CNN reports that Nantucket Public Schools in Massachusetts had its safety and security systems, as well as student and staff devices, shut down following a ransomware attack, which also prompted the early dismissal of 1,700 students.
BleepingComputer reports that 29,968 QNAP network-attached storage devices could be compromised with potential attacks leveraging a critical SQL injection flaw, tracked as CVE-2022-27596, which has been patched by QNAP on Monday.
SiliconAngle reports that more than 10,000 users across various organizations have been targeted by a new phishing email campaign using fake DocuSign messages to facilitate login credential theft.
While not a stark enterprise threat, security experts warn that if an unenrolled Chromebook at a school district or a retailer does not get detected, a hacker could potentially install malware on the network.
Horizon3.ai researchers say security teams should prioritize the patch or the workarounds for the VMware vRealize vulnerabilities to prevent remote code execution.
Attempts to exploit the Realtek Jungle SDK vulnerability, CVE-2021-35394, was observed by Palo Alto’s Unit 42 researchers an eye-popping 134 million times as of December 2022 and is still ongoing.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.