Sprawling Active Attack Aims to Take Over 1.6M WordPress Sites

cybersecurity threat to watch

Cyberattackers are targeting security vulnerabilities in four plugins plus Epsilon themes, to assign themselves administrative accounts. An active attack against more than 1.6 million WordPress sites is underway, with researchers spotting tens of millions of attempts to exploit four different plugins and several Epsilon Framework themes. The goal, they said, is complete site takeover using…

Read More

Ripple Effects Felt Across the Internet With AWS Outage

cybersecurity threat to watch

Problems within the Amazon Web Services infrastructure caused large chunks of the Internet to either load slowly or not load at all starting 12:00 ET/15:30 GMT on Dec. 7, according to data from real-time outage monitoring service DownDetector. Amazon said the problems were in the US-EAST-1 region, which refers to Amazon’s data centers in Virginia, and impacted Elastic Compute Cloud…

Read More

Phishing Remains the Most Common Cause of Data Breaches

cybersecurity threat to watch

Despite heightened concerns over ransomware, fewer organizations in a Dark Reading survey reported being an actual victim of a ransomware attack over the past year. Phishing, malware, and denial-of-service attacks remained the most common causes for data breaches in 2021. Data from Dark Reading’s latest Strategic Security Survey shows that more companies experienced a data breach over…

Read More

Unpatched Windows Zero-Day Allows Privileged File Access

cybersecurity threat to watch

An unpatched Windows security vulnerability could allow information disclosure and local privilege escalation (LPE), researchers have warned. The issue (CVE-2021-24084) has yet to get an official fix, making it a zero-day bug – but a micropatch has been rolled out as a stop-gap measure. Security researcher Abdelhamid Naceri originally reported the vulnerability as an information-disclosure issue in…

Read More

US Banks Will Be Required to Report Cyberattacks Within 36 Hours

cybersecurity threat to watch

There is currently no specific time frame during which banks must report to federal regulators that a security incident had occurred. A new notification rules changes that to 36 hours. Under a new cybersecurity incident notification rule, banks in the United States will be required to notify federal regulators of any cybersecurity incidents within 36…

Read More

3 Must-Know Technologies to Protect Your Hybrid Workforce

cybersecurity threat to watch

A recent Gartner survey found that 82% of companies plan on offering a remote work option at least some of the time. These businesses face the challenge of providing consistent, high-performance access, applying unified security policies across users and devices, and protecting sensitive data against an ever-increasing volume of cyber threats. To address these concerns, security architectures…

Read More

DDOS Attacks on VOIP Surge 35% in Q3

cybersecurity threat to watch

Security experts have warned of a surge in distributed denial of service (DDoS) attacks in the third quarter, with quantity, size and complexity all increasing in the period. The findings come from Lumen’s Q3 DDoS Report, which revealed that the firm mitigated 35% more attacks in the quarter than Q2 2021. The vendor claimed that the largest…

Read More