News

IT News

AI, startups, tech and digital transformation — Kazakhstan & the world

ShinyHunters Attacked 9000 Educational Institutions via Canvas
Кибербезопасность

ShinyHunters Attacked 9000 Educational Institutions...

The global cyberattack on educational institutions has highlighted the vulnerability of critical infrastructure that thousands of organizations depend on. Instructure, the owner of the Canvas platform, confirmed that access has been restored for most users, but individual universities continue to experience disruptions. The incident underscores the need for enhanced protection of educational services and preparedness for coordinated attacks.

Iranian hackers attack US infrastructure via ransomware
Кибербезопасность

Iranian hackers attack US infrastructure via ransomware

KELA has warned of Iranian state hackers collaborating with ransomware groups to attack critical US infrastructure. Instead of directly deploying malware, they act as access brokers, passing networks to affiliates like NoEscape and ALPHV. This blurs the line between espionage and cybercrime, increasing legal risks for victims. Today, this is critical due to the evolution of Pay2Key into a professional platform masking destructive attacks as extortion.

DoJ disrupted IoT botnets on 3 million devices with DDoS 31.4 Tbps
Кибербезопасность

DoJ disrupted IoT botnets on 3 million devices with DDoS 31.4 Tbps

On March 20, 2026, the DoJ, in collaboration with Canadian and German authorities, took down the command servers of the AISURU, Kimwolf, JackSkid, and Mossad botnets. The operation prevented hundreds of thousands of attacks, including hyper-volumetric strikes of 30 Tbps. This is critical for businesses: such attacks can disable cloud services and infrastructure, necessitating immediate IoT device security enhancements.

Critical Vulnerabilities in Atlassian Jira and Confluence, March 2026
Кибербезопасность

Critical Vulnerabilities in Atlassian Jira and Confluence, March 2026

On March 18, 2026, the University of California, Berkeley, warned of high-critical vulnerabilities in Atlassian's self-hosted products, including Jira and Confluence. These flaws allow hackers to inject OS commands, bypass file paths, and cause denial of service. The issue is pressing today, as thousands of companies in Central Asia use these tools for project management, risking data breaches and downtime.

CISA Warns: Zimbra and SharePoint Vulnerabilities Actively Exploited
Кибербезопасность

CISA Warns: Zimbra and SharePoint Vulnerabilities Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 19, 2026, urgently recommended patching two critical vulnerabilities in popular systems. CVE-2025-66376 in Zimbra Collaboration Suite allows arbitrary code execution, and CVE-2026-20963 in Microsoft SharePoint allows deserialization of untrusted data with a CVSS of 8.8. This is important now, as attacks are already underway, and Interlock ransomware has been exploiting a zero-day in Cisco since January 26. Businesses in Central Asia should check their systems for these vulnerabilities.

© 2024 Alashed IT. Все права защищены.

it.alashed.kz

Обсудить проектКейсы