November Patch Tuesday does its chores
A cleanup month brings 63 patches… wait, no, 68… how about 61?
Meduza reports: A court in Paris has jailed Russian basketball player Daniil Kasatkin on suspicion of involvement in a hacker group’s extortion activities. The 26-year-old was arrested on June 21 at Charles de Gaulle airport at the request of the United States, which has charged him with conspiracy to commit computer fraud. According to American investigators, Kasatkin…
Ivanti confirms zero-day exploitation of a remotely exploitable code execution flaw in its Connect Security product line. The post Ivanti Warns of New Zero-Day Attacks Hitting Connect Secure Product appeared first on SecurityWeek.
Jayant Chakravarti reports: The Australian financial regulator has filed a lawsuit against FIIG Securities, accusing the leading investment and financing company of lacking adequate cybersecurity controls to stop a threat actor from stealing confidential personal information of 18,000 customers. The Australian Securities and Investments Commission said it decided to sue Brisbane-headquartered FIIG Securities in Federal Court after…
Brian Krebs reports: The U.S. government today imposed economic sanctions on Funnull Technology Inc., a Philippines-based company that provides computer infrastructure for hundreds of thousands of websites involved in virtual currency investment scams known as “pig butchering.” In January 2025, KrebsOnSecurity detailed how Funnull was being used as a content delivery network that catered to cybercriminals…
Business Recorder reports: Pakistan Petroleum Limited (PPL), an oil and gas exploration firm, has reported a ransomware attack on parts of its IT infrastructure, detected on August 6, 2025, but said the incident was swiftly contained with no compromise of critical systems or sensitive data. The E&P disclosed the development in its notice to the…
The Economic Times reports: Utilities under fire: Nova Scotia Power cyberattack raises alarm Nova Scotia Power and its parent company, Emera, are scrambling to contain the fallout of a cyberattack on critical infrastructure that disrupted IT systems but spared physical operations. The cybersecurity breach came to light on April 25, when the utility discovered unauthorized…