Government organizations and other government-related targets had their networks targeted in attacks exploiting an already patched FortiOS SSL-VPN zero-day flaw, tracked as CVE-2022-42475, reports BleepingComputer.
IcedID malware, also known as BokBot, has been leveraged in a new attack to achieve Active Directory domain compromise less than a day after securing initial access, according to The Hacker News.
Royal Mail compromised by LockBit ransomware gang The LockBit ransomware gang was behind the "cyber incident" at U.K.-based postal service company Royal Mail, which disrupted overseas but not domestic letter and parcel deliveries, reports The Guardian.
The BianLian ransomware emerged in August and raised the threat bar by encrypting files at high speeds, claiming the seventh most active double extortion group in 2022.
The Scattered Spider threat operation has been engaging in a Bring Your Own Vulnerable Driver attack exploiting an old high-severity Intel Ethernet diagnostics driver flaw to bypass endpoint detection and response systems, according to BleepingComputer.
Over 460K individuals impacted by MFHS ransomware attack More than 460,000 patients, employees, and vendors had their data compromised following a ransomware attack against Pennsylvania-based nonprofit health provider Maternal & Family Health Services, according to TechCrunch.