Archive of

Vicksburg ransomware attack forces Mississippi city offline

The city of Vicksburg, Mississippi, has shut down its computer systems following a ransomware attack, Mayor Willis Thompson told residents on Thursday evening.

Thompson announced the incident in a statement published in the local newspaper. He said the city is investigating the attack and described the shutdown as "temporary." Emergency services have not been affected, but residents cannot currently pay their utility bills through the usual channels.

Vicksburg has more than 20,000 residents and lies about 40 minutes west of Jackson, the state capital.

No shut-offs or late fees during the investigation

To ease concerns about the payment disruption, the mayor said no one's services will be disconnected while the investigation continues. The city will also not issue penalties for late payments.

Read More


CloudSyncD macOS backdoor hides in fake Zoom installer

A newly documented macOS backdoor called CloudSyncD is reaching victims through a fake Zoom installer, according to researchers at Jamf. The malware gives attackers persistent, quiet access to infected Macs.

Jamf first came across CloudSyncD in mid-September, while it was still under development. Within a few days the researchers found more samples. These suggested the operators had finished testing and begun using the malware against real targets.

A disk image posing as Zoom

The attack depends on social engineering. Victims are persuaded or tricked into downloading what looks like a Zoom installer for Mac. If they fall for it, they receive a disk image that mounts as a volume named Zoom.

Read More


Dell patches max severity CSM flaws enabling admin takeover

Dell has fixed two maximum severity vulnerabilities in Container Storage Modules (CSM), the software that links the company's enterprise storage arrays to Kubernetes environments. The company is urging customers to update as soon as possible.

CSM works with Dell's main storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT. It adds features on top of the standard Container Storage Interface (CSI) drivers, which Kubernetes uses to talk to external storage systems.

Two critical flaws in the Authorization module

According to a security advisory Dell published on Thursday, both flaws sit in the CSM Authorization security module. Dell traces both to the same type of weakness: "missing authentication for critical functions."

Read More


Microsoft X account hijacked to push Clippy crypto token

Attackers took over Microsoft's official account on X on Thursday and used it to promote a cryptocurrency token in what looks like a pump-and-dump scheme. The @Microsoft account has more than 13 million followers.

In a pump-and-dump scheme, promoters inflate interest in an asset, often a little-known token, so they can sell their own holdings at a higher price before the value collapses. Access to a widely followed corporate account gives that kind of hype a large and trusting audience.

How the hijack unfolded

According to The Verge, which first reported the incident, the compromise became visible when @Microsoft followed and reposted a tweet from @clippymsftcto. That account impersonated Clippy, the animated paperclip assistant Microsoft shipped with older versions of Office. X has since suspended it.

Read More


Warlock ransomware hits water, telecom via SharePoint flaws

The group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint servers. Its recent victims include critical infrastructure operators, a regional government body and a university, according to a new report from Symantec.

Over the past two months, the operator has compromised at least four organizations in Portuguese- and Spanish-speaking countries. Symantec says the victims were a water utility, a telecommunications provider, a regional government body and a university.

Who is behind Warlock

Warlock is thought to be run by a China-based group that Symantec tracks as Longlegs. Other researchers call it Storm-2603. The group has been connected to operations known as CL-CRI-1040, CamoFei and ChamelGang.

Read More