In Other News: National Laboratory Breach, Airplane GPS Attacks, Russia Accuses Allies of Hacking

November 24, 2023 at 06:42AM This week’s cybersecurity roundup includes stories on cyberattacks targeting Russia, a cybersecurity firm COO admitting to hacking hospitals, a hacker breaching hotel networks and faking his own death, a data breach at Idaho National Laboratory, a large phishing campaign distributing malware, GPS attacks against commercial flights, Ukraine firing top cyber … Read more

Stop social engineering at the IT help desk

November 23, 2023 at 04:12AM MGM Resorts International recently fell victim to a costly ransomware attack. Hackers used social engineering tactics to convince an employee to reveal sensitive user credentials, enabling them to bypass cyber security defenses and launch the attack. Similar incidents have occurred, highlighting the challenge of verifying the identity of requesters for … Read more

New Relic warns customers it’s experienced a cyber … something

November 23, 2023 at 12:03AM New Relic, a web tracking and analytics company, issued a security advisory to its customers about a recent cyber security incident. The advisory urges customers to remain vigilant for suspicious activity, but provides no further details about the nature of the incident. New Relic assures customers that they will be … Read more

185,000 Individuals Impacted by MOVEit Hack at Car Parts Giant AutoZone 

November 22, 2023 at 09:06AM AutoZone, the car parts retailer, has informed nearly 185,000 individuals that their personal information was compromised in the MOVEit hacking campaign. Cybercriminals exploited a vulnerability in the MOVEit Transfer application to steal information, including social security numbers. AutoZone has temporarily disabled the application, patched the vulnerability, and rebuilt the affected … Read more

Kansas Officials Blame 5-Week Disruption of Court System on ‘Sophisticated Foreign Cyberattack’

November 22, 2023 at 07:12AM The Kansas court system experienced a sophisticated cyberattack in which sensitive data was stolen and a ransomware attack was carried out. The attack disrupted access to records for over five weeks, affecting the state’s appellate courts and causing attorneys to resort to paper filings. The stolen data includes district court … Read more

AutoZone Files MOVEit Data Breach Notice With State of Maine

November 21, 2023 at 05:39PM AutoZone’s CISO, Doug Baldwin, reported a data breach to the state of Maine affecting 184,995 individuals, with 293 residents affected. The breach, discovered this month but occurring on May 28, involved a threat actor exploiting a vulnerability in the MOVEit application. AutoZone has disabled the application, conducted an investigation, and … Read more

Hacktivists breach U.S. nuclear research lab, steal employee data

November 21, 2023 at 04:28PM The Idaho National Laboratory (INL) has confirmed a cyberattack after hacktivist group ‘SiegedSec’ leaked stolen human resources data online. The INL is a nuclear research center with 5,700 specialists and 50 experimental nuclear reactors. The hacktivists leaked personal employee information and proof of the breach. The incident is under investigation … Read more

Auto parts giant AutoZone warns of MOVEit data breach

November 21, 2023 at 01:09PM AutoZone, the leading automotive spare parts retailer in the US, has suffered a data breach as part of the Clop MOVEit file transfer attacks. Approximately 185,000 people were affected by the breach, which occurred on May 28, 2023. While the specific data compromised has not been disclosed, identity theft protection … Read more

Canadian Military, Police Impacted by Data Breach at Moving Companies

November 21, 2023 at 08:39AM The Canadian government has reported a data breach involving two moving and relocation services firms contracted by the government. The breach exposed personal information of present and former public service employees, as well as members of the Canadian Armed Forces and Royal Canadian Mounted Police. The government is offering credit … Read more

Third-party data breach affecting Canadian government could involve data from 1999

November 21, 2023 at 08:31AM The government of Canada has confirmed a security breach in which its data was accessed after two third-party service providers were attacked. The breach potentially affects current and former government employees, members of the armed forces, and Royal Canadian Mounted Police workers. The government is currently analyzing a significant volume … Read more