SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • October 13, 2023
  • Rss Fetcher

A ransomware gang offers cash for employees to betray their firms.
Welcome to Cyber Security Today. It’s Friday, October 13th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.

 
The Everest ransomware group is again trying to lure employees to help it compromise their firm in exchange for cash. The Register reports that in a new post on its dark web victim blog the gang promises a “good percentage” of any profits it gets from a successful attack to employees that hand over their access for infiltration. In particular they’re looking for greedy people in the U.S. Canada and Europe. It isn’t clear if the gang is adding to its toolkit by selling the access it gets to other gangs or it wants to use the access to spread its ransomware.
A Western U.S. housing authority has allegedly been compromised by a ransomware gang. The NoEscape group lists the authority on its site, says a news story on Databreaches.net. The claim has not been verified.
Two weeks ago Progress Software urged administrators overseeing its WS_FTP file transfer software to patch the application fast to close a vulnerability. Yesterday researchers at Sophos Group said those that haven’t patched will be in trouble. A ransomware gang called Reichsadler Cybercrime Group is trying to exploit unpatched installations of the server. Progress Software is also the developer of another file transfer suite called MOVEit.
On a similar line, Microsoft warned that a nation-state threat actor is trying to exploit an unpatched vulnerability in Atlassian’s Confluence server. This group has been at it since September 14th. A patch for that hole has been available for over a week, so there’s no excuse for your server to be hit now.
WordPress administrators are being warned to watch their sites for a backdoor that slipped into their content management application. It works as a standalone script and pretends to be a plug-in. The alert comes from researchers at Wordfence, who say the malware has the ability to create an admin account. The report doesn’t say how the malware gets installed, but possibly an employee downloaded something that looks like a legitimate plug-in. One way to fight this is make sure staff are restricted in what they can add to WordPress.
West Texas Gas, an energy provider in Texas and Oklahoma, is notifying over 56,000 customers that some of their personal information was stolen in May. Data taken includes names, debit or credit card numbers as well as the security codes, access codes or passwords for their accounts.
Former Uber CEO Joe Sullivan is appealing his conviction earlier this year of obstruction of justice in connection with the massive 2016 data breach at the ride-sharing company. Prosecutors said he withheld information about that incident from the Federal Trade Commission, which was investigating a 2014 data theft.
Finally, Apple has released more security updates, this time for older iPhones, iPads and iPad minis still eligible for patches. Make sure your device is at least running version 16.7.1 of the operating system.
That’s it for now. But later today the Week in Review podcast will be out. Guest commentator David Shipley of Beauceron Security will be here to talk about the SEC’s investigation into the huge number of MOVEit hacks, data thefts from DNA testing service 23andMe and more.
Links to details about news in every podcast episode are in the text version at ITWorldCanada.com. That’s where you’ll also find other stories of mine.
Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.The post Cyber Security Today, Oct. 13, 2023 – A ransomware gang offers cash for employees to betray their firms first appeared on IT World Canada.

Previous Post
Next Post

Recent Posts

  • Best Joystick & GPS Spoofer for Pokémon GO on iOS & Android
  • Top 3 Free Pokémon GO Spoofers for iOS & Android
  • Why call one API when you can use GraphQL to call them all?
  • TCL Launches the TCL 503 Smartphone in South Africa
  • Tariffs on SA Exports: How Can Local Businesses Prepare for the Impact

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.