Bleeping Computer: Bloomberg Crypto X account snafu leads to Discord phishing attack

Bleeping Computer: Bloomberg Crypto X account snafu leads to Discord phishing attack. “The official Twitter account for Bloomberg Crypto was used earlier today to redirect users to a deceptive website that stole Discord credentials in a phishing attack. As first spotted by crypto fraud investigator ZachXBT, the profile contained a link to a Telegram channel with 14,000 members, further pushing visitors to join a fake Bloomberg Discord server with 33,968 members.”

Bleeping Computer: Google: Hackers exploited Zimbra zero-day in attacks on govt orgs

Bleeping Computer: Google: Hackers exploited Zimbra zero-day in attacks on govt orgs. “According to Google’s threat analysts, the threat actors exploited the vulnerability on government systems in Greece, Moldova, Tunisia, Vietnam, and Pakistan to steal email data, user credentials, and authentication tokens, perform email forwarding, and lead victims to phishing pages.”

Washington Post: Tech giants ramp up cloud security under pressure from Washington

Washington Post: Tech giants ramp up cloud security under pressure from Washington. “After a recent theft of emails from top U.S. officials raised alarms about the country’s increasing dependence on the biggest cloud computing companies, Amazon, Google and Microsoft have begun to explain more of the work they do to secure the data of tens of millions of online customers.”

Engadget: City of Oakland declares state of emergency in wake of ransomware attack

Engadget: City of Oakland declares state of emergency in wake of ransomware attack. “While Oakland previously assured residents that 911 dispatch and fire emergency services weren’t affected by the breach, its police department warned people that the attack has delayed response times. It’s now encouraging people to file reports online for non-emergency complaints. Oakland also had to close some of its buildings and is now asking people to email government offices’ service counters before coming to visit.”

Bleeping Computer: Fake OnlyFans dating sites abuse UK Environment Agency open redirect

Bleeping Computer: Fake OnlyFans dating sites abuse UK Environment Agency open redirect. “Threat actors abused an open redirect on the official website of the United Kingdom’s Department for Environment, Food & Rural Affairs (DEFRA) to direct visitors to fake OnlyFans adult dating sites. OnlyFans is a content subscription service where paid subscribers get access to private photos, videos, and posts from adult models, celebrities, and social media personalities.”

Bleeping Computer: Royal Mail halts international services after cyberattack

Bleeping Computer: Royal Mail halts international services after cyberattack. “The Royal Mail, UK’s leading mail delivery service, has stopped its international shipping services due to ‘severe service disruption’ caused by what it described as a ‘cyber incident.’ While delivery and collection services across the UK have been unaffected by the incident, the company advised customers to hold export times while the issues are resolved, as they cannot be dispatched to overseas destinations.”

Iowa Capital Dispatch: Iowa counties’ records inaccessible in wake of suspected cyberattack

Iowa Capital Dispatch: Iowa counties’ records inaccessible in wake of suspected cyberattack. “Iowa’s county recorders maintain land records, issue marriage licenses and register births and deaths. They also issue titles and liens on boats, snowmobiles and ATVs. The biggest immediate effect of the apparent hack is that the public, as well as the recorders themselves, can’t currently access real estate records.”