Aggregator
PowerSchool customers hit by downstream extortion threats
The large education tech vendor was hit by a cyberattack and paid a ransom in December. Now, a threat actor is attempting to extort the company’s customers with stolen data.
The post PowerSchool customers hit by downstream extortion threats appeared first on CyberScoop.
Ransomware Attack Update for the 7th of May 2025
Cyberattacks on Critical Infrastructures Makes Us Very Vulnerable
Many don’t realize that
cyberattacks against Critical Infrastructure sectors, can cause more than an inconvenience
of a temporary power outage.
Critical Infrastructures are a
favorite of aggressive Nation State cyber threats. In addition to communications disruptions,
power outages, and healthcare billing, these attacks can also seek to disrupt
food distribution.
The result – empty shelves and
people scrambling to acquire groceries.
There is currently a cyber-attack affecting
the main grocery retailer in Scotland, resulting in empty shelves for many foodstuffs.
Nothing is as effective at changing
people’s attitudes and motivating capitulation than the unavailability of
food. It is an age-old strategy used for
sieging forts, towns, and even nations.
Cybersecurity now protects many of
the critical path systems for food production, transportation, and distribution.
It puts a different spin on the
value of cybersecurity and how aggressive nations can wreak havoc on the
citizens of their adversary. It is
something to consider as we move into an age where cyber-attacks are being
leveraged as a foreign policy tool.
Cybersecurity is key and we must remain diligent to protect
our critical infrastructure sectors!
For more Cybersecurity Insights: https://www.cybersecurityinsights.us/
Follow me on Substack for updates: https://substack.com/@matthewrosenquist
or LinkedIn: https://www.linkedin.com/in/matthewrosenquist/
The post Cyberattacks on Critical Infrastructures Makes Us Very Vulnerable appeared first on Security Boulevard.
Pakistani Firm Shipped Fentanyl Analogs, Scams to US
CVE-2010-0720 | Systemsoftware Erotik Auktionshaus news.php ID sql injection (EDB-11489 / XFDB-56330)
CVE-2022-3246 | Blog2Social Social Media Auto Post & Scheduler Plugin up to 6.9.9 on WordPress sql injection
CVE-2022-3395 | WP All Export Pro Plugin up to 1.7.8 on WordPress POST Parameter cc_sql sql injection
CVE-2022-35132 | Usermin up to 1.850 GPG Module os command injection
CVE-2022-38870 | Free5gc 3.2.1 information disclosure (Issue 387)
CVE-2022-3097 | LBStopAttack Plugin up to 1.1.2 on WordPress Setting cross-site request forgery
CVE-2022-36451 | Mitel MiCollab up to 9.5.0.101 Client Server server-side request forgery
CVE-2022-35739 | PRTG Network Monitor up to 22.2.77.2204 Cascading Style Sheet cross site scripting
CVE-2021-42553 | STMicroelectronics stm32_mw_usb_host buffer overflow (Nessus ID 235069)
Agentic AI: the Start of a New Cybersecurity Career Path
At RSAC 2025, the message came through loud and clear: Agentic AI is no longer just a concept. It's being deployed today. While much of the buzz focused on performance gains and trust concerns, another story emerged - one that speaks directly to security professionals and those entering the field.
HHS to Build 'Secure' Data Platform for Autism Research
The U.S. Department of Health and Human Services said it will build a data platform "allowing researchers to 'securely'" access data from Medicare and Medicaid claims, patient electronic medical records and consumer wearables to better understand autism spectrum disorder causes and treatments.
Patient Monitor Manufacturer Is Still Recovering From Attack
A cyberattack against on-premises systems is affecting product manufacturing, fulfillment and distribution operations of Masimo, a manufacturer of patient monitoring devices, the California-based company told the U.S. Securities and Exchange Commission on Tuesday.
OX Security Raises $60M Series B to Combat Code Risk From AI
With code increasingly generated by AI and attackers using AI for exploits, OX Security raised $60 million to scale R&D and help developers prioritize critical vulnerabilities. The company aims to close detection gaps and reduce time-to-remediation in application security.
UK Government to Roll Out Passkeys Late This Year
The U.K. government is set to replace SMS-based verification systems for digital services with passkeys later this year in a bid to shore-up cyber defenses. The authentication initiative is being developed by the U.K. National Cybersecurity Center using FIDO standards.
Agentic AI: the Start of a New Cybersecurity Career Path
At RSAC 2025, the message came through loud and clear: Agentic AI is no longer just a concept. It's being deployed today. While much of the buzz focused on performance gains and trust concerns, another story emerged - one that speaks directly to security professionals and those entering the field.