An Apache vulnerability is being used to install ransomware. Exploitation of Citrix vulnerability in the wild. AP sustains DDoS attack. HHS reaches settlement in HIPAA data breach incident. More evidence of OSINT's reach. On the Solution Spotlight: Simone Petrella and Rick Howard speak with Ben Rothke about his article and thoughts on "Is there really an information security jobs crisis?" Andrea Little Limbago from Interos joins us to discuss SEC and the disclosure rules. And, Microsoft draws a lesson from Russia's war: cyber defense now has the advantage over cyber offense.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/211\n\nSelected reading.\nCritical Apache ActiveMQ Vulnerability Exploited to Deliver Ransomware (SecurityWeek)\xa0\nHelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks (BleepingComputer)\xa0\nCritical Vulnerability: Exploitation of Apache ActiveMQ CVE-2023-46604 (Huntress)\xa0\nSuspected Exploitation of Apache ActiveMQ CVE-2023-46604 (Rapid7)\xa0\nHHS\u2019 Office for Civil Rights Settles Ransomware Cyber-Attack Investigation (U.S. Department of Health and Human Services)\nAP news site hit by apparent denial-of-service attack (AP News)\xa0\nAssociated Press hit by Anonymous Sudan DDoS attack? (Tech Monitor)\nSatellites and social media offer hints about Israel's ground war strategy in Gaza (NPR)\xa0\nRevisiting the Gaza Hospital Explosion (New York Times)\nMicrosoft Vows to Revamp Security Products After Repeated Hacks (Bloomberg)\xa0\nA new world of security: Microsoft\u2019s Secure Future Initiative (Microsoft On the Issues)\xa0\nAnnouncing Microsoft Secure Future Initiative to advance security engineering (Microsoft Security)\xa0\nUkraine at D+617: Advantage defense. (CyberWire)\nLearn more about your ad choices. Visit megaphone.fm/adchoices