Embargo ransomware escalates attacks to cloud environments

September 27, 2024 at 11:11AM Microsoft warns that the ransomware threat actor Storm-0501 is now targeting hybrid cloud environments and has expanded its tactics to compromise all victim assets. The group has targeted various organizations in the United States and uses various methods to gain access, move laterally, steal data, and deploy the Embargo ransomware. … Read more

China’s Salt Typhoon cyber spies are deep inside US ISPs

September 25, 2024 at 05:51PM A new Beijing-linked cyber espionage group called Salt Typhoon has breached US internet service providers, possibly preparing for future cyber attacks, according to The Wall Street Journal. This follows a similar intrusion by a different Chinese group, Flax Typhoon, targeting critical infrastructure. Experts suggest these activities are part of a … Read more

China claims Taiwan, not civilian hackers, behind website vandalism

September 24, 2024 at 09:31PM Taiwan denies Chinese allegations that its military was involved in cyber attacks critical of China’s government. China’s Ministry of State Security accused a group called Anonymous64 of being part of Taiwan’s cyber warfare wing, but Taiwan’s Ministry of National Defense refuted the claims as “not true”. The ongoing tension reflects … Read more

6 Cybersecurity Headaches Sports Organizations Have to Worry About

September 24, 2024 at 07:11PM Sports franchises and event organizers face a range of security threats, including cyber-attacks, data breaches, and exploitation. Athletes’ reliance on social media poses risks, while event attendees are vulnerable due to e-ticketing and mobile devices. Partnerships and information sharing are crucial for major events, while new revenue models create additional … Read more

Kansas water plant cyberattack forces switch to manual operations

September 24, 2024 at 03:57PM Arkansas City, Kansas, faced a cyberattack on its water treatment facility, prompting manual operations while authorities investigate. City officials reassured residents that the water supply remains secure and operational. The incident coincided with a warning about Russian-linked threat actors targeting the U.S. water sector, reflecting ongoing cybersecurity challenges in the … Read more

Critical Automated Tank Gauge Bugs Threaten Critical Infrastructure

September 24, 2024 at 03:44PM Multiple critical security vulnerabilities have been found in automatic tank gauge (ATG) systems, posing threats to critical infrastructure by allowing attackers to potentially gain full control of the systems. Researchers warn of the potential for cyberattacks impacting fuel availability, environmental disruption, and physical damage. Mitigation efforts are ongoing, emphasizing the … Read more

Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber Attacks

September 21, 2024 at 11:37AM The hacktivist group Twelve has been observed conducting destructive cyber attacks against Russian targets. They encrypt victims’ data and destroy infrastructure, causing maximum damage without financial gain. The group, linked to the Russo-Ukrainian war, utilizes various tools and tactics, sharing similarities with the ransomware group DARKSTAR. Their attacks involve exploiting … Read more

Ukraine bans Telegram on military, govt devices over security risks

September 20, 2024 at 01:39PM Ukraine’s National Coordination Centre for Cybersecurity has restricted the use of Telegram messaging app due to national security concerns, particularly its security risks in the ongoing war with Russia. This includes concerns over Russian intelligence accessing user data. The ban applies to government, military, and critical infrastructure personnel, while ordinary … Read more

Healthcare’s Diagnosis is Critical: The Cure is Cybersecurity Hygiene

September 19, 2024 at 08:24AM The healthcare industry faces a critical need for cybersecurity due to increasing cyberattacks, with ransomware holding hospitals’ systems hostage and causing patient care disruptions. Poor cybersecurity hygiene exposes vulnerabilities, leading to devastating consequences. Healthcare organizations can improve by continuous monitoring, 24×7 security operations, third-party risk management, regular patching and encryption, … Read more

Threat Actors Target Accounting Software Used by Construction Contractors

September 18, 2024 at 11:14AM Huntress warns of cyberattacks targeting Foundation Accounting Software, widely used in construction. Threat actors are brute forcing the application and exploiting default credentials, compromising organizations in various sub-industries. The attackers target MSSQL accounts, execute OS commands, and automate attacks. Only 33 publicly exposed hosts running the software with unchanged default … Read more