Security Affairs newsletter Round 439 by Pierluigi Paganini – International edition
ALPHV/BlackCat ransomware gang hacked the hotel chain Motel One
FBI warns of dual ransomware attacks
Progress Software fixed two critical severity flaws in WS_FTP Server
Child abuse site taken down, organized child exploitation crime suspected – exclusive
A still unpatched zero-day RCE impacts more than 3.5M Exim servers
Chinese threat actors stole around 60,000 emails from US State Department in Microsoft breach
Misconfigured WBSC server leaks thousands of passports
CISA adds JBoss RichFaces Framework flaw to its Known Exploited Vulnerabilities catalog
Cisco urges to patch actively exploited IOS zero-day CVE-2023-20109
Dark Angels Team ransomware group hit Johnson Controls
GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023
Russian zero-day broker is willing to pay $20M for zero-day exploits for iPhones and Android devices
China-linked APT BlackTech was spotted hiding in Cisco router firmware
Watch out! CVE-2023-5129 in libwebp library affects millions applications
DarkBeam leaks billions of email and password combinations
'Ransomed.vc' in the Spotlight - What is Known About the Ransomware Group Targeting Sony and NTT Docomo
Top 5 Problems Solved by Data Lineage
Threat actors claim the hack of Sony, and the company investigates
Canadian Flair Airlines left user data leaking for months
The Rhysida ransomware group hit the Kuwait Ministry of Finance
BORN Ontario data breach impacted 3.4 million newborns and pregnancy care patients
Xenomorph malware is back after months of hiatus and expands the list of targets
Smishing Triad Stretches Its Tentacles into the United Arab Emirates
Crooks stole $200 million worth of assets from Mixin Network
A phishing campaign targets Ukrainian military entities with drone manual lures
Alert! Patch your TeamCity instance to avoid server hack
Is Gelsemium APT behind a targeted attack in Southeast Asian Government?
Nigerian National pleads guilty to participating in a millionaire BEC scheme
New variant of BBTok Trojan targets users of +40 banks in LATAM
Deadglyph, a very sophisticated and unknown backdoor targets the Middle East
Alphv group claims the hack of Clarion, a global manufacturer of audio and video equipment for cars
Security Affairs newsletter Round 438 by Pierluigi Paganini – International edition
National Student Clearinghouse data breach impacted approximately 900 US schools
Government of Bermuda blames Russian threat actors for the cyber attack
Recently patched Apple and Chrome zero-days exploited to infect devices in Egypt with Predator spyware
CISA adds Trend Micro Apex One and Worry-Free Business Security flaw to its Known Exploited Vulnerabilities catalog
Information of Air Canada employees exposed in recent cyberattack
Sandman APT targets telcos with LuaDream backdoor
Apple rolled out emergency updates to address 3 new actively exploited zero-day flaws
Ukrainian hackers are behind the Free Download Manager supply chain attack
Space and defense tech maker Exail Technologies exposes database access
Pro-Russia hacker group NoName launched a DDoS attack on Canadian airports causing severe disruptions
Experts found critical flaws in Nagios XI network monitoring software
The dark web drug marketplace PIILOPUOTI was dismantled by Finnish Customs
International Criminal Court hit with a cyber attack
GitLab addressed critical vulnerability CVE-2023-5009
Trend Micro addresses actively exploited zero-day in Apex One and other security Products
ShroudedSnooper threat actors target telecom companies in the Middle East
Recent cyber attack is causing Clorox products shortage
Earth Lusca expands its arsenal with SprySOCKS Linux malware
Microsoft AI research division accidentally exposed 38TB of sensitive data
German intelligence warns cyberattacks could target liquefied natural gas (LNG) terminals
Deepfake and smishing. How hackers compromised the accounts of 27 Retool customers in the crypto industry
FBI hacker USDoD leaks highly sensitive TransUnion data
North Korea's Lazarus APT stole almost $240 million in crypto assets since June
Clop gang stolen data from major North Carolina hospitals
CardX released a data leak notification impacting their customers in Thailand
Security Affairs newsletter Round 437 by Pierluigi Paganini – International edition
TikTok fined €345M by Irish DPC for violating children’s privacy
Dariy Pankov, the NLBrute malware author, pleads guilty
Dangerous permissions detected in top Android health apps
Caesars Entertainment paid a ransom to avoid stolen data leaks
Free Download Manager backdoored to serve Linux malware for more than 3 years
Lockbit ransomware gang hit the Carthage Area Hospital and the Clayton-Hepburn Medical Center in New York
The iPhone of a Russian journalist was infected with the Pegasus spyware
Kubernetes flaws could lead to remote code execution on Windows endpoints
Threat actor leaks sensitive data belonging to Airbus
A new ransomware family called 3AM appears in the threat landscape
Redfly group infiltrated an Asian national grid as long as six months
Mozilla fixed a critical zero-day in Firefox and Thunderbird
Microsoft September 2023 Patch Tuesday fixed 2 actively exploited zero-day flaws
Save the Children confirms it was hit by cyber attack
Adobe fixed actively exploited zero-day in Acrobat and Reader
A new Repojacking attack exposed over 4,000 GitHub repositories to hack
MGM Resorts hit by a cyber attack
Anonymous Sudan launched a DDoS attack against Telegram
Iranian Charming Kitten APT targets various entities in Brazil, Israel, and the U.A.E. using a new backdoor
GOOGLE FIXED THE FOURTH CHROME ZERO-DAY OF 2023
CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities Catalog
UK and US sanctioned 11 members of the Russia-based TrickBot gang
New HijackLoader malware is rapidly growing in popularity in the cybercrime community
Some of TOP universities wouldn’t pass cybersecurity exam: left websites vulnerable
Evil Telegram campaign: Trojanized Telegram apps found on Google Play
Rhysida Ransomware gang claims to have hacked three more US hospitals
Akamai prevented the largest DDoS attack on a US financial company
Security Affairs newsletter Round 436 by Pierluigi Paganini – International edition
US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog
Ragnar Locker gang leaks data stolen from the Israel's Mayanei Hayeshua hospital
North Korea-linked threat actors target cybersecurity experts with a zero-day
Zero-day in Cisco ASA and FTD is actively exploited in ransomware attacks
Zero-days fixed by Apple were used to deliver NSO Group’s Pegasus spyware
Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs
A malvertising campaign is delivering a new version of the macOS Atomic Stealer
Two flaws in Apache SuperSet allow to remotely hack servers
Chinese cyberspies obtained Microsoft signing key from Windows crash dump due to a mistake
Google addressed an actively exploited zero-day in Android
A zero-day in Atlas VPN Linux Client leaks users' IP address
MITRE and CISA release Caldera for OT attack emulation
ASUS routers are affected by three critical remote code execution flaws
Hackers stole $41M worth of crypto assets from crypto gambling firm Stake
Freecycle data breach impacted 7 Million users
Meta disrupted two influence campaigns from China and Russia
A massive DDoS attack took down the site of the German financial agency BaFin
"Smishing Triad" Targeted USPS and US Citizens for Data Theft
University of Sydney suffered a security breach caused by a third-party service provider
Cybercrime will cost Germany $224 billion in 2023
PoC exploit code released for CVE-2023-34039 bug in VMware Aria Operations for Networks
Security Affairs newsletter Round 435 by Pierluigi Paganini – International edition
LockBit ransomware gang hit the Commission des services electriques de Montréal (CSEM)
UNRAVELING EternalBlue: inside the WannaCry’s enabler
Researchers released a free decryptor for the Key Group ransomware
Fashion retailer Forever 21 data breach impacted +500,000 individuals
Russia-linked hackers target Ukrainian military with Infamous Chisel Android malware
Akira Ransomware gang targets Cisco ASA without Multi-Factor Authentication
Paramount Global disclosed a data breach
National Safety Council data leak: Credentials of NASA, Tesla, DoJ, Verizon, and 2K others leaked by workplace safety organization
Abusing Windows Container Isolation Framework to avoid detection by security products
Critical RCE flaw impacts VMware Aria Operations Networks
UNC4841 threat actors hacked US government email servers exploiting Barracuda ESG flaw
Hackers infiltrated Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) for months
FIN8-linked actor targets Citrix NetScaler systems
Japan's JPCERT warns of new 'MalDoc in PDF' attack technique
Attackers can discover IP address by sending a link over the Skype mobile app
Cisco fixes 3 high-severity DoS flaws in NX-OS and FXOS software
Cloud and hosting provider Leaseweb took down critical systems after a cyber attack
Crypto investor data exposed by a SIM swapping attack against a Kroll employee
China-linked Flax Typhoon APT targets Taiwan
Researchers released PoC exploit for Ivanti Sentry flaw CVE-2023-38035