Ivanti products are under active zero-day exploitation. Phemedrone is a new open-source info-stealer. Bishop Fox finds exposed SonicWall firewalls. GitLab and VMware patch critical vulnerabilities. The Secret Service foils a phishing scam. Europol shuts down a cryptojacking campaign. Ransomware hits a Majorca municipality. RUSI looks at ransomware. Ben Yelin explains the New York Times going after OpenAI over the data scraping. And the sad case of an Ohio lottery winner.\xa0\nRemember to leave us a 5-star rating and review in your favorite podcast app.\nMiss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you\u2019ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.\n\nCyberWire Guest\nGuest and partner Ben Yelin joins us today to discuss \u201cThe Most Critical Elements of the FTC\u2019s Health Breach Rulemaking.\u201d Ben is the Program Director for Public Policy & External Affairs at the University of Maryland Center for Health and Homeland Security and Co-Host of N2K\u2019s Caveat Podcast.\n\nSelected Reading\nIvanti Connect Secure zero-days now under mass exploitation (Bleeping Computer)\nWindows SmartScreen flaw exploited to drop Phemedrone malware (Bleeping Computer)\nOver 178,000 SonicWall next-generation firewalls (NGFW) online exposed to hack (Security Affairs)\nGitLab Fixes Password Reset Bug That Allows Account Takeover (Security Boulevard)\nPatches Available for a Critical Vulnerability in VMware Aria Automation: CVE-2023-34063 (Malware News)\nUS court docs expose fake antivirus renewal phishing tactics (Bleeping Computer)\nHacker spins up 1 million virtual servers to illegally mine crypto (Bleeping Computer)\nRansomware gang demands \u20ac10 million after attacking Spanish council (The Record)\nRansomware: Victim Insights on Harms to Individuals, Organisations and Society (Royal United Services Institute)\nCybersecurity incident delays payouts for big Ohio Lottery winners (Beacon Journal)\n\nShare your feedback.\nWe want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.\xa0\n\nWant to hear your company in the show?\nYou too can reach the most influential leaders and operators in the industry. Here\u2019s our media kit. Contact us at cyberwire@n2k.com to request more info.\nThe CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. \xa9 2023 N2K Networks, Inc.\nLearn more about your ad choices. Visit megaphone.fm/adchoices