ProactiveIT Cyber Security Daily: Recent Episodes

Scott Gombar

ProactiveIT Cyber Security Daily - We share daily cybersecurity, tech and compliance risk news updates, Monday-Friday.

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 442 It is Thursday September 30th 2021. I am your host Scott Gombar and Conti Wants to Destroy Your Backups CISA releases tool to help orgs fend off insider threat risks Trucking giant Forward Air reports ransomware data breach Apple AirTag Zero-Day Weaponizes Trackers Conti Ransomware Expands Ability to Blow Up Backups Data Breaches Reported by Horizon House and Samaritan Center of Puget Sound PHI of 29,000 Patients Potentially Compromised in McAllen Surgical Specialty Center Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 441 It is Wednesday September 29th 2021. I am your host Scott Gombar and What Happens When Microsoft 365 MFA Doesn’t Work? NSA, CISA share VPN security tips to defend against hackers FinFisher malware hijacks Windows Boot Manager with UEFI bootkit Twitter web client outage forces users to log out, blocks logins Microsoft 365 MFA outage locks users out of their accounts Class Action Lawsuits Filed Against San Diego Health Over Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 440 It is Tuesday September 28th 2021. I am your host Scott Gombar and Massive Attack Takes Out Numerous VoIP Providers Microsoft: Nobelium uses custom malware to backdoor Windows domains Ethereum dev admits to helping North Korea evade crypto sanctions Bandwidth.com is latest victim of DDoS attacks against VoIP providers Fifth of Healthcare Providers Report Increase in Patient Mortality After a Ransomware Attack Data Breaches Reported by Vista Radiology, Indian Creek Foundation & Mankato Clinic Vice Society Ransomware Gang Attacks United Health Centers of San Joaquin Valley

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 439 It is Monday September 27th 2021. I am your host Scott Gombar and New Windows Flaw Exists in All Computers Shipped Since 2012 Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords Urgent Chrome Update Released to Patch Actively Exploited Zero-Day Vulnerability VMware vCenter Server Vulnerability CVE-2021-22005 Under Active Exploit Windows 10 emergency update resolves KB5005565 app freezes, crashes Microsoft WPBT flaw lets hackers install rootkits on Windows devices Email Breaches Reported by Eastern Los Angeles Regional Center & Mercy Grace Private Practice K and B Surgical Center & Healthpointe Medical Group Notify Patients About Hacking Incidents

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 438 It is Friday September 24th 2021. I am your host Scott Gombar and Farm Co-ops Are Being Targeted, What’s the Impact? Cisco Releases Security Updates for Multiple Products Apple Releases Security Updates CISA Releases Guidance: IPv6 Considerations for TIC 3.0 Hacking group used ProxyLogon exploits to breach hotels worldwide Crystal Valley Farm Coop Hit with Ransomware Ransomware Attacks Reported by Family Medical Center of Michigan & Buddhist Tzu Chi Medical Foundation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 437 It is Thursday September 23rd 2021. I am your host Scott Gombar and Conti is Escalating How REvil May Have Ripped Off Its Own Affiliates Microsoft Warns of a Wide-Scale Phishing-as-a-Service Operation Hackers are scanning for VMware CVE-2021-22005 targets, patch now! FBI, CISA, and NSA warn of escalating Conti ransomware attacks U.S. Vision Subsidiary Reports Hacking Incident Affecting 180,000 Individuals August 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 436 It is Monday September 20th 2021. I am your host Scott Gombar and Who Wants to Join the Elon Musk Club? Microsoft MSHTML Flaw Exploited by Ryuk Ransomware Gang AT&T Phone-Unlocking Malware Ring Costs Carrier $200M New Malware Targets Windows Subsystem for Linux to Evade Detection New "Elon Musk Club" crypto giveaway scam promoted via email Stolen Laptop Contained the PHI of Dignity Health Patients 1,738 Patients of Coalinga State Hospitals Notified About Improper Disclosure of PHI 36,500 Patients of Austin Cancer Centers Notified About PHI Exposure

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 435 It is Friday September 17th 2021. I am your host Scott Gombar and Just a Few Warnings to End the Week REvil/Sodinokibi Ransomware Universal Decryptor Key Is Out Third Critical Bug Affects Netgear Smart Switches — Details and PoC Released. FBI-CISA-CGCYBER Advisory on APT Exploitation of ManageEngine ADSelfService Plus Vulnerability New Windows security updates break network printing Walgreens Covid-19 Test Registration System Has Been Exposing Patient Data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 434 It is Thursday September 16th 2021. I am your host Scott Gombar and South Africa’s DOJ Hit with Ransomware, Ransomware gang threatens to wipe decryption keys, and Microsoft is going passwordless... Attackers Impersonate DoT in Two-Day Phishing Scam 3 Former U.S. Intelligence Officers Admit to Hacking for UAE Company Ransomware encrypts South Africa's entire Dept of Justice network Ransomware gang threatens to wipe decryption key if negotiator hired Microsoft rolls out passwordless login for all Microsoft accounts HealthReach Community Health Centers Reports Improper Disposal Incident Affecting Almost 117,000 Patients Desert Wells Family Medicine Ransomware Attack Causes Permanent Loss of EHR Data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 433 It is Wednesday September 15th 2021. I am your host Scott Gombar and It’s the Sept 2021 Post Patch Tuesday Roundup Google Chromebook bug causes black screens after login BlackMatter ransomware hits medical technology giant Olympus Microsoft September 2021 Patch Tuesday fixes 2 zero-days, 60 flaws OCR Announces 20th Financial Penalty Under HIPAA Right of Access Enforcement Initiative Jackson Health Investigating Nurse Social Media HIPAA Violation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 432 It is Monday September 13th 2021. I am your host Scott Gombar and REvil is Back, Windows 0-Day exploits are being shared, and more.. WordPress Releases Security Update WhatsApp to Finally Let Users Encrypt Their Chat Backups in the Cloud Windows MSHTML zero-day exploits shared on hacking forums REvil ransomware is back in full attack mode and leaking data MyRepublic discloses data breach exposing government ID cards Philadelphia Mental Health Service Provider Breach Affects 29,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 431 It is Friday September 10th 2021. I am your host Scott Gombar and New Info on the Windows MSHTML Zero-Day Cisco Releases Security Updates for Multiple Products Citrix Releases Security Updates for Hypervisor ‘Azurescape’ Kubernetes Attack Allows Cross-Container Cloud Compromise Yandex is battling the largest DDoS in Russian Internet history Windows MSHTML zero-day defenses bypassed as new info emerges TX: Denton County Discovers COVID-19 Application Leaked Data of 346,000 Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 430 It is Thursday September 9th 2021. I am your host Scott Gombar and Hackers leak passwords for 500,000 Fortinet VPN accounts Zoho Releases Security Update for ADSelfService Plus Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird TeamTNT’s New Tools Target Multiple OS Howard University shuts down network after ransomware attack Hackers leak passwords for 500,000 Fortinet VPN accounts

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 429 It is Wednesday September 8th 2021. I am your host Scott Gombar and Is REvil Back? Microsoft shares temp fix for ongoing Office 365 zero-day attacks Jenkins project's Confluence server hacked to mine Monero McDonald's leaks password for Monopoly VIP database to winners Ransomware gang threatens to leak data if victim contacts FBI, police REvil ransomware's servers mysteriously come back online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 428 It is Tuesday September 7th 2021. I am your host Scott Gombar and US govt warns orgs to patch massively exploited Confluence bug

IoT Attacks Skyrocket, Doubling in 6 Months ProtonMail Shares Activist's IP Address With Authorities Despite Its "No Log" Claims Traffic Exchange Networks Distributing Malware Disguised as Cracked Software Netgear fixes severe security bugs in over a dozen smart switches US govt warns orgs to patch massively exploited Confluence bug CareATC Email Accounts Accessed by Unauthorized Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 427 It is Friday September 3rd 2021. I am your host Scott Gombar and Bluetooth BrakTooth bugs could affect billions of devices

Cisco Patches Critical Authentication Bug With Public Exploit WhatsApp Photo Filter Bug Could Have Exposed Your Data to Remote Attackers Translated Conti ransomware playbook gives insight into attacks Atlassian Confluence flaw actively exploited to install cryptominers FBI warns of ransomware gangs targeting food, agriculture orgs Autodesk reveals it was targeted by Russian SolarWinds hackers Bluetooth BrakTooth bugs could affect billions of devices

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 426 It is Thursday September 2nd 2021. I am your host Scott Gombar and If You Ever Want a Job Again Don’t Do This Google Releases Security Updates for Chrome Windows 10 KB5005101 Cumulative Update released with 34 fixes Feds Warn of Ransomware Attacks Ahead of Labor Day Microsoft: Windows Server 2022 is now generally available FTC bans stalkerware maker Spyfone from surveillance business Twitter adds Safety Mode to automatically block online harassment Fired NY credit union employee nukes 21GB of data in revenge Outpatient Facilities Targeted by Cyber Actors More Frequently Than Hospitals 600,000 DuPage Medical Group Patients Notified About PHI Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 425 It is Wednesday September 1st 2021. I am your host Scott Gombar and Hive Ransomware is Actively Targeting Healthcare FBI-CISA Advisory on Ransomware Awareness for Holidays and Weekends Windows 11 will be released on October 5th to newer devices Microsoft 365 Usage Analytics now anonymizes user info by default Fortress Home Security Open to Remote Disarmament FBI Alert: Hive Ransomware is Actively Targeting Healthcare

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 424 It is Tuesday August 31st 2021. I am your host Scott Gombar and Microsoft shares guidance on securing Azure Cosmos DB accounts CISA Adds Single-Factor Authentication to list of Bad Practices Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping Windows Update will tell if you can upgrade to Windows 11 Google App bug blocks Android users from receiving, making calls Microsoft shares guidance on securing Azure Cosmos DB accounts San Andreas Regional Center Victim of Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 423 It is Monday August 30th 2021. I am your host Scott Gombar and T-Mo Updates (It’s Not Good). Windows 11 to only support one Intel 7th gen CPU, no AMD Zen 1 CPUs Boston Public Library discloses cyberattack, system-wide technical outage T-Mobile CEO: Hacker brute-forced his way through our network 48,000 Individuals Affected by Ransomware Attack on CarePointe ENT PHI of 9,800 Patients of Atlanta Allergy & Asthma Exposed in Cyberattack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 422 It is Friday August 27th 2021. I am your host Scott Gombar and Microsoft and Google to invest billions to bolster US cybersecurity Cisco Releases Security Updates for Multiple Products Ragnarok ransomware releases master decryptor after shutdown Synology: Multiple products impacted by OpenSSL RCE vulnerability FBI shares technical details for Hive ransomware Western Digital confirms speed crippling SN550 SSD flash change Kaseya patches Unitrends server zero-days, issues client mitigations Microsoft accidentally lowers OneDrive for Business storage limits Microsoft and Google to invest billions to bolster US cybersecurity Metro Infectious Disease Consultants Reports 172,000-Record Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 421 It is Thursday August 26th 2021. I am your host Scott Gombar and New Hampshire town loses $2.3 million to overseas scammers F5 Releases August 2021 Security Advisory OpenSSL Releases Security Update  VMware Releases Security Updates for Multiple Products  California Man Hacked iCloud Accounts to Steal Nude Photos New SideWalk Backdoor Targets U.S.-based Computer Retail Business Microsoft will add secure preview for Office 365 quarantined emails FIN8 cybercrime gang backdoors US orgs with new Sardonic malware New Hampshire town loses $2.3 million to overseas scammers South Florida Community Care Plan Notifies Patients About Insider Email Breach Revere Health Phishing Attack Impacts 12,000 Patients California DOJ Must Be Notified About Breaches of the Health Data of 500 or More California Residents

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 420 It is Wednesday August 25th 2021. I am your host Scott Gombar and Ransomware Gang Leaves Clues Modified Version of WhatsApp for Android Spotted Installing Triada Trojan CISA Releases Five Pulse Secure-Related MARs Samsung can remotely disable their TVs worldwide using TV Block SteelSeries bug gives Windows 10 admin rights by plugging in a device New zero-click iPhone exploit used to deploy NSO spyware Ransomware gang's script shows exactly the files they're after

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 419 It is Tuesday August 24th 2021. I am your host Scott Gombar and the July HIPAA Breach Report Has Arrived ProxyShell Attacks Pummel Unpatched Exchange Servers FBI: OnePercent Group Ransomware targeted US orgs since Nov 2020 Phishing campaign uses UPS.com XSS vuln to distribute malware Botnet targets hundreds of thousands of devices using Realtek SDK Nokia subsidiary discloses data breach after Conti ransomware attack HVAC Vendor Allegedly Hacked: Access Gained to Hospital Systems July 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 418 It is Monday August 23rd 2021. I am your host Scott Gombar and Phone Companies’ Customer Data Exposed Hurricane-Related Scams Critical Cisco Bug in Small Business Routers to Remain Unpatched Nigerian Threat Actors Solicit Employees to Deploy Ransomware for Cut of Profits Razer bug lets you become a Windows 10 admin by plugging in a mouse Microsoft Exchange servers being hacked by new LockFile ransomware T-Mobile data breach just got worse — now at 54 million customers AT&T denies data breach after hacker auctions 70 million user database Contact Tracing Survey Data of 750,000 Hoosiers Exposed Online 1.4 Million Individuals Affected by St. Joseph’s/Candler Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 417 It is Friday August 13th 2021. I am your host Scott Gombar and an Evasive Phishing Campaign Active Since July 2020 Mozilla Releases Security Updates for Thunderbird Ransomware Payments Explode Amid ‘Quadruple Extortion’ GitHub deprecates account passwords for authenticating Git operations Hackers now backdoor Microsoft Exchange using ProxyShell exploits Ransomware gang uses PrintNightmare to breach Windows servers Microsoft: Evasive Office 365 phishing campaign active since July 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 416 It is Thursday August 12th 2021. I am your host Scott Gombar and LockBit hits Accenture with a Ransomware Attack. Kaseya’s ‘Master Key’ to REvil Attack Leaked Online Bugs in Managed DNS Services Cloud Let Attackers Spy On DNS Traffic Microsoft confirms another Windows print spooler zero-day bug Hacker behind biggest cryptocurrency heist ever returns stolen funds Accenture Confirms LockBit Ransomware Attack Email Account Breaches Reported by A2Z Diagnostics and Vision for Hope

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 415 It is Wednesday August 11th 2021. I am your host Scott Gombar and It’s the August Post Patch Tuesday Episode Citrix Releases Security Update for ShareFile Storage Zones Controller Adobe Releases Security Updates for Multiple Products  Mozilla Releases Security Updates for Firefox SAP Releases August 2021 Security Updates Intel Releases Multiple Security Updates Microsoft revives deprecated RDCMan after fixing security flaw Crytek confirms Egregor ransomware attack, customer data theft Over $600 million reportedly stolen in cryptocurrency hack Microsoft fixes Windows Print Spooler PrintNightmare vulnerability Microsoft August 2021 Patch Tuesday fixes 3 zero-days, 44 flaws eCh0raix ransomware now targets both QNAP and Synology NAS devices

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 414 It is Tuesday August 10th 2021. I am your host Scott Gombar and Ransomware Attacks on Synology NAS Devices. Beware! New Android Malware Hacks Thousands of Facebook Accounts One million stolen credit cards leaked to promote carding market Microsoft adds Fusion ransomware attack detection to Azure Sentinel Synology warns of malware infecting NAS devices with ransomware Long Island Jewish Forest Hills Hospital Notifies Patients About Insider Breach Dynamic Health Care Malware Attack Affects Multiple Nursing and Rehabilitation Facilities in Illinois

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 413 It is Monday August 9th 2021. I am your host Scott Gombar and Exchange Admins Patch NOW! Ivanti Releases Security Update for Pulse Connect Secure Amazon Kindle Vulnerable to Malicious EBooks Zoom Settlement: An $85M Business Case for Security Investment Australian govt warns of escalating LockBit ransomware attacks Microsoft Exchange servers scanned for ProxyShell vulnerability, Patch Now Computer hardware giant GIGABYTE hit by RansomEXX ransomware NCH Corporation and Others Announce Data Breaches Gastroenterology Consultants Notifies Patients About January 2021 Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 412 It is Friday August 6th 2021. I am your host Scott Gombar and 73% of Businesses Suffered a Data Breach Linked to a Phishing Attack in the Past Year Cisco Releases Security Updates  VMware Releases Security Updates for Multiple Products Linux version of BlackMatter ransomware targets VMware ESXi servers CISA teams up with Microsoft, Google, Amazon to fight ransomware New DNS vulnerability allows 'nation-state level spying' on companies Angry Conti ransomware affiliate leaks gang's attack playbook New Windows PrintNightmare zero-days get free unofficial patch UF Health Says PHI Potentially Compromised in May 2021 Cyberattack 73% of Businesses Suffered a Data Breach Linked to a Phishing Attack in the Past 12 Months Healthcare Industry has Highest Number of Reported Data Breaches in 2021

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 411 It is Thursday August 5th 2021. I am your host Scott Gombar and Can You Trust Your Employees? Google Releases Security Updates for Chrome ‘I’m Calling About Your Car Warranty’, aka PII Hijinx Several Malware Families Targeting IIS Web Servers With Malicious Modules Energy group ERG reports minor disruptions after ransomware attack Cisco fixes critical, high severity pre-auth flaws in VPN routers LockBit ransomware recruiting insiders to breach corporate networks Phishing Attacks Reported by Academic HealthPlans and Wayne County Hospital Guidehouse Reports Breach Affecting Multiple Healthcare Provider Clients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 410 It is Wednesday August 4th 2021. I am your host Scott Gombar and Critical Vulnerability Impacts at least 80% of US Hospitals Raccoon Stealer Bundles Malware, Propagates Via Google SEO Microsoft halts Windows 365 trials after running out of servers Windows 10 to automatically block potentially unwanted apps Windows PetitPotam attacks can be blocked using new method Ransomware Volumes Hit Record Highs as 2021 Wears On PwnedPiper critical bug set impacts major hospitals in North America Star Refining & Express MRI Report Phishing Attacks Harris County, TX: PHI of 26,000 Individuals Exposed Online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 409 It is Monday August 2nd 2021. I am your host Scott Gombar and Emails from 27 US Attorneys’ offices breached by SolarWind’s hackers. NSA Warns Public Networks are Hacker Hotbeds Novel Meteor Wiper Used in Attack that Crippled Iranian Train System DarkSide ransomware gang returns as new BlackMatter operation Remote print server gives anyone Windows admin privileges on a PC FBI warns investors of fraudsters posing as brokers and advisers DOJ: SolarWinds hackers breached emails from 27 US Attorneys’ offices More Than 447K Patients Affected by Phishing Attack on Orlando Family Physicians PHI Potentially Compromised in Ransomware Attacks on Eye Center and Law Firm Accidental Disclosures of PHI at LA Fire Department and Standard Modern Company

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 408 It is Thursday July 29th 2021. I am your host Scott Gombar and What Are the Most Exploited Vulnerabilities? New US security memorandum bolsters critical infrastructure cybersecurity Biden: Severe cyberattacks could escalate to 'real shooting war' Critical Microsoft Hyper-V bug could haunt orgs for a long time Northern Ireland suspends vaccine passport system after data leak LockBit ransomware now encrypts Windows domains using group policies Microsoft Teams now automatically blocks phishing attempts Top Routinely Exploited Vulnerabilities McLaren Health Care and Greenwood Leflore Hospital Impacted by Elekta Ransomware Attack Phishing Attacks Reported by UC San Diego Health and UnitedHealthcare Florida Heart Associates Operating at 50% Capacity 2 Months After Ransomware Attack Overlake Hospital Medical Center Proposes Settlement to Resolve Data Breach Case

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 407 It is Tuesday July 27th 2021. I am your host Scott Gombar and Another Kaseya Problem?? Babuk Ransomware Gang Ransomed, New Forum Stuffed With Porn Microsoft Defender ATP now secures removable storage, printers Apple fixes zero-day affecting iPhones and Macs, exploited in the wild Researchers warn of unpatched Kaseya Unitrends backup vulnerabilities Paperwork Containing PHI of Oklahoma Heart Hospital Patients Accidentally Donated to Charity UNC Health and Nebraska DHHS Report Phishing Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 406 It is Monday July 26th 2021. I am your host Scott Gombar and We’re Not Taking 2FA/MFA Seriously. FIN7’s Liquor Lure Compromises Law Firm with Backdoor Microsoft 365 drops support for Internet Explorer 11 in August Microsoft shares mitigations for new PetitPotam NTLM relay attack Fake Windows 11 installers now used to infect you with malware MacOS malware steals Telegram accounts, Google Chrome data Apple fixes bug that breaks iPhone WiFi when joining rogue hotspots Twitter reveals surprisingly low two-factor auth (2FA) adoption rate Former Scripps Health Worker Charged Over HIPAA Violation in COVID-19 Unemployment Benefit Fraud Case

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 405 It is Friday July 23rd 2021. I am your host Scott Gombar and 740 ransomware victims named on data leak sites in the 2nd quarter  Cisco Releases Security Updates Drupal Releases Security Updates Critical Jira Flaw in Atlassian Could Lead to RCE Phish Swims Past Email Security With Milanote Pages Kaseya obtains universal decryptor for REvil ransomware victims Akamai DNS global outage takes down major websites, online services Ransomware gang breached CNA’s network via fake browser update 740 ransomware victims named on data leak sites in Q2 2021

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 404 It is Thursday July 22nd 2021. I am your host Scott Gombar and The June 2021 HIPAA Breach Report Has Arrived Apple Releases Security Updates Google Releases Security Updates for Chrome Adobe Releases Security Updates for Multiple Products  Malware Targeting Pulse Secure Devices MacOS Being Picked Apart by $49 XLoader Data Stealer NPM Package Steals Passwords via Chrome’s Account-Recovery Tool Chinese state hackers breached over a dozen US pipeline operators Microsoft shares workaround for Windows 10 SeriousSAM vulnerability June 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 403 It is Wednesday July 21st 2021. I am your host Scott Gombar and The Vulnerabilities Keep Coming, And Some Never Left Citrix Releases Security Updates  Fortinet Releases Security Updates for FortiManager and FortiAnalyzer Oracle Releases July 2021 Critical Patch Update 16-Year-Old HP Printer-Driver Bug Impacts Millions of Windows Machines DuckDuckGo's new email privacy service forwards tracker-free messages Microsoft Teams chat feature rolling out to Windows 11 New Windows 10 vulnerability allows anyone to get admin privileges New Linux kernel bug lets you get root on most modern distros FBI: Threat actors may be targeting the 2020 Tokyo Summer Olympics Significant Historical Cyber-Intrusion Campaigns Targeting ICS Email Account Breaches Reported by MultiPlan and Hawaii Independent Physicians Association Advocate Aurora Health, Jefferson Health, and Intermountain Healthcare Affected by Elekta Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 402 It is Tuesday July 20th 2021. I am your host Scott Gombar and China Named in Cyber Threat Activities Ruthless Attackers Target Florida Condo Collapse Victims Leaked NSO Group Data Hints at Widespread Pegasus Spyware Infections Five Critical Password Security Rules Your Employees Are Ignoring Microsoft takes down domains used to scam Office 365 users U.S. Government Releases Indictment and Several Advisories Detailing Chinese Cyber Threat Activity Lake County Health Department Notifies 25,000 Patients About Two Data Breaches Sierra Nevada Primary Care Physicians Alerts Patients About Theft of PHI

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 401 It is Monday July 19th 2021. I am your host Scott Gombar and Law Firm for Fortune 500 Hit With Ransomware & Data Breach Google Releases Security Updates for Chrome Cisco Releases Security Updates Windows 11 features, expected release date, and latest news HelloKitty ransomware is targeting vulnerable SonicWall devices D-Link issues hotfix for hard-coded password router vulnerabilities Critical Cloudflare CDN flaw allowed compromise of 12% of all sites Ransomware hits law firm counseling Fortune 500, Global 500 companies 30,000 Florida Blue Members Impacted by Brute Force Attack on Member Portal

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 400 It is Thursday July 15th 2021. I am your host Scott Gombar and A Critical Ransomware Risk from SonicWall Windows Hello Bypass Fools Biometrics Safeguards in PCs BazarBackdoor sneaks in through nested RAR and ZIP archives Google Chrome will add HTTPS-First Mode to keep your data safe Google: Russian SVR hackers targeted LinkedIn users with Safari zero-day SonicWall warns of 'critical' ransomware risk to EOL SMA 100 VPN appliances PHI of Over 200,000 Individuals Potentially Compromised in ClearBalance Phishing Attack Supply Chain Ransomware Breach Affects 1.2 Million

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 399 It is Thursday July 15th 2021. I am your host Scott Gombar and A Critical Ransomware Risk Warning from SonicWall Windows Hello Bypass Fools Biometrics Safeguards in PCs BazarBackdoor sneaks in through nested RAR and ZIP archives Google Chrome will add HTTPS-First Mode to keep your data safe Google: Russian SVR hackers targeted LinkedIn users with Safari zero-day SonicWall warns of 'critical' ransomware risk to EOL SMA 100 VPN appliances PHI of Over 200,000 Individuals Potentially Compromised in ClearBalance Phishing Attack Supply Chain Ransomware Breach Affects 1.2 Million

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 398 It is Wednesday July 14th 2021. I am your host Scott Gombar and It’s the July 2021 Post Patch Tuesday Roundup Unpatched Critical RCE Bug Allows Industrial, Utility Takeovers Critical Flaws Reported in Etherpad — a Popular Google Docs Alternative Amazon starts rolling out Ring end-to-end encryption globally Adobe updates fix 28 vulnerabilities in 6 programs Microsoft July 2021 Patch Tuesday fixes 9 zero-days, 117 flaws New BIOPASS malware live streams victim's computer screen REvil ransomware gang's web sites mysteriously shut down Hackers use new SolarWinds zero-day to target US Defense orgs

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 397 It is Tuesday July 13th 2021. I am your host Scott Gombar and SolarWinds patches critical vulnerability Critical ForgeRock Access Management Vulnerability Microsoft fixes Outlook crash issues when using Search bar Fashion retailer Guess discloses data breach after ransomware attack SolarWinds patches critical Serv-U vulnerability exploited in the wild Wisconsin Dermatology Practice Reports Data Breach Affecting 4,400 Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 396 It is Monday July 12th 2021. I am your host Scott Gombar and Kaseya patches VSA vulnerabilities Oil & Gas Targeted in Year-Long Cyber-Espionage Campaign Lazarus Targets Job-Seeking Engineers with Malicious Documents Microsoft's Windows Cloud PC service almost here - What we know so far Mint Mobile hit by a data breach after numbers ported, data accessed FBI warns cryptocurrency owners, exchanges of ongoing attacks Insurance giant CNA reports data breach after ransomware attack Kaseya patches VSA vulnerabilities used in REvil ransomware attack Coastal Family Health Center Cyberattack Affects 62,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 395 It is Friday July 9th 2021. I am your host Scott Gombar and Malware Through Live Chat Support Cisco Releases Security Updates for Multiple Products Critical vulnerabilities in Philips Vue PACS devices could allow remote takeover REvil victims are refusing to pay after flawed Kaseya ransomware attack Windows security update KB5004945 breaks printing on Zebra printers Morgan Stanley reports data breach after vendor Accellion hack ‘How can I help you today?’ Scammers dupe online support agents through live chat platforms

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 394 It is Thursday July 8th 2021. I am your host Scott Gombar and The Nightmare Continues MacOS Targeted in WildPressure APT Malware Campaign Kaspersky Password Manager caught out making easily bruteforced passwords Fake Kaseya VSA security update backdoors networks with Cobalt Strike Microsoft: PrintNightmare now patched on all Windows versions Ransomware Attacks Reported by 5 HIPAA Covered Entities and Business Associates UW Health Discovers 4-Month Breach of Its MyChart Portal

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 393 It is Wednesday July 7th 2021. I am your host Scott Gombar and Updates to the Kaseya Attack Western Digital Users Face Another RCE Microsoft pushes emergency update for Windows PrintNightmare zero-day US warns of action against ransomware gangs if Russia refuses Hacker dumps private info of pro-Trump GETTR social network members Microsoft 365 to let SecOps lock hacked Active Directory accounts Kaseya Patches Imminent After Zero-Day Exploits, 1,500 Impacted PHI of Veterans with PTSD Potentially Compromised in OSU Data Breach PHI Exposed in Email Incidents at Discovery Practice Management, One Medical, and Peoples Community Health Clinic

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 392 It is Tuesday July 6th 2021. I am your host Scott Gombar and Anyone Have $70 Million Lying Around? TrickBot Botnet Found Deploying A New Ransomware Called Diavol US water company WSSC Water hit by a ransomware attack QNAP fixes critical bug in NAS backup, disaster recovery app REvil ransomware asks $70 million to decrypt all Kaseya attack victims HHS: Take Action Now to Secure Vulnerable PACS Servers Dominion National Proposes $2 Million Settlement to Resolve Class Action Data Breach Lawsuit

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 391 It is Monday July 5th 2021. I am your host Scott Gombar and Kaseya Supply Chain Ransomware Attack Updates Android Apps with 5.8 million Installs Caught Stealing Users' Facebook Passwords Windows Update bug blocks Azure Virtual Desktops security updates US chemical distributor shares info on DarkSide ransomware data theft CISA-FBI Guidance for MSPs and their Customers Affected by the Kaseya VSA Supply-Chain Ransomware Attack Coop supermarket closes 500 stores after Kaseya ransomware attack Kaseya was fixing zero-day just as REvil ransomware sprung their attack REvil is increasing ransoms for Kaseya ransomware attack victims University Medical Center of Southern Nevada Suffers REvil Ransomware Attack Northwestern Memorial HealthCare and Renown Health Affected by Elekta Cyberattack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 390 It is Friday July 2nd 2021. I am your host Scott Gombar and Fed Says Disable Print Spoolers If Not Needed NSA-CISA-NCSC-FBI Joint Cybersecurity Advisory on Russian GRU Brute Force Campaign LinkedIn’s 1.2B Data-Scrape Victims Already Being Targeted by Attackers Hacked Data for 69K LimeVPN Users Up for Sale on Dark Web Babuk ransomware is back, uses new version on corporate networks Twitter now lets you use security keys as the only 2FA method CISA: Disable Windows Print Spooler on servers not used for printing

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 389 It is Thursday July 1st 2021. I am your host Scott Gombar and PoC for Windows Vulnerability Exists, and Is Circulating Multiple vulnerabilities in WordPress plugin pose website remote code execution risk CISA’s CSET Tool Sets Sights on Ransomware Threat Leaked Babuk Locker ransomware builder used in new attacks Microsoft finds Netgear router bugs enabling corporate breaches Windows 10 KB5004760 emergency update fixes PDF opening issue PoC Exploit Circulating for Critical Windows Print Spooler Bug

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 388 It is Wednesday June 30th 2021. I am your host Scott Gombar and Western Digital My Book Lives are being wiped clean Data for 700M LinkedIn Users Posted for Sale in Cyber-Underground Cobalt Strike Usage Explodes Among Cybercrooks Hackers Trick Microsoft Into Signing Netfilter Driver Loaded With Rootkit Malware Unpatched Virtual Machine Takeover Bug Affects Google Compute Engine The known Windows 11 issues and how you can fix them Microsoft's Halo dev site breached using dependency hijacking Hackers use zero-day to mass-wipe My Book Live devices Email Data Breaches Reported by UofL Health and Jawonio Ohio Hospital Worker Snooped on 7,300 Patient Records over 12 Years

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 387 It is Thursday June 24th 2021. I am your host Scott Gombar and John McAfee is Dead VMware Releases Security Updates Critical Palo Alto Cyber-Defense Bug Allows Remote ‘War Room’ Access Scammer arrested for phishing operation, sent 25,000 texts in a day Tulsa warns of data breach after Conti ransomware leaks police citations Microsoft fixes high-pitched noise bug in Windows 10 PYSA ransomware backdoors education orgs using ChaChi malware Antivirus creator John McAfee reportedly found dead in prison cell Prominence Health Plan Data Breach Impacts up to 45,000 Individuals Associates San Juan Regional Medical Center Data Breach Affects 68,792 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 386 It is Wednesday June 23rd 2021. I am your host Scott Gombar and Using Ransomware for Massages? Lexmark Printers Open to Arbitrary Code-Execution Zero-Day Email Bug Allows Message Snooping, Credential Theft Brave launches its privacy-focused no-tracking search engine SonicWall bug that affected 800K firewalls was only partially fixed Mysterious ransomware payment traced to a sensual massage site

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 385 It is Tuesday June 22nd 2021. I am your host Scott Gombar and Is Windows 11 Really Coming? Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft Tor Browser fixes vulnerability that tracks you using installed apps ADATA suffers 700 GB data leak in Ragnar Locker ransomware attack Windows 11 name confirmed for two weeks and everyone missed it South Texas Health System and Atricure Report Email Incidents

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 384 It is Monday June 21st 2021. I am your host Scott Gombar and the May HIPAA Breach Report Has Arrived North Korea Exploited VPN Flaw to Hack South's Nuclear Research Institute Fertility clinic discloses data breach exposing patient info Google force installs Massachusetts MassNotify Android COVID app iPhone bug breaks WiFi when you join hotspot with unusual name US supermarket chain Wegmans notifies customers of data breach May 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 383 It is Friday June 18th 2021. I am your host Scott Gombar and More Than 1 Billion CVS Records Exposed Due to Unprotected Database Cisco Smart Switches Riddled with Severe Security Holes Microsoft no longer offers Windows 7 drivers via Windows Update Egg free Cake Box suffer data breach exposing credit card numbers Google fixes seventh Chrome zero-day exploited in the wild this year Carnival Cruise hit by data breach, warns of data misuse risk Vigilante malware blocks victims from downloading pirated software CVS Health Records for 1.1 Billion Customers Exposed NorthWest Congenital Heart Care Reports Theft of Device Containing PHI of 1,166 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 382 It is Thursday June 17th 2021. I am your host Scott Gombar and Imagine Your Bike Getting Hacked. Millions of Connected Cameras Open to Eavesdropping IKEA Fined $1.2M for Elaborate ‘Spying System’ Scammers mail fake Ledger devices to steal your cryptocurrency Ukraine arrests Clop ransomware gang members, seizes servers Peloton Bike+ Bug Gives Hackers Complete Control Arizona Asthma and Allergy Institute Notifies 70,372 Patients About Data Breach SEIU 775 Benefits Group Data Breach Impacts 140,000 Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 381 It is Wednesday June 16th 2021. I am your host Scott Gombar and VPN attacks up nearly 2000% Apple Hurries Patches for Safari Bugs Under Active Attack Largest US propane distributor discloses '8-second' data breach Google Workspace adds new phishing protection, client-side encryption VPN attacks up nearly 2000% as companies embrace a hybrid workplace

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 380 It is Tuesday June 15th 2021. I am your host Scott Gombar and Is Windows 11 Coming? CISA Advisory (Medical) ZOLL Defibrillator Dashboard Volkswagen Vendor Exposed Data of 3.3m Drivers Android screen lock protection thwarted by Facebook Messenger Rooms exploit Microsoft: Scammers bypass Office 365 MFA in BEC attacks Microsoft: SEO poisoning used to backdoor targets with malware Windows 11 may be unveiled next week — Here's what we know

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 379. It is Monday June 14th 2021. I am your host Scott Gombar and Was Your TurboTax Account Hacked? REvil Hits US Nuclear Weapons Contractor: Report Baby Clothes Giant Carter’s Leaks 410K Customer Records McDonald's discloses data breach after theft of customer, employee info Network security firm COO charged with medical center cyberattack Linux system service bug lets you get root on most modern distros Windows 10 has an optional update problem, and it's annoying Interpol shuts down thousands of fake online pharmacies Intuit notifies customers of hacked TurboTax accounts Five Rivers Health Centers Phishing Attack Affects Almost 156,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 378. It is Friday June 11th 2021. I am your host Scott Gombar and Let’s End the Week on a Positive Note Beef Supplier JBS Paid Hackers $11 Million Ransom After Cyberattack Foodservice supplier Edward Don hit by a ransomware attack CD Projekt: Data stolen in ransomware attack now circulating online Hackers breach gaming giant Electronic Arts, steal game source code Microsoft Teams bug is prompting users to select a certificate Hackers can exploit bugs in Samsung pre-installed apps to spy on users Slilpp, the largest stolen logins market, seized by law enforcement Humana and Cotiviti Facing Class Action Lawsuit over 63,000-Record Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 377. It is Thursday June 10th 2021. I am your host Scott Gombar and That May Not Be The Construction Company You Hired Mysterious Custom Malware Collects Billions of Stolen Data Points Google fixes sixth Chrome zero-day exploited in the wild this year Microsoft warns of cryptomining attacks on Kubernetes clusters Spain's Ministry of Labor and Social Economy hit by cyberattack FBI warns of BEC scammers impersonating construction companies

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 376. It is Wednesday June 9th 2021. I am your host Scott Gombar and It’s the June 2021 Post Patch Tuesday Roundup Adobe issues security updates for 41 vulnerabilities in 10 products TrickBot Coder Faces Decades in Prison New UAF Vulnerability Affecting Microsoft Office to be Patched Today StackOverflow, Twitch, Reddit, others down in Fastly CDN outage Windows 10 targeted by PuzzleMaker hackers using Chrome zero-days Computer memory maker ADATA hit by Ragnar Locker ransomware Intel fixes 73 vulnerabilities in June 2021 Platform Update Microsoft June 2021 Patch Tuesday fixes 6 exploited zero-days, 50 flaws Third-Party Phishing Attack Affects Up to 34,862 Lafourche Medical Group Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 375. It is Tuesday June 8th 2021. I am your host Scott Gombar and The Future of Ransomware NSW Health confirms data breached due to Accellion vulnerability US recovers most of Colonial Pipeline's $4.4M ransomware payment US truck and military vehicle maker Navistar discloses data breach Windows Container Malware Targets Kubernetes Clusters The cost of ransomware attacks worldwide will go beyond $265 billion in the next decade

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 374. It is Monday June 7th 2021. I am your host Scott Gombar and Revil is Not Dead, but Is Anonymous? Unpatched VMware vCenter Software TikTok Quietly Updated Its Privacy Policy to Collect Users' Biometric Data Live streams go down across Cox radio & TV stations in apparent ransomware attack Microsoft starts autoupdating Windows 10 2004 to Windows 10 21H1 GitHub's new policies allow removal of PoC exploits used in attacks Anonymous Threatens Elon Musk in Video Telling 'Narcissistic Rich Dude' to 'Expect Us' REvil Ransomware Gang Spill Details on US Attacks New Evil Corp ransomware mimics PayloadBin gang to evade US sanctions Ransomware Attacks Affect Sturdy Memorial Hospital and UF Health Risk and Compliance Firm Reports Breach of 47,035 Records

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 373. It is Friday June 4th 2021. I am your host Scott Gombar and Pulse Secure Vulnerability used to Hack NYC MTA. Cisco Releases Security Updates for Multiple Products Google PPC Ads Used to Deliver Infostealers Exchange Servers Targeted by ‘Epsilon Red’ Malware US Supreme Court restricts broad scope of CFAA law UF Health Florida hospitals back to pen and paper after cyberattack WordPress force installs Jetpack security update on 5 million sites Google Chrome now warns you of extensions from untrusted devs Massachusetts' largest ferry service hit by ransomware attack Chinese threat actors hacked NYC MTA using Pulse Secure zero-day 147,000 Patients Affected by Scripps Health Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 372. It is Thursday June 3rd 2021. I am your host Scott Gombar and What’s Next for Microsoft Windows? Mozilla Releases Security Updates for Firefox Cisco Releases Security Updates for Multiple Products DoJ Charges Rhode Island Woman in Phishing Scheme Against Politicians FBI: REvil cybergang behind the JBS ransomware attack WhatsApp caves in: Won't limit features if you reject privacy changes FUJIFILM shuts down network after suspected ransomware attack Microsoft to announce Windows 10's successor on June 24 Diabetes, Endocrinology & Lipidology Center Pays $5,000 to Resolve HIPAA Right of Access Case More than 3.2 Million Individuals Affected by 20/20 Hearing Care Network Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 371. It is Wednesday June 2nd 2021. I am your host Scott Gombar and Is Cyber Liability Insurance Causing an Uptick in Ransomware Attacks? US seizes domains used by APT29 in recent USAID phishing attacks US: Russian threat actors likely behind JBS ransomware attack Critical WordPress plugin zero-day under active exploitation Windows 10's package manager flooded with duplicate, malformed apps Cyber-Insurance Fuels Ransomware Payment Surge

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 370. It is Tuesday June 1st 2021. I am your host Scott Gombar and Your Package Was Not Delivered Hackers Exploit Post-COVID Return to Offices HPE Fixes Critical Zero-Day in Server Management Software Your Amazon Devices to Automatically Share Your Wi-Fi With Neighbors Joint CISA-FBI Cybersecurity Advisory on Sophisticated Spearphishing Campaign Food giant JBS Foods shuts down production after cyberattack Interpol intercepts $83 million fighting financial cyber crime Beware: Walmart phishing attack says your package was not delivered Ransomware Attacks Affect Community Access Unlimited and CareSouth Carolina Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 369. It is Friday May 28th 2021. I am your host Scott Gombar and Japanese Government Breached after Fujitsu Hack Drupal Releases Security Updates Updates to Alert on Pulse Connect Secure Google Chrome now 23% faster after JavaScript engine improvements Canada Post hit by data breach after supplier ransomware attack FBI: APT hackers breached US local govt by exploiting Fortinet bugs HPE fixes critical zero-day vulnerability disclosed in December Japanese government agencies suffer data breaches after Fujitsu hack 4 More Healthcare Organizations Announce Patients Affected by Recent Ransomware Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 368. It is Thursday May 27th 2021. I am your host Scott Gombar and Is it a HIPAA Violation to Ask for Proof of Vaccine Status? ‘Privateer’ Threat Actors Emerge from Cybercrime Swamp BazaLoader Masquerades as Movie-Streaming Service PDF Feature ‘Certified’ Widely Vulnerable to Attack Cybercriminals Exploiting API Keys to Steal Cryptocurrency Office 365 bug: Exchange Online, Outlook emails sent to junk folder ZocDoc Says Programming Error Resulted in Exposure of Patient Data Clinical Laboratory Settles HIPAA Security Rule Violations with OCR for $25,000 Is it a HIPAA Violation to Ask for Proof of Vaccine Status?

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 367. It is Wednesday May 26th 2021. I am your host Scott Gombar and Another Pulse Secure Vulnerability...

Google Chrome 91 released with new features, security improvements VMware warns of critical bug affecting all vCenter Server installs Walmart apologizes for offensive, racist registration emails Iranian hacking group targets Israel with wiper disguised as ransomware Pulse Secure VPNs Get Quick Fix for Critical RCE

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 366. It is Tuesday May 25th 2021. I am your host Scott Gombar and North Korea behind Cryptocurrency Thefts American Express Fined for Sending Millions of Spam Messages Restaurant Reservation System Patches Easy-to-Exploit XSS Bug Audio maker Bose discloses data breach after ransomware attack 'Dearthy Star' pleads guilty to selling info of 65K health care employees Apple fixes three zero-days, one abused by XCSSET macOS malware Bluetooth flaws allow attackers to impersonate legitimate devices North Korean hackers behind CryptoCore multi-million dollar heists

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 365. It is Monday May 24th 2021. I am your host Scott Gombar and FBI Says Conti hit 16 US Healthcare & First Responder Organizations DarkSide Getting Taken to ‘Hackers’ Court’ For Not Paying Affiliates FBI Analyst Charged With Stealing Counterterrorism and Cyber Threat Info Windows 10X on hold, features coming to Windows 10 instead Microsoft Exchange admin portal blocked by expired SSL certificate FBI: Conti ransomware attacked 16 US healthcare, first responder orgs New England Dermatology Discovers Specimen Bottles Disposed of Incorrectly for 10 Years Health Plan of San Joaquin Email Security Breach Affects 420,433 Individuals Rehoboth McKinley Christian Health Care Services Notifies Patients about February 2021 Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 364. It is Friday May 21st 2021. I am your host Scott Gombar and a Malware Campaign with FAKE Ransomware?? Cisco Releases Security Updates for Multiple Products   23 Android Apps Expose Over 100,000,000 Users' Personal Data Conti ransomware gives HSE Ireland free decryptor, still selling data Irish High Court issues injunction to prevent HSE data leak Comcast now blocks BGP hijacking attacks and route leaks with RPKI Microsoft releases SimuLand, a test lab for simulated cyberattacks Slack is down, massive outage blocks user logins and messages Microsoft: Massive malware campaign delivers fake ransomware PHI of up to 50,000 Patients of Arizona Asthma and Allergy Institute Exposed Online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 363. It is Thursday May 20th 2021. I am your host Scott Gombar and The April HIPAA Breach Report is Here Microsoft, Google Clouds Hijacked for Gobs of Phishing Windows PoC Exploit Released for Wormable RCE DarkSide Ransomware Gang Extorted $90 Million from Several Victims in 9 Months Recent Windows 10 update blocks Microsoft Teams, Outlook logins Qlocker ransomware shuts down after extorting hundreds of QNAP users May Android security updates patch 4 zero-days exploited in the wild Hackers scan for vulnerable devices minutes after bug disclosure UHS Data Breach Lawsuit Allowed to Proceed but only for Patient Whose Surgery was Cancelled April 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 362. It is Tuesday May 18th 2021. I am your host Scott Gombar and Has the World Had Enough of Ransomware? Student health insurance carrier Guard.me suffers a data breach Conti ransomware also targeted Ireland's Department of Health FBI spots spear-phishing posing as Truist Bank bank to deliver malware FBI warns of scammers targeting families of missing persons Exploit released for wormable Windows HTTP vulnerability Three major hacking forums ban ransomware ads as some ransomware gangs shut down 140,000 SEIU 775 Benefits Group Members’ PHI Potentially Compromised

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 361. It is Monday May 17th 2021. I am your host Scott Gombar and Ireland’s Health Services hit with $20 million ransom demand Toshiba unit hacked by DarkSide, conglomerate to undergo strategic review Insurer AXA hit by ransomware after dropping support for ransom payments Herff Jones credit card breach impacts college students across the US DarkSide Ransomware Suffers ‘Oh, Crap!’ Server Shutdowns Ireland’s Health Services hit with $20 million ransomware demand Verizon: Healthcare Phishing and Ransomware Attacks Increase while Insider Breaches Fall

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 360. It is Friday May 14th 2021. I am your host Scott Gombar and Darkside is Raking it In This Week WordPress Releases Security Update Apple’s ‘Find My’ Network Exploited via Bluetooth Insurance giant CNA fully restores systems after ransomware attack Crypto exchange glitch causes duplicate purchases, delayed credits Rapid7 source code, credentials accessed in Codecov supply-chain attack Chemical distributor pays $4.4 million to DarkSide ransomware Colonial Pipeline Shells Out $5M in Extortion Payout, Report Records of 200,000 Military Veterans Exposed Online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 359. It is Thursday May 13th 2021. I am your host Scott Gombar and President Orders Increase in Cybersecurity Defense Gig Workers Being Paid $500 for Payroll Passwords Telegram Fraudsters Ramp Up Forged COVID-19 Vaccine Card Sales ‘FragAttacks’: Wi-Fi Bugs Affect Millions of Devices Microsoft: Threat actors target aviation orgs with new malware Trust Wallet, MetaMask crypto wallets targeted by new support scam Microsoft: Windows 10 1809 and 1909 have reached end of service Biden issues executive order to increase U.S. cybersecurity defenses University of Florida Health Shands Employee Accessed PHI Without Authorization for 2 Years

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 358. It is Wednesday May 12th 2021. I am your host Scott Gombar and It’s the May Post Patch Tuesday Episode Adobe Releases Security Updates for Multiple Products  Citrix Releases Security Updates for Workspace App for Windows Juniper Networks Releases Security Updates Google Releases Security Updates for Chrome Wormable Windows Bug Opens Door to DoS, RCE U.S. Declares Emergency in 17 States Over Fuel Pipeline Cyber Attack Microsoft May 2021 Patch Tuesday fixes 55 flaws, 3 zero-days Ransomware gang leaks data from Metropolitan Police Department Microsoft Outlook bug prevents viewing or creating email worldwide Ransomware Attack on New York Medical Group Impacts 330K Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 357. It is Tuesday May 11th 2021. I am your host Scott Gombar and Darkside with a Conscience?

City of Chicago Hit by Data Breach at Law Firm Jones Day City of Tulsa's online services disrupted in ransomware incident Microsoft: Office 365 is blocking emails from Google, LinkedIn domains US and Australia warn of escalating Avaddon ransomware attacks DarkSide ransomware will now vet targets after pipeline cyberattack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 356. It is Monday May 10th 2021. I am your host Scott Gombar and Ransomware Attack Hits US Pipeline iPhone Hack Allegedly Used to Spy on China’s Uyghurs Facebook Will Limit Your WhatsApp Features For Not Accepting Privacy Policy Google Chrome's new privacy feature restricts online user tracking Twitter scammers impersonate SNL in Elon Musk cryptocurrency scams Ransomware gangs have leaked the stolen data of 2,100 companies so far Microsoft: Business email compromise attack targeted dozens of orgs Foxit Reader bug lets attackers run malicious code via PDFs Cuba Ransomware partners with Hancitor for spam-fueled attacks Largest U.S. pipeline shuts down operations after ransomware attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 355. It is Friday May 7th 2021. I am your host Scott Gombar and 40% of all mobile phones are vulnerable VMware Releases Security Update Mozilla Releases Security Updates for Firefox  Cisco Releases Security Updates for Multiple Products  Ryuk Ransomware Attack Sprung by Frugal Student New Spectre Flaws in Intel and AMD CPUs Affect Billions of Computers Google wants to enable multi-factor authentication by default Qualcomm vulnerability impacts nearly 40% of all mobile phones CaptureRx Ransomware Attack Affects Multiple Healthcare Provider Clients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 354. It is Thursday May 6th 2021. I am your host Scott Gombar and Cisco vulnerabilities allow the creation of admin accounts. Anti-Spam WordPress Plugin Could Expose Website User Data Peloton’s Leaky API Spilled Riders’ Private Data Twitter kills 'Open for a surprise' tweets with new mobile feature No, active Microsoft Teams Free organizations will not be deleted VMware fixes critical RCE bug in vRealize Business for Cloud Windows Defender bug fills Windows 10 boot drive with thousands of files Cisco bugs allow creating admin accounts, executing commands as root Lawmakers Call for Investigation into Breach of the Contact Tracing Data of 72,000 Pennsylvanians

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 353. It is Wednesday May 5th 2021. I am your host Scott Gombar and There’s No Easy Conversation Today Apple Releases Security Updates Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs U.S. Agency for Global Media data breach caused by a phishing attack DOD expands bug disclosure program to all publicly accessible systems Network Solutions and Register.com hit by ongoing DNS outage Twilio discloses impact from Codecov supply-chain attack Worldwide phishing attacks deliver three new malware strains Critical 21Nails Exim bugs expose millions of servers to attacks Midwest Transplant Network Suffers Suspected Ransomware Attack Health Aid of Ohio Security Incident Affects up to 141,00 Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 352. It is Tuesday May 4th 2021. I am your host Scott Gombar and May the Fourth Be With You Apple fixes 2 iOS zero-day vulnerabilities actively used in attacks Deepfake Attacks Are About to Surge, Experts Warn Over 40 Apps With More Than 100 Million Installs Found Leaking AWS Keys PoC exploit released for Microsoft Exchange bug dicovered by NSA Toronto hit by ‘potential cyber breach’ from Accellion file transfer software Health care giant Scripps Health hit by ransomware attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 351. It is Monday May 3rd 2021. I am your host Scott Gombar and First Horizon Bank Accounts Hacked Codecov Releases New Detections for Supply Chain Compromise CISA Updates Alert on Pulse Connect Secure Babuk quits ransomware encryption, focuses on data-theft extortion Your stolen ParkMobile data is now free for wannabe scammers First Horizon bank online accounts hacked to steal customers’ funds Californian Healthcare Provider Discovers Patient Data was Exposed on the Internet for Over a Year

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 350. It is Friday April 30th 2021. I am your host Scott Gombar and Stopping Ransomware 101 CISA Releases ICS Advisory on Real-Time Operating System Vulnerabilities Cisco Releases Security Updates for Multiple Products Experian API Leaks Most Americans’ Credit Scores Microsoft Office SharePoint Targeted With High-Risk Phish, Ransomware Attacks New ransomware group uses SonicWall zero-day to breach networks QNAP warns of AgeLocker ransomware attacks on NAS devices Security expert coalition shares actions to disrupt ransomware PHI of 31,000 Individuals Potentially Compromised in River Springs Health Plans Phishing Attack Einstein Healthcare Network Facing Class Action Lawsuit over 2020 Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 349. It is Thursday April 29th 2021. I am your host Scott Gombar and FOMO Leads to Phishing Apple Releases Security Updates Chase Bank Phish Swims Past Exchange Email Protections Cybercriminals Widely Abusing Excel 4.0 Macro to Distribute Malware F5 BIG-IP Found Vulnerable to Kerberos KDC Spoofing Vulnerability DigitalOcean data breach exposes customer billing information New stealthy Linux malware used to backdoor systems for years SMS phishing scam lures Rogers customers with outage refunds Wyoming Department of Health Announces GitHub Data Breach Affecting 164,000 Individuals Ransom Payment Increase Driven by Accellion FTA Data Exfiltration Extortion Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 348. It is Wednesday April 28th 2021. I am your host Scott Gombar and Stomping Out Emotet Google Releases Security Updates for Chrome Hackers Threaten to Leak D.C. Police Informants' Info If Ransom Is Not Paid Microsoft Teams worldwide outage impacts user logins, chats FBI shares 4 million email addresses used by Emotet with Have I Been Pwned Phishing Attack on Home Medical Equipment Provider Affects 153,000 Individuals Several Healthcare Providers Postpone Radiation Treatments Due to Cyberattack on Software Vendor

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 347. It is Tuesday April 27th 2021. I am your host Scott Gombar and Guidance on Defending Against a Software Supply Chain Attack Released Apple fixes macOS zero-day bug exploited by Shlayer malware Flubot Spyware Spreading Through Android Devices Nvidia Warns: Severe Security Bugs in GPU Driver, vGPU Software Hacker dumps sensitive household records of 250M Americans DC Police confirms cyberattack after ransomware gang leaks data Microsoft announces end of life for multiple .NET Framework versions Apple iCloud Mail outage causing email sending, receiving issues CISA and NIST Release New Interagency Resource: Defending Against Software Supply Chain Attacks Manquen Vance Email Breach Impacts 7,018 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 346. It is Monday April 26th 2021. I am your host Scott Gombar and REvil vs. Apple

Passwordstate Password Manager Update Hijacked to Install Backdoor on Thousands of PCs Costco Issues Scam Warning Hacker leaks 20 million alleged BigBasket user records for free Windows 10 package manager can now remove any app from the command line Emotet malware nukes itself today from all infected computers worldwide HashiCorp is the latest victim of Codecov supply-chain attack REvil’s Big Apple Ransomware Gambit Looks to Pay Off Twitter accidentally sends suspicious emails asking to confirm accounts

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 345. It is Friday April 23rd 2021. I am your host Scott Gombar and Simple Styling to Hide Warnings in Microsoft Emails..

Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns Researchers Find Additional Infrastructure Used By SolarWinds Hackers Trend Micro flaw actively exploited in the wild Apple, you've AirDrop'd the ball: Academics detail ways to leak contact info of nearby iThings for spear-phishing Exchange Online down: Microsoft 365 outage affects email delivery QNAP removes backdoor account in NAS backup, disaster recovery app Attackers can hide 'external sender' email warnings with HTML and CSS

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 344. It is Thursday April 22nd 2021. I am your host Scott Gombar and Logins for 1.3 million Windows RDP servers have been leaked. Novel Email-Based Campaign Targets Bloomberg Clients with RATs QR Codes Offer Easy Cyberattack Avenues as Usage Spikes Hackers threaten to leak stolen Apple blueprints if $50 million ransom isn't paid Massive Qlocker ransomware attack uses 7zip to encrypt QNAP devices Microsoft Autoruns is crashing when listing Windows 10 startups Google fixes exploited Chrome zero-day dropped on Twitter last week WhatsApp Pink malware can now auto-reply to your Signal, Telegram texts Logins for 1.3 million Windows RDP servers collected from hacker market Data Breaches Reported by VEP Healthcare and the American College of Emergency Physicians

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 343. It is Wednesday April 21st 2021. I am your host Scott Gombar and Eversource Customers, Your Data Was Exposed! Mozilla Releases Security Update for Firefox, Firefox ESR, and Thunderbird VMware Releases Security Update Oracle Releases April 2021 Critical Patch Update CISA Releases Alert on Exploitation of Pulse Connect Secure Vulnerabilities Fake Microsoft Store, Spotify sites spread info-stealing malware Hundreds of networks reportedly hacked in Codecov supply-chain attack REvil gang tries to extort Apple, threatens to sell stolen blueprints SonicWall warns customers to patch 3 zero-days exploited in the wild Eversource Energy data breach caused by unsecured cloud storage

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 342. It is Tuesday April 20th 2021. I am your host Scott Gombar and 15 Minutes Could Expose Your Driver's License Number Malware That Spreads Via Xcode Projects Now Targeting Apple's M1-based Macs Drinks giant C&C Group subsidiary shuts down IT systems following security incident Google Alerts continues to be a hotbed of scams and malware Microsoft disables Google's FLoC tracking in Microsoft Edge, for now Rogers is down: Canadian users report voice and data outages Geico data breach exposed customers' driver's license numbers March 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 341. It is Monday April 19th 2021. I am your host Scott Gombar and The Next Supply Chain Hack? WordPress Releases Security and Maintenance Update Google Project Zero Cuts Bug Disclosure Timeline to a 30-Day Grace Period WordPress to automatically disable Google FLoC on websites Twitter is suffering from another worldwide outage today Microsoft fixes Windows 10 bug that can corrupt NTFS drives Major BGP leak disrupts thousands of networks globally U.S. Federal Investigators Are Reportedly Looking Into Codecov Security Breach, Undetected for Months

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 340. It is Friday April 16th 2021. I am your host Scott Gombar and What the Russians Are Using to Hack Attackers Target ProxyLogon Exploit to Install Cryptojacker US Sanctions Russia and Expels 10 Diplomats Over SolarWinds Cyberattack A Casino Gets Hacked Through a Fish-Tank Thermometer Windows Terminal released with new settings UI and more Celsius email system breach leads to phishing attack on customers Microsoft Edge's new Kids Mode is now rolling out to everyone NSA: Top 5 vulnerabilities actively abused by Russian govt hackers Montefiore Medical Center Fires Employee for Unauthorized Record Access

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 339. It is Thursday April 15th 2021. I am your host Scott Gombar and The Electrical Grid is Under Attack Google Chrome 90 released with HTTPS as the default protocol Threat Actors Targeting Cybersecurity Researchers 100,000 Google Sites Used to Install SolarMarket RAT New WhatsApp Bugs Could've Let Attackers Hack Your Phone Remotely Risk startup LogicGate confirms data breach Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins Second Google Chrome zero-day exploit dropped on twitter this week Vivaldi, Brave, DuckDuckGo reject Google's FLoC ad tracking tech Experts see 'unprecedented' increase in hackers targeting electric grid HHS Information Blocking and Interoperability Regulations Now in Effect

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 338. It is Wednesday April 14th 2021. I am your host Scott Gombar and It’s the April Post Patch Tuesday Roundup Adobe Patches Slew of Critical Security Bugs in Bridge, Photoshop Google Releases Security Updates for Chrome SAP Releases April 2021 Security Updates Chrome Zero-Day Exploit Posted on Twitter Apply Microsoft April 2021 Security Update to Mitigate Newly Disclosed Microsoft Exchange Vulnerabilities Man Arrested for AWS Bomb Plot New NAME:WRECK Vulnerabilities Impact Nearly 100 Million IoT Devices FBI nuked web shells from hacked Exchange Servers without telling owners Capcom: Ransomware gang used old VPN device to breach the network Microsoft April 2021 Patch Tuesday fixes 108 flaws, 5 zero-days PHI of More than 200,000 Washington D.C. Health Plan Members Stolen by Hackers 221,000 Total Health Care Members Impacted by Email Account Breach Adventist Health Physicians Network Fined $40,000 for Privacy Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 337. It is Tuesday April 6th 2021. I am your host Scott Gombar and Microsoft Winning the Browser War? LinkedIn Spear-Phishing Campaign Targets Job Hunters Criminals send out fake “census form” reminder – don’t fall for it! Asteelflash electronics maker hit by REvil ransomware attack Adult content from hundreds of OnlyFans creators leaked online New Microsoft Edge grew 1,300% this year, overtaking Firefox PHI from Multiple Covered Entities Published on GitHub

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 336. It is Monday April 5th 2021. I am your host Scott Gombar and Eight States Can’t Do Vehicle Inspections Due to Malware VMware Releases Security Update FBI: APTs Actively Exploiting Fortinet VPN Security Holes 533 Million Facebook Users' Phone Numbers and Personal Data Leaked Online Brown University hit by cyberattack, some systems still offline Capital One notifies more clients of SSNs exposed in 2019 data breach Ubiquiti cyberattack may be far worse than originally disclosed Ransomware gang leaks data from Stanford, Maryland universities Microsoft outage caused by overloaded Azure DNS servers Malware attack is preventing car inspections in eight US states

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 335.  It is ThursdayApril 1st 2021.  I am your host Scott Gombar and Tick Tock, No, Not the App

Nearly 20% of Ransomware Victims that pay the ransom do not get their data back

Citrix Releases Security Updates for Hypervisor

VMware Releases Security Updates

Google Releases Security Updates for Chrome

DMV: CT emissions testing program having 'technical issues'

Child Tweets Gibberish from U.S. Nuke Account

APT Charming Kitten Pounces on Medical Researchers

800Gbps DDoS extortion attack hits gambling company

Microsoft kills off the Cortana app for Android and iOS

CISA gives federal agencies 5 days to find hacked Exchange servers

Lexington Medical Center and CalViva Health Affected by Third-Party Data Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 334.  It is Wednesday March 31st 2021.  I am your host Scott Gombar and Wanna Cry?

VMware fixes bug allowing attackers to steal admin credentials

SolarWinds Attackers Accessed DHS Emails, Report

US govt warns that buying fake COVID-19 vaccine cards is a crime

Scammers target universities in ongoing IRS phishing attacks

Microsoft Exchange attacks increase while WannaCry gets a restart

Ransomware: Home Health Firm Reports 2nd Cloud Vendor Incident

University of Miami Health and Mott Community College Data Compromised in Ransomware Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 333.  It is Tuesday March 30th 2021.  I am your host Scott Gombar and A Ransomware Refund?

Hades Ransomware Gang Exhibits Connections to Hafnium

PHP Infiltrated with Backdoor Malware

Windows 10 KB5000842 cumulative update fixes freezing issues

Docker Hub images downloaded 20M times come with cryptominers

Harris Federation hit by ransomware attack affecting 50 schools

Ransomware admin is refunding victims their ransom payments

New Jersey Plastic Surgery Practice Pays $30K to OCR to Settle HIPAA Right of Access Case

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 332.  It is Monday March 29th 2021.  I am your host Scott Gombar and Hello, We Recently Ransomwared a Business You’re a Client Of

OpenSSL Releases Security Update

Apple Releases Security Updates 

Executive Order Would Strengthen Cybersecurity Requirements for Federal Agencies

Watch Out! That Android System Update May Contain A Powerful Spyware\

CompuCom MSP expects over $20M in losses after ransomware attack

Microsoft: Black Kingdom ransomware group hacked 1.5K Exchange servers

SolarWinds patches critical code execution bug in Orion Platform

Ransomware gang urges victims’ customers to demand a ransom payment

Cancer Treatment Centers of America Announces 105,000-Record Data Breach

SalusCare Takes Legal Action Against Amazon to Obtain AWS Audit Logs to Investigate Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 331. It is Friday March 26th 2021. I am your host Scott Gombar and An Update to the CNA Ransomware Attack Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird Cisco Releases Security Updates Samba Releases Security Updates Webshells Observed in Post-Compromised Exchange Servers Facebook Disrupts Spy Effort Aimed at Uyghurs Microsoft Offers Up To $30K For Teams Bugs Cloudflare Page Shield: Early warning system for malicious scripts BackBlaze mistakenly shared backup metadata with Facebook Insurance giant CNA hit by new Phoenix CryptoLocker ransomware Hospice CEO Pleads Guilty to Falsifying Healthcare Claims and Inappropriate Medical Record Access Massachusetts Mental Health Clinic Settles HIPAA Right of Access Case for $65,000 Misconfiguration Resulted in Exposure of the PHI of 65,000 Mobile Anesthesiologists Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 330.  It is Wednesday March 24th 2021.  I am your host Scott Gombar and Just a Bunch of Ransomware & Stuff

Office 365 Cyberattack Lands Disgruntled IT Contractor in Jail

WARNING: A New Android Zero-Day Vulnerability Is Under Active Attack

CNA insurance firm hit by a cyberattack, operations impacted

Purple Fox malware worms its way into exposed Windows systems

Ransomware gang leaks data stolen from Colorado, Miami universities

Microsoft warns of phishing attacks bypassing email gateways

High-availability server maker Stratus hit by ransomware

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 329.  It is Tuesday March 23rd 2021.  I am your host Scott Gombar and More on Accellion and MS Exchange

CISA Warns of Security Flaws in GE Power Management Devices

Adobe Fixes Critical ColdFusion Flaw in Emergency Update

Popular remote lesson monitoring program could be exploited to attack student PCs

Energy giant Shell discloses data breach after Accellion hack

Microsoft Exchange servers now targeted by Black Kingdom ransomware

California Department of State Hospitals Discovers Unauthorized Data Copying by IT Employee

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 328.  It is Monday March 22nd 2021.  I am your host Scott Gombar and Acer Hit with a $50 Million Ransomware Attack

Zoom Screen-Sharing Glitch ‘Briefly’ Leaks Sensitive Data

Bogus Android Clubhouse App Drops Credential-Swiping Malware

Critical F5 BIG-IP Bug Under Active Attacks After PoC Exploit Posted Online

Windows 10 KB5001649 update is rolling out again to fix printing

Facebook outage affecting WhatsApp, Messenger and Instagram

Microsoft Defender adds automatic Exchange ProxyLogon mitigation

Computer giant Acer hit by $50 million ransomware attack

More Health Insurers Confirmed as Victims of Accellion Ransomware Attack and Multiple Lawsuits Filed

February 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 327.  It is Friday March 19th 2021.  I am your host Scott Gombar and Over $4.2 billion officially lost to cybercrime in 2020

Cisco Releases Security Updates

Tutor LMS for WordPress Open to Info-Stealing Security Holes

$4,000 COVID-19 ‘Relief Checks’ Cloak Dridex Malware

Mysterious bug is deleting Microsoft SharePoint, Teams files

CISA releases new SolarWinds malicious activity detection tool

Microsoft warns of more printing issues caused by March updates

US taxpayers targeted with RAT malware in ongoing phishing attacks

New CopperStealer malware steals Google, Apple, Facebook accounts

FBI: Over $4.2 billion officially lost to cybercrime in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 326.  It is Thursday March 18th 2021.  I am your host Scott Gombar and Trickbot Hasn’t Gone Away..

Mimecast: SolarWinds Attackers Stole Source Code

99.2% of US government Android users are running outdated OS versions

Audacity 3.0 released with new AUP3 file format, speed improvements

Microsoft's Azure SDK site tricked into listing fake package

Microsoft is auto-installing the Windows 10 WebView2 Runtime

CISA-FBI Joint Advisory on TrickBot Malware

PHI of 26,600 Individuals Potentially Copied in Colorado Retina Associates Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 325. It is Wednesday March 17th 2021. I am your host Scott Gombar and What Happened with Microsoft Yesterday? Latest Mirai Variant Targets SonicWall, D-Link and IoT Devices DuckDuckGo browser extension vulnerability leaves Edge users open to potential cyber-snooping Teen hacker agrees to 3 years in prison for Twitter Bitcoin scam FBI warns of escalating Pysa ransomware attacks on education orgs Hacker leaks payment data from defunct WeLeakInfo breach site Hackers hide credit card data from compromised stores in JPG file Microsoft explains the cause of yesterday's massive service outage Reinvestigation of 2019 Metro Presort Ransomware Attack Reveals PHI May Have Been Compromised 2020 Saw Major Increase in Healthcare Hacking Incidents and Insider Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 324. It is Tuesday March 16th 2021. I am your host Scott Gombar and It’s a Microsoft Kind of Day Buffalo Public Schools cancels classes after cyberattack Microsoft releases one-click Exchange On-Premises Mitigation Tool Windows 10 emergency updates released to fix printing crashes Blender website in maintenance mode after hacking attempt Microsoft fixes Office issue causing memory, disk space errors Microsoft 365 outage knocks down Teams, Exchange Online Ransomware Gangs Claim Three More Healthcare Victims

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 323.  It is Monday March 15th 2021.  I am your host Scott Gombar and Don’t Tweet the Word Memphis

Updates on Microsoft Exchange Server Vulnerabilities

Microsoft Exchange Exploits Pave a Ransomware Path

Another Google Chrome 0-Day Bug Found Actively Exploited In-the-Wild

REvil Group Claims Slew of Ransomware Attacks

Microsoft shares temporary fix for Windows 10 printing crashes

Scammers promote fake cryptocurrency giveaways via Twitter ads

Twitter bug automatically suspends you when tweeting 'Memphis'

Unsecured Amazon S3 Buckets Contained ID Card Scans of 52,000 Individuals

New London Hospital Data Breach Affects Almost 35,000 Patients

Multistate Settlement Resolves 2019 American Medical Collection Agency Data Breach Investigation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 322.  It is Friday March 12th 2021.  I am your host Scott Gombar and It was a Banner Year for CyberAttacks

Linux Systems Under Attack By New RedXOR Malware

ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber Attacks

Molson Coors brewing operations disrupted by cyberattack

CISA: No federal civilian agency hacked in Exchange attacks, so far

2020 was a ‘record-breaking’ year in US school hacks, security failures

Cost of 2020 US Healthcare Ransomware Attacks Estimated at $21 Billion

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 321.  It is Thursday March 11th 2021.  I am your host Scott Gombar and Fire Causes Websites to go Offline

F5 Security Advisory for RCE Vulnerabilities in BIG-IP, BIG-IQ

Nim-Based Malware Loader Spreads Via Spear-Phishing Emails

Windows 10 crashes when printing due to Microsoft March updates

More hacking groups join Microsoft Exchange attack frenzy

Ryuk ransomware hits 700 Spanish government labor agency offices

OVH data center burns down knocking major sites offline

Phishing Attack Impacts Saint Alphonsus Health System and Saint Agnes Medical Center Patients

Sandhills Medical Foundation has Data Stolen in Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 320.  It is Wednesday March 10th 2021.  I am your host Scott Gombar and Surveillance cameras at Tesla, Cloudflare and other businesses hacked. 

Adobe Releases Security Updates

Apple Releases Security Updates

SAP Releases March 2021 Security Updates

Microsoft March 2021 Patch Tuesday fixes 82 flaws, 2 zero-days

Microsoft Exchange attacks: Now Microsoft rushes out a patch for older versions of Exchange

iPhone Call Recorder bug gave acess to other people's conversations

US seizes more domains used in COVID-19 vaccine phishing attacks

Hackers access surveillance cameras at Tesla, Cloudflare, banks, more

Arizona high court: Man can sue for health privacy breach

Ransomware attack exposed info of 210K MultiCare patients, providers, workers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 319.  It is Tuesday March 9th 2021.  I am your host Scott Gombar and Exchange Vulnerability Fallout Continues

Fake Google reCAPTCHA Phishing Attack Swipes Office 365 Passwords

Microsoft 365 adds 'External' email tags for increased security

Google Chrome to block port 554 to stop NAT Slipstreaming attacks

Flagstar Bank hit by data breach exposing customer, employee data

Unpatched QNAP devices are being hacked to mine cryptocurrency

European Banking Authority discloses Exchange server hack

Two Employees Fired for Impermissible PHI Disclosures to Third Parties

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 318.  It is Monday March 8th 2021.  I am your host Scott Gombar and 30,000+ Exchange Servers Have Been Compromised

Microsoft IOC Detection Tool for Exchange Server Vulnerabilities

D-Link, IoT Devices Under Attack By Tor-Based Gafgyt Variant

Massive Supply-Chain Cyberattack Breaches Several Airlines

WordPress Injection Anchors Widespread Malware Campaign

Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked!

Ransomware gang plans to call victim's business partners about attacks

Samsung fixes critical Android bugs in March 2021 updates

Ongoing phishing attacks target US brokers with fake FINRA audits

At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email Software

PHI of More Than 100,000 Elara Caring Patients Potentially Compromised in Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 317.  It is Friday March 5th 2021.  I am your host Scott Gombar and More Details After Office Supply Retailer Turned MSP Hit With Cyberattack

Joint NSA and CISA Guidance on Strengthening Cyber Defense Through Protective DNS

Update to Alert on Mitigating Microsoft Exchange Server Vulnerabilities

Microsoft reveals 3 new malware strains used by SolarWinds hackers

VMware releases fix for severe View Planner RCE vulnerability

CompuCom MSP hit by DarkSide ransomware cyberattack

Tens of Thousands of Individuals Affected by AllyAlign Health Ransomware Attack

Up to 100,000 Individuals Affected by Cochise Eye and Laser Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 316.  It is Thursday March 4th 2021.  I am your host Scott Gombar and If You Are Using On-Prem MS Exchange Listen Up

CompuCom MSP confirms ongoing outage following malware incident

Microsoft: Windows 10 'Known Issue Rollback' auto-fixes update bugs

BEC scammers are targeting investors for massive payouts

GRUB2 boot loader reveals multiple high severity vulnerabilities

US government warns of Social Security scams using fake federal IDs

Cybersecurity firm Qualys is the latest victim of Accellion hacks

Cash App phishing kit deployed in the wild, courtesy of 16Shop

Microsoft Exchange Zero-Day Attackers Spy on U.S. Targets

IBM X-Force: Healthcare Cyberattacks Doubled in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 315.  It is Wednesday March 3rd 2021.  I am your host Scott Gombar and Amazon, Zillow, Lyft, and Slack are being targeted by a ‘Dependency Confusion’ Vulnerability

Microsoft Releases Out-of-Band Security Updates for Exchange Server

Compromised Website Images Camouflage ObliqueRAT Malware

Google fixes second actively exploited Chrome zero-day bug this year

Payroll giant PrismHR outage likely caused by ransomware attack

Malaysia Airlines discloses a nine-year-long data breach

SolarWinds reports $3.5 million in expenses from supply-chain attack

Microsoft announces Windows Server 2022 with new security features

Malicious NPM packages target Amazon, Slack with new dependency attacks

Roundup of Recent Healthcare Phishing and Malware Incidents

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 314.  It is Tuesday March 2nd 2021.  I am your host Scott Gombar and SEO for Hackers, Courses Now Offered

Passwords, Private Posts Exposed in Hack of Gab Social Network

Working Windows and Linux Spectre exploits found on VirusTotal

World's leading dairy group Lactalis hit by cyberattack

Tether cryptocurrency firm says docs in $24 million ransom are 'forged'

Hackers use black hat SEO to push ransomware, trojans via Google

Universal Health Services Ransomware Attack Cost $67 Million in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 313.  It is Monday March 1st 2021.  I am your host Scott Gombar and A Warning for AOL Users...

Windows 10 Cloud PC: The latest info about Microsoft's new service

Microsoft fixes Windows 10 drive corruption bug — what you need to know

T-Mobile discloses data breach after SIM swapping attacks

Ryuk ransomware now self-spreads to other Windows LAN devices

Beware: AOL phishing email states your account will be closed

Email Security Breach Impacts 45,000 Covenant Healthcare Patients

Gore Medical Management Alerted to 2017 Breach of 79,100 Patients’ PHI

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 312.  It is Friday February 26th 2021.  I am your host Scott Gombar and VMWare Admins Get it Together Now

Cisco Releases Security Updates 

Malicious Mozilla Firefox Extension Allows Gmail Takeover

North Korean hackers target defense industry with custom malware

TD Bank suffered systemwide banking outage, services now recovered

VC giant Sequoia Capital discloses data breach after failed BEC attack

Attackers scan for vulnerable VMware servers after PoC exploit release

March 1, 2021: Deadline for Reporting 2020 Small Healthcare Data Breaches

Cyberattack Forces St. Margaret’s Health –Spring Valley to Shut Down Computer Systems

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 311.  It is Thursday February 25th 2021.  I am your host Scott Gombar and Accellion Damage Is Becoming More Evident

Mozilla Releases Security Updates for Thunderbird, Firefox ESR, and Firefox

Experts Warns of Notable Increase in QuickBooks Data Files Theft Attacks

Federal Reserve nationwide outage impacts US banking system

NASA and the FAA were also breached by the SolarWinds hackers

Ransomware gang extorts jet maker Bombardier after Accellion breach

Exploitation of Vulnerabilities in Accellion File Transfer Appliance Gave Hackers Access to Data of Kroger Customers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 310.  It is Wednesday February 24th 2021.  I am your host Scott Gombar and Microsoft Email Users Hit with FedEx Phishing Attack

SonicWall Releases Additional Patches

ServiceNow admin credentials among hundreds of passwords exposed in cloud security blunder

VMware fixes critical RCE bug in all default vCenter installs

Finnish IT services giant TietoEVRY discloses ransomware attack

LinkedIn is down for many, and we are not sure why

Twitter removes accounts of Russian government-backed actors

10K Microsoft Email Users Hit in FedEx Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 309.  It is Tuesday February 23rd 2021.  I am your host Scott Gombar and What Is the Cost to Paying the Ransom

Microsoft Word for Windows is finally getting predictive typing

Assume Clubhouse Conversations Are Being Recorded, Researchers Warn

Chinese Hackers Hijacked NSA-Linked Hacking Tool: Report

TDoS Attacks Take Aim at Emergency First-Responder Services

Parents alerted to NurseryCam security breach

Texas electric company warns of scammers threatening to cut power

Global Accellion data breaches linked to Clop ransomware gang

Ransom Paid to Recover Healthcare Data Stolen in Cyberattack on Online Storage Vendor

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 308.  It is Monday February 22nd 2021.  I am your host Scott Gombar and January HIPAA Breach Report is Out

Malformed URL Prefix Phishing Attacks Spike 6,000%

Mysterious Silver Sparrow Malware Found Nesting on 30K Macs

Credential-Stuffing Attack Targets Regional Internet Registry

Underwriters Laboratories (UL) certification giant hit by ransomware

CIS now offers free ransomware protection to all US hospitals

US cities disclose data breaches after vendor's ransomware attack

Lakehead University shuts down campus network after cyberattack

Warning: Google Alerts abused to push fake Adobe Flash updater

Kroger data breach exposes pharmacy and employee data

Wilmington Surgical Associates Facing Class Action Lawsuit Over Netwalker Ransomware Attack

January 2021 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 307.  It is Friday February 19th 2021.  I am your host Scott Gombar and Will Changes to LastPass Impact You?

Google Releases Security Updates for Chrome

Cisco Releases Security Updates for AnyConnect Secure Mobility Client

North Korean Malicious Cyber Activity: AppleJeus

Mac Malware Targets Apple’s In-House M1 Processor

Kia Motors Hit With $20M Ransomware Attack – Report

Microsoft: SolarWinds hackers downloaded some Azure, Exchange source code

LastPass Free to force users to choose between mobile, desktop

21st Century Oncology Data Breach Settlement Receives Preliminary Approval

Email Error Results in Impermissible Disclosure of the PHI of 900 Campbell County Health Patients

Ransomware Gangs Leak Sensitive Data Stolen from Capital Medical Center and Rehoboth McKinley Christian Health Care Services

Grand River Medical Group Email Breach Impacts 34,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 306.  It is Tuesday February 16th 2021.  I am your host Scott Gombar and 25.9 million business account credentials belonging to employees of Fortune 1000 companies are on the darkweb.

Apple will proxy Safe Browsing requests to hide iOS users' IP from Google

DDoS attack takes down EXMO cryptocurrency exchange servers

Microsoft will alert Office 365 admins of Forms phishing attempts

Rampant password reuse puts companies and customers at risk

Sharp HealthCare Pays $70,000 to Resolve HIPAA Right of Access Violation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 305.  It is Monday February 15th 2021.  I am your host Scott Gombar and Tax Season is Here, So Are the Scams.

VMware Releases Security Update

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores

Yandex Employee Caught Selling Access to Users' Email Inboxes

Copycats imitate novel supply chain attack that hit tech giants

Egregor ransomware members arrested by Ukrainian, French police

Google Chrome, Microsoft Edge getting this Intel security feature

Leading Canadian rental car company hit by DarkSide ransomware

‘Annoyingly Believable’ Tax Scam Targets Mobile Users

Scammers target US tax pros in ongoing IRS phishing attacks

Ransomware Gang Dumps Data Stolen from Two U.S. Healthcare Providers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 304.  It is Friday February 12th 2021.  I am your host Scott Gombar and Microsoft Fixes a 12 Year Old Vulnerability in Microsoft Defender.

Military, Nuclear Entities Under Target By Novel Android Malware

If you use Slack on Android, reset your password now

Mobile Health Apps Found to Expose Records of Millions of Users

Alert (AA21-042A) Compromise of U.S. Water Treatment Facility

Internet Explorer 11 zero-day vulnerability gets unofficial micropatch

Microsoft releases emergency fix for Windows 10 WiFi crashes

Buggy WordPress plugin exposes 100K sites to takeover attacks

12-year-old Windows Defender bug gives hackers admin rights

Renown Health Pays $75,000 to Settle HIPAA Right of Access Case

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 303.  It is Thursday February 11th 2021.  I am your host Scott Gombar and Leaky Database exposes 1.5 billion Comcast records

Microsoft Launches Phase 2 Mitigation for Netlogon Remote Code Execution Vulnerability (CVE-2020-1472)

SAP Commerce Critical Security Bug Allows RCE

SIM hijackers arrested after stealing millions from US celebrities

Microsoft Office February security updates patch Sharepoint, Excel RCE bugs

Microsoft fixes Windows 10 bug letting attackers trigger BSOD crashes

Researchers discover exposed Comcast database containing 1.5 billion records

Nebraska Medicine Notifies 219,000 Patients About September 2020 Malware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 302.  It is Wednesday February 10th 2021.  I am your host Scott Gombar and It’s The February Post Patch Tuesday Episode

Apple fixes SUDO root privilege escalation flaw in macOS

Adobe fixes critical Reader vulnerability exploited in the wild

Microsoft February 2021 Patch Tuesday fixes 56 flaws, 1 zero-day

Microsoft Warns of Windows Win32k Privilege Escalation

We uncovered a Facebook phishing campaign that tricked nearly 500,000 users in two weeks

Emsisoft Suffers System Breach

HelloKitty ransomware behind CD Projekt Red cyberattack, data theft

Researcher hacks Microsoft, Apple, more in novel supply chain attack

Class Action Lawsuit Filed Against US Fertility Over September 2020 Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 301.  It is Tuesday February 9th 2021.  I am your host Scott Gombar and It’s Safer Internet Day

Critical WordPress Plugin Flaw Allows Site Takeover

Fake Forcepoint Google Chrome Extension Hacks Windows Users

Big jump in RDP attacks as hackers target staff working from home

Mortgage loan servicing company discloses ransomware attack to multiple states

Android app joins the dark side, sends malware update to millions

Microsoft to alert Office 365 users of nation-state hacking activity

Hacker modified drinking water chemical levels in a US city

Email Account Breach at Law Firm Affects More Than 36,000 UPMC Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 300.  It is Monday February 8th 2021.  I am your host Scott Gombar and Morse Code Used in Phishing Attacks

Unpatched WordPress Plugin Code-Injection Bug Afflicts 50K Sites

Ransomware Attacks Hit Major Utilities

Fortinet fixes critical vulnerabilities in SSL VPN and web firewall

Mozilla fixes Windows 10 NTFS corruption bug in Firefox

The Great Suspender Chrome extension's fall from grace

Malicious extension abuses Chrome sync to steal users’ data

SitePoint discloses data breach after stolen info used in attacks

New phishing attack uses Morse code to hide malicious URLs

Hackers post detailed patient medical records from two hospitals to the dark web

Ramsey County and Crisp Regional Health Services Affected by Ransomware Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 299.  It is Friday February 5th 2021.  I am your host Scott Gombar and Plex Media Server Owners Beware

Google fixes Chrome zero-day actively exploited in the wild

Microsoft Office 365 Attacks Sparked from Google Firebase

New Malware Hijacks Kubernetes Clusters to Mine Monero

Hackers had access to SolarWinds email system for months: report

Windows 10 2004 now in broad deployment, available to everyone

Hackers steal StormShield firewall source code in data breach

Plex Media servers actively abused to amplify DDoS attacks

5 Healthcare Providers Have Started Notifying Patients About Recent Phishing Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 298.  It is Thursday February 4th 2021.  I am your host Scott Gombar and More Bad News for SolarWinds

Google Releases Security Updates for Chrome

SonicWall fixes actively exploited SMA 100 zero-day vulnerability

Cisco fixes critical code execution bugs in SMB VPN routers

Windows 10 KB4598291 update fixes device deactivation, freezing issues

Five Critical Android Bugs Patched, Part of Feb. Security Bulletin

Over a Dozen Chrome Extensions Caught Hijacking Google Search Results for Millions

3 New Severe Security Vulnerabilities Found In SolarWinds Software

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 297.  It is Wednesday February 3rd 2021.  I am your host Scott Gombar and Agent Tesla Takes Out Microsoft’s Anti-Malware Interface

Apple Releases Security Updates

US federal payroll agency hacked using SolarWinds software flaw

Babyk Ransomware won't hit charities, unless they support LGBT, BLM

Trickbot malware now maps victims’ networks using Masscan

Netgain ransomware incident impacts local governments

Agent Tesla Trojan ‘Kneecaps’ Microsoft’s Anti-Malware Interface

Intel agency warns of threats from China collecting sensitive US health data

Montefiore Medical Center and Bethesda Hospital Fire Employees for HIPAA Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 296.  It is Tuesday February 2nd 2021.  I am your host Scott Gombar and More Impersonation Scams Running Rampant

Hezbollah-Linked Lebanese Cedar APT Infiltrates Hundreds of Servers

A New Software Supply‑Chain Attack Targeted Millions With Spyware

Data breach exposes 1.6 million Washington unemployment claims

US govt: Number of identity theft reports doubled last year

Phishing campaign lures US businesses with fake PPP loans

SonicWall SMA 100 zero-day exploit actively used in the wild

European volleyball org's Azure bucket exposed reporter passports

Scammers posing as FBI agents threaten targets with jail time

Failure to Patch Results in 7-Year Breach of Florida Medicaid Applicants’ PHI

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 295.  It is Monday February 1st 2021.  I am your host Scott Gombar and Beware of Fake Social Media Accounts

Many WordPress Sites Affected by Vulnerabilities in 'Popup Builder' Plugin

USCellular hit by a data breach after hackers access CRM software

SpamCop anti-spam service suffers an outage after its domain expired

Windows 10 features that boost your PC's security and privacy

Beware: Malicious Home Depot ad gets top spot in Google Search

North Korean Hackers Building Fake Persona on Social Networks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 294.  It is Friday January 29th  2021.  I am your host Scott Gombar and NAT Slipstreaming..What Is It?

Pirated themes and plugins are the most widespread threat to WordPress sites

Rocke Group’s Malware Now Has Worm Capabilities

Microsoft: 8 trillion daily signals power our cybersecurity services

Hezbollah hackers attack unpatched Atlassian servers at telcos, ISPs

Microsoft: DPRK hackers 'likely' hit researchers with Chrome exploit

Remote Attackers Can Now Reach Protected Network Devices via NAT Slipstreaming

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 293.  It is Thursday January 28th  2021.  I am your host Scott Gombar and It’s Not Always Bad News

Apple Patches Three Actively Exploited Zero-Days, Part of iOS Emergency Update

Linux malware uses open-source tool to evade detection

Microsoft rolls out Application Guard for Office to all customers

Emotet botnet disrupted after global takedown operation

Netwalker ransomware dark web sites seized by law enforcement

Almost 190,000 Patients Affected by Roper St. Francis Healthcare Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 292.  It is Wednesday January 27th  2021.  I am your host Scott Gombar and Internet Outages in the Northeast US

Firefox 85 adds supercookie protection, removes Flash support

TikTok Bug Could Have Exposed Users' Profile Data and Phone Numbers

FTC Reports Scammers Impersonating FTC

Microsoft releases new Windows 10 Intel CPU microcode updates

New Linux SUDO flaw lets local users gain root privileges

Verizon Fios fiber cut causes Internet outage in Northeastern US

Mimecast links security breach to SolarWinds hackers

Google fixes severe Golang Windows RCE vulnerability

Rady Children’s Hospital Facing Class Action Lawsuit over Blackbaud Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 291. It is Tuesday January 26th 2021. I am your host Scott Gombar and Add Taunting to Ransomware Tactics 8+ million Teespring user records leaked on hacker forum Beware of active UK NHS COVID-19 vaccination phishing campaign Windows 10 NTFS corruption bug gets unofficial temporary fix Leading crane maker Palfinger hit in global cyberattack ProtonVPN causes Windows BSOD crashes due to antivirus conflicts Ransomware gang taunts IObit with repeated forum hacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 290.  It is Monday January 25th  2021.  I am your host Scott Gombar and Imagine Being Hacked Using Your Own Zero-Day

Amazon Kindle RCE Attack Starts with an Email

ADT Tech Hacks Home-Security Cameras to Spy on Women

Discord-Stealing Malware Invades npm Packages

Another ransomware now uses DDoS attacks to force victims to pay

Windows 10X feature will prevent unauthorized factory resets

Intel: Hackers stole unpublished earnings info from corporate site

SonicWall firewall maker hacked using zero-day in its VPN device

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 289.  It is Friday January 22nd  2021.  I am your host Scott Gombar and Your Password is on Google

Oracle Releases January 2021 Security Bulletin

Drupal Releases Security Updates

Microsoft Edge gets a password generator, leaked credentials monitor

Google Forms Set Baseline For Widespread BEC Attacks

Windows Remote Desktop servers now used to amplify DDoS attacks

QNAP warns users to secure NAS devices against Dovecat malware

Google Searches Expose Stolen Corporate Credentials

Einstein Healthcare Network Announces August Breach

Data Breaches Reported by Gainwell Technologies, TaylorMade Diagnostics, and Mattapan Community Health Center

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 288.  It is Thursday January 21st  2021.  I am your host Scott Gombar and A Who’s Who of DNSpooq Advisories

Google Chrome now checks for weak passwords, helps fix them

Microsoft shares how SolarWinds hackers evaded detection

Hacker leaks full database of 77 million Nitro PDF user records

Hacker posts 1.9 million Pixlr user records for free on forum

List of DNSpooq vulnerability advisories, patches, and updates

US spinal care practice among first to issue healthcare data breach warning in 2021

At Least 560 U.S. Healthcare Facilities Were Impacted by Ransomware Attacks in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 287.  It is Wednesday January 20th  2021.  I am your host Scott Gombar and We Haven’t Talked About SolarWinds in a Few Days

Google Chrome 88 released: RIP Flash Player and FTP support

Linux Devices Under Attack by New FreakOut Malware

Bugs in Signal, Facebook, Google chat apps let attackers spy on users

DNSpooq bugs let attackers hijack DNS on millions of devices

Malwarebytes says SolarWinds hackers accessed its internal emails

SolarWinds Malware Arsenal Widens with Raindrop

2020 Healthcare Data Breach Report: 25% Increase in Breaches in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 286.  It is Tuesday January 19th  2021.  I am your host Scott Gombar and It’s The December 2020 HIPAA Breach Report

IObit forums hacked in widespread DeroHE ransomware attack

Microsoft Defender to enable full auto-remediation by default

OpenWRT Forum user data stolen in weekend data breach

FBI warns of vishing attacks stealing corporate accounts

Over 22 bn records exposed in data breaches in 2020: Report

December 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 285.  It is Monday January 18th  2021.  I am your host Scott Gombar and Ransomware Now Accounts for half of healthcare data breaches

Today we pay our respects to a great man. Thank you for all you did Dr. Martin Luther King Jr. There’s still a lot of work to be done. Injustice anywhere is a threat to justice everywhere

Microsoft Implements Windows Zerologon Flaw ‘Enforcement Mode’

Apple Kills MacOS Feature Allowing Apps to Bypass Firewalls

WhatsApp Delays Controversial 'Data-Sharing' Privacy Policy Update By 3 Months

Undisclosed Apache Velocity XSS vulnerability impacts GOV sites

Windows 10 bug causes a BSOD crash when opening a certain path

Windows Finger command abused by phishing to download malware

Hackers leaked altered Pfizer data to sabotage trust in vaccines

Ransomware attacks now to blame for half of healthcare data breaches

M.D. Anderson Cancer Center Has $4.3 Million OCR HIPAA Fine Overturned on Appeal

Health Insurer Pays $5.1 Million To Settle Data Breach Affecting Over 9.3 Million People

South Country Health Alliance Breach Impacts 66,874 Plan Members

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 284.  It is Friday January 15th  2021.  I am your host Scott Gombar and DNS Recommendations from the NSA

Juniper Networks Releases Security Updates for Multiple Products

Cisco Releases Security Updates for Multiple Products

Office January security updates fix remote code execution bugs

Telegram Bots at Heart of Classiscam Scam-as-a-Service

Critical WordPress-Plugin Bug Found in ‘Orbit Fox’ Allows Site Takeover

Windows 10 bug corrupts your hard drive on seeing this file's icon

Verified Twitter accounts hacked in $580k ‘Elon Musk’ crypto scam

NSA advises companies to avoid third party DNS resolvers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 283.  It is Thursday January 14th  2021.  I am your host Scott Gombar and 2020 Year in HIPAA Review

Sophisticated Hacks Against Android, Windows Reveal Zero-Day Trove

CISA: Hackers bypassed MFA to access cloud service accounts

Skype is down worldwide - Microsoft working on issues

SolarLeaks site claims to sell data stolen in SolarWinds attacks

OCR Continues HIPAA Right of Access Crackdown with $200,000 Fine

2020 HIPAA Violation Cases and Penalties

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 282.  It is Wednesday January 13th  2021.  I am your host Scott Gombar and It’s the January Post Patch Tuesday Episode

SAP Releases January 2021 Security Updates

Adobe Fixes 7 Critical Flaws, Blocks Flash Player Content

Mozilla Releases Security Update for Thunderbird

Microsoft January 2021 Patch Tuesday fixes 83 flaws, 1 zero-day

Capcom: 390,000 people may be affected by ransomware data breach

Hackers leak stolen Pfizer COVID-19 vaccine data online

Mimecast discloses Microsoft 365 SSL certificate compromise

Intel adds hardware-based ransomware detection to 11th gen CPUs

HITECH Act Amendment Creating Cybersecurity Safe Harbor Signed into Law

LSU Health Discovers Additional Hospital Affected by September 2020 Email Account Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 281.  It is Tuesday January 12th  2021.  I am your host Scott Gombar and SolarWinds Attackers Were Lurking for More than a Year

Microsoft Releases Security Updates for Edge

Millions of Social Profiles Leaked by Chinese Data-Scrapers

70TB of Parler users’ messages, videos, and posts leaked by security researchers

SolarWinds Hack Potentially Linked to Turla APT

Microsoft Sysmon now detects malware process tampering attempts

Mac malware uses 'run-only' AppleScripts to evade analysis

DarkSide ransomware decryptor recovers victims' files for free

United Nations data breach exposed over 100k UNEP staff records

Networking giant Ubiquiti alerts customers of potential data breach

Third malware strain discovered in SolarWinds supply chain attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 280.  It is Monday January 11th  2021.  I am your host Scott Gombar and What to expect from Microsoft and Windows 10 in 2021

CISA Releases New Alert on Post-Compromise Threat Activity in Microsoft Cloud Environments and Tools to Help Detect This Activity

SolarWinds Hires Chris Krebs, Alex Stamos in Wake of Hack

New Attack Could Let Hackers Clone Your Google Titan 2FA Security Keys

New Zealand Reserve Bank suffers data breach via hacked storage partner

Dassault Falcon Jet reports data breach after ransomware attack

Nissan NA source code leaked due to default admin:admin credentials

What to expect from Microsoft and Windows 10 in 2021

Lake Region Healthcare Recovering from Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 279.  It is Friday January 8th  2021.  I am your host Scott Gombar and Another Chain Link in the Attack?

Google Releases Security Updates for Chrome

Mozilla Releases Security Updates for Firefox, Firefox for Android, and Firefox ESR

Hacker sells Aurora Cannabis files stolen in Christmas cyberattack

Windows PsExec zero-day vulnerability gets a free micropatch

SEO scammer extorts site owners using porn backlinks threat

US Judiciary adds safeguards after potential breach in SolarWinds hack

JetBrains denies involvement in the SolarWinds supply-chain hack

Fired Healthcare Exec Stalls Critical PPE Shipment for Months

Email Breaches Reported by Mattapan Community Health Center and Prestera Center for Mental Health Services

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 278.  It is Thursday January 7th  2021.  I am your host Scott Gombar and The SolarWinds Hits Keep Coming

RCE ‘Bug’ Found and Disputed in Popular PHP Scripting Framework

Cybercriminals Ramp Up Exploits Against Serious Zyxel Flaw

A COVID-19 shot for $150? Online scams surge as slow vaccine rollout frustrates

CISA Updates Emergency Directive 21-01 Supplemental Guidance and Activity Alert on SolarWinds Orion Compromise

WhatsApp: Share your data with Facebook or delete your account

Windows 10 WSL now can run Linux commands on startup

SolarWinds hackers had access to over 3,000 US DOJ email accounts

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 277.  It is Wednesday January 6th  2021.  I am your host Scott Gombar and Ryuk is the Top Threat for the Healthcare Sector

Microsoft Office January updates fix Outlook crash issues

Major Gaming Companies Hit with Ransomware Linked to APT27

Telegram Triangulation Pinpoints Users’ Exact Locations

Google Warns of Critical Android Remote Code Execution Bug

ElectroRAT Drains Cryptocurrency Wallet Funds of Thousands

Vodafone's ho. Mobile admits data breach, 2.5m users impacted

Babuk Locker is the first new enterprise ransomware of 2021

Hacker posts data of 10,000 American Express accounts for free

Ryuk ransomware is the top threat for the healthcare sector

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 276.  It is Tuesday January 5th  2021.  I am your host Scott Gombar and China Backed APT Group Now Using Ransomware

Rumors of SolarWinds N-Central being impacted be SolarWinds Orion Breach

Researcher Breaks reCAPTCHA With Google’s Speech-to-Text API

British Court Rejects U.S. Request to Extradite WikiLeaks' Julian Assange

Microsoft Defender for Office 365 to allow testing without setup

TransLink confirms ransomware data theft, still restoring systems

Citrix adds NetScaler ADC setting to block recent DDoS attacks

Slack suffers its first massive outage of 2021

China's APT hackers move to ransomware attacks

Breaches Reported by Northwestern Memorial Hospital, Apex Laboratory, and Five Points Eye Care

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 275.  It is Monday January 4th  2021.  I am your host Scott Gombar and Happy New Year

Ticketmaster To Pay $10 Million Fine For Hacking A Rival Company

Beware: PayPal phishing texts state your account is 'limited'

Wasabi cloud storage service knocked offline for hosting malware

Google Chrome fixes antivirus 'file locking' bug on Windows 10

Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products

Microsoft Says SolarWinds Hackers Accessed Some of Its Source Code

More Than 114,000 Patients Affected by Wilmington Surgical Associates Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 274.  It is Wednesday December 30th  2020.  I am your host Scott Gombar and Is WFH Here to Stay?

Japanese Aerospace Firm Kawasaki Warns of Data Breach

A Google Docs Bug Could Have Allowed Hackers See Your Private Documents

Swatters hijack smart home devices to watch emergency responders

Microsoft: SolarWinds hackers' goal was the victims' cloud data

US Treasury warns of ransomware targeting COVID-19 vaccine research

2020 Work-for-Home Shift: What We Learned

Two Florida Healthcare Providers Attacked with Ransomware

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 273.  It is Tuesday December 29th  2020.  I am your host Scott Gombar and Revil Threatens to Release Intimate Pictures of Celebs

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Multi-platform card skimmer found on Shopify, BigCommerce stores

Aida Cruises cancels trips due to mysterious "IT restrictions"

Home appliance giant Whirlpool hit in Nefilim ransomware attack

One in ten shopping ads promoted on Google potentially lead to phishing sites

REvil gang threatens to release intimate pictures of celebs who are customers of The Hospital Group

484,000 Aetna Members Impacted by EyeMed Phishing Incident

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 272.  It is Monday December 28th  2020.  I am your host Scott Gombar and From Defeat Comes Victory

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA Releases Free Detection Tool for Azure/M365 Environment

Emotet Returns to Hit 100K Mailboxes Per Day

Lazarus Group Hits COVID-19 Vaccine-Maker in Espionage Attack

Windows Zero-Day Still Circulating After Faulty Fix

Apple iCloud outage prevents device activations, access to data

SolarWinds releases updated advisory for new SUPERNOVA malware

Fake Amazon gift card emails deliver the Dridex malware

CrowdStrike releases free Azure security tool after failed hack

OCR Announces its 19th HIPAA Penalty of 2020

Former GenRx Pharmacy Patients’ PHI Potentially Compromised in Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 271.  It is Wednesday December 23rd  2020.  I am your host Scott Gombar and A Ransomware Task Force is Formed

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Roanoke College delays spring semester after cyberattack

Safe-Inet, Insorg VPN services shut down by law enforcement

Microsoft: Don't delete Windows 10 root certificate expiring this month

SolarWinds hackers breached US Treasury officials’ email accounts

Partial lists of organizations infected with Sunburst malware released online

Microsoft and McAfee headline newly-formed 'Ransomware Task Force'

November 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 270.  It is Tuesday December 22nd  2020.  I am your host Scott Gombar and A Second Orion Attacker?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Smart Doorbell Disaster: Many Brands Vulnerable to Attack

Dark Web Pricing Skyrockets for Microsoft RDP Servers, Payment-Card Data

Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack

Critical Bugs in Dell Wyse Thin Clients Allow Code Execution, Client Takeovers

New SUPERNOVA backdoor found in SolarWinds cyberattack analysis

FTC Settles 2019 Consumer Data Breach Case with SkyMed

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 269.  It is Monday December 21st  2020.  I am your host Scott Gombar and More Updates to the SolarWinds Breach

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

NSA Releases Cybersecurity Advisory on Detecting Abuse of Authentication Mechanisms

Flavors designer Symrise halts production after Clop ransomware attack

Stealthy Magecart malware mistakenly leaks list of hacked stores

The SolarWinds cyberattack: The hack, the victims, and what we know

Lost Storage Device Contained Unencrypted PHI of Cedar Springs Hospital Patients

Email Account Breaches Reported by Meharry Medical College and MEDNAX Services

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 268.  It is Friday December 18th  2020.  I am your host Scott Gombar and It’s Ugly

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

5M WordPress Sites Running ‘Contact Form 7’ Plugin Open to Attack

Ransomware masquerades as mobile version of Cyberpunk 2077

Iranian nation-state hackers linked to Pay2Key ransomware

Nation-state hackers breached US think tank thrice in a row

CISA: Hackers breached US govt using more than SolarWinds backdoor

Nuclear Weapons Agency Hacked in Widening Cyberattack – Report

Microsoft confirms breach in SolarWinds hack, denies infecting others

FBI, CISA officially confirm US govt hacks after SolarWinds breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 267.  It is Thursday December 17th  2020.  I am your host Scott Gombar and HPE discloses critical zero-day vulnerability

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird

New Goontact spyware discovered targeting Android and iOS users

Malicious Chrome, Edge extensions with 3M installs still in stores

FireEye, Microsoft create kill switch for SolarWinds backdoor

Emulated mobile devices used to steal millions from US, EU banks

HPE discloses critical zero-day in server management software

House Passes Bill Calling for HHS to Recognize Adoption of Cybersecurity Best Practices When Making Regulatory Determinations

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 266.  It is Wednesday December 16th  2020.  I am your host Scott Gombar and The Hits Keep Coming

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Releases Security Updates for Multiple Products

Firefox 84 dramatically boosts performance on Apple Silicon Macs

Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure

Ransomware attack causing billing delays for Missouri city

Gmail hit by a second outage within a single day

Microsoft to quarantine compromised SolarWinds binaries tomorrow

SEC filings: SolarWinds says 18,000 customers were impacted by recent hack

45 Million Medical Images Left Exposed Online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 265.  It is Tuesday December 15th  2020.  I am your host Scott Gombar and DHS & Treasury Hit by Cyberattack Using Solarwinds Orion.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Microsoft Office 365 Credentials Under Attack By Fax ‘Alert’ Emails

Google outage affecting YouTube, Gmail and more

Subway marketing system hacked to send TrickBot malware emails

DHS Among Those Hit in Sophisticated Cyberattack by Foreign Adversaries – Report

Tufts Health Plan Members’ PHI Exposed in EyeMed Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 264.  It is Friday December 11th  2020.  I am your host Scott Gombar and U.S. warns of increased cyberattacks against K-12 distance learning

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Releases Security Updates for Acrobat and Reader

Remote code execution vulnerability uncovered in Starbucks mobile platform

Hackers can use WinZip insecure server connection to drop malware

Fake data breach alerts used to steal Ledger cryptocurrency wallets

250,000 stolen MySQL databases for sale on dark web auction site

U.S. warns of increased cyberattacks against K-12 distance learning

Six More Healthcare Providers Impacted by Ransomware Attacks

Dental Care Alliance Data Breach Impacts More Than 1 Million Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 263.  It is Thursday December 10th  2020.  I am your host Scott Gombar and Ransomware Gangs Are Getting Faster..What That Means For You

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

COVID-19 Vaccine Cyberattacks Steal Credentials, Spread Zebrocy Malware

Lightning does strike twice: If you get hacked once, you'll probably be attacked again within a year

Ransomware gangs are getting faster at encrypting networks. That will make them harder to stop

Qbot malware switched to stealthy new Windows autostart method

Pfizer COVID-19 vaccine documents accessed in EMA cyberattack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 262.  It is Wednesday December 9th  2020.  I am your host Scott Gombar and It’s the December Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Patches/Updates Available from SAP, OpenSSL, Adobe, Apache Struts, D-Link Routers and Microsoft

FireEye Cyberattack Compromises Red-Team Security Tools

Spearphishing Attack Spoofs Microsoft.com to Target 200M Office 365 Users

‘Amnesia:33’ TCP/IP Flaws Affect Millions of IoT Devices

Ransomware forces hosting provider Netgain to take down data centers

Scammers spoof Target's gift card balance checking page

All Kubernetes versions affected by unpatched MiTM vulnerability

Insider Data Breaches Reported by Montefiore Medical Center and Mercy Health

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 261.  It is Tuesday December 8th  2020.  I am your host Scott Gombar and Anyone Have $34 Million?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Advisory for Vulnerability in AnyConnect Software

NSA Releases Advisory on Russian State-Sponsored Malicious Cyber Actors Exploiting CVE-2020-4006

PlayStation Now bugs let sites run malicious code on Windows PCs

Microsoft announces Azure cloud for top secret government data

QNAP patches QTS vulnerabilities allowing NAS device takeover

Foxconn electronics giant hit by ransomware, $34 million ransom

Greater Baltimore Medical Center Hit by Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 260.  It is Monday December 7th  2020.  I am your host Scott Gombar and Healthcare Organizations are Under Siege

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Apache Releases Security Advisory for Apache Tomcat

US and Australia to develop shared cyberattack training platform

Largest global staffing agency Randstad hit by Egregor ransomware

BlackShadow hackers extort Israeli insurance company for $1 million

Metro Vancouver's transit system hit by Egregor ransomware

Johnson & Johnson CISO: Healthcare orgs are seeing nation-state attacks every single minute of every single day

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 259.  It is Friday December 4th  2020.  I am your host Scott Gombar and More Tricks for Trickbot

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Releases Security Updates to Address CVE-2020-4006

Apple Releases Security Updates for iCloud for Windows

Credit card stealing malware hides in social media sharing icons

Kmart, Latest Victim of Egregor Ransomware – Report

Several Unpatched Popular Android Apps Put Millions of Users at Risk of Hacking

Ransomware gang says they stole 2 million credit cards from E-Land

IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply Chain

TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 258.  It is Thursday December 3rd  2020.  I am your host Scott Gombar and Using Dropbox to Store Malware Stolen Data. This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Mozilla Releases Security Update for Thunderbird

Xerox Releases Security Updates for DocuShare

Healthcare 2021: Cyberattacks to Center on COVID-19 Spying, Patient Data

iPhone Bug Allowed for Complete Device Takeover Over the Air

Phishing targets US brokerage firms using FINRA lookalike domain

Microsoft Office November 2020 updates fix Outlook, Skype issues

FBI and Homeland Security warn of APT attacks on US think tanks

Russian hacking group uses Dropbox to store malware-stolen data

Email Account Breaches Reported by University of Minnesota Physicians and McLeod Health

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 257. It is Wednesday December 2nd 2020. I am your host Scott Gombar and Another Day, Another School Ransomware Attack This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut. You can visit us at nwajtech.com Cayman Islands Bank Records Exposed in Open Azure Blob Zoom Impersonation Attacks Aim to Steal Credentials Electronic Medical Records Cracked Open by OpenClinic Bugs Android app still exposing messages of 100M users despite bug fix Alabama school district shut down by ransomware attack Healthcare Provider Discovers Patient Data Exposed Online for Over 4 Years

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 256.  It is Tuesday December 1st  2020.  I am your host Scott Gombar and They’re Baaaack...

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Happy Giving Tuesday

MacOS Users Targeted By OceanLotus Backdoor

Baltimore students told to ditch Windows PCs after ransomware attack

Windows 10 Cumulative Update Preview KB4586853 Released

Gootkit malware returns to life alongside REvil ransomware

Healthcare provider AspenPointe data breach affects 295K patients

Mayo Clinic Faces Multiple Lawsuits over Insider Privacy Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 255.  It is Monday November 30th 2020.  I am your host Scott Gombar and The Problem With Long Weekends

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Drupal Releases Security Updates

Fortinet FortiOS System File Leak

TurkeyBombing Puts New Twist on Zoom Abuse

Pennsylvania county pays 500K ransom to DoppelPaymer ransomware

IIoT chip maker Advantech hit by ransomware, $12.5 million ransom

Phishing lures employees with fake 'back to work' internal memos

Truck routing provider Rand McNally hit by cyberattack

cPanel 2FA bypassed in minutes via brute-force attacks

Sophos alerts customers of info exposure after security breach

Baltimore County Public Schools hit by ransomware attack

UVM Health Restores Electronic Health Record System One Month After Ransomware Attack

US Fertility Reports Ransomware Attack Involving Data Theft

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 254.  It is Wednesday November 25th 2020.  I am your host Scott Gombar and Trickbot Has New Tricks

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Happy Thanksgiving

‘Minecraft Mods’ Attack More Than 1 Million Android Devices

Post-Breach, Peatix Data Reportedly Found on Instagram, Telegram

Crooks impersonate US govt agencies offering financial aid

New WAPDropper malware stealthily subscribes you to premium services

TrickBot malware uses obfuscated Windows batch script to evade detection

Three More Healthcare Providers Suffer Cyberattacks Involving Ransom Demands

Phishing Incidents Reported by Connecticut Department of Social Services, Mercy Iowa City and LSU Care Services

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 253. It is Tuesday November 24th 2020. I am your host Scott Gombar and the October HIPAA Breach Roundup Has Arrived This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut. You can visit us at nwajtech.com VMware Releases Workarounds for CVE-2020-4006 Manchester United: IT Systems Disrupted in Cyberattack Spotify Users Hit with Rash of Account Takeovers GoDaddy Employees Used in Attacks on Multiple Cryptocurrency Services TikTok fixes bugs allowing account takeover with one click Tesla Model X key fobs could be hacked to steal cars, fix released FBI warns of recently registered domains spoofing its sites October 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 252.  It is Monday November 23rd 2020.  I am your host Scott Gombar and Ragnar Locker Ransomware activity is increasing

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Robot Vacuums Suck Up Sensitive Audio in ‘LidarPhone’ Hack

Good Heavens! 10M Impacted in Pray.com Data Exposure

Google Services Weaponized to Bypass Security in Phishing, BEC Campaigns

Mercy Iowa City Discloses Highly Sensitive Data Breach Impacting Over 60,000 Iowans

Oregon County Hit by Ransomware Attack

Derby's Griffin Hospital website taken down in major ransomware incident

Hacker posts exploits for over 49,000 vulnerable Fortinet VPNs

TrickBot turns 100: Latest malware released with new features

Joe Biden's 'Vote Joe' website defaced by Turkish Hackers

FBI warns of increasing Ragnar Locker ransomware activity

HIPAA Right of Access Failure Results in $65,000 Fine for University of Cincinnati Medical Center

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 251.  It is Friday November 20th 2020.  I am your host Scott Gombar and Not a Good Day for Android

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Updates from Cisco, Drupal, Google Chrome, Mozilla and VMWare

REvil ransomware demands 500K ransom to Managed.com hosting provider

Why ransomware is still so successful: Over a quarter of victims pay the ransom

Cybercriminals Batter Automakers With Ransomware, IP Theft Cyberattacks

IoT Cybersecurity Improvement Act Passed, Heads to President’s Desk

Mount Locker ransomware now targets your TurboTax tax returns

Facebook Messenger bug allowed Android users to spy on each other

Android chat app with 100 million installs exposes private messages

PHI Potentially Compromised in Security Incidents at People Incorporated and My Choice HouseCalls

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 250.  It is Wednesday November 18th 2020.  I am your host Scott Gombar and Nearly ¼ million Windows machines are still vulnerable to BlueKeep

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for Security Manager

Chrome 87 released with performance boost and security fixes

Firefox 83 boosts security with HTTPS-Only mode, zero-day fix

Phishing emails double in November in run-up to Black Friday and Cyber Monday

Google confirms Chrome crashing bug on Macs with Apple CPUs

Hackers are actively probing millions of WordPress sites

Office 365 phishing campaign detects sandboxes to evade detection

Coil payments platform leaks user emails in 'Privacy Policy' update

Ransomware attack forces web hosting provider Managed.com to take servers offline

More than 245,000 Windows systems still remain vulnerable to BlueKeep RDP bug

North Dakota and Delaware State Departments Report Breaches of PHI

Ransomware Attacks Impact First Impressions Orthodontics, Kids First Dentistry & Orthodontics, and Hendrick Health Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 249.  It is Tuesday November 17th 2020.  I am your host Scott Gombar and Windows Kerberos Authentication Breaks after Updates

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Citrix SD-WAN Bugs Allow Remote Code Execution

Dating Site Bumble Leaves Swipes Unsecured for 100M Users

Cold storage giant Americold services impacted by cyberattack

Zoom rolls out security enhancements to stop zoombombing trolls

Windows Kerberos authentication breaks due to security updates

Delaware Public health reports data breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 248.  It is Monday November 16th 2020.  I am your host Scott Gombar and New Malware to Worry About

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Facebook security warning: Thousands of passwords stolen

Ticketmaster Scores Hefty Fine Over 2018 Data Breach

Nation-State Attackers Actively Target COVID-19 Vaccine-Makers

Retail giant Cencosud hit by Egregor Ransomware attack, stores impacted

Malwarebytes is kicking Windows printers offline

Hacker shares 3.2 million Pluto TV accounts for free on forum

IRS announces move to protect businesses from identity theft

New Jupyter malware steals browser data, opens backdoor

Luxottica Data Breach Impacts 829,454 Individuals in the United States

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 247.  It is Friday November 13th 2020.  I am your host Scott Gombar and Then There Was Eleven

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

2 More Google Chrome Zero-Days Under Active Exploitation

Scalper-Bots Shake Down Desperate PS5, Xbox Series X Shoppers

Microsoft urges users to stop using phone-based multi-factor authentication

The North Face resets passwords after credential stuffing attack

Popular stock photo service hit by data breach, 8.3M records for sale

‘Security Threat’ Forces Hendrick Health to EHR Downtime Procedures

NY Specialist Pays OCR $15K for HIPAA Right of Access Failures

Medical Device Vendor Zoll Sues IT Firm Over Breach Affecting 277K

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 246.  It is Thursday November 12th 2020.  I am your host Scott Gombar and  YouTube Was Down

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Intel fixes 95 vulnerabilities in November 2020 Platform Update

Samsung fixes critical Android flaws with November 2020 updates

Ragnar Locker Ransomware Gang Takes Out Facebook Ads in Key New Tactic

Alleged source code of Cobalt Strike toolkit shared online

Microsoft now lets you run multiple Android apps in Windows 10

YouTube went down around the world, but it’s now fixed

Ransomware Attack on Medicaid Billing Service Provider Impacts 116,000 Individuals

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 245.  It is Wednesday November 11th 2020.  I am your host Scott Gombar and It’s the November Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Thank you to the men and women who have served and are currently serving in the US Armed Forces.

Updates Available from:  Mozilla, SAP, Cisco, Adobe and Microsoft

Microsoft November 2020 Patch Tuesday fixes 112 vulnerabilities

Microsoft fixes Windows zero-day disclosed by Google last month

Apple to Deliver ‘Privacy Labels’ for Apps, Revealing Data-Sharing Details

Microsoft is investigating undeletable Outlook.com emails

Microsoft Store, Outlook, and Xbox Live are down worldwide

Ubuntu's Gnome desktop could be tricked into giving root access

Scammers impersonating the IRS threaten victims with legal action

PHI Incidents Recently Reported by Healthcare Providers and Business Associates

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 244.  It is Tuesday November 10th 2020.  I am your host Scott Gombar and Compal Hit With a $17 Million Ransomware Attack, 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Millions of Hotel Guests Worldwide Caught Up in Mass Data Leak

Microsoft Exchange Attack Exposes New xHunt Backdoors

Ultimate Member Plugin for WordPress Allows Site Takeover

Google Chrome to block JavaScript redirects on web page URL clicks

Fake Microsoft Teams updates lead to Cobalt Strike deployment

Laptop maker Compal hit by ransomware, $17 million demanded

Cyberattack on UVM Health Network Impedes Chemotherapy Appointments

$350,000 Settlement Reached to Resolve Saint Francis Healthcare Data Breach Lawsuit

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 243.  It is Monday November 9th 2020.  I am your host Scott Gombar and Trump Lawsuit Site Leaked Voter Data

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

WordPress Sites Open to Code Injection Attacks via Welcart e-Commerce Bug

Hackers Abusing RMS and Teamviewer to Target Industrial Enterprises

RansomExx ransomware also encrypts Linux systems

Trump lawsuit site to report rejected votes leaked voter data

Luxottica data breach exposes LensCrafters, EyeMed patient info

Office for Civil Rights Announces 10th HIPAA Fine Under Right of Access Initiative

Healthcare Providers Affected by Email Account Breach at Payment Processing Vendor

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 242.  It is fRIday November 6th 2020.  I am your host Scott Gombar and Ransomware is Expensive, Even if You Don’t Pay the Ransom

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Updates from Cisco include a patch for Cisco AnyConnect vulnerability

Apple patches three actively exploited iOS zero-days

VMware Issues Updated Fix For Critical ESXi Flaw

Two-Thirds of Financial Services Firms Suffered Cyber-Attack in the Past Year

Brazil's court system under massive RansomExx ransomware attack

Capcom hit by Ragnar Locker ransomware, 1TB allegedly stolen

Ascend Clinical and Alamance Skin Center Suffer Ransomware Attacks

Blackbaud SEC Filing Provides Further Information on Data Breach and Mitigation Costs

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 241.  It is Thursday November 5th 2020.  I am your host Scott Gombar and Surprise, Surprise, Ransomware Operators Don’t Always Delete the Data.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Police to Livestream Ring Camera Footage of Mississippi Residents

Microsoft fixes Windows 10 issue behind displays going black

QBot phishing lures victims using US election interference emails

Japanese game dev Capcom hit by cyberattack, business impacted

Cisco discloses AnyConnect VPN zero-day, exploit code available

Microsoft outage breaks sites, Windows Store, Xbox, and other services

Scam PSA: Ransomware gangs don't always delete stolen data when paid

Wakefern Food Corporation Settles HIPAA Breach Case with NJ Attorney General for $235,000

Email Security Breaches Reported by Arkansas Otolaryngology Center and Centerstone of Indiana

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 240.  It is Wednesday November 4th 2020.  I am your host Scott Gombar and Blackbaud sued in 23 class action lawsuits after ransomware attack

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Warns Windows, MacOS Users of Critical Acrobat and Reader Flaws

Second-Hand USBs Purchased on eBay Expose Personal and Financial Information of Users

Leading toy maker Mattel hit by ransomware

New RegretLocker ransomware targets Windows virtual machines

SaltStack reveals new critical vulnerabilities, patch now

Blackbaud sued in 23 class action lawsuits after ransomware attack

ONC Extends Deadline for Compliance with its Information Blocking and Interoperability Rule

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 239.  It is Tuesday November 3rd 2020.  I am your host Scott Gombar and It’s Election Day in the USA

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Oracle Releases Out-of-Band Security Alert

Google patches one more actively exploited Chrome zero-day

WordPress Pushes Out Multiple Flawed Security Updates

Unpatched Windows Zero-Day Exploited in the Wild for Sandbox Escape

Privacy-focused Brave browser grew over 130% in the past year

GitHub breaks site layout after forgetting to renew certificate

Gold seller JM Bullion hacked to steal customers' credit cards

Failure to Terminate Former Employee’s Access Rights Results in $202,000 HIPAA Fine for New Haven, CT

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 238.  It is Friday October 30th 2020.  I am your host Scott Gombar and A Stark Warning for Healthcare

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 30 Think Before You Click

Microsoft Warns of Continued Exploitation of CVE-2020-1472

CISA and CNMF Identify a New Malware Variant: Zebrocy

CISA, FBI, and CNMF Identify a New Malware Variant: ComRAT

Oracle WebLogic Server RCE Flaw Under Active Attack

Wisconsin Republican Party says hackers stole $2.3 million

Home Depot Confirms Data Breach in Order Confirmation SNAFU

Maze ransomware is shutting down its cybercrime operation

Georgia county voter information leaked by ransomware gang

REvil ransomware gang claims over $100 million profit in a year

2 More Hospitals Hit by Growing Wave of Ransomware Attacks, As Feds Issue Warning

Aetna Hit with $1 Million HIPAA Fine for Three Data Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 237.  It is Thursday October 29th 2020.  I am your host Scott Gombar and RIP Google Music

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 29 Always Lock Your Devices

New warnings from Apple indicate iPhone 12's MagSafe feature may not be its best idea

Trump Campaign Website Defaced by Cryptocurrency Scam

Home Depot blunder emails customer order info to strangers

RIP Google Play Music, 2011 – 2020

Russian Turla hackers breach European government organization

QNAP warns of new QTS bugs that allow take over of devices

Microsoft's first 'vertical cloud,' the Microsoft Cloud for Healthcare, is now generally available

Oregon hospital shuts down computer system after ransomware attack: 4 notes

Sonoma Valley Hospital Suffers Significant EHR Downtime Event

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 236.  It is Wednesday October 28th 2020.  I am your host Scott Gombar and MFA Isn’t Optional...IMHO

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 28  Perform a Data Audit

Researchers: LinkedIn, Instagram Vulnerable to Preview-Link RCE Security Woes

Google Removes 21 Malicious Android Apps from Play Store

Mac users unable to print after Apple revoked HP certificate

Microsoft Edge gets Vertical Tabs feature you won't find in Chrome

Microsoft releases update to remove Adobe Flash from Windows

Mozilla rolls out new Firefox version to fix Windows reboot bug

Enel Group hit by ransomware again, Netwalker demands $14 million

Steelcase furniture giant hit by Ryuk ransomware attack

Amazon sacks insiders over data leak, alerts customers

Google employees personal info exposed in law firm data breach

Majority of Microsoft 365 Admins Don’t Enable MFA

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 235.  It is Monday October 26th 2020.  I am your host Scott Gombar and A Massive Data Breach at Nitro Impacts Microsoft, Google, Apple, and others...

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 27  Review Access Controls Regularly

Microsoft Releases Security Update for Edge

Sopra Steria confirms being hit by Ryuk ransomware attack

Vastaamo Breach: Hackers Blackmailing Psychotherapy Patients

Nando’s Hackers Feast on Customer Accounts

‘Among Us’ Mobile Game Under Siege by Attackers

Over 100 irrigation systems left exposed online without a password

Microsoft upgrades password spray attack detection capabilities

Massive Nitro data breach impacts Microsoft, Google, Apple, more

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 234.  It is Monday October 26th 2020.  I am your host Scott Gombar and The National Cybersecurity Guard…..

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 26  Have a Disaster Recovery Plan in Place

HPE fixes maximum severity remote auth bypass bug in SSMC console

Emotet malware now wants you to upgrade Microsoft Word

YouTube-dl removed from GitHub after RIAA DMCA notice

WastedLocker ransomware hits Boyne Resorts ski resort operator

Microsoft adds protection for critical accounts in Office 365

New RAT malware gets commands via Discord, has ransomware feature

Cyber Attack Leaves Half Of Chenango County's Computers Held By Ransomware

Phishing groups are collecting user data, email and banking passwords via fake voter registration forms

Exclusive: National Guard called in to thwart cyberattack in Louisiana weeks before election

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 233.  It is Friday October 23rd 2020.  I am your host Scott Gombar and How The President’s Twitter Account Was Hacked

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 23  Be Proactive In Your Compliance & Cybersecurity

NVIDIA patches high severity GeForce Experience vulnerabilities

Microsoft Teams Phishing Attack Targets Office 365 Users

WordPress deploys forced security update for dangerous bug in popular plugin

French IT giant Sopra Steria hit by Ryuk ransomware

Russian state hackers stole data from US government networks

Ransomware hits election infrastructure in Georgia county

President Trump’s Twitter accessed by security expert who guessed password ‘maga2020!’

September 2020 Healthcare Data Breach Report: 9.7 Million Records Compromised

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 232.  It is Thursday October 22nd 2020.  I am your host Scott Gombar and Iran and Russia Have Interfered With the US Election This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 22  Confirm Requests Via Multiple Lines of Communication

Oracle Kills 402 Bugs in Massive October Patch Update

Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird

Egregor Claims Responsibility for Barnes & Noble Attack, Leaks Data

Google Chrome now blocks site notifications with abusive content

QNAP warns of Windows Zerologon flaw affecting some NAS devices

US govt: Iran behind fake Proud Boys voter intimidation emails

Dickinson County Health Suffers Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 231.  It is Wednesday October 21st 2020.  I am your host Scott Gombar and Let’s Talk About the Top 25 Vulnerabilities Actively Being Attacked by China

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 21  Don’t Plug Unknown Devices Into Your Computer

VMware Releases Security Updates for Multiple Products

New Google Chrome version fixes actively exploited zero-day bug

Adobe Fixes 16 Critical Code-Execution Bugs Across Portfolio

Google’s Waze Can Allow Hackers to Identify and Track Users

Pharma Giant Pfizer Leaks Customer Prescription Info, Call Transcripts

Cisco warns of attacks targeting high severity router vulnerability

Darkside ransomware donates $20K of extortion money to charities

NSA: Top 25 vulnerabilities actively abused by Chinese hackers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 230.  It is Tuesday October 20th 2020.  I am your host Scott Gombar and QAnon/8Chan sites were taken down, temporarily

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 20  Avoid Connecting to Unsecured Wireless Networks

Microsoft Exchange, Outlook Under Siege By APTs

Fooling self-driving cars by displaying virtual objects

Coinbase phishing hijacks Microsoft 365 accounts via OAuth app

US Treasury hits bitcoin mixer with $60 million penalty

FBI warns of newly registered domains spoofing US Census Bureau

Hackers hijack Telegram, email accounts in SS7 mobile attack

QAnon/8Chan Sites Briefly Knocked Offline

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 229. It is Monday October 19th 2020. I am your host Scott Gombar and Google Warned Users of 33,000 State-Sponsored Attacks in 2020 This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut. You can visit us at nwajtech.com Cyber Security Awareness Tip 19 Keep Your Browser(s) Up to Date Adobe Releases Security Updates for Magento Microsoft Fixes RCE Flaws in Out-of-Band Windows Update Google says it mitigated a 2.54 Tbps DDoS attack in 2017, largest known to date Dickey’s BBQ Breach: Meaty 3M Payment Card Upload Drops on Joker’s Stash Watch out for Emotet malware's new 'Windows Update' attachment Hackers now abuse BaseCamp for free malware hosting Google warned users of 33,000 state-sponsored attacks in 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 228.  It is Friday October 16th 2020.  I am your host Scott Gombar and 62% of SMBs Do Not Conduct Annual Security Audits

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 16  Beware of Malvertising .

Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts

Carnival Corp. Ransomware Attack Affects Three Cruise Lines

Barnes & Noble Hack: A Reading List for Phishers and Crooks

Robinhood Internal Probe Finds Hackers Hit Almost 2,000 Accounts

SMBs’ size doesn’t make them immune to cyberattacks

Twitter outage blocks users from tweeting, seeing notifications

Piedmont Cancer Institute Phishing Attack Impacts 5,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 227.  It is Thursday October 15th 2020.  I am your host Scott Gombar and Patch Windows “Bad Neighbor” TCP/IP Bug Now

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 15 Stay up to date with current threats.

Apache Releases Security Updates for Apache Tomcat

Google, Intel Warn on ‘Zero-Click’ Kernel Bug in Linux-Based IoT Devices

Critical SonicWall VPN Portal Bug Allows DoS, Worming RCE

Morgan Stanley Receives $60 Million Fine for Improper Handling of Customer Data

Microsoft is forcibly installing Office PWAs in Windows 10

Zoom rolls out end-to-end encryption (E2EE) next week

US Cyber Command: Patch Windows 'Bad Neighbor' TCP/IP bug now

Canva design platform actively abused in credentials phishing

Sen. Warner Seeks Answers about Suspected Universal Health Services Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 226.  It is Wednesday October 14th 2020.  I am your host Scott Gombar and It’s the October Post  Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 14 Regular System Audits and Inventories are an Important Part of Cybersecurity

Microsoft October 2020 Patch Tuesday fixes 87 security bugs

SAP Releases October 2020 Security Updates

Mozilla releases Firefox 81.0.2 to fix Twitter errors

Critical Flash Player Flaw Opens Adobe Users to RCE

Backdoor Discovered in Xplora Children's Smartwatch

Miami-based tech company suffers massive 1TB customer and business data leak

3TB of clips from exposed home security cameras posted online

Windows 10 now warns when apps are configured to run at startup

London Borough of Hackney suffers ‘serious’ cyberattack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 225.  It is Tuesday October 13th 2020.  I am your host Scott Gombar and Microsoft for the Win, Maybe?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 13 Have a Mobile Device Action Plan

Hackers Publish Public School District's Stolen Data Online

Children and parent info exposed in Georgia DHS data breach

Windows Update can be abused to execute malicious files

QBot uses Windows Defender Antivirus phishing bait to infect PCs

Hackers used VPN flaws to access US govt elections support systems

BazarLoader used to deploy Ryuk ransomware on high-value targets

TrickBot botnet targeted in takedown operations, little impact seen

OCR Announces 9th Financial Penalty under its HIPAA Right of Access Initiative

228,000 Individuals Impacted by Legacy Community Health Services Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 224.  It is Monday October 12th 2020.  I am your host Scott Gombar and What Happens When IT is Hit With Ransomware?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 12 Be Aware, Don’t Overshare

Wormable Apple iCloud Bug Allows Automatic Photo Theft

Fitbit Spyware Steals Personal Data via Watch Face

Sophisticated Android Ransomware Executes with the Home Button

Robinhood says some customer accounts may have become target of hackers

Tyler Technologies paid ransomware gang for decryption key

Largest cruise line operator Carnival confirms ransomware data theft

Software AG IT giant hit with $23 million ransom by Clop ransomware

Community Health Systems Pays $5 Million to Settle Multi-State Breach Investigation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 223.  It is Friday October 9th 2020.  I am your host Scott Gombar and Updates, Vulnerabilities, Credential Stuffing and Ransomware...oh my

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 9 Cyber Liability Insurance is a Must 

Cisco Releases Security Updates

Adobe Creative Cloud down: Users report login, data access issues

Microsoft Azure Flaws Open Admin Servers to Takeover

Amazon Prime Day Spurs Spike in Phishing, Fraud Attacks

Gmail users: Expect to see these new security alerts, says Google

Sam's Club customer accounts hacked in credential stuffing attacks

Massachusetts school district shut down by ransomware attack

Former Mayo Clinic Employee Accessed Medical Records of 1,600 Patients Without Authorization

OCR Imposes $160,000 Penalty on Healthcare Provider for HIPAA Right of Access Failure

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 222.  It is Thursday October 8th 2020.  I am your host Scott Gombar and Is Your Comcast Remote Spying on You?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 8  Use MFA

IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish

Using a WordPress flaw to leverage Zerologon vulnerability and attack companies’ Domain Controllers

Microsoft to tailor Windows 10 setups based on how you use your PC

Microsoft adds consent phishing protection to Office 365

Phishing emails lure victims with inside info on Trump's health

Microsoft 365 outage takes down Outlook and Microsoft Teams again

QNAP fixes critical flaws that could lead to device takeover

Comcast TV Remote Hack Opens Homes to Snooping

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 221.  It is Wednesday October 7th 2020.  I am your host Scott Gombar and The Anatomy of a $15 million Scam

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 7  Ensure You Patch Your Operating Systems and All Applications

Chrome 86 rolls out with massive user security enhancements

Unpatched Apple T2 Chip Flaw Plagues Macs

Post Grid WordPress Plugin Flaws Allow Site Takeovers

Hackers abuse Windows error service in fileless malware attack

Ransomware threat surge, Ryuk attacks about 20 orgs per week

Cloudflare can now send DDoS alerts for sites are under attack

The anatomy of a $15 million cyber heist on a US company

Georgia Man Pleads Guilty to Attempting to Frame a Former Acquaintance for Violating HIPAA Rules

Magnolia Pediatrics and Accents on Health Suffer Ransomware Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 220.  It is Tuesday October 6th 2020.  I am your host Scott Gombar and  Backups Are Only as Good as the Last Test

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 6 Test Your Backups

New Flaws in Top Antivirus Software Could Make Computers More Vulnerable

Google releases fix for ChromeOS bug causing 100% CPU utilization

Microsoft: Iranian hackers actively exploiting Windows Zerologon flaw

Hacker group compromises mobile provider to steal credit cards

Slack outage causes lag, message errors, blank screens worldwide

Clinical Trial Software Provider Hit with Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 219.  It is Monday October 5th 2020.  I am your host Scott Gombar and Emotet Malware Taking Part in the Election.  

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 5 Backup Your Data Regularly

Years-Long ‘SilentFade’ Attack Drained Facebook Victims of $4M

Attacks Aimed at Disrupting the Trickbot Botnet

New ransomware vaccine kills programs wiping Windows shadow volumes

Online avatar service Gravatar allows mass collection of user info

Grindr fixed a bug allowing full takeover of any user account

HP Device Manager backdoor lets attackers take over Windows systems

Emotet malware takes part in the 2020 U.S. elections

New Jersey hospital paid ransomware gang $670K to prevent data leak

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 218.  It is Friday October 2nd 2020.  I am your host Scott Gombar and If You Help Ransomware Attackers Collect You Could Be Sanctioned.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 2 Use Strong Passwords that are easy to remember but hard to guess

CISA and CNMF Identify a New Malware Variant

Windows 10 KB4577063 update fixes Internet connectivity, WSL2 issues

NVIDIA fixes high severity flaws in Windows display driver

New service checks if your email was used in Emotet attacks

Twitter is down with users seeing "Something went wrong" errors

US govt warns of sanction risks for facilitating ransomware payments

PHI of 26,861 Patients Potentially Compromised in Oaklawn Hospital Phishing Attack

Anthem Inc. Settles State Attorneys General Data Breach Investigations and Pays $48.2 Million in Penalties

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 217.  It is Thursday October 1st 2020.  I am your host Scott Gombar and Welcome to Cybersecurity Awareness Month

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyber Security Awareness Tip 1

CISA Releases Telework Essentials Toolkit

CISA and MS-ISAC Release Ransomware Guide

Microsoft pulls SQL Server 2019 update due to snapshot issues

Two charged for hacking NBA, NFL players' social media accounts

QNAP warns customers of recent wave of ransomware attacks

Swiss watchmaker Swatch shuts down IT systems to stop cyberattack

Blackbaud: Ransomware gang had access to banking info and passwords

Cleveland-area hospital goes offline after apparent cyberattack

Major hospital system struggling to recover computer network operations after cyberattack

4 More U.S. Healthcare Providers Discover Email Account Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 216.  It is Wednesday September 30th 2020.  I am your host Scott Gombar and There are 247,000+ Unpatched Exchange Servers, and The Bad Guys Know

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Las Vegas Students’ Personal Data Leaked, Post-Ransomware Attack

Two major flight tracking services hit by crippling cyberattacks

Fake software crack sites used to push Exorcist 2.0 Ransomware

Cisco fixes actively exploited bugs in carrier-grade routers

Ransomware hits US-based Arthur J. Gallagher insurance giant

Microsoft clarifies patch confusion for Windows Zerologon flaw

Over 247K Exchange servers unpatched for actively exploited flaw

MU Health Care Phishing Attack Impacts 5,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 215.  It is Tuesday September 29th 2020.  I am your host Scott Gombar and Ransomware Attacks Takes Down Nationwide Hospital Network

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Mac, Linux Users Now Targeted by FinSpy Variants

‘Data security incident’ shuts down Montgomery County’s computer network

New Ransomware Actor Demands Multimillion-Dollar Ransom

Microsoft Office 365 is down in the USA, shows 'transient' error

FBI warns of disinformation campaigns about hacked voter systems

REvil ransomware deposits $1 million in hacker recruitment drive

Universal Health Services Ransomware Attack Impacts Hospitals Nationwide

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 214.  It is Monday September 28th 2020.  I am your host Scott Gombar and A Lesson in Default Settings

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Releases Security Updates

Ring’s Flying In-Home Camera Drone Escalates Privacy Worries

Feds Hit with Successful Cyberattack, Data Stolen

Fortinet VPN with Default Settings Leave 200,000 Businesses Open to Hackers

KuCoin cryptocurrency exchange hacked for $150 million

New Google ChromeOS updates cause 100% CPU usage, heating issues

Tyler Technologies warns clients to change remote support passwords

Louis Vuitton fixes data leak and account takeover vulnerability

Twitter is warning devs that API keys and tokens may have leaked

Premera Blue Cross pays 2nd-largest HIPAA fine for 2014 breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 213.  It is Friday September 25th 2020.  I am your host Scott Gombar and  No You Didn’t Win a New iPhone.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Unpatched Domain Controllers Remain Vulnerable to Netlogon Vulnerability, CVE-2020-1472

Cisco Patch-Palooza Tackles 29 High-Severity Bugs

Major Instagram App Bug Could've Given Hackers Remote Access to Your Phone

Microsoft confirms Group Policy Editor bug in Windows Server 2016

Phishing attacks are targeting your social network accounts

Scammers drain bank accounts using AnyDesk and SIM-swapping

SMS phishing scam pretends to be Apple “chatbot” – don’t fall for it!

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 212.  It is Thursday September 24th 2020.  I am your host Scott Gombar and Business Associates be Forewarned.  

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA: LokiBot Stealer Storms Into a Resurgence

Government software provider Tyler Technologies hit by ransomware

AgeLocker ransomware targets QNAP NAS devices, steals data

U.S. fitness chains suffer data breach affecting 600K customers

Hackers sell access to your network via remote management apps

Business Associate Fined $2.3 Million for Breach of 6 Million Records and Multiple HIPAA Failures

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 211.  It is Wednesday September 23rd 2020.  I am your host Scott Gombar and the NIST CSF is Your Friend..Use It.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Mozilla Releases Security Updates for Firefox and Firefox ESR

Google Cloud Buckets Exposed in Rampant Misconfiguration

Unsecured Microsoft Bing Server Exposed Users' Search Queries and Location

Cyber insurer's security scans reduced ransomware claims by 65%

Russian hackers use fake NATO training docs to breach govt networks

Only 44% of healthcare providers conform to protocols outlined by the NIST CSF

Minnesota Suffers Second-Largest Data Breach

Montefiore Medical Center and Geisinger Fire Employees for Improper PHI Access

August 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 210.  It is Tuesday Sept 22nd 2020. I am your host Scott Gombar and 4 Changes Needed to Curb the Ransomware Surge

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Samba Releases Security Update for CVE-2020-1472

Texas businesses targeted in Department of State Health RFQ phishing

Ray-Ban owner Luxottica reportedly hit with cyberattack

Guard your data with these privacy-focused search engines & browsers

Strava app shows your info to nearby users unless this setting is disabled

The ransomware crisis is getting worse. We need to make these four big changes

Systemic Noncompliance with HIPAA Results in $1.5 Million Financial Penalty for Athens Orthopedic Clinic

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 209.  It is Monday September 21st 2020. I am your host Scott Gombar and Listen to an iPhone with AM Radio

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA Releases Emergency Directive on Microsoft Windows Netlogon Remote Protocol

A Bug Could Let Attackers Hijack Firefox for Android via Wi-Fi Network

Researchers discover six-year espionage campaign targeting Iranian dissidents

Google App Engine feature abused to create unlimited phishing pages

Microsoft explains why Windows 10 is crashing on Lenovo laptops

Microsoft removes Windows Defender ability after security concerns

LISTENING TO AN IPHONE WITH AM RADIO

CCPA Amendment Update: California Legislature Approves Exceptions for HIPAA De-Identified Information and Other Health Data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 208.  It is Friday September 18th 2020. I am your host Scott Gombar and Ransomware Operators and Spammers Find Ways to Avoid Detection

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Drupal Releases Security Updates

Apple Releases Security Updates

Apple Bug Allows Code Execution on iPhone, iPad, iPod

California Elementary Kids Kicked Off Online Learning by Ransomware

Ransomware attack at German hospital leads to death of patient

Drug spammers start using new technique to bypass spam filters

Maze ransomware now encrypts via virtual machines to evade detection

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 207.  It is Thursday September 17th 2020. I am your host Scott Gombar and Billions of IoT Devices Vulnerable via Bluetooth

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

2 Hackers Charged for Defacing Sites after U.S. Airstrike Killed Iranian General

Dunkin' Donuts drops some dough to glaze over lawsuit accusing it of covering up customer account hacks

This security awareness training email is actually a phishing scam

Staples data breach caused by bug in order tracking system

New macOS Malware Variant Goes Unnoticed by Antivirus Scanners

Privacy-focused search engine DuckDuckGo is growing fast

Google Chrome is making it easier to reset compromised passwords

Bluetooth Spoofing Bug Affects Billions of IoT Devices

University Hospital New Jersey hit by SunCrypt ransomware, data leaked

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 206.  It is Wednesday September 16th 2020. I am your host Scott Gombar and Iran is Working Hard Too

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Iran-Based Threat Actor Exploits VPN Vulnerabilities

Cloud Leak Exposes 320M Dating-Site Records

MFA Bypass Bugs Opened Microsoft 365 to Attack

Google Drive is having an outage, users see spinning wheel

Adobe releases out-of-band security update for Adobe Media Encoder

Surge in DDoS attacks targeting education and academic sector

Windows 10 ‘Finger’ command can be abused to download or steal files

HIPAA Compliance: ONC Updates Security Risk Assessment Tool

OCR Settles with 5 Providers Over HIPAA Right of Access Violations

Patient Monitoring Software Vulnerabilities Identified

Department of Veteran Affairs Reports Breach of Payment System and Potential Theft of Veterans’ SSNs

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 205.  It is Tuesday September 15th 2020. I am your host Scott Gombar and Not Again...

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Exploit for Netlogon Remote Protocol Vulnerability, CVE-2020-1472

Chinese Government-affiliated Malicious Cyber Actors Targeting U.S. Government Agencies

US govt: China-sponsored hackers targeting Exchange, Citrix, F5 flaws

Microsoft Edge is getting a built-in password generator

TikTok Fixes Flaws That Opened Android App to Compromise

Office 365 Phishing Attack Leverages Real-Time Active Directory Validation

Staples discloses data breach exposing customer info

Magento stores hit by largest automated hacking attack since 2015

Starling Physicians Email Breach Impacts 7,777 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 204.  It is Monday September 14th 2020. I am your host Scott Gombar and Schools Are Being Targeted

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

WordPress Plugin Flaw Allows Attackers to Forge Emails

Walmart is selling Gateway PCs and no, the year is not 1999

Windows 10 is getting a built-in video conferencing feature

Postal Service left vulnerable IT applications unaddressed for years, inspector general finds

New Linux Malware Steals Call Details from VoIP Softswitch Systems

Ransomware Hits US District Court in Louisiana

Fairfax County schools hit by Maze ransomware, student data leaked

Razer data leak exposes personal information of gamers

US staffing firm Artech discloses ransomware attack, data breach

Amazon Opens Applications for HIPAA-Eligible Alexa Skills

Hennepin County Medical Center Faces Possible Legal Action Over Snooping on George Floyd’s Medical Records

Inova Health System Says 1.05 Million Individuals Impacted by Blackbaud Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 203.  It is Friday September 11th 2020. I am your host Scott Gombar and Never Forget

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA Insights: Email-Based Attacks on Elections-Related Entities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

Equinix data center giant hit by Netwalker Ransomware, $4.5M ransom

Microsoft: State-backed hackers are targeting the 2020 US elections

Google Chrome's new Tab Groups feature now available for everyone

Microsoft: Windows 10 1903 support ending in December 2020

Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks

Ransomware And Zoom-Bombing: Cyberattacks Disrupt Back-to-School Plans

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 202.  It is Thursday September 10th 2020. I am your host Scott Gombar and Azure Will Now Install Security Updates Automatically on Windows VMs

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Samsung fixes critical Android flaws with September updates

Windows 10 2004 KB4571756 breaks Windows Subsystem for Linux 2

Reflected XSS in WordPress Plugin Admin Pages

Azure now installs security updates on Windows VMs automatically

Leading US video delivery provider confirms ransomware attack

Up to 308,000 Patients Potentially Affected by Baton Rouge Clinic Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 201.  It is Wednesday September 9th 2020. I am your host Scott Gombar and It’s the September Post Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Releases Security Updates

Google Releases Security Updates for Chrome

Intel fixes critical flaw in corporate remote management platform

Microsoft September 2020 Patch Tuesday fixes 129 vulnerabilities

Classes to Resume in Hartford Wednesday After Ransomware Attack Postpones First Day of School

France, Japan, New Zealand warn of sudden spike in Emotet attacks

Netwalker ransomware hits Pakistan's largest private power utility

Hackers use legit tool to take over Docker, Kubernetes platforms

Data-sharing lawsuit against U of Chicago Medical Center, Google dismissed

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 200.  It is Tuesday September 8th 2020. I am your host Scott Gombar and You Might Want to Rethink Being the Boss

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

New PIN Verification Bypass Flaw Affects Visa Contactless Payments

WordPress Sites Attacked in Their Millions

Ransomware gang says they are behind Newcastle University attack

Windows 10 Sandbox activation enables zero-day vulnerability

Windows 10 themes can be abused to steal Windows accounts

CEOs Could Be Held Personally Liable for Cyberattacks that Kill

PHI of Almost 140,000 Individuals Potentially Compromised in Imperium Health Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 199.  It is Monday September 7th 2020. I am your host Scott Gombar and Happy Labor Day

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Facebook Debuts Third-Party Vulnerability Disclosure Policy

Attackers Steal Outlook Credentials Via Overlay Screens on Legitimate Sites

Evilnum hackers targeting financial firms with a new Python-based RAT

NCSC: 60% Rise in Girls Applying to CyberFirst Summer Courses

Hacker Steals $7.5 Million from Maryland Non-Profit by Compromising Employee’s Personal Computer

DoS and DDoS Attacks against Multiple Sectors

Microsoft to finally kill Adobe Flash support by January 2021

U.S. Department of Defense discloses critical and high severity bugs

OCR Publishes New Resources for MHealth App Developers and Cloud Services Providers

Blackbaud Data Breach Healthcare Victim Count Rises to Almost 1 Million

Assured Imaging Ransomware Attack Affects Almost 245,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 198.  It is Friday September 4th 2020. I am your host Scott Gombar and More Incorrectly Configured AWS S3 Buckets Lead to Large Data Breach

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

WhatsApp reveals six previously undisclosed vulnerabilities on new security site

Student arrested in Miami-Dade Schools cyberattacks ‘a good kid,’ neighbors say

Microsoft releases KB4571744 to fix Windows 10 update issue

Warner Music Group finds hackers compromised its online stores

Microsoft Defender can ironically be used to download malware

Google rolls out Secure DNS support to Chrome for Android

Online marketing company exposes 38+ million US citizen records

56,000 Northwestern Memorial HealthCare Donors Impacted by Blackbaud Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 197.  It is Thursday September 3rd 2020. I am your host Scott Gombar and Is Your Company Exposing Network Services to the Internet?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Microsoft Office update changes Outlook fallback encryption

Joker Spyware Plagues More Google Play Apps

Magento plugin Magmi vulnerable to hijacking admin sessions

Cisco fixes critical code execution bug in Jabber for Windows

Data breach confirmed in ransomware attack on Haywood County Schools

Cyberattack, plus software failure, responsible for Miami-Dade Schools’ woes, Carvalho says

Hackers actively exploiting severe bug in over 300K WordPress sites

Epic Fail: Emotet malware uses fake ‘Windows 10 Mobile’ attachments

Emotet Surfaces With 'Red Dawn' Threat

Attackers abuse Google DNS over HTTPS to download malware

33% of companies expose unsafe network services to the internet

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 196.  It is Wednesday September 2nd 2020. I am your host Scott Gombar and It’s National Insider Threat Awareness Month

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

National Insider Threat Awareness Month

Firefox 80.0.1 rolls out to fix crashes and download issues

U.S. Voter Databases Offered for Free on Dark Web, Report

Pioneer Kitten APT Sells Corporate Network Access

Credit card data smuggled via private Telegram channel

Google now pays for bugs used to bypass its anti-fraud systems

Healthcare execs say telehealth is their No. 1 pandemic tech problem

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 195.  It is Tuesday September 1st 2020. I am your host Scott Gombar and Windows 10 2004 Not Having a Good Day

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Stolen Fortnite Accounts Earn Hackers Millions Per Year

Critical Slack Bug Allows Access to Private Channels, Conversations

American Payroll Association discloses credit card theft incident

Windows 10 2004 now blocked on devices with LTE cellular modems

Lenovo warns of Windows 10 2004 crashing ThinkPad laptops

Malware authors trick Apple into trusting malicious Shlayer apps

Hackers are backdooring QNAP NAS devices with 3-year old RCE bug

Robinhood, Vanguard, TD Ameritrade affected by stock trading outages

Cisco warns of actively exploited bug in carrier-grade routers

Utah Pathology Services Email Breach Potentially Affects 112,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 194.  It is Monday August 31st 2020. I am your host Scott Gombar and It Feels Like a Healthcare Day

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Ex-Cisco Employee Pleads Guilty to Deleting 16K Webex Teams Accounts

DoJ Aims to Seize 280 Cryptocurrency Accounts Used by Hackers

A Whopping Rise in Healthcare Cyber Incidents

You have two days left to purchase 2-year TLS/SSL certificates

Namecheap Outage

CenturyLink routing issue led to outages on Hulu, Steam, Discord, more

Former Nursing Home Employee Accused of Defrauding Residents Out of $25,000

HHS Announces Limited HIPAA Privacy Rule Waivers Due to Hurricane Laura and the Californian Wildfires

Radiology Groups Issue Warning About PHI Exposure in Online Medical Presentations

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 193.  It is Friday August 28th 2020. I am your host Scott Gombar and It Was Tesla

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates

QakBot Banking Trojan Returned With New Sneaky Tricks to Steal Your Money

Local Government Organizations Most Frequently Targeted by Ransomware

Expect rapid growth in BEC scams to continue, despite global crackdown

Is the electric grid closer to a devastating cyberattack that could mean lights out?

Lemon_Duck cryptominer malware now targets Linux devices

REvil ransomware operators breached healthcare org Valley Health Systems

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 192.  It is Thursday August 27th 2020. I am your host Scott Gombar and Banks Beware

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Russian Arrested After Offering $1 Million to U.S. Company Employee for Planting Malware

Cyber-Attack on Rialto School District

Microsoft delays Windows 10 1803 end of service due to pandemic

Microsoft tests fix for bug that defrags SSD drives too often

North Korean Malicious Cyber Activity: FASTCash

New ZeaDynasplint Systems Data Breach Impacts Almost 103,000 Individualsland stock exchange halted trading after DDoS attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 191.  It is Wednesday August 26th 2020. I am your host Scott Gombar and You Might Want to Think Twice About That Job Offer

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Firefox 80 released with new and faster extensions blocklist

Safari Bug Revealed After Apple Takes Nearly a Year to Patch

Popular iOS SDK Caught Spying on Billions of Users and Committing Ad Fraud

Ryuk successor Conti Ransomware releases data leak site

DarkSide Ransomware hits North American real estate developer

Lazarus Group Targets Cryptocurrency Firms Via LinkedIn Messages

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 190.  It is Tuesday August 25th 2020. I am your host Scott Gombar and It Was a Day of Outages

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Chrome 85 fixes WebGL code execution vulnerability

Iran-Linked ‘Newbie’ Hackers Spread Dharma Ransomware Via RDP Ports

Steel sheet giant Hoa Sen Group hacked by Maze ransomware operators

FBI investigating COVID-19 data breach in South Dakota

Office 365 now opens attachments in a sandbox to prevent infections

Microsoft 365 Admin Portal is down, Office 365 services also affected

Zoom went down and schools got a digital snow day

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 189.  It is Monday August 24th 2020. I am your host Scott Gombar and Let’s Talk About Vishing

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Former Uber CSO Charged With Paying ‘Hush Money’ in 2016 Breach Cover-Up

Researchers Sound Alarm Over Malicious AWS Community AMIs

A Google Drive 'Feature' Could Let Attackers Trick You Into Installing Malware

US govt warns remote workers of ongoing vishing campaign

WordPress WooCommerce stores under attack, patch now

DarkSide: New targeted ransomware demands million dollar ransoms

US financial regulator warns of phishing sites impersonating brokers

University of Utah hit by ransomware, pays $457K ransom

AI Company Exposed 2.5 Million Patient Records Over the Internet

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 188.  It is Friday August 21st 2020. I am your host Scott Gombar and Your Keys Can Now Be Copied Just by Listening

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates

WSL2 now rolling out to devices running Windows 10 1903 and 1909

2020 CWE Top 25 Most Dangerous Software Weaknesses

Senate Bill Would Expand Facial-Recognition Restrictions Nationwide

Microsoft Out-of-Band Security Update Fixes Windows Remote Access Flaws

Memory leak in IBM DB2 gives access to sensitive data, causes DoS

Transparent Tribe APT targets government, military by infecting USB devices

Tens of suspects arrested for cashing-out Santander ATMs using software glitch

Hackers can now clone your keys just by listening to them with a smartphone

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 187.  It is Thursday August 20th 2020. I am your host Scott Gombar and The July 2020 HIPAA Breach Report Has Arrived

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

North Korean Malicious Cyber Activity

Hackers hijack design platform to go phishing

Emotet’s Rapid Infection Further Contaminates US, UK Businesses Using COVID-19 Spam

Gun exchange site confirms data breach after database posted online

Spotify hit with outage after forgetting to renew a certificate

Microsoft Teams users can't join meetings hosted in North America

July 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 186.  It is Tuesday August 18th 2020. I am your host Scott Gombar and No Zoom Meeting For You.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Large Orgs Plagued with Bugs, Face Giant Patch Backlogs

Researchers Warn of Active Malware Campaign Using HTML Smuggling

Publicly reported data breaches down 52%, exposed records way up!

Zoom web client outage prevents users from joining meetings

Cryptojacking worm steals AWS credentials from Docker systems

Gym app management platform exposed info of thousands of users

R1 RCM Medical Collection Agency Suffers Ransomware Attack

Blackbaud Ransomware Attack Impacts 657,392 Northern Light Health Foundation Donors

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 185.  It is Tuesday August 18th 2020. I am your host Scott Gombar and It’s a Rough Year for Carnival

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Researchers Exploited A Bug in Emotet to Stop the Spread of Malware

Popular Notepad++ text editor banned in China

Google Chrome will warn users when submitting insecure forms

Microsoft fixes actively exploited Windows bug reported 2 years ago

World's largest cruise line operator Carnival hit by ransomware

Healthcare Data Leaks on GitHub: Credentials, Corporate Data and the PHI of 150,000+ Patients Exposed

Medical Software Database Containing Personal Information of 3.1 Million Patients Exposed Online

Emotet stopped temporarily by security researchers, Notepad++ blocked in China for speaking up, Microsoft fixed active exploit discovered 2 years ago, Carnival cruises hit with a ransomware attack..again, and two interesting HIPAA breaches to report

Listen to Episode 185

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 184.  It is Monday August 17th 2020. I am your host Scott Gombar and Education is the Key

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Mac Users Targeted by Spyware Spreading via Xcode Projects

PoC Exploit Targeting Apache Struts Surfaces on GitHub

Instagram Retained Deleted User Data Despite GDPR Rules

Business technology giant Konica Minolta hit by new ransomware

Canada suffers cyberattack used to steal COVID-19 relief payments

U.S. spirits and wine giant hit by cyberattack, 1TB of data stolen

SANS shares details on attack that led to their data breach

Protected Health Information of 129K Individuals Potentially Compromised in Behavioral Health Network Malware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 183.  It is Friday August 14th 2020. I am your host Scott Gombar and A New Warning from the NSA

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Amazon Alexa ‘One-Click’ Attack Can Divulge Personal Data

ReVoLTE Attack Allows Hackers to Listen in on Mobile Calls

CISA alerts of phishing attack targeting SBA loan relief accounts

U.S. stock broker regulator FINRA warns of copycat phishing site

NSA discloses new Russian-made Drovorub malware targeting Linux

Data Breaches Reported by University of Maryland Faculty Physicians and Highpoint Foot & Ankle Center

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 182.  It is Thursday August 13th 2020. I am your host Scott Gombar and More Ransomware Attacks on HealthcareThis podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Critical Intel Flaw Afflicts Several Motherboards, Server Systems, Compute Modules

Microsoft Reveals New Innocent Ways Windows Users Can Get Hacked

Sensitive data of cyber security firm & other businesses leaked online

SANS infosec training org suffers data breach after phishing attack

Almost 20,000 Patients Affected by Owens Ear Center Ransomware Attack

Ashley County Medical Center Nurse Terminated for Improper Medical Record Access

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 181.  It is Wednesday August 12th 2020. I am your host Scott Gombar and It’s the Post Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Adobe Releases Security Updates

Microsoft Releases August 2020 Security Updates

Microsoft Addresses RCE and Spoofing Vulnerabilities Under Active Exploitation

SAP Releases August 2020 Security Updates

Apple Releases Security Updates for iCloud for Windows

Critical Flaws Affect Citrix Endpoint Management (XenMobile Servers)

vBulletin fixes ridiculously easy to exploit zero-day RCE bug

Colorado city forced to pay $45,000 ransom to decrypt files

Four Healthcare Providers and a Ventilator Manufacturer Attacked with Ransomware

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 180.  It is Tuesday August 4th 2020. I am your host Scott Gombar and What is HIPAA Certification?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Chinese Malicious Cyber Activity

Meetup Critical Flaws Allow ‘Group’ Takeover, Payment Theft

Newsletter plugin bugs let hackers inject backdoors on 300K sites

Zello resets all user passwords after data breach

FBI sees surge in online shopping scams, FTC says most reports ever

Three suspects charged for roles in Twitter hack, Bitcoin scam

What is HIPAA Certification?

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 179.  It is Monday August 3rd 2020. I am your host Scott Gombar and Who Hacked Twitter, and How?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Ransomware feared as possible saboteur for November election

Havenly discloses data breach after 1.3M accounts leaked online

Confirmed: Garmin received decryptor for WastedLocker ransomware

US government sites abused to redirect users to porn sites

Canadian MSP discloses data breach, failed ransomware attack

Travel company CWT avoids ransomware derailment by paying $4.5m blackmail demand

Twitter: Epic Account Hack Caused by Mobile Spearphishing

6,000 Patients Notified About Email Security Breach at Beaumont Health

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 178.  It is Friday July 31st 2020. I am your host Scott Gombar and US Defense Contractors Being Targeted by North Korea

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for Multiple Products

KDE archive tool flaw let hackers take over Linux accounts

Office 365 phishing abuses Google Ads to bypass email filters

TrickBot's new Linux malware covertly infects Windows devices

US defense contractors targeted by North Korean phishing attacks

ONC releases updated recommendations for pediatric health IT

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 177.  It is Thursday June 30th 2020. I am your host Scott Gombar and Enable MFA Already

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Billions of Devices Impacted by Secure Boot Bypass

Michigan online bar exam temporarily taken down by 'sophisticated' cyberattack

Vermont Tax Department exposed 3 years worth of tax return info

Zoom bug allowed attackers to crack private meeting passwords

Cisco fixes severe flaws in data center management solution

The IRS asks tax professionals to enable multi-factor authentication

PHI Compromised in CVS Pharmacy and Walgreens Break-ins

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 176.  It is Wednesday June 29th 2020. I am your host Scott Gombar and I Guess We’re Gonna Be Busy for the Rest of This Week.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Firefox 79 is out – it’s a double-update month so patch now!

Magento gets security updates for severe code execution bugs

Critical Wordpress plugin bug lets hackers take over hosting account

Researchers Warn of High-Severity Dell PowerEdge Server Flaw

Undetectable Linux Malware Targeting Docker Servers With Exposed APIs

Emotet malware now steals your email attachments to attack contacts

Hacker leaks 386 million user records from 18 companies for free

Industrial VPN vulnerabilities put critical infrastructure at risk

Netflix credential phishing hides behind working CAPTCHA

NY hospital reverts to pen & paper after online breach: 4 details

University of Utah Reports Phishing Attack Involving the PHI of up to 10,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 175.  It is Tuesday July 28th 2020. I am your host Scott Gombar and A Warning from the NSA

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Encryption Under ‘Full-Frontal Nuclear Assault’ By U.S. Bills

MS Office Vulnerabilities Being Actively Exploited by Attackers

Promo.com discloses data breach after 22M user records leaked online

Garmin confirms ransomware attack, services coming back online

UK and US warn QNAP owners to upgrade firmware to block malware

NSA Urgently Warns on Industrial Cyberattacks, Triconex Critical Bug

Lifespan Pays $1,040,000 to OCR to Settle Unencrypted Stolen Laptop Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 174.  It is Monday July 27th 2020. I am your host Scott Gombar and There are Virtual Vigilantes Among Us

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Website Security Breach Exposes 1 Million DNA Profiles

Emotet malware operation hacked to show memes to victims

5 severe D-Link router vulnerabilities disclosed, patch now

Dave data breach affects 7.5 million users, leaked on hacker forum

US govt confirms active exploitation of F5 BIG-IP RCE flaw

Garmin outage caused by confirmed WastedLocker ransomware attack

June 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 173.  It is Friday July 24th 2020. I am your host Scott Gombar and No Workout Tracking For You Today

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for ASA and FTD Software

Citrix Releases Security Updates for Workspace App for Windows

ASUS Home Router Bugs Open Consumers to Snooping Attacks

Garmin Suffers Reported Ransomware Attack

UK govt warns of ransomware, BEC attacks against sports sector

Remove unwanted Windows 10 apps with this new open source tool

New cryptojacking botnet uses SMB exploit to spread to Windows systems

Small North Carolina Healthcare Provider Fined $25,000 for HIPAA Security Rule Noncompliance

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 172.  It is Thursday July 23rd 2020. I am your host Scott Gombar and How You Can Make $2 Million

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Leak Exposes Private Data of Genealogy Service Users

Google: Here come 11 new security features across Gmail, Meet and Chat

Twilio exposes SDK, attackers inject it with malvertising code

Lazarus hackers deploy ransomware, steal data using MATA malware

Microsoft Outlook crashes, deletes mails for some POP accounts

New ‘Meow’ attack has wiped dozens of unsecured databases

US offers $2 million for info on Ukrainians charged for SEC hack

Critical SharePoint flaw dissected, RCE details now available

Experts predict support for some, but not all, telehealth expansion measures

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 171.  It is Wednesday July 22nd 2020. I am your host Scott Gombar and They’re Back

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Microsoft Releases Security Update for Edge

Mozilla Releases Security Update for Thunderbird

Diebold ATM Terminals Jackpotted Using Machine’s Own Software

Critical Adobe Photoshop Flaws Patched in Emergency Update

Breach Lawsuit Against Pediatric Dental Practice Dismissed

Emotet botnet is now heavily spreading QakBot malware

Emotet-TrickBot malware duo is back infecting Windows machines

Quantum Imaging and Therapeutic Associates Investigating Possible Facebook HIPAA Breach

47,754 Individuals Impacted by Lorien Health Services Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 170.  It is Friday July 17th 2020. I am your host Scott Gombar and So How Did Twitter Get Hacked? This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Releases Security Updates

Threat Actors Introduce Unique ‘Newbie’ Hacker Forum

Report: CIA most likely behind APT34 and FSB hacks and data dumps

Federal agencies told to patch wormable Windows DNS bug in 24 hours

T-Mobile announces free Scam Shield robocall and scam protection

Scammers hacked Twitter and hijacked accounts using admin tool

36,000 Members Affected by Central California Alliance for Health Email Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 169.  It is Thursday July 16th 2020. I am your host Scott Gombar and Outlook is Broken and Twitter is Hacked

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for Multiple Products

Microsoft Outlook is crashing worldwide with 0xc0000005 errors, how to fix

A New Flaw In Zoom Could Have Let Fraudsters Mimic Organisations

4 Dangerous Brazilian Banking Trojans Now Trying to Rob Users Worldwide

Twitter Confirms it was Hacked in an Unprecedented Cryptocurrency Scam

HIPAA breach impacts 350 Delaware Division of Developmental Disabilities clients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 168.  It is Wednesday July 15th 2020. I am your host Scott Gombar and That’s Right, It’s The Post Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apache Releases Security Advisories for Apache Tomcat

Adobe Releases Security Updates for Multiple Products

Google Releases Security Updates for Chrome

Oracle Releases July 2020 Security Bulletin

Microsoft July 2020 Patch Tuesday: 123 vulnerabilities, 18 Critical!

WhatsApp is down, users reporting worldwide outage

A hacker is selling details of 142 million MGM hotel guests on the dark web

Critical SAP Bug Allows Full Enterprise System Takeover

17-Year-Old Critical 'Wormable' RCE Vulnerability Impacts Windows DNS Servers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 167.  It is Tuesday July 14th 2020. I am your host Scott Gombar and It’s Already Too Late

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Remote working: This free tool tests how good your security really is

Hacker breaches security firm in act of revenge

New AgeLocker Ransomware uses Googler's utility to encrypt files

LiveAuctioneers reports data breach after user records sold online

Benefit Recovery Specialists Hacked and PHI of 274,837 Individuals Exposed

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 166.  It is Monday July 13th 2020. I am your host Scott Gombar and Phishing Kits for Sale on a Hacker Forum

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Releases Security Updates for Multiple Products

Zoom fixes zero-day RCE bug affecting Windows 7, more updates soon

Honeywell Sees Rise in USB-Borne Malware That Can Cause Major ICS Disruption

TrickBot malware mistakenly warns victims that they are infected

US Secret Service creates new Cyber Fraud Task Force

Apple: Closing MacBooks with camera covers leads to display damage

Over 1,300 phishing kits for sale on hacker forum

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 165.  It is Friday July 10th 2020. I am your host Scott Gombar and Flaws in Ultrasound and Open-Source Hospital Systems

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Juniper Networks Releases Security Updates for Multiple Products

Zoom Zero-Day Allows RCE, Patch on the Way

Advertising Plugin for WordPress Threatens Full Site Takeovers

Google Patches Critical Android Vulnerabilities With July 2020 Updates

Conti ransomware shows signs of being Ryuk's successor

Google will ban ads for stalkerware starting August 11

Alerts: Flaws in Ultrasound, Open-Source Hospital Systems

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 164.  It is Thursday July 9th 2020. I am your host Scott Gombar and 15 Billion Credentials Are Up For Grabs on Hacker Forums

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Releases Security Update for VeloCloud

Casino App Clubillion Leaks PII on “Millions” of Users

Microsoft warns of Office 365 phishing via malicious OAuth apps

First look: Microsoft's Project Freta detects Linux malware for free

Kinda sorta weakened version of EARN IT Act creeps closer

15 Billion Credentials Currently Up for Grabs on Hacker Forums

Health Plan Member Portals Accessed Using Stolen Credentials

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 163.  It is Wednesday July 8th 2020. I am your host Scott Gombar and Texas Does Everything Big Apparently

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA Releases Securing Industrial Control Systems: A Unified Initiative

Windows 10: The beginning of the end for Control Panel

Microsoft takes down domains used in COVID-19-related cybercrime

US Treasury shares tips on spotting money mule and imposter scams

First reported Russian BEC scam gang targets Fortune 500 firms

Citrix fixes 11 flaws in ADC, Gateway, and SD-WAN WANOP appliances

Texas County Sheriff's Office Suffers Ransomware Attack

Texas Bicycle Sharing Company Breached by Malware

US Secret Service reports an increase in hacked managed service providers (MSPs)

Mitigating critical F5 BIG-IP RCE flaw not enough, bypass found

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 162.  It is Tuesday July 7th 2020. I am your host Scott Gombar and Boston Bans Government Use of Facial Recognition

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Foreign cyber criminals take aim at Americans working from home

EDP energy giant confirms Ragnar Locker ransomware attack

Ransomware attack on insurance MSP Xchanging affects clients

North Korean hackers linked to credit card stealing attacks on US stores

Boston bans government use of facial recognition

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 161.  It is Monday July 6th 2020. I am your host Scott Gombar and Some Companies are Now Reporting Ransomware Attacks as Data Breaches

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

F5 Releases Security Advisory for BIG-IP TMUI RCE vulnerability, CVE-2020-5902

Samba Releases Security Updates

Sodinokibi Ransomware Operators hit electrical energy company Light S.A.

Companies start reporting ransomware attacks as data breaches

Windows 10 2004 breaks OneDrive connectivity for some users

Up to 58,000 Individuals Impacted by Healthcare Fiscal Management Ransomware Attack

30,000 Patients’ PHI Exposed in NC and TX Phishing Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 160.  It is Friday July 3rd 2020. I am your host Scott Gombar and One out of Every 142 passwords is still 123456

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for Multiple Products

Apache Guacamole Opens Door for Total Control of Remote Footprint

Facebook Privacy Glitch Gave 5K Developers Access to ‘Expired’ Data

Inside a ransomware attack: From the first breach to the ransom demand

Hacker ransoms 23k MongoDB databases and threatens to contact GDPR authorities

One out of every 142 passwords is '123456'

Hundreds arrested after encrypted messaging network takeover

Microsoft unveils new Windows 10 Start Menu with theme-aware tiles

$185,000 Settlement Proposed to Resolve Grays Harbor Community Hospital Ransomware Lawsuit

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 159.  It is Thursday July 2nd 2020. I am your host Scott Gombar and Extent of Magellan Health Ransomware Becomes Clearer, and It’s Not Pretty

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Mozilla rolls out emergency Firefox update to fix search issues

New Android Spyware Tools Emerge in Widespread Surveillance Campaign

Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings

Federal Reserve shares tips on mitigating synthetic identity fraud

Windows POS malware uses DNS to smuggle stolen credit cards

Dozens of US news sites hacked in WastedLocker ransomware attacks

Extent of Magellan Health Ransomware Becomes Clear: More Than 364,000 Individuals Affected

American Medical Tech Reports 2019 Email Hack Impacting 47K Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 158.  It is Wednesday July 1st 2020. I am your host Scott Gombar and Huawei and ZTE are Now Security Threats

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Firefox 78 adds WebRender support to Windows PCs with Intel GPU

Half of Internet Users Fall Victim to Cyber Attacks

EvilQuest wiper uses ransomware cover to steal files from Macs

Microsoft releases OOB security updates for Windows 10 RCE bugs

US designates China's Huawei and ZTE as national security threats

Clever Phishing scam targets websites with free DNSSEC offer

Business giant Xerox allegedly suffers Maze Ransomware attack

Google joins Apple in limiting web certificates to one year

2020 Breach Notification Law Update: Vermont, District of Columbia, Maine, and California Expand Requirements

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 157.  It is Tuesday June 30th 2020. I am your host Scott Gombar and Politicians Being Mistaken for Criminals..Imagine That.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Netgear Router Vulnerabilities

Palo Alto Releases Security Updates for PAN-OS

REvil Ransomware Gang Adds Auction Feature for Stolen Data

AWS Facial Recognition Platform Misidentified Over 100 Politicians As Criminals

Seller floods hacker forum with data stolen from 14 companies

UC San Francisco pays $1.14 million for ransomware decryptor

Roblox accounts being hacked in support of Trump reelection

Over 100k daily brute-force attacks on RDP in pandemic lockdown

Data Breach Settlement Has an Unusual Provision

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 156.  It is Monday June 29th 2020. I am your host Scott Gombar and DHS Is Warning Healthcare Practices About Vulnerabilities

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apache Releases Security Advisory for Apache Tomcat

TikTok To Stop Clipboard Snooping After Apple Privacy Feature Exposes Behavior

GeoVision access control devices let hackers steal fingerprints

Almost 300 Windows 10 executables vulnerable to DLL hijacking

Evil Corp blocked from deploying ransomware on 30 major US firms

New Ransom X Ransomware used in Texas TxDOT cyberattack

DHS has sent hundreds of vulnerability notifications to medical sector during coronavirus pandemic

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 155.  It is Friday June 26th 2020. I am your host Scott Gombar and LG Allegedly Hit by Maze Ransomware Attack

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Advisory for Telnet Vulnerability in IOS XE Software

Nationwide Facial Recognition Ban Proposed By Lawmakers

WikiLeaks Founder Charged With Conspiring With LulzSec & Anonymous Hackers

Hackers hide credit card stealing scripts in favicon EXIF data

LG Electronics allegedly hit by Maze ransomware attack

Telehealth data breaches to worsen as adoption skyrockets

Georgia Hospital Accused of Falsification of COVID-19 Test Results Suspends Employees Over Suspected HIPAA Breach

Breaches Reported by St. Luke’s Health-Memorial Lufkin, RiverPointe Post Acute, and Iowa Total Care

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 154.  It is Thursday June 25th 2020. I am your host Scott Gombar and Ransomware Surge Part 2

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

New Bill Targeting ‘Warrant-Proof’ Encryption Draws Ire

Ransomware Attacks in Healthcare: Are We Seeing a Surge?

NVIDIA patches high severity flaws in Windows, Linux drivers

Microsoft: Attackers increasingly exploit Exchange servers

VMware fixes critical vulnerability in Workstation and Fusion

Exposed Frost & Sullivan databases for sale on hacking forum

American Medical Technologies Email Breach Affects 47,767 Patients

Ransomware Attacks Reported by North Shore Pain Management & Florida Orthopaedic Institute

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 153.  It is Wednesday June 24th 2020. I am your host Scott Gombar and Get Ready for a Ransomware Surge

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Adobe Releases Security Updates for Magento

80,000 printers are exposing their IPP port online

New WastedLocker Ransomware distributed via fake program updates

REvil ransomware scans victim's network for Point of Sale systems

Ryuk ransomware deployed two weeks after Trickbot infection

May 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 152.  It is Tuesday June 23rd 2020. I am your host Scott Gombar and Blueleaks Exposes 24 Years of Police Records.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Former DIA Analyst Sentenced to Prison Over Data Leak

Office 365 now checks docs for known threats before editing

Microsoft says June 2020 updates break Outlook for some users

BlueLeaks data dump exposes over 24 years of police records

Hackers use Google Analytics to steal credit cards, bypass CSP

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 151.  It is Monday June 22nd 2020. I am your host Scott Gombar and Connectwise Again?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Microsoft Releases Security Updates for Windows

Google Yanks 106 ‘Malicious’ Chrome Extensions

Fake Data Breach Notifications Leading to Malware and Scams

Security surprise: Four zero-days spotted in attacks on researchers' fake networks

Malwarebytes causing performance issues in Windows 10 2004

Nigerian entrepreneur pleaded guilty to $11M Caterpillar fraud

ConnectWise Partners Hit By Ransomware Via Automate Flaw

New York Patients’ Data Breach Claims Sent Back to State Court

Hacker arrested for stealing, selling PII of 65K hospital employees

Breaches Reported by Hanger Clinic, Gateway Health, and Sunrise Treatment Center

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 150.  It is Friday June 19th 2020. I am your host Scott Gombar and Happy Juneteenth

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Multiple Security Updates

ISC Releases Security Advisories for BIND

Drupal Releases Security Updates

79 Netgear router models risk full takeover due to unpatched bug

BofA Phish Gets Around DMARC, Other Email Protections

Wells Fargo phishing baits customers with calendar invites

Business Associate Incidents Added to Breach Tally

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 149.  It is Thursday June 18th 2020. I am your host Scott Gombar and Amazon Stops Largest DDoS Attack Ever Seen

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Releases Security Updates for Multiple Products

Shlayer Mac Malware Returns with Extra Sneakiness

LinkedIn ‘Job Offers’ Targets Aerospace, Military Firms With Malware

AWS said it mitigated a 2.3 Tbps DDoS attack, the largest ever

IT giant Cognizant confirms data breach after ransomware attack

Cisco fixes severe flaws in Webex Meetings for Windows, macOS

DraftKings discloses SBTech ransomware attack in SEC filing

Care New England's computer system down due to data security incident

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 148.  It is Wednesday June 17th 2020. I am your host Scott Gombar and What Caused the TMobile Outage?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

‘Ripple20’ Bugs Impact Hundreds of Millions of Connected Devices

Plex fixes Media Server bugs allowing full system takeover

VLC Media Player 3.0.11 fixes severe remote code execution flaw

Windows 10 out-of-band updates released to fix printing issues

Chipmaker MaxLinear reports data breach after Maze Ransomware attack

T-Mobile outage caused by configuration error, not a DDoS attack

‘Anonymous’ takes down Atlanta Police Dept. site after police shooting

Cano Health Discovers 2-Year Email Account Breach

Ransomware Attacks Reported by Rangely District Hospital and Electronic Waveform Lab

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 147.  It is Tuesday June 16th 2020. I am your host Scott Gombar and a COVID-19 related HIPAA Violation for the Cowboys?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Spies Can Listen to Your Conversations by Watching a Light Bulb in the Room

T-Mobile’s US network goes down, impacting Verizon, AT&T, and other carriers

South African bank to replace 12m cards after employees stole master key

Hackers Breached A1 Telekom, Austria's largest ISP

Accessories giant Claire's hacked to steal credit card info

Attackers impersonate secure messaging site to steal bitcoins

Ezekiel Elliott tested positive for coronavirus and thinks someone violated HIPAA

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 146.  It is Monday June 15th 2020. I am your host Scott Gombar and Air Gapped Doesn’t Equal 100% Security

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Black Lives Matter Emails Deliver TrickBot Malware

Microsoft Joins Ban on Sale of Facial Recognition Tech to Police

Hackers Claim High-Profile Victims in Healthcare

City Pays Ransom Despite Pre-Ransomware Outbreak Hack Alert

Air-Gapped Systems are Becoming a Treasure Trove for Attackers

Windows 10 Alert: Defragger bug defrags SSD Drives too often

Facebook paid for a 0-day to help FBI unmask child predator

HHS Issues Guidance for Providers on Soliciting COVID-19 Blood and Plasma Donations

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 145.  It is Friday June 12th 2020. I am your host Scott Gombar and The Risks of Telehealth

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

WordPress Releases Security and Maintenance Update

IC3 Releases Alert on Mobile Banking Apps

Fortune 500 insurance firm Genworth discloses data breach

A Bug in Facebook Messenger for Windows Could've Helped Malware Gain Persistence

City of Knoxville shuts down network after ransomware attack

IBM Cloud global outage caused by "incorrect" BGP routing

Telehealth App Breach Spotlights Privacy, Security Risks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 144.  It is Thursday June 11th 2020. I am your host Scott Gombar and Something New and Something Old

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Critical Intel Flaws Fixed in Active Management Technology

VMware Releases Security Update for Horizon Client for Windows

Microsoft Office June security updates fix critical RCE bugs

US Companies Lost Over $1.2 Trillion Due to Data Breaches in 2019

Honda cyberattack halts plants in India, Brazil, Turkey

Fake Black Lives Matter voting campaign spreads Trickbot malware

Expiring SSL certs expected to break smart TVs, fridges, and IoTs

New Windows 10 SMBv3 flaw can be used for data theft, RCE attacks

Everett & Hurite Ophthalmic Association Email Breach Impacts 34,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 143.  It is Wednesday June 10th 2020. I am your host Scott Gombar and It’s the Post Patch Tuesday Episode

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Releases Security Updates

Microsoft June Patch Tuesday Fixes 129 Flaws in Largest-Ever Update3

Magecart Targets Emergency Services-related Sites via Insecure S3 Buckets

NASA Hit By 366% Rise In Cybersecurity Incidents After Budget Cuts

BRIEF: Minnesota School District Addresses Cybersecurity Breach

University of Utah Health Suffers Further Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 142.  It is Tuesday June 9th 2020. I am your host Scott Gombar and Your Password is the Problem….Still

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Singapore’s Contact Tracing Wearable Causes Privacy Backlash

80% hacking attacks linked to bad password habits: Report

Maze Ransomware adds Ragnar Locker to its extortion cartel

CallStranger UPnP bug allows data theft, DDoS attacks, LAN scans

US energy providers hit with new malware in targeted attacks

Facebook sues companies for registering impostor domains

$107,000 Stolen from Kentucky Employees’ Health Plan Members in Two Recent Cyberattacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 141.  It is Monday June 8th 2020. I am your host Scott Gombar and Both Campaigns Are Actively Being Targeted by Foreign Hackers

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Unpatched Microsoft Systems Vulnerable to CVE-2020-0796

Google Releases Security Updates for Chrome

Fake ransomware decryptor double-encrypts desperate victims' files

US aerospace services provider breached by Maze Ransomware

FTC Slams Children’s App Developer for COPPA Violations

Trump and Biden campaigns were targeted by foreign hackers, Google says

St Joseph Health System Discovers Medical Record Storage Facility Improperly Disposed of Patient Records

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 140.  It is Thursday June 4th 2020. I am your host Scott Gombar and We’re Gonna Be Here For A Whilre

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Attackers Target 1M+ WordPress Sites To Harvest Database Credentials

Sophisticated Info-Stealer Targets Air-Gapped Devices via USB

Two Critical Flaws in Zoom Could've Let Attackers Hack Systems via Chat

Hospitals 'overwhelmed' by cyberattacks fuelled by booming black market

YouTube channel credentials in high demand on hacker forums

Ransomware gang says it breached one of NASA's IT contractors

Netwalker ransomware continues assault on US colleges, hits UCSF

Office 365 phishing baits remote workers with fake VPN configs

San Francisco retirement program SFERS suffers data breach

Patch SAP Adaptive Server Enterprise now to avoid takeover risk

Ransomware gangs team up to form extortion cartel

Kaiser Permanente Discovers 8-Year Employee HIPAA Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 139.  It is Wednesday June 3rd 2020. I am your host Scott Gombar and Study Says You Don’t Change Your Passwords

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Firefox 77 rolls out WebRender to more Windows 10 laptops

Apple Releases Security Updates

Cisco Releases Security Updates for NX-OS Software

Microsoft fixes Outlook crashes in June Office 2020 updates

Two Critical Android Bugs Open Door to RCE

VMware Cloud Director flaw lets hackers take over virtual datacenters

REvil ransomware creates eBay-like auction site for stolen data

After a breach, users rarely change their passwords, study finds

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 138.  It is Tuesday June 2nd 2020. I am your host Scott Gombar and Don’t Say I Didn’t Warn You?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Minneapolis Police Department Hack Likely Fake, Says Researcher

Financial Services Sector Witnessing Increased Attacks

Joomla team discloses data breach

Google brings the Advanced Protection Program to Nest devices

Contact tracers concerned police tracking protesters will hurt COVID-19 aid

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 137.  It is Monday June 1st 2020. I am your host Scott Gombar and Is Anonymous Still Relevant?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Releases Security Updates for Multiple Products

NSA Warns of Sandworm Backdoor Attacks on Mail Servers

New Mexico County Government Falls Victim to Ransomware

Amtrak resets user passwords after Guest Rewards data breach

Valak malware steals credentials from Microsoft Exchange servers

Anonymous Hackers Threaten To ‘Expose The Many Crimes’ Of Minneapolis Police

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 136.  It is Friday May 29th 2020. I am your host Scott Gombar and What Country Are the Majority of COVID-19 Phishing Attacks Coming From?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Phishing attack impersonates Amazon Web Services to steal user credentials

Majority of COVID phishing attacks coming from US IP addresses, report finds

NSA Releases Advisory on Sandworm Actors Exploiting an Exim Vulnerability

Cisco hacked by exploiting vulnerable SaltStack servers

200K sites with buggy WordPress plugin exposed to wipe attacks

Minted discloses data breach after 5M user records sold online

Microsoft IIS servers hacked by Blue Mockingbird to mine Monero

Mat-Su Surgical Associates Suffers Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 135.  It is Thursday May 28th 2020. I am your host Scott Gombar and Nearly 20% of Law Firms Show Signs of Compromise

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Releases Security Updates

Hackers Sell Data from 26 Million LiveJournal Users on Dark Web

Michigan State University hit by ransomware

Real estate app leaking thousands of user records and sensitive private messages

Ransomware's big jump: ransoms grew 14 times in one year

$100 million in bounties paid by HackerOne to ethical hackers

Nearly One Fifth of Law Firms Show Signs of Compromise

Washington D.C. Significantly Overhauls its Data Breach Notification Law

23% of leading banks had an exposed database with potential data leakage

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 134.  It is Wednesday May 27th 2020. I am your host Scott Gombar and Cybersecurity Help Needed

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

New Android Flaw Affecting Over 1 Billion Phones Let Attackers Hijack Apps

States plead for cybersecurity funds as hacking threat surges

Samsung develops new security chip for smartphones

New [F]Unicorn ransomware hits Italy via fake COVID-19 infection map

Russian cyberspies use Gmail to control updated ComRAT malware

Internet Giants unite to stop warrantless snooping on web histories

How to Stay HIPAA Compliant from Home

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 133.  It is Tuesday May 26th 2020. I am your host Scott Gombar and Even Cyber Attacks Take a Day Off

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

ThreatList: People Know Reusing Passwords Is Dumb, But Still Do It

70 Percent of Mobile, Desktop Apps Contain Open-Source Bugs

The DHS Prepares for Attacks Fueled by 5G Conspiracy Theories

Hacker extorts online shops, sells databases if ransom not paid

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 132.  It is Monday May 25th 2020. I am your host Scott Gombar and Thank You to Our Military Personnel Past & Present

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates

Microsoft Releases Security Update for Edge

NSO Group Impersonates Facebook Security Team to Spread Spyware — Report

Hackers release a new jailbreak that unlocks every iPhone

Microsoft: Beware this massive phishing campaign using malicious Excel macros to hack PCs

eBay port scans visitors' computers for remote access programs

Microsoft's PowerToys gets two new features on Windows 10

Online education site EduCBA discloses data breach after hack

Latest Windows 10 Updates Breaks Wireless LTE Connectivity

The ransomware that attacks you from inside a virtual machine

Geisinger Wyoming Valley Medical Center and District Medical Group Disclose Data Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 131.  It is Friday May 22nd 2020. I am your host Scott Gombar and The Award Goes to Cybersecurity

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Crooks Tap Google Firebase in Fresh Phishing Tactic

Cybersecurity makes World Economic Forum’s top 10 Covid-19 global fallout list

Hackers tried to use Sophos Firewall zero-day to deploy Ransomware

Hacker shares 40 million Wishbone user records for free

Office 365 phishing uses Supreme Court theme and working CAPTCHA

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 130.  It is Thursday May 21st 2020. I am your host Scott Gombar and 44% of HIPAA Breaches in April Were Through Email

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

A few software updates Brazil's Biggest Cosmetic Brand Natura Exposes Personal Details of Its Users

Ukrainian Police Arrest Hacker Who Tried Selling Billions of Stolen Records

Vigilante hackers target 'scammers' with ransomware, DDoS attacks

Snake ransomware leaks patient data from Fresenius Medical Care

Home Chef announces data breach after hacker sells 8M user records

April 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 129.  It is Wednesday May 20th 2020. I am your host Scott Gombar and Denial of Service, Ransomware and Financially Motivated Data Breaches Are This Years Winners

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Chrome 83 released with massive security and privacy upgrades

Bluetooth Bugs Allow Impersonation Attacks on Legions of Devices

British Airline EasyJet Suffers Data Breach Exposing 9 Million Customers' Data

European Parliament Hit With Huge Security Breach Compromising Hundreds of MEPs

BEC Scammers target unemployment and CARES Act claims

Verizon Data Breach Report: DoS Skyrockets, Espionage Dips

Mille Lacs Health System Phishing Attack Impacts 10,600 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 128.  It is Tuesday May 19th 2020. I am your host Scott Gombar and Things in Texas Are Always Bigger

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Likely Breach Shuts Down Arkansas Unemployment Program

Edison Mail iOS Bug Exposes Emails to Strangers

Security threats associated with shadow IT

REvil Ransomware found buyer for Trump data, now targeting Madonna

Google Chrome to tidy up tabs with Tab Groups Collapse feature

Fake U.S. Dept of Treasury emails spreads new Node.js malware

Ransomware attack impacts Texas Department of Transportation

FBI warns of ProLock ransomware decryptor not working properly

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 127.  It is Monday May 18th 2020. I am your host Scott Gombar and What Do They Have On Trump?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Paying Ransomware Crooks Doubles Clean-up Costs, Report

Criminal group that hacked law firm threatens to release Trump documents

European supercomputers hacked in mysterious cyberattacks

WordPress malware finds WooCommerce sites for Magecart attacks

Critical WordPress plugin bug allows for automated takeovers

Wannabe ransomware operators arrested before hospital attacks

Management and Network Services Notifies 30,132 Patients About PHI Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 126.  It is Friday May 15th 2020. I am your host Scott Gombar and Let the Contact Tracing Games Begin

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Improper Microsoft Patch for Reverse RDP Attacks Leaves 3rd-Party RDP Clients Vulnerable

COVID-19 blamed for 238% surge in cyberattacks against banks

Hacker selling 550 million stolen user records on hacking forum

Scammers steal $10 million from Norway's state investment fund

New Microsoft 365 sign-in pages already spoofed for phishing

Woman stalked by sandwich server via her COVID-19 contact tracing info

Utah Says No to Apple/Google COVID-19 Tracing; Debuts Startup App

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 125.  It is Thursday May 14th 2020. I am your host Scott Gombar and Privacy vs. Health

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Leaked NHS Docs Reveal Roadmap, Concerns Around Contact-Tracing App

Pandemic has spawned 'record-breaking' cybercriminal activity: Report

Google WordPress plugin bug can be exploited for black hat SEO

RIP: Microsoft to drop support for Windows 10 on 32-bit systems

US warns of Chinese hackers targeting COVID-19 research orgs

Programming languages: Python apps might soon be running on Android

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 124.  It is Wednesday May 13th 2020. I am your host Scott Gombar and It’s the Post Patch Tuesday Episode.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Adobe Releases Security Updates

May 2020 Patch Tuesday: Microsoft fixes 111 vulnerabilities, 13 Critical

North Korean Malicious Cyber Activity

Ransomware Hit ATM Giant Diebold Nixdorf

US govt shares list of most exploited vulnerabilities since 2016

Healthcare giant Magellan Health hit by ransomware attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 123.  It is Tuesday May 12th 2020. I am your host Scott Gombar and There Were 400 Million Malware Infections in April

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Publishes Workarounds for Vulnerabilities in vRealize Operations Manager

Thunderbolt flaws affect millions of computers – even locking unattended devices won't help

Researchers detected 400 million malware infections in April 2020

Texas Courts hit by ransomware, network disabled to limit spread

WordPress plugin bugs can let hackers take over almost 1M sites

Maze ransomware fails to encrypt Pitney Bowes, steals files

FTC Seeks Comment on Breach Notification Rule for Health Data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 122.  It is Monday May 11th 2020. I am your host Scott Gombar and Data Breaches & Ransomware Galore

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Update on Cognizant

Black Hat USA, DEF CON 28 Go Virtual

Hackers Breach 3.5 Million MobiFriends Dating App Credentials

DigitalOcean Data Leak Incident Exposed Some of Its Customers Data

What one cybersecurity company has learned from responding to Maze ransomware

Hacker group floods dark web with data stolen from 11 companies

North Korean hackers infect real 2FA app to compromise Macs

Sodinokibi ransomware can now encrypt open and locked files

REvil ransomware threatens to leak A-list celebrities' legal docs

Email Breach Impacts 35,529 Patients of Saint Francis Healthcare Partners

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 121.  It is Friday May 8th 2020. I am your host Scott Gombar and If Maze is Involved It’s Not Over

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cisco Releases Security Updates for Multiple Products

An Update on Cognizant

Samsung patches 0-click vulnerability impacting all smartphones sold since 2014

This phishing campaign targets executives with fake emails from their phone provider

Half of Companies Have Suffered a Cybersecurity Issue Amid COVID-19 Crisis

Here’s how federal authorities are dealing with COVID-19 related online scams

Critical WordPress plugin bug lets hackers take over 1M sites

Microsoft Teams call drops on desktop caused by iOS bug

HHS Issues Security, Privacy Guidance for COVID-19 Issues

Healthcare Workers in Michigan and Illinois Fired for HIPAA Violations

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 120.  It is Thursday May 7th 2020. I am your host Scott Gombar and Yes You Have to Prepare for Tornadoes Too

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyberattack on NTPC Further Exposes the Cybersecurity Risks of Energy Sector

Instacart Patches Security Bug That Would Have Let Attackers Spoof SMS Messages

Google Releases Security Updates for Chrome 

SAP announces security issues in cloud-based products

Critical Citrix ShareFile bugs could give access to private files

Hackers use website favicon to camouflage credit card skimmer

Phishing Attack at BJC HealthCare Impacts Patients at 19 Hospitals

Patients Notified Medical Records Exposed at Tornado Hit Secure Medical Record Facility

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 119.  It is Wednesday May 6th 2020. I am your host Scott Gombar and Be Ready for More COVID-19 Scams

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Nearly 2,000 malicious COVID-19-themed domains created every day

US financial industry regulator warns of widespread phishing campaign

Massive campaign targets 900,000 WordPress sites in a week

Microsoft releases May Office updates with fixes for auth issues

Microsoft launches IoT-focused bounty program with $100K awards

Firefox 76 released with integrated data breach alerts

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 118.  It is Tuesday May 5th 2020. I am your host Scott Gombar and What’s Consumer Trust Like After a Ransomware Attack

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Consumers will opt for competitors after a single ransomware-related service disruption

Data Security Flaw Exposes Details Of Thousands Of Legal Documents

GoDaddy notifies users of breached hosting accounts

LockBit ransomware self-spreads to quickly encrypt 225 systems

Hackers exploit Salt RCE bugs in widespread attacks, PoCs public

Office 365 to stop data theft by disabling external forwarding

Ciitizen HIPAA Right of Access Study Shows Significant Improvement in Compliance

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 117.  It is Monday, May 4th 2020. I am your host Scott Gombar and May the Fourth Be With You

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883

SaltStack Patches Critical Vulnerabilities in Salt

Hackers breach company’s MDM server to spread Android malware

Trump Declares National Emergency As Foreign Hackers Threaten U.S. Power Grid

Microsoft Teams Impersonation Attacks Flood Inboxes

TrickBot Attack Exploits COVID-19 Fears with DocuSign-Themed Ploy

Targeted Phishing Attacks Successfully Hacked Top Executives At 150+ Companies

Protecting Patient's Data - A Major Concern During the COVID-19 Pandemic

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 116.  It is Friday May 1st 2020. I am your host Scott Gombar and It’s Been a Rough Week for WordPress

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

WordPress Releases Security Update

Critical WordPress e-Learning Plugin Bugs Open Door to Cheating

Ninja Forms WordPress plugin patch prevents takeover of 1M sites

New Android Malware Targets PayPal, CapitalOne App Users

Chegg Confirmed Data Breach of Employee Records

Average Ransomware Payments Soared in the First Quarter

Clop ransomware leaks ExecuPharm's files after failed ransom

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 115.  It is Thursday April 30th 2020. I am your host Scott Gombar and Yes Parking Meters Can be Hit With Ransomware Too

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

VMware Releases Security Updates for ESXi

High-Severity Cisco IOS XE Flaw Threatens SD-WAN Routers

Millions of Brute-Force Attacks Hit Remote Desktop Accounts

Google Confirms New Security Threat For 2 Billion Chrome Users

Smart Parking Meter Company Hit by Sodinokibi

US govt updates Microsoft Office 365 security best practices

Ransomware Attackers Claim Three More Healthcare Victims

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 114.  It is Wednesday April 29th 2020. I am your host Scott Gombar and A Warning from Microsoft re: Pirated Movies

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Critical Security Patches Released for Magento, Adobe Illustrator and Bridge

A few updates are available.  Samba, Google Chrome and Juniper

Hackers are creating backdoor accounts and cookie files on WordPress sites running OneTone

Biopharmaceutical Firm Suffers Ransomware Attack, Data Dump

Microsoft warns of malware surprise pushed via pirated movies

233,000 Patients Notified About PHI Breach at Genetic Testing Lab

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 113.  It is Tuesday April 28th 2020. I am your host Scott Gombar and Let’s Talk About Mistakes That Lead to Ransomware

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

U.S. Universities Hit With ‘Adult Dating’ Spear-Phishing Attack

Insider Threats Jump 47 Percent, as Incident Costs Reach $11.45 Million, New Study Shows

WordPress plugin bug lets hackers create rogue admin accounts

Twitter kills SMS-based tweeting in most countries

Microsoft Teams patched against image-based account takeover

5 common mistakes that lead to ransomware

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 112.  It is Monday April 27th 2020. I am your host Scott Gombar and Ransomware is Down but All Attacks are Up

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Nintendo Confirms Breach of 160,000 Accounts

Latest Apple Text-Bomb Crashes iPhones via Message Notifications

Hackers are exploiting a Sophos firewall zero-day

Contact tracing apps unsafe if Bluetooth vulnerabilities not fixed

Ransomware attacks against key sectors fall amidst coronavirus outbreak

Researchers: 30,000% increase in pandemic-related threats

March 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 111.  It is Friday April 24th 2020. I am your host Scott Gombar and No Security Training For A Year Will Lead to Epic Failures

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Skype Phishing Attack Targets Remote Workers’ Passwords

Hackers Trick 3 British Private Equity Firms Into Sending Them $1.3 Million

Most Remote Workers Have Received No Security Training for a Year

Online leak undermines Torrance’s claim that no personal data was affected by cyberattack

Windows 10 KB4549951 update fails to install, causes BSODs

HHS Delays Enforcement of New Interoperability and Information Sharing Rules

HHS’ Office of Inspector General Proposes Rule for Civil Monetary Penalties for Information Blocking

cybersecurity #cybersecurityawareness #cybersecuritynews #cybersecurityexpert #cybersecuritytraining #cybersecuritytips #cybersecurityleader #techtip #techie #techy #meridenct #newhavenct #ProactiveIT #NwajTech

TechTuesdayTip #MSP #ManagedServicesProvider #IT #HealthcareIT #LawFirmIT #HIPAA #HICP #MSSP #techtuesday

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 110.  It is Thursday April 23rd 2020. I am your host Scott Gombar and Data Breaches, Updates and Google..oh my.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

More Updates

Apple Patches Two iOS Zero-Days Abused for Years

Connected Home Hubs Open Houses to Full Remote Takeover

Nearly 25,000 email addresses and passwords allegedly from NIH, WHO, Gates Foundation and others are dumped online

US #COVID19 Relief Fund Leaks Data on Thousands of Firms

Google wants to make it easier to analyse health data in the cloud

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 109.  It is Wednesday April 22nd 2020. I am your host Scott Gombar and Fitbit to Track COVID-19?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

NFL Tackles Cybersecurity Concerns Ahead of 2020 Draft Day

Researcher Discloses 4 Zero-Day Bugs in IBM's Enterprise Security Software

Detroit hospital network says data breach affected more than 100,000 patient accounts

Hacker returns $25 million after their IP address is exposed

Work-from-Home Exposes Already-Infected Machines in 50K US Organizations

DoppelPaymer Ransomware hits Los Angeles County city, leaks files

New Orleans Hit With Ransomware Again

Scripps, Stanford working with Fibit to assess wearables' COVID-19 tracking abilities

PHI of 41,000 Patients Exposed in Aurora Medical Center and UPMC Altoona Phishing Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 108.  It is Tuesday April 21st 2020. I am your host Scott Gombar and You Didn’t Really Think It Would Work, Did You?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

German government might have lost tens of millions of euros in COVID-19 phishing attack

Hackers selling 267 million Facebook records on hacker forum

FBI says that sharing personal info online only helps scammers

Students, university clash over forced installation of remote exam monitoring software on home PCs

Beaumont Health Notifies 112,000 Patients About May 2019 Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 107.  It is Monday April 20th 2020. I am your host Scott Gombar and It’s an AMAZEing Monday

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

CISA Warns Patched Pulse Secure VPNs Could Still Expose Organizations to Hackers

GitHub users being hit with credential stealing phishing messages

Apple Releases Security Update for Xcode

US govt: Hacker used stolen AD credentials to ransom hospitals

Leading accounting firm MNP hit with cyberattack

Microsoft: Trickbot in hundreds of unique COVID-19 lures per week

IT services giant Cognizant suffers Maze Ransomware cyber attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 106.  It is Friday April 17th 2020. I am your host Scott Gombar and No Zoom News is Good Zoom News

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

‘Double Extortion’ Ransomware Attacks Spike

Streaming TV Fraudsters Steal Millions of Ad Dollars in ‘ICEBUCKET’ Attack

Malware found on 45 percent of home office networks

Hospital Computer System Not Fully Restored After Attack

Linksys forces password reset for Smart Wi-Fi accounts after router DNS hack pointed users at COVID-19 malware

Gmail blocked 18M COVID-19-themed phishing emails in a week

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 105.  It is Thursday April 16th 2020. I am your host Scott Gombar and How to Determine What Companies to Work With After COVID-19

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

PPE, COVID-19 Medical Supplies Targeted by BEC Scams

U.S. Offers Rewards up to $5 Million for Information on North Korean Hackers

49 New Google Chrome Extensions Caught Hijacking Cryptocurrency Wallets

EA Sports down – Gaming giant hit by massive DDoS attacks

Bad Actors Infiltrated New York’s State Government Computer Network

Cyber security researchers uncover hidden backdoors and secret commands in 12,000 Android apps

Exploit for Zoom Windows zero-day being sold for $500,000

Free tools and services for businesses during the COVID-19 crisis

Washington University School of Medicine Breach Impacts 14,795 Oncology Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 104.  It is Wednesday April 15th 2020. I am your host Scott Gombar and Thank You Jackie Robinson

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Yesterday was Patch Tuesday

Microsoft April 2020 Patch Tuesday fixes 3 zero-days, 15 critical flaws

Intel April Platform Update fixes high severity security issues

Cyberattacks Target Healthcare Orgs on Coronavirus Frontlines

Ransomware attacks lock 2 Manitoba law firms out of computer systems

Exclusive: Personal data of 1.41m US doctors sold on hacker forum

TikTok users beware: Hackers could swap your videos with their own

PHI of 16,600 Patients Potentially Compromised in Ransomware Attack on Andrews Braces

Phishing Attacks Reported by Hartford Healthcare and Saint Francis Ministries

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 103.  It is Tuesday April 14th 2020. I am your host Scott Gombar and The Economy is Booming

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Oracle Tackles a Massive 405 Bugs for Its April Quarterly Patch Update

Cybercrime May Be the World's Third-Largest Economy by 2021

US consumers report $12M in COVID-19 scam losses since January

Over 500,000 Zoom accounts sold on hacker forums, the dark web

Court Rules McHenry County Health Department Must Disclose COVID-19 Patients’ Names to 911 Dispatchers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 102.  It is Monday April 13th 2020. I am your host Scott Gombar and That Was a Long Month

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

\Compromised Zoom Credentials Swapped in Underground Forums

Apple, Google Team on Coronavirus Tracking – Sparking Privacy Fears

New IRS Site Could Make it Easy for Thieves to Intercept Some Stimulus Payments

SFO Hit by Web Compromise

Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw

Gambling company to set aside $30 million to deal with cyber-attack fallout

New Wiper Malware impersonates security researchers as prank

HIPAA Penalties Waived for Good Faith Operation of COVID-19 Community-Based Testing Sites

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 101.  It is Friday April 10th 2020. I am your host Scott Gombar and the Price is Right

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit

Cisco ‘Critical Update’ Phishing Attack Steals Webex Credentials

Large email extortion campaign underway, DON'T PANIC!

Over 3.6M users installed iOS fleeceware from Apple’s App Store

Phishing emails impersonate the White House and VP Mike Pence

Travelex Reportedly Paid $2.3 Million Ransom to Restore Operations

Visa urges merchants to migrate e-commerce sites to Magento 2.x

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 100.  It is Thursday April 9th 2020. I am your host Scott Gombar and We’ve Reached the Century Mark

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

‘Fake Fingerprints’ Bypass Scanners with 3D Printing

PowerPoint ‘Weakness’ Opens Door to Malicious Mouse-Over Attack

ThreatList: Skype-Themed Apps Hide a Raft of Malware

Microsoft releases April 2020 Office updates with crash fixes

Dark Nexus: A New Emerging IoT Botnet Malware Spotted in the Wild

PHI Exposed in Phishing Attacks on Healthcare Resource Group and Confido

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 99.  It is Wednesday April 8th 2020. I am your host Scott Gombar and It Happens More Than You Think

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Atlassian issues advice on how to keep your IT service desk secure... after hundreds of portals found facing the internet amid virus lockdown

Microsoft and Google postpone insecure authentication removal

Chrome 81 Released With 32 Security Fixes and Web NFC API

Firefox 75 released with Windows 10 performance improvements

NASA under 'significantly increasing' hacking, phishing attacks

Drug testing firm sends data breach alerts after ransomware attack

Two schoolkids sue Google for collecting biometrics

Thousands of Android apps contain undocumented backdoors, study finds

Hackers’ forum hacked, OGUsers database dumped (again)

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 98.  It is Tuesday April 7th 2020. I am your host Scott Gombar and It Doesn’t Matter What Day It Is.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Government VPN Servers Targeted in Zero-Day Attack

PayPal and Venmo Are Letting SIM Swappers Hijack Accounts

80% of all exposed Exchange servers still unpatched for critical flaw

FBI warns again of BEC scammers exploiting cloud email services

PSA: Fake Zoom installers being used to distribute malware

Interpol: Ransomware attacks on hospitals are increasing

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 97.  It is Monday April 6th 2020. I am your host Scott Gombar and Keep Zoom-Bombing & See What Happens

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Mobility Reports Show Impact of Lockdown

Microsoft: How one Emotet infection took out this organization's entire network

Firefox Zero-Day Flaws Exploited in the Wild Get Patched

How Just Visiting A Site Could Have Hacked Your iPhone or MacBook Camera

DOJ Says Zoom-Bombing is Illegal, Could Lead to Jail Time

Windows PCs Exposed to Attacks by Critical HP Support Assistant Bugs

12 Easy Ways to Secure Your Zoom Meetings

35,800 Patients of The Otis R. Bowen Center for Human Services Notified About Email Security Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 96.  It is Friday April 3rd 2020. I am your host Scott Gombar and 3 Weeks and Counting

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig

Magecart Hackers Inject iFrame Skimmers in 19 Sites to Steal Payment Data

FBI Releases Guidance on Defending Against VTC Hijacking and Zoom-bombing

Zoom blog on recent cybersecurity measures

WordPress Plugin Bug Can Be Exploited to Create Rogue Admins

IRS Warns of Surge in Economic Stimulus Payment Scams

FBI Warns of Attacks on Remote Work, Distance Learning Platforms

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 95.  It is Thursday April 2nd 2020. I am your host Scott Gombar and It’s Tough Being King

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Releases Security Updates for Chrome

Cybersecurity Lawyer Who Flagged The WHO Hack Warns Of 'Massive' Remote Work Risks

‘Secure’ Backup Company Leaks 135 Million Records Online

FCC will require phone carriers to authenticate calls by June 2021

Two Zoom Zero-Day Flaws Uncovered

Top Email Protections Fail in Latest COVID-19 Phishing Campaign

Hacker Group Backdoors Thousands of Microsoft SQL Servers Daily

Microsoft is Alerting Hospitals Vulnerable to Ransomware Attacks

Ransomware Attacks Reported by Stockdale Radiology and Affordacare Urgent Care Clinics

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 94.  It is Wednesday April 1st 2020. I am your host Scott Gombar and I’m No April Fool

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

COVID 19 – The New IT Reality

COVID-19 Fraud Alert from the HHS Office of the Inspector General

Millions of Guests Impacted in Marriott Data Breach, Again

Critical WordPress Plugin Bug Lets Hackers Turn Users Into Admins

Vulnerabilities Expose Lexus, Toyota Cars to Hacker Attacks

Keep Your Zoom Meetings Safe

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 93.  It is Tuesday March 31st 2020. I am your host Scott Gombar and Zoom, Zoom, Zoom

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

It’s World Backup Day!

Zoom Kills iOS App’s Data-Sharing Facebook Feature

COVID-19: Hackers Begin Exploiting Zoom's Overnight Success to Spread Malware

Windows 10 KB4554364 Update Fixes Internet Connectivity Issues

FBI Warns of Ongoing Zoom-Bombing Attacks on Video Meetings

Banking Malware Spreading via COVID-19 Relief Payment Phishing

How to stay on top of coronavirus scams – and all the others too

Apple’s iOS 13.4 hit by VPN bypass vulnerability

5 tips for keeping your data safe this World Backup Day

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 92.  It is Monday March 30th 2020. I am your host Scott Gombar and Be Careful of Bears Baring Gifts

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Phishing Attack Says You're Exposed to Coronavirus, Spreads Malware

FTC Warns VoIP Providers to Stop Facilitating Coronavirus Scams

US Small Business Administration Grants Used as Phishing Bait

FBI: Hackers Sending Malicious USB Drives & Teddy Bears via USPS

New Coronavirus Scam Urges Users to Trade in Bitcoin and Earn Millions

Thousands Targeted Through Fake Google Updates That Hackers Pushed Via Compromised WordPress Sites

A mysterious hacker group is eavesdropping on corporate email and FTP traffic

OCR Issues Bulletin on Civil Rights Laws and HIPAA Flexibilities That Apply During the COVID-19 Emergency

California Business Associate Reports Potential Breach of Upwards of 70,000 Records

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 91.  It is Friday March 27th 2020. I am your host Scott Gombar and Life Without Baseball Sucks. 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Emerging APT Mounts Mass iPhone Surveillance Campaign

Your Social Security Number Costs $4 On The Dark Web, New Report Finds

Apple iOS users served mobile malware in Poisoned News campaign

Three-Quarters of Large Firms Suffered Security Breach Last Year

Google Warned Users of 40,000 State-Sponsored Attacks in 2019

Ryuk Ransomware Keeps Targeting Hospitals During the Pandemic

New Windows 10 Bug Causes Internet Connectivity Issues, Fix in April

Chubb Cyber Insurer Allegedly Hit By Maze Ransomware Attack

Watch out! Scummy scammers target home deliveries

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 90.  It is Thursday March 26th 2020. I am your host Scott Gombar and Is that Deja vu? 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Releases Security Updates

Chinese Hackers Exploit Cisco, Citrix Flaws in Massive Espionage Campaign

GE Employees Lit Up with Sensitive Doc Breach

TrickBot Mobile App Bypasses 2‐Factor Authentication for Net Banking Services

Cincinnati Firm Faces $5m Data Breach Lawsuit

Hackers Are Taking Over Twitter Accounts to Advertise Face Masks

WordPress Malware Distributed via Pirated Coronavirus Plugins

Malware Disguised as Google Updates Pushed via Hacked News Sites

Microsoft Fixes Windows Defender Scan Bug With New Update

Hawaii Pacific Health Discovers 5-Year Insider Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 89.  It is Wednesday March 25th 2020. I am your host Scott Gombar and It Used to be All So Simple.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Technical Details on KrØØk WiFi Vulnerability Exploit Released

COVID-19 Cyberattacks Roundup From the Past Week

Critical RCE Bug Affects Millions of OpenWrt-based Network Devices

WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike

Critical Adobe Flaw Fixed in Out-of-Band Security Update

Vulnerability Exposed Tesla Central Touchscreen to DoS Attacks

Facebook Messenger may ban mass-forwarding of messages

Three More Ransomware Families Create Sites to Leak Stolen Data

HPE Warns of New Bug That Kills SSD Drives After 40,000 Hours

TeamViewer Stops Commercial Use Checks in Coronavirus-Affected Regions

Windows Defender Fix For Windows 10: Enable Network Scanning

February 2020 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 88.  It is Tuesday March 24th 2020. I am your host Scott Gombar and You May as Well Sit Back & Enjoy the Ride.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Google Just Confirmed A Powerful Chrome COVID-19 Security Move That Will Impact All Users

COVID-19 Vaccine Test Center Hit By Cyber Attack, Stolen Data Posted Online

Microsoft Warns of Hackers Exploiting Unpatched Windows Bugs

Fake Corona Antivirus Software Used to Install Backdoor Malware

Tech Giant GE Discloses Data Breach After Service Provider Hack

Hackers Hijack Routers’ DNS to Spread Malicious COVID-19 Apps

Fake Coronavirus ‘Vaccine’ Website Busted in DoJ Takedown

Pysa Operators Join ‘Big-Game Hunting’ by Releasing New Version of Ransomware

CEO Claims More Fake LinkedIn Users Are Claiming to be Employees

New York's SHIELD Act could change companies’ security practices nationwide

HHS.gov Open Redirect Used by Coronavirus Phishing to Spread Malware

Phishing Attacks Reported by University of Utah Health, Oregon DHS, and LifeSprk

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 87.  It is Monday March 23rd 2020. I am your host Scott Gombar and Let’s Go Around the World in 15 Minutes.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Trolls ZoomBomb work-from-home videocall with filth

All-in-one CrazyCoin Worm Leverages EternalBlue Exploit Kit to Spread Across Target Systems

Hackers breach FSB contractor and leak details about IoT hacking project

UK Fintech Firm Finastra Hit By Ransomware, Shuts Down Servers

German army’s sensitive data found on laptop bought from eBay

Israel Govt's New 'Shield' App Tracks Your Coronavirus Exposure

Windows Defender Bug in Windows 10 Skips Files During Scans

Netwalker Ransomware Infecting Users via Coronavirus Phishing

YouTube and Amazon Also Lowering Video Quality in Europe

FBI Warning: Phishing Emails Push Fake Govt Stimulus Checks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 86.  It is Friday March 20th 2020. I am your host Scott Gombar and It’s Flashback Friday

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Healthcare devices at higher cybersecurity risk now due to coronavirus

Critical RCE Bug in Windows 7 and Server 2008 Gets Micropatch

WHO Chief Impersonated in Phishing to Deliver HawkEye Malware

Sodinokibi Ransomware Data Leaks Now Sold on Hacker Forums

Netflix Reduces Video Quality in Europe by 25% to Lower Load

Microsoft Delays Windows 10 1709 End of Service Due to Pandemic

Netflix Party Lets You Watch Shows With Friends to Fight Isolation

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 85.  It is Thursday March 19th 2020. I am your host Scott Gombar and Is That a Conscience I See?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Researchers Uncover a Nigerian Hacker's Pursuit of his Million Dollar Dream

TrickBot Now Exploits Infected PCs to Launch RDP Brute Force Attacks

Hackers Created Thousands of Coronavirus (COVID-19) Related Sites As Bait

Hackers hit government websites

Most Ransomware Gets Executed Three Days After Initial Breach

Ransomware Gangs to Stop Attacking Health Orgs During Pandemic

Trickbot, Emotet Malware Use Coronavirus News to Evade Detection

Cloud Database Leak Exposes 425GB of Small Biz Financial Data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 84.  It is Wednesday March 18th 2020. I am your host Scott Gombar and No News is Good News?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

President relaxes HIPAA penalties

MonitorMinor: The Most Wicked Stalkerware?

Adobe Fixes Nine Critical Vulnerabilities in Reader, Acrobat

37% Health Orgs Shirk Mobile Security for Efficiency, Increasing Risk

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 83.  It is Tuesday March 17th 2020. I am your host Scott Gombar and I Promise There’s Less Than 10 People Here.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Cyberattack on HHS meant to slow coronavirus response, sources say

The attack happened Sunday night, sources said.

Confessions app Whisper spills almost a billion records

Windows 10 KB4551762 Security Update Fails to Install, Causes Issues

FBI Warns of Human Traffickers Luring Victims on Social Networks

VMware Releases Security Updates for Multiple Products

Convincing Google Impersonation Opens Door to MiTM, Phishing

Researchers expose vulnerabilities of password managers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 82.  It is Monday March 16th 2020. I am your host Scott Gombar. Toilet Paper Anyone?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Researchers Discover New PXJ Ransomware Strain

Exploring Various Ways in Which Hackers Are Milking the COVID-19 Scare

Hackers find new target as Americans work from home during outbreak

Browser vendor leaks data via open server

Litigation Case Claims Violation of CCPA Under Statutory Private Right of Action

BlackWater, a malware that uses Cloudflare Workers for C2 Communication

COVID-19 Testing Center Hit By Cyberattack

US Govt Shares Tips on Securing VPNs Used by Remote Workers

Slack Bug Allowed Automating Account Takeover Attacks

The EARN IT Bill Is the Government’s Plan to Scan Every Message Online

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 81.  It is Friday March 13th 2020. I am your host Scott Gombar and Life Changes Rapidly

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

HACKERS ARE USING CORONAVIRUS MAPS TO SPREAD MALWARE

Microsoft Releases Out-of-Band Security Updates for SMB RCE Vulnerability

Phishing Attack Skirts Detection With YouTube

WordPress Plugin Bug Allows Malicious Code Injection on 100K Sites

New CoronaVirus Ransomware Acts as Cover for Kpot Infostealer

Advanced Russian Hackers Use New Malware in Watering Hole Operation

Hackers Get $1.6 Million for Card Data from Breached Online Shops

Office 365 ATP To Block Email Domains That Fail Authentication

Data of millions of eBay and Amazon shoppers exposed

Analytics firm’s VPN and ad-blocking apps are secretly grabbing user data

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 80.  It is Thursday March 12th 2020. I am your host Scott Gombar and Say Whaaaat?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Covid-19 (Coronavirus) Phishing Attacks

Intel Patches High Severity Flaws in Windows Graphics Drivers

Bugs in Avast AntiTrack expose users to cyber attacks

SECURITY ALERT: New LinkedIn OneDrive Phishing Campaign Detected by Heimdal™ Security

Microsoft Releases the March 2020 Security Updates for Office

No HIPAA breaches for the 2nd consecutive day.

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 79.  It is Tuesday March 10th 2020. I am your host Scott Gombar and Google’s Watching, Amazon is Researching

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

https://www.us-cert.gov/ncas/current-activity

Firefox Bug Opens iPhone AirPods to Third-Party Snooping

Microsoft Hijacks Necurs Botnet that Infected 9 Million PCs Worldwide

New Variant of TrickBot Being Spread by Word Document

Microsoft March 2020 Patch Tuesday Fixes 115 Vulnerabilities

Microsoft Leaks Info on Wormable Windows SMBv3 CVE-2020-0796 Flaw

Entercom Radio Giant Says Data Breach Exposed User Credentials

Google data puts innocent man at the scene of a crime

Meet Project Gesundheit: Amazon’s secret project to cure the common cold

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 78.  It is Tuesday March 10th 2020. I am your host Scott Gombar and Just Reboot.  That Fixes Everything

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

HHS finalizes interoperability rules: 7 things to know

AMD Downplays CPU Threat Opening Chips to Data Leak Attacks

Microsoft Exchange Server Flaw Exploited in APT Attacks

CISA Warns Against COVID-19 Cyber Scams and Provides Security Tips

Fake Tech Support Company Dupes 40K Victims Out of $8m

Intricate Phishing Scam Uses Support Chatbot to ‘Assist’ Victims

99% of compromised Microsoft enterprise accounts lack MFA

One billion Android smartphones racking up security flaws

University of Kentucky and UK HealthCare Impacted by Month-Long Cryptominer Attack

53% of Healthcare Organizations Have Experienced a PHI Breach in the Past 12 Months

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 77.  It is Monday March 9th 2020. I am your host Scott Gombar and It’s Your Lucky Day.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Virgin Media Data Leak Exposes Details of 900,000 Customers

This Unpatchable Flaw Affects All Intel CPUs Released in Last 5 Years

More than 600 Microsoft Subdomains Pose Threat to Users

Zoho Releases Security Update on ManageEngine Desktop Central

Ryuk Ransomware Behind Durham, North Carolina Cyberattack

New US Bill Aims to Protect Researchers who Disclose Govt Backdoors

Ransomware Threatens to Reveal Company's 'Dirty' Secrets

Relation Insurance and Rainbow Hospice Care Experience Email Security Breaches

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 76.  It is Friday, March 6th 2020. I am your host Scott Gombar and Where Do I Start?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Critical Netgear Bug Impacts Flagship Nighthawk Router

Let’s Encrypt Pushes Back Deadline to Revoke Some TLS Certificates

High-Severity Cisco Webex Flaws Fixed

Hackers Compromise T-Mobile Employee' Email Accounts and Steal User' Data

A Massive U.S. Property and Demographic Database Exposes 200 Million Records

Cisco Releases Security Updates

Point-to-Point Protocol Daemon Vulnerability

Google Releases Security Updates for Chrome

Microsoft Releases March 2020 Office Updates With Fixes, Improvements

Ryuk Ransomware Attacked Epiq Global Via TrickBot Infection

Carnival Cruise Line Operator Discloses Potential Data Breach

J.Crew Disables User Accounts After Credential Stuffing Attack

Ransomware Attackers Use Your Cloud Backups Against You

6 Healthcare Organizations Discover PHI Has Potentially Been Compromised

HHS’ Office for Civil Rights Announces First HIPAA Penalty of 2020

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 75.  It is Thursdayday, February 27th 2020. I am your host Scott Gombar and Just Another Day in the Hood.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Six suspected drug dealers went free after police lost evidence in ransomware attack

Smart speakers mistakenly eavesdrop up to 19 times a day

Iranian APT Targets Govs With New Malware

Stalkerware Attacks Increased 50 Percent Last Year, Report

Unpatched Security Flaws Open Connected Vacuum to Takeover

New Wi-Fi Encryption Vulnerability Affects Over A Billion Devices

Sodinokibi Ransomware May Tip NASDAQ on Attacks to Hurt Stock Prices

Hackers Scanning for Vulnerable Microsoft Exchange Servers, Patch Now!

18 Sniffers Steal Payment Card Data from Print Store Customers

Medical Records of 156,400 Personal Touch Home Care Patients Compromised in Ransomware Attack on EHR Hosting Company

Data Breaches Reported by Rady Children’s Hospital, Aveanna Healthcare and Endeavor Energy Resources

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 74.  It is Wednesday, February 26th 2020. I am your host Scott Gombar and You Just Never Know.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

DoppelPaymer Ransomware Launches Site to Post Victim's Data

Multiple WordPress Plugin Vulnerabilities Actively Being Attacked

Firefox enables DNS-over-HTTPS by default (with Cloudflare) for all U.S. users

OpenSMTPD Releases Version 6.6.4p1 to Address a Critical Vulnerability

Microsoft Wants to do Away with Windows 10 Local Accounts

Credit Card Skimmer Running on 13 Sites, Despite Notification

Maze Ransomware Attack on Accounting Firm Impacts Patients of New York Medical Group

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 73.  It is Tuesday, February 25th 2020. I am your host Scott Gombar and Poor PayPal

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple Takes Heat Over ‘Vulnerable’ iOS Cut-and-Paste Data

PayPal Users Hit With Fraudulent Target Charges via Google Pay

New Mozart Malware Gets Commands, Hides Traffic Using DNS

Malvertising in Govt, Enterprise Targets Old Software, Macs

Racoon Malware Steals Your Data From Nearly 60 Apps

Windows 10 Gets Temp Patch for Critical Flaw Fixed In Buggy Update

UW Medicine Faces Class Action Lawsuit Over 974,000-Record Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 72.  It is Monday, February 24th 2020. I am your host Scott Gombar and Is It Monday Yet?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

PayPal ‘Critical’ Login Hack: New Report Warns You Are Now At Risk From Thieves

Google Releases Security Updates for Chrome

Privacy Concerns Raised Over New Google Chrome Feature

New Jersey Hospital Network Faces Lawsuit Over Ransomware Attack

New ‘Haken’ Malware Found On Eight Apps In Google Play Store

Windows 10 Gets Temp Fix for Critical Security Vulnerability

Slickwraps Data Breach Exposes Financial and Customer Info

New Mexico Sues Google for Mining Children's Data

NRC Health Recovering from Ransomware Attack

Communication Errors Result in Impermissible Disclosure of 5,300 Patients’ PHI

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 71.  It is Friday, February 21st 2020. I am your host Scott Gombar and WhatsApp With That?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

DOD DISA discloses data breach

Cisco Releases Security Updates

Adobe Releases Security Updates for After Effects and Media Encoder

WhatsApp Phishing URLs Skyrocket With Over 13,000% Surge

PHI of 109,000 Patients Potentially Compromised in Washington Phishing Attack

2020 Protenus Breach Barometer Report Reveals 49% Increase in Healthcare Hacking Incidents

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 70.  It is Thursday, February 20th 2020. I am your host Scott Gombar and It’s Not a Coincidence

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Details of 10.6 million MGM hotel guests posted on a hacking forum

Hackers can trick a Tesla into accelerating by 50 miles per hour

BlueKeep Flaw Plagues Outdated Connected Medical Devices

Cybercrooks Conceal Stolen Credit Card Data On Barcodes To Make Fraudulent Purchases

US Senator Proposes New Data Protection Bill

VMware Releases Security Updates for vRealize Operations for Horizon Adapter

Microsoft Rolls Out New Windows 10 Optional Update Experience

Zero-Day in WordPress Plugin Exploited to Create Admin Accounts

MyEyeDr. Patients Notified of Ransomware Attack and Improper Disposal Incident

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 69.  It is Wednesday, February 19th 2020. I am your host Scott Gombar and It’s Not Just Computer Based Viruses.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Apple says the coronavirus will cause it to miss its revenue goals

IBM: Average data breach costs U.S. companies $8.19M

U.S Man Arrested for laundering $300 Million By Running Darknet-based Cryptocurrency laundering Service

Hacker Scheme Threatens AdSense Customers with Account Suspension

Lenovo, HP, Dell Peripherals Face Unpatched Firmware Bugs

WHO Warns of Phishing Scams Related to Coronavirus Alert

US Govt Warns of Ransomware Attacks on Pipeline Operations

Ring Forces 2FA On All Users to Secure Cameras from Hackers

Firefox 73.0.1 Released With Fixes for Linux, Windows Crashes

Windows, Linux Devices at Risk Due to Unsigned Peripheral Firmware

Wise Health System Notifies 66,934 Patients of Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 68.  It is Tuesday, February 18th 2020. I am your host Scott Gombar and I’ve Got (Almost) Nothing

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Critical Bug in WordPress Theme Plugin Opens 200,000 Sites to Hackers

A Dozen Vulnerabilities Affect Millions of Bluetooth LE Powered Devices

Microsoft Surface Laptop 3 Screens Are Spontaneously Cracking

Google pulls 500 malicious Chrome extensions after researcher tip-off

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 67.  It is Monday, February 17th 2020. I am your host Scott Gombar and You Say It’s Your Birthday!

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world

Apple iPhone Users Targeted with Bogus Dating App for Valentine’s Day

Hackers Can Seize Control of Ballots Cast Using the Voatz Voting App, Researchers Say

SMS Phishing Campaign Targets Mobile Bank App Users in North America

North Korean Malicious Cyber Activity

Be Cautious of Romance Scams

Targeted Phishing Attack Aims For Well-Known Corporate Brands

Microsoft Confirms Windows 10 KB4524244 Issues and Pulls the Update

Plastic Surgery Patient Photos, Info Exposed by Leaky Database

Malware Attack Disables Servers at Physician Network Affiliated with Boston Children’s Hospital

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 66.  It is Friday, February 14th 2020. I am your host Scott Gombar and Robots in Disguise?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Hacking group publishes 'full dump' of law firm's data; another responds to cybersecurity incident

Puerto Rico Gov Hit By $2.6M Phishing Scam

Privacy Experts Skeptical of Proposed Data Protection Agency

Palm Beach County Potentially Suffered Ransomware Attack Just Before 2016 Presidential Election

U.S. Store Chain Rutter’s Hit by Credit Card Stealing Malware

Windows 10 KB4532693 Update Bug Hides User Data, Loads Wrong Profile

2019 Healthcare Data Breach Report

A 2-in-1 transformer drone? Coming to a battlefield near you

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 65.  It is Thursday, February 13th 2020. I am your host Scott Gombar and Numbers Don’t Lie

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com  BEC Scams Accounted For $1.7 Billion, Half Of Total Cybercrime Losses In 2019: FBI Report.  FBI: $3.5B Lost in 2019 to Known Cyberscams, Ransomware

Ransomware Attacks Have Cost US Healthcare Organizations Over $157 Million Since 2016

Operational Technology Attacks Increased By Over 2000% In 2019, Reveals IBM Report

Chinese tech giant Huawei can reportedly access the networks it helped build that are being used by mobile phones around the world. It's been using backdoors intended for law enforcement for over a decade, The Wall Street Journal reported Tuesday, citing US officials. The details were disclosed to the UK and Germany at the end of 2019 after the US had noticed access since 2009 across 4G equipment, according to the report.

Three Cybersecurity Bills Blocked by Senate Majority Again

SoundCloud Tackles DoS, Account Takeover Issues

New SchoolSafety.gov Provides Cyber Guidance for K-12 Schools

WordPress Cookie Consent Plugin Fixes Critical Flaw for 700K Users

Microsoft Urges Exchange Admins to Disable SMBv1 to Block Malware

Office 365 Users Get Automated Protection From Malicious Docs

Hospital Sisters Health System Email Breach Impacts 16,167 Patients

Sunshine Behavioral Health Group Discovers PHI Exposed Over Internet

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 64.  It is Wednesday, February 12th 2020. I am your host Scott Gombar and It’s the Aftermath

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Multiple Vendor Updates

Adobe Addresses Critical Flash, Framemaker Flaws

Update Microsoft Windows Systems to Patch 99 New Security Flaws

Sensitive Data On 36,000 Jail Inmates Leaked

FBI Warns About Ongoing Attacks Against ICS Sector Companies

Total Number of Breached Records Increased by 284% to Cross 15 Billion in 2019

Amex, Chase Fraud Protection Emails Used as Clever Phishing Lure

Google Removes Dashlane Password Manager from Chrome Web Store

Three more HIPAA Breaches to Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 63.  It is Tuesday, February 11th 2020. I am your host Scott Gombar and It’s Safer Internet Day!

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Safer Internet Day

Altice (Cablevision) suffered a data breach in November 2019 through phishing.  It was determined in January that one of the accounts compromised included a report that was password protected.  That report included names, employment information, social security numbers, date of birth and in some instances drivers license numbers.  They did not state how many people were included in that breach but numerous ex-employees were sent notification.

Android Users Targeted in Two Newly Discovered Malware Campaigns

Dell SupportAssist Bug Exposes Business, Home PCs to Attacks

Ragnar Locker Ransomware Targets MSP Enterprise Support Tools

Windows Server 2008 Servers Don’t Boot After KB4539602 Update

U.S. Charges Chinese Military Hackers for Equifax Breach

FBI director warns of sustained Russian disinformation threat

FBI: MSP Engineer Arrested In Attempt To Sell Access To Clients

Slew of Email Security Breaches Reported by Healthcare Organizations

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 62.  It is Monday, February 10th 2020. I am your host Scott Gombar and Evolution is Inevitable

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Frustration grows in China as face masks compromise facial recognition

Apple fined for slowing down old iPhones

North Miami Beach Affected By Cyber Attack

Don’t Fall For The PayPal SMS Scam That Steals Your Personal Details

Google Chrome To Bar HTTP File Downloads

Magecart Gang Attacks Olympic Ticket Reseller and Survival Food Sites

Emotet Hacks Nearby Wi-Fi Networks to Spread to New Victims

Windows 7 Users Suddenly Can't Shut Down Their PCs, How to Fix

Lock My PC Used By Tech Support Scammers, Dev Offers Free Recovery

Health Share of Oregon Notifies 654,000 Members About Business Associate Data Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 61.  It is Friday, February 7th 2020. I am your host Scott Gombar and Does Anyone Have $15?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

DoJ Asks Victims of the Quantum DDoS Service to Come Forward

Ransomware Exploits GIGABYTE Driver to Kill AV Processes

BEC Scammers’ Interest in the Real Estate Sector Rises

Critical Android Bluetooth Flaw Exploitable without User Interaction

Cisco Releases Security Updates for Multiple Products

U.S. Finance Sector Hit with Targeted Backdoor Campaign

The $15 terabyte hard drive is coming

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 60.  It is Thursday, February 6th 2020. I am your host Scott Gombar and I am Not Gonna Say It Again...Who Am I Kidding

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Do not open emails purporting to have Coronavirus updates, alerts, warnings or vaccines.  Delete them and/or report them as phishing because that’s what they are. If you want to stay up to date on the latest Coronavirus news follow the CDC, HHS and other related government agencies on Twitter

Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

New Lemon Duck Malware Campaign Targets IoT, Large Manufacturers

Ransomware Attack Hinders Toll Group Operations

These Highly Exploited Vulnerabilities Indicate Organizations are Still Failing to Apply Patches

GDPR Officials Probe Tinder For Potential Privacy Infringement

Bug in Philips Smart Light Allows Hopping to Devices on the Network

Charming Kitten Hackers Impersonate Journalist in Phishing Attacks

Mailto (NetWalker) Ransomware Targets Enterprise Networks

Windows 10 Search Is Broken and Shows Blank Results, How to Fix

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 59.  It is Wednesday, Feb 5th 2020. I am your host Scott Gombar and the floodgates have opened. 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Chrome 80 Released With 56 Security Fixes, Cookie Changes, More  80.0.3987.87

NIST Releases Draft Guidelines To Curb The Ransomware Epidemic

NIST tests methods of recovering data from smashed smartphones

Twitter hands over student’s account to his college

Google Bug Sent Private Google Photos Videos to Other Users

WhatsApp Bug Allowed Attackers to Access the Local File System

FBI Warns of DDoS Attack on State Voter Registration Site

Emotet Gets Ready for Tax Season With Malicious W-9 Forms

IRS Launches “Identity Theft Central” Webpage

Report: Only Three Out of Top 100 Airports Pass Cybersecurity Checks

New York Nursing Center and Phoenix Children’s Hospital Affected by Phishing Attacks

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 58.  It is Tuesday, Feb 4th 2020. I am your host Scott Gombar and Now For This Mornings Traffic

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

New EmoCheck Tool Checks if You're Infected With Emotet

Iranian Hackers Target U.S. Gov. Vendor With Malware

Sudo Bug Lets Non-Privileged Linux and macOS Users Run Commands as Root

Attackers Exploit Security Flaws in Smart Building Systems

OpenSMTPD Vulnerability

DoD to Require Cybersecurity Certification From Defense Contractors

DoppelPaymer Ransomware Sells Victims' Data on Darknet if Not Paid

'Hack' Creates Fake Google Maps Traffic Jams With 99 Cell Phones

Data Breaches Reported by Manchester Ophthalmology, UnitedHealthcare, and Cook County Health

Malware Attack Results in Corruption of Medical Records: 30,000 Patients Affected

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 57.  It is Monday, Feb 3rd 2020. I am your host Scott Gombar and You’re Not in Kansas Anymore, Toto

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Congrats to the Kansas City Chiefs on their win in Super Bowl 54.

Phishing Scams using the Coronavirus Outbreak as the subject have been spotted around the world including in the US.  

Adobe Releases Security Updates for Magento

Sodinokibi Ransomware Group Sponsors Hacking Contest

Russia Threatens Facebook, Twitter With Fines, Demands User Data

UN hacked via unpatched SharePoint server

Louisiana Criticizes MSP Industry’s Security Practices; Employs MSSP

Ashley Madison Hack Returns To ‘Haunt’ Its Victims: 32 Million Users Now Watch And Wait

Ransomware infects City of Racine computer systems

Ransomware Attacks Hit Three Law Firms in Last 24 Hours

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 56.  It is Friday, January 31st, 2020. I am your host Scott Gombar and We’re Making Up For Yesterday

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Facebook to Pay $550M to Settle Class Action Case Over Facial Recognition

Dell, HP Memory-Access Bugs Open Attacker Path to Kernel Privileges

Google Sets Record High in Bug-Bounty Payouts

Cisco Releases Security Updates for Cisco Small Business Switches

UN Offices in Geneva and Vienna Suffered Major Hacking Attack Last Year, Says New Research

Trello exposed! Search turns up huge trove of private data

NEC Defense Contracts Info Potentially Compromised in Breach

Microsoft Detects New Evil Corp Malware Attacks After Short Break

Severe ‘Perfect 10.0’ Microsoft Flaw Confirmed: ‘This Is A Cloud Security Nightmare’

Website Error Exposed Personal and Health Data of LabCorp Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 55.  It is Thursday, January 30th, 2020. I am your host Scott Gombar and Thursday is the New Friday, Allegedly.  

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Intel to Soon Roll-out Fixes for CacheOut Bugs

Tax Identity Theft Awareness Week

Malware Tries to Trump Security Software With POTUS Impeachment

Google Chrome Tests Replacing URLs With Search Queries in Address Bar

200K WordPress Sites Exposed to Takeover Attacks by Plugin Bug

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 54.  It is Wednesday, January 29th, 2020. I am your host Scott Gombar and Oh the Irony

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Wawa Breach May Have Compromised More Than 30 Million Payment Cards

Zoom Bug Could Have Let Uninvited People Join Private Meetings

NSA Releases Guidelines to Improve Cloud Security

New Report Shows Employees at Large Organization Send Over 130 Emails Every Week to the Wrong Person

Apple Releases Multiple Security Updates

FBI Warns of Rise in Social Security Scams Spoofing Its Phone Number

Magento 2.3.4 Fixes Critical Code Execution Vulnerabilities

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 53.  It is Tuesday, January 28th, 2020. I am your host Scott Gombar and Today is World Data Privacy Day

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

World Data Privacy Day: Learn To Manage And Safeguard Your Personal Data

N.Y. Could Ban Cities from Paying Ransomware Attackers

Windows 7 To Get Post End of Life Update to Fix Wallpaper Bug

Hackers hijack social media accounts for the NFL and 15 teams

Iowa Department of Human Services Notifies 4,784 Patients About Improper Disposal Incident

Beaumont Health Discovers 20-Month Insider Breach

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 52.  It is Monday January 27th, 2020. I am your host Scott Gombar and I Can’t Even Imagine 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

SolarWinds RMM Tool Has Open Zero-Day Exploit: Huntress Labs

Average Cost To Recover From Ransomware Skyrockets To Over $84,000

Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings - Cisco has released patches for this vulnerability

10% of All Macs Shlayered, Malware Cocktail Served

U.S. Govt Agency Hit with New CARROTBALL Malware Dropper

Nearly 200,000 Patients Impacted by PIH Health Phishing Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 51.  It is Friday January 24th, 2020. I am your host Scott Gombar and Nothing to See Here Folks.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Boardman business sues IT provider over $1.7M hacking theft

Cisco Warns of Critical Network Security Tool Flaw

Buchbinder Car Renter Exposes Info of Over 3 Million Customers

TrickBot Now Steals Windows Active Directory Credentials

Critical MDhex Vulnerabilities Shake the Healthcare Sector

Euro Cup and Olympics Ticket Reseller Hit by MageCart

Maze Ransomware Not Getting Paid, Leaks Data Left and Right

Sodinokibi Ransomware Threatens to Publish Data of Automotive Group

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 50.  It is Thursday January 23rd, 2020. I am your host Scott Gombar and We’ve Reached the Big 5 Oh

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com 

Increased Emotet Malware Activity

Thousands of WordPress Sites Hacked to Fuel Scam Campaign

Citrix Releases Scanner to Detect Hacked Citrix ADC Appliances

Twitter Releases Updated Android App to Fix Crashes

A timeline of events surrounding the Bezos phone hack

Microsoft Leaves 250M Customer Service Records Open to the Web

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 49.  It is Wednesday, Jan 22, 2020. I am your host Scott Gombar and 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Today is the last day to put in a claim if you were a victim of the Equifax breach in 2017.

The State of Maryland to Criminalize Ransomware Possession

Cybercriminals are Selling Access to Company Networks to Make Quick Money

FBI Warns Job Applicants of Scams Using Spoofed Company Sites

Phishing Incident at UPS Store Chain Exposes Customer Info

BitPyLock Ransomware Now Threatens to Publish Stolen Data

600 Computers Taken Down After Florida Library Cyberattack

December 2019 Healthcare Data Breach Report

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 48.  It is Tuesday January 21, 2020. I am your host Scott Gombar and Growth is a Good Thing, Right?

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Juice Jacking On the Rise

Cyberattacks against North Dakota state government skyrocket to 15M per month

Emotet Malware Dabbles in Extortion With New Spam Template

FTCode Ransomware Now Steals Saved Login Credentials

Mitsubishi Electric Warns of Data Leak After Security Breach

US Retailer Hanna Andersson Hacked to Steal Credit Cards

Facebook and Instagram ban alleged ‘brainwashing’ service

Phishing Attack Reported by Adventist Health Sonora

Hacker leaks passwords for more than 500,000 servers, routers, and IoT devices

LastPass is in the midst of a major outage

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 47.  It is Monday January 20, 2020. I am your host Scott Gombar and The Time Is Always Right to do What is Right

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

New US Bill Wants to Assign State Cybersecurity Coordinators

Feds Cut Off Access to Billions of Breached Records with Site Takedown

https://www.us-cert.gov/ncas/current-activity

New Jersey Synagogue Suffers Sodinokibi Ransomware Attack

FBI Says State Actors Hacked US Govt Network With Pulse VPN Flaw

Hackers Are Securing Citrix Servers, Backdoor Them for Access Citrix Patches CVE-2019-19781 Flaw in Citrix ADC 11.1 and 12.0

Fraudsters Set Up Site Selling Temporary Social Security Numbers

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 46.  It is Friday, January 17, 2020. I am your host Scott Gombar and TGIF Unless You’re Patching

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Cybercriminals Leverage Microsoft Sway in a Phishing Attack

Google Chrome Adds Protection for NSA's Windows CryptoAPI Flaw

TrickBot Now Uses a Windows 10 UAC Bypass to Evade Detection

Phishing Attack on SouthEast Eye Specialist Group Impacts 13,000 Patients

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 45.  It is Thursday, January 16, 2020. I am your host Scott Gombar and Google Cares About Your Privacy..No Really.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Equifax Settles Class-Action Breach Lawsuit for $380.5M

Google Chrome Aims to Make Browser User-Agents Obsolete

Google Plans to Nix Third-party Tracking Cookies

Online Pharmacy PlanetDrugsDirect Discloses Security Breach

Enloe Medical Center Continues to Experience EMR Downtime Due to Ransomware Attack

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 44.  It is Wednesday, January 15, 2020. I am your host Scott Gombar and Let Me Update You

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Lots of Critical Updates to Address. 

NSA's First Public Vulnerability Disclosure: An Effort to Build Trust

Microsoft's January 2020 Patch Tuesday Fixes 49 Vulnerabilities

United Nations Targeted With Emotet Malware Phishing Attack

Ryuk Ransomware Uses Wake-on-Lan To Encrypt Offline Devices

Critical WordPress Plugin Bug Allows Admin Logins Without Password

Apple Denies FBI Request to Unlock Shooter’s iPhone—Again

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 43.  It is Tuesday, January 14, 2020. I am your host Scott Gombar and It’s the End of an Era

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

It’s patch Tuesday but this patch Tuesday is special.  Today marks the end of support from Microsoft for Windows 7 and Windows Server 2008 R2. They are offering extended support plans but it’s probably a good idea to update to Windows 10 and Server 2016/19 if you have not yet.  

Scammers Dupe Texas School District Out of $2.3M

CISA Releases Test for Citrix ADC and Gateway Vulnerability

BEC Scammers Use Aging Report Phishing to Find New Targets

More Than 100 Law Firms Have Reported Data Breaches. And the Problem Is Getting Worse

Sodinokibi Ransomware Attack Hits Albany NY but the way it got in might be surprising

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 42.  It is Monday, January 13, 2020. I am your host Scott Gombar and Don’t Say We Didn’t Warn You.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

New York Phishing Attack: Nassau County Recovers $710,000

UPDATE: PoC Exploits Released for Citrix ADC and Gateway RCE Vulnerability

Sodinokibi Ransomware Publishes Stolen Data for the First Time

Maze Ransomware Publishes 14GB of Stolen Southwire Files

Sodinokibi Ransomware Hits New York Airport Systems

US Govt Warns of Attacks on Unpatched Pulse VPN Servers

Beware of Amazon Prime Support Scams in Google Search Ads

Hundreds of millions of cable modems are vulnerable to new Cable Haunt vulnerability

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 41.  It is Friday January 10, 2020. I am your host Scott Gombar and We Return You to Your Regularly Scheduled Programming.  

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Drake Lyrics Used as Calling Card in Malware Attack

Exploit Fully Breaks SHA-1, Lowers the Attack Bar

Liverpool Voyeur Used IM-RAT to Video Women at Home

Juniper Networks Releases Security Updates

Cisco Releases Security Updates for Multiple Products

TrickBot Gang Created a Custom Post-Exploitation Framework

Travelex Update

New Iranian data wiper malware hits Bapco, Bahrain's national oil company

Google Removed Over 1.7K Joker Malware Infected Apps from Play Store

https://www.hipaajournal.com/up-to-25k-patients-of-the-native-american-rehabilitation-association-of-the-northwest-affected-by-malware-attack/

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 40.  It is Thursday January 9, 2020. I am your host Scott Gombar and What Happens in Vegas is Happening Everywhere.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

City of Las Vegas wakes up to a cyber attack

Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy

50 Percent of Websites Using WebAssembly Show Malicious Behavior: Report

Update: Attackers Are Scanning for Vulnerable Citrix Servers, Secure Now

TikTok Flaws Allowed Hackers to Delete Videos, Steal User Info

SNAKE Ransomware Is the Next Threat Targeting Business Networks

From CES 2020:  CES 2020: Ford wants this two-legged robot to deliver packages to your door

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 39.  It is Wednesday Jan 8, 2020. I am your host Scott Gombar and Just When You Thought We’d Go a Week WIthout a HIPAA Breach

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Facebook  has begun cracking down on DeepFake Videos. They will remove videos that are uploaded in an attempt to deceive but will not remove videos determined to be satirical.  

If videos have been edited or synthesized in ways that aren’t obvious to an average person and intend to mislead people into thinking that a subject of the video said words that they did not actually say.

If videos are the product of artificial intelligence or machine learning that merges, replaces or superimposes content onto a video, making it appear to be authentic.

Google has removed several apps with zero day exploits or critical vulnerabilities from the Google Play Store.  They include Camero, FileCrypt, CallCam and Pulse Secure VPN App

Cisco Releases Security Updates

Microsoft Phishing Scam Exploits Iran Cyberattack Scare

Firefox 72 Out With Fingerprinter Blocking, Hidden Notification Prompts

Medical Info of Roughly 50K Exposed in Minnesota Hospital Breach

Hospital Employee Pleads Guilty to Five-Year Account Hacking Spree

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 38.  It is Tuesday Jan 7, 2020. I am your host Scott Gombar and These Are Not The Updates You Are Looking For.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

A Note to Dentists:  While Researching Practices in my area I have discovered several dentists websites are compromised.  

Continued Warnings re: Tensions Between US and Iran from CISA US Government Says Iran Can Disrupt Critical Infrastructure

Update to Travelex Ransomware Attack: Sodinokibi Ransomware Hits Travelex, Demands $3 Million

IT Executive Steals $6 Million, Busted by Word Doc Metadata

Update to Infotrax Data Breach: InfoTrax Gets Slap on The Wrist After Being Breached 20+ Times

Fake Windows 10 Desktop Used in New Police Browser Lock Scam

CES 2020: Amazon's Alexa will help you pay for gas at Exxon or Mobil stations

Lots of new 2 in 1 Laptops at CES 2020 including a Lenovo foldable targeted at the mobile workforce ($2500)

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 37.  It is Monday Jan 6, 2020. I am your host Scott Gombar. Even Your Bathroom Can Go High Tech

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

A Note:  IT and Businesses should be extra vigilant.  Cyber Attacks are a very real threat with the escalating situation between Iran and the US.  There has already been one reported website take down. There’s bound to be more. It might be a good time for an audit to ensure your systems are protected and your backups are secure.

In 2019 Municipalities, Schools and Healthcare Providers were huge Ransomware targets.  That looks to continue in 2020.    

https://www.us-cert.gov/ncas/current-activity/2020/01/04/dhs-releases-ntas-bulletin

Ransomware attack hits City of Ingleside

FBI Warns of Maze Ransomware Focusing on U.S. Companies

Colorado Town Wires Over $1 Million to BEC Scammers

Richmond, MI School District Shuts Down after Ransomware Attack

Charmin at CES 2020: RollBot, SmellSense and V.I.Pee as innovation meets absurd

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 36.  It is Friday Jan 3, 2020. I am your host Scott Gombar. Tik Tok Tik Tok 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

CCPA went into effect on Jan 1.  California Consumer Protection Act

Maze Ransomware Sued for Publishing Victim's Stolen Data

Landry's Restaurant Chain Suffers Payment Card Theft Via PoS Malware

Python 2.7 Reaches End of Life After 20 Years of Development

TikTok Banned By U.S. Army Over China Security Concerns

Xiaomi Cameras Connected to Google Nest Expose Video Feeds From Others

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 35.  It is Thursday Jan 2, 2020. I am your host Scott Gombar. This is 2020

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Secure New Internet-Connected Devices

2020 Cybersecurity Trends to Watch

Sextortion Email Scammers Try New Tactics to Bypass Spam Filters

Ransomware Stats for 2019 as reported by Emsisoft

In 2019, the U.S. was hit by a record number of ransomware attacks that impacted at least 948 government agencies, educational institutions and healthcare facilities at a cost of more than $7.5 billion by a conservative estimate. The impacted organizations included:

103 federal, state and municipal governments and agencies.

759 healthcare providers.

86 universities, colleges and school districts, with operations at up to 1,224 individual schools potentially affected.

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 34.  It is Tuesday December 31, 2019. I am your host Scott Gombar. Happy New Year!!

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Cloud Hopper cyberattacks, launched by APT10 vs. MSPs and CSPs worldwide, were larger than previously disclosed, a new report says

The Curious Case of 20 Unsecured Buckets Containing Nearly 48 Million Records

Special Olympics New York Hacked to Send Phishing Emails

https://www.hipaajournal.com/category/hipaa-breach-news/

Ambulance Company Pays $65,000 to Settle Allegations of Longstanding HIPAA Noncompliance

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 33.  It is Monday December 30, 2019. I am your host Scott Gombar and Let’s Get Local for a Minute. 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Connecticut Receives $5 Million for Election Cybersecurity

U.S. Coast Guard Says Ryuk Ransomware Took Down Maritime Facility

Wyze Exposes User Data via Unsecured ElasticSearch Cluster

Microsoft Outlook for the Web to Support Sending Email As Alias

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 32.  It is Friday December 27, 2019. I am your host Scott Gombar and All is Still Quiet. 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

A Twitter app flaw used to match 17 million phone numbers to user accounts

Ryuk Ransomware Stops Encrypting Linux Folders

New Magellan 2.0 SQLite Vulnerabilities Affect Many Programs

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 31.  It is Thursday December 26, 2019. I am your host Scott Gombar and Almost All is Quiet. 

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Maze Ransomware Releases Files Stolen from City of Pensacola

Chinese hacker group caught bypassing 2FA

New Mexico Hospital Discovers Malware on Imaging Server

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 30.  It is Tuesday December 24, 2019. I am your host Scott Gombar. Merry Christmas All

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

If you haven’t updated Google Chrome to the latest version yet..do it.  

Citrix vulnerability jeopardizes over 80,000 companies globally

Twitter Fixes Bug that Enabled Takeover of Android App Accounts

A flaw in the Twitter for Android App has been patched.  The vulnerability allows would be attackers to take control of Twitter accounts and send tweets and dms.  If you use Twitter on Android please update immediately.

A note from the FBI re: LockerGoga and MegaCortex

"Since January 2019, LockerGoga ransomware has targeted large corporations and organizations in the United States, United Kingdom, France, Norway, and the Netherlands. The MegaCortex ransomware, first identified in May 2019, exhibits Indicators of Compromise (IOCs), command and control (C2) infrastructure, and targeting similar to LockerGoga."

Have a BCDR plan.  Backup regularly. Test Backups and Keep a backup offline

Ensure all software and operating systems are up to date

Enable 2FA and have a strong password policy

Disable RDP wherever it is not needed.  Ensure RDP ports are blocked externally.  Use RDP over VPN. Use third party software to further secure RDP

Audit the creation of new accounts.

Run port scans to ensure unneeded ports are closed and nothing is listening that shouldn’t be listening..

Disable SMBv1 

Monitor AD for access levels, account changes and new accounts

Make sure you are using the most up-to-date PowerShell and uninstall any older versions.

"Enable PowerShell logging and monitor for unusual commands, especially execution of Base64 encoded PowerShell"

New Mozi P2P Botnet Takes Over Netgear, D-Link, Huawei Routers

Colorado Department of Human Services and Sinai Health System Alert Patients About HIPAA Breaches

Holiday Tip -  If you’re giving anyone a gaming console for holidays unpack it, set it up and install all the updates and then pack it up.  Update servers are hit pretty hard on Christmas day. Doing this allows the gift recipient to enjoy the gift rather than wait for updates.

Merry Christmas All.  We will talk again Thursday.  Stay Secure.

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 29.  It is Monday December 23, 2019. I am your host Scott Gombar and Say Hello Old Friend.

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Apple’s Bug Bounty Opens for Business, $1M Payout Included.

Apple has officially opened its invite only private bug-bounty program to the public.  You can earn bounties of up to $1 million.

To earn the $1 million bounty you will need to provide a working zero-click exploit with full kernel execution and persistence on Apple’s latest devices.  Other requirements will also need to be met.  

There are other bounties between $25,000 and $500,000 vulnerabilities in Macs, iOS devices, and Apple TV ranging in compromises of lock screen bypass, icloud account access and other attacks.

One Day, Three Credit Card Data Breach Notifications.  You have probably heard about the Wawa Compromise.  If you haven’t here are the details.

Dropbox Zero-Day Vulnerability Gets Temporary Fix.  There is currently a zero-day vulnerability for Dropbox on Windows that allows attackers to gain permissions typically reserved for SYSTEM.  This is the most privileged account on Windows.  

Dropbox has not released a patch for this zero-day vulnerability but OPatch has released a temporary fix.  

Cisco Security Appliances Targeted for DoS Attacks via Old Bug.

PayPal Phishing Attack Promises to Secure Accounts, Steals Everything.

Windows Remote Desktop Services Used for Fileless Malware Attacks.

View Details

Good Morning and Welcome to the ProactiveIT Cyber Security Daily number 28.  It is Friday December 20, 2019. I am your host Scott Gombar and May the Force Be WIth You

This podcast is brought to you by Nwaj Tech, a Client Focused and Security Minded IT Consultant based in Central Connecticut.  You can visit us at nwajtech.com

Star Wars sites purporting to have pirated versions of the Rise of Skywalker are popping up.  The goal of these phishing sites is to install malware. Avoid these sites unless you want to risk a malicious attack.

Other Rise of Skywalker phishing sites are stealing credit/debit care info.

CISA has advised that there is a Drupal update available to address a critical flaw.  Update Drupal to 7.69, 8.7.11, or 8.8.1 to prevent remote hackers from compromising web servers.

If you’re using 301 Redirects – Easy Redirect Manager you'll want to update it immediately to address a critical vulnerability.  The vulnerability allows any authenticated user including subscribers to modify, delete or create a redirect rule that could potentially take a site down.  The latest versions is 2.45.  

Google Offers Financial Support to Open Source Projects for Cybersecurity

K-12 Cybersecurity Act Introduced to Protect Schools from Ransomware

New Dudell Malware Hides Behind Microsoft Excel Documents

Emotet Malware Uses Greta Thunberg Demonstration Invites as Lure

CMS Blue Button 2.0 Coding Bug Exposed PHI of 10,000 Medicare Beneficiaries

https://www.buzzfeednews.com/article/carolinehaskins1/data-leak-exposes-personal-data-over-3000-ring-camera-users?fbclid=IwAR2HFBEjq98XyEGUTF99rLiKSVYJ4Makl1bcLDtdHEPiVJVaoc6cYo5zAqA

267 million - mostly American - Facebook users' IDs, names and phone numbers are exposed online and shared on the dark web

A database exposing the names, phone numbers and Facebook user IDs of millions of platform users was left unsecured on the web for nearly two weeks before it was removed.

Security researcher Bob Diachenko, who along with Comparitech discovered the unsecured Elasticsearch database, believe it belongs to a cybercriminal organization, as opposed to Facebook. Diachenko went to the internet service provider (ISP) managing the IP address of the server so that the access could be removed.

“A database this big is likely to be used for phishing and spam, particularly via SMS,” according to the Thursday report. “Facebook users should be on the lookout for suspicious text messages. Even if the sender knows your name or some basic information about you, be skeptical of any unsolicited messages.”

https://www.theverge.com/2019/12/19/21030114/robocalls-bill-congress-president-trump-sign-law-illegal-fcc-ajit-pai

View Details

Google Releases Security Updates for Chrome for Windows, Mac, and Linux

Google has released security updates for Chrome version 79.0.3945.88 for Windows, Mac, and Linux. This version addresses a vulnerability that an attacker could exploit to take control of an affected system.

Microsoft Issues Out-of-Band Update for SharePoint Bug

The out-of-band patch addresses the important-severity vulnerability by changing how affected APIs process requests. Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Foundation 2010 SP2 and 2013 SP1 and Microsoft SharePoint Server 2019 are impacted; 

LifeLabs Pays Hackers Who Accessed 15M Customers’ Lab Test Results

Google (GSuite) will soon block Less Secure Apps, switch to OAuth for authentication’

After 15 June 2020, users who try to connect the Google accounts to an LSA for the first time won’t be allowed to, but those who have already connected to LSAs before that date will still be permitted.

That grace period won’t last forever, though. After 15 February 2021, access to LSAs will cease for all G Suite accounts, even those that were already using them.

Honda Exposes 26,000 Records of North American Customers.

Microsoft Security Essentials To Get Updates After Windows 7 EoS. Siemens Contractor Jailed for Sabotage With Logic Bombs.

Canadian Insurance Firm Hit By Maze Ransomware, Denies Data Theft

View Details

Update on Hackensack Meridian Ransomware Attack - A ransom was paid to decrypt the files but no word on how much.

Alexa, Google Home Eavesdropping Hack Not Yet Fixed

Flaw in Slack Allows Workspace Members to Access Files in Private Channels

The 25  Most Common Passwords Found From Breaches in 2019

Intel Rapid Storage Technology vulnerability exists in older versions.  Update available

Bug Sent WhatsApp Into Crash Loop, Caused Chat History Loss

Lazarus Hackers Target Linux, Windows With New Dacls Malware

Ransomware Hit Over 1,000 U.S. Schools in 2019

Truman Medical Centers Notifies 114,466 Patients of Potential PHI Exposure

New Blog Post - Dental Practices & HIPAA, Is It Necessary?

View Details

Tech Tuesday Tip - with ease of use comes risk. New Crytojacking campaign avoids detection through process hollowing. TP-Link Archer router vulnerable to attack. 435,000 Security certs can be compromised with less than $3000. High School students find soy cams in their hotel rooms. Police get geofence info from Google for suspected arsonists. Hackensack Meridian Health in NJ recovering from Ransomware attack. New blog post on NwajTech.com "Ring Cameras Hacked but who is to blame"

View Details

WordPress Update available (5.3.1). Critical Remote Code Execution threaten power plants in the US, Germany and Russia. HIPAA breaches for Right of Access and Improper Disposal. Attackers did not hack Ring Cameras, stop using weak passwords and New Orleans declares state of emergency after Ransomware attack.

View Details

It's a Friday the 13th reference, get it? Holiday Cyber Attacks expected to increase by 20%. NGINX co-founders arrested. Microsoft warms of Gallium Threat on Telcos worldwide. Maze ransomware demands $6 million from Southwire and another Ransomware will now publish victims data if not paid.

View Details

Update on the Pensacola FL Ransomware Attack. 460,000 payment cards sold on the black market. New vulnerability impacting Intel processors dubbed 'plundervolt'. iOS patches Vulnerability in AirDrop. Zeppelin Ransomware attacks targeting healthcare in Europe, Canada and US. Phishing attacks reported at Sunrise Community Health and Katherine Shaw Bethea Hospital and another Florida Ransomware attack reported, this time at PRIDE.

View Details

Updates to Google Chrome, Adobe and Microsoft Windows. Banner Health settles for $6,000,000. Another Amazon Storage account left open to the public exposing thousands of birth certificate applications.

View Details

An update on the Louisiana OMV and other state offices Ransomware attack. NJ Hospital hit with undisclosed technology disruption. Another AWS S3 Bucket left open n leading to massive document leaks for Dunkin Donuts, GE And Forever 21. Pensacola FL hit with a Cyber Attack. Snatch Ransomware reboots Windows computers into safe mode to disable anti-malware and Trickbot continues to evolve and add attack vectors.

View Details

A busy weekend for Cyber News. AT&T, Verizon and TMobile bills left exposed on unsecured AWS S3 Bucket. Facebook pays $4 million for compromised ads accounts. VMWare releases patches for vulnerabilities in ESXi and Horizon DaaS. A clever Microsoft Phishing scam. A fake (free) VPN pushes information stealing Trojans. Nvidia patches severe flaw in Mercedes Infotainment system, Nintendo Switch and Some Chromebooks. Another class action b lawsuit filed against TikTok. Mac uses targeted again with fileless trojan. And the big news....110 dental practices hit n with Ransomware because their MSP wasn't using MFA.

View Details

An update on the CYRUSOne Data Center Ransomware attack. New Linux Vulnerability let's attackers hijack VPN Sessions. New PCI Security standards for contactless payments. Microsoft releases security advisory for Microsoft Hello for Business. Hackerone pays $20,000 bounty for but found on their own site and rogue employee accessed ePHI they weren't supposed to access in Nebraska

View Details

Zerocleare being used by Iran to wipe devices targeting the energy sector in the middle East. "Ultimate" MiTM attack steals $1 million from Israeli startup. Dutch politician facing 3 years for hacking iCloud accounts and stealing/leaking nude photos. Healthcare threat detections are up 45% in Q3 2019.

View Details

Windows 7 EOL is coming in just over a month. What does that mean for you? Avast and AVG browser plugins spying on users? Smith+Wesson site hacked to steal customer payment info. FTC warns of scam spreading terrorism allegations. And an November HIPAA breach n round up... hint, don't store PHI in email.

View Details

Unprotected database exposes millions of text messages. New Chrome password stealer sends credentials to a MongoDB. Strandhogg vulnerability affects Android OS. Facebook and Amazon Ads manager targeted by new info stealing Trojan. CISA encourages collaboration with Vulnerability disclosures.

View Details

FBI warns of Smart TVs being vulnerable. Europol shuts down Imminent Monitor Rat. Magento Marketplace breached. Netflix account freeze phishing email and deactivated accounts reactivated. Scammers pose as CISA reps over the phone and Ransomware attack at Great Plains Health.

View Details

It's no coincidence that our 13th episode comes on Black Friday. We discussed Twitter MFA, Facebook outage, COPRA, Governments hacking Google Accounts, protecting your identity on Black Friday and tomorrow is national computer security day.

View Details

Android SDKs taking Twitter and Facebook user data and selling it. Windows 10 1909 update causing file explorer issues for some. HP Warns that some SSD drives will fail at exactly 32768 hours. List of impacted SSD drives:. VO0480JFDGT

VO0960JFDGU

VO1920JFDGV

VO3840JFDHA

MO0400JFFCF

MO0800JFFCH

MO1600JFFCK

MO3200JFFCL

VO000480JWDAR

VO000960JWDAT

VO001920JWDAU

VO003840JWDAV

VO007680JWCNK

VO015300JWCNL

VK000960JWSSQ

VK001920JWSSR

VK003840JWSST

VK003840JWSST

VK007680JWSSU

VO015300JWSSV

View Details

NYPD hit with Ransomware but respond quickly. NYC Restaurant Chain's POS's hacked exposing customer credit card numbers. Trickbot targeting OpenSSH and OpenVPN. Microsoft Windows 10 will not update if you're using an older version of Avast or AVG. And the October 2019 HIPAA round up.

View Details

Fairly quiet weekend but One Plus smartphone maker reports data breach, Open VNC Software has multiple vulnerabilities (for over 20 years), and a 110 Nursing Homes hit with Ransomware.

View Details

TMobile prepaid accounts breached. IRS Tax fraud awareness week is coming. Update Outlook on Android. HIPAA fines increase with inflation. Multiple HIPAA breaches reported this week.

View Details

Bitdefender reports ransomware attacks have continued to rise (in ransom amounts too). High Severity Windows UAC enables privilege escalation. Hackers Dump 2.2 million gaming and crytocurrency passwords online. 400 Vetenarians hit with Ransomware. Unprotected PACS servers lead to leak of 1.19 billion medical images.

View Details

Louisiana State Services hit by ransomware. Fake Windows Update Ransomware attacks. Google discloses Android's Google Camera has a Vulnerability. Fake McDonald's ads lead to banking trojan. Wordfence advises of high severity vulnerability in WP Maintenance plugin.

View Details

An update to the Penmex ransomware attack, WhatsApp mp4 exploit, Disney+ was NOT hacked, NextCry and our #TechTuesdayTip

View Details

Two School districts hit with ransomware attacks, Chinese Hacking competition leads to hacks of Google Chrome, Safari, D Link, Office365. 100,000 malicious websites posing as retailers and an active Phishing campaign targeting office365 admins.

View Details

Today's topics include impersonating the USPS, Checkm8 Vulnerability in iOS, Qualcomm vulnerabilities in Android, just how many records have been exposed so far this year and a misconfigured AWS S3 Bucket leads to 93 million healthcare records exposed.

View Details

Updates on the Pemex Ransomware attacks and Google Collecting PHI. MegaCortex Ransomware changes passwords, Purelocker Ransomware also targets Mac OSX and Linux, and IT Failures at Infotrax result in $1,000,000 fine.

View Details

Facebook Privacy Concerns again, Emotet Activity Increases, Mexican Oil Company hit with Ransomware $4.9 Million, and a local (Connecticut) physicians office breached.

View Details

The latest cyber security news. DDoS attack on Amazon and others. Intel, Magento and Adobe Vulnerabilities. Plus Patch Tuesday.