploited […]

Cybersecurity

Google fixes three Chromecast device vulnerabilities

Google said it patched three vulnerabilities in a version of its Chromecast media-streaming hardware discovered by security researchers earlier this year. When chained together, the bugs could allow someone to maliciously install a custom operating system and unsigned code on the Chromecast with Google TV. Patches for the bugs — tagged as CVE-2023-48424, CVE-2023-48425 and […]

Cybersecurity

Payments processor Tipalti investigating ransomware attack

Dive Brief: Accounts payable software vendor Tipalti said it’s investigating a ransomware attack that prolific threat group AlphV claimed responsibility for on Saturday.  “Over the past weekend, a ransomware group claimed that they allegedly gained access to confidential information belonging to Tipalti and its customers,” Tipalti said in a Monday post on X, the social […]