Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly.
A Chinese-speaking cybercrime group called Gambling Goblin is installing malicious Apache modules on compromised Brazilian government and educational web servers. The modules reverse-proxy visitors to attacker-controlled pages that promote online gambling and sports betting, while the traffic still appears to originate from the legitimate domains.
A BGP hijack attack diverted Softaculous traffic to deliver a malicious Virtualizor update to some server installations. The attack occurred between August 28 and August 30, allowing attackers to establish persistent root-level access on compromised hypervisors.
Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.
Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media.
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.