Chinese Cyberspies Employ Ransomware in Attacks for Diversion post, juni 27, 2024juli 3, 2025 Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft. A joint report from SentinelLabs and Recorded Future analysts presents the case of ChamelGang, a suspected Chinese advanced persistent threat (APT) that… Continue Reading
Indonesia Refuses to Pay $8M Ransom After Cyberattack post, juni 25, 2024juni 26, 2024 More than 200 regional and national government agencies have been impacted by the ransomware attack, and few of them are once again operational. A cybercrime group is demanding $8 million after compromising Indonesia’s national data center — an amount the government is refusing to pay. More than 200 government agencies have… Continue Reading
Thousands of Car Dealerships Stalled Out After Software Provider Cyberattack post, juni 20, 2024juni 21, 2024 CDK Global, which makes software for car dealers, experienced a cyber incident that halted vehicle sales and service across the US. A supply chain cyberattack on software provider CDK Global forced thousands of car dealerships to shut down Wednesday, a traditionally busy day for sales with the Juneteenth holiday. Continue Reading
Ransomware crew may have exploited Windows make-me-admin bug as a zero-day post, juni 12, 2024februari 24, 2025 The Black Basta ransomware gang may have exploited a now-patched Windows privilege escalation bug as a zero-day, according to Symantec’s threat hunters. Microsoft plugged the hole in the Windows Error Reporting Service in the March Patch Tuesdsay, and warned orgs that the vulnerability, tracked as CVE-2024-26169, could allow an attacker to… Continue Reading
Cylance clarifies data breach details, except where the data came from post, juni 11, 2024juni 12, 2024 BlackBerry-owned cybersecurity shop Cylance says the data allegedly belonging to it and being sold on a crime forum doesn’t endanger customers, yet it won’t say where the information was stored originally. Saying very little about where the data came from, Cylance says it is related to company marketing between 2015… Continue Reading
RansomHub extortion gang linked to now-defunct Knight ransomware post, juni 5, 2024 Security researchers analyzing the relatively new RansomHub ransomware-as-a-service believe that it has evoloved from the currently defunct Knight ransomware project. RansomHub has a short history and operated mainly as a data theft and extortion group that sells stolen files to the highest bidder. Continue Reading
Services disrupted as London hospitals hit by cyber-attack post, juni 5, 2024juni 12, 2024 Attack is having a ‘major impact’ on Guy’s and St Thomas’ NHS trust, and is understood to have also affected other hospitals. Major London hospitals have had to cancel operations and blood transfusions after being hit by a cyber-attack that led to them declaring it a “critical incident”. Continue Reading
Police seize over 100 malware loader servers, arrest four cybercriminals post, mei 30, 2024mei 30, 2024 An international law enforcement operation codenamed ‘Operation Endgame’ has seized over 100 servers worldwide used by multiple major malware loader operations, including IcedID, Pikabot, Trickbot, Bumblebee, Smokeloader, and SystemBC. The action, which occurred between May 27 and 29, 2024, involved 16 location searches across Europe and led to the arrest… Continue Reading
FBI takes down BreachForums ransomware website and Telegram channel post, mei 15, 2024mei 16, 2024 The FBI, in combination with police around the world, have taken control of the website and Telegram channel of ransomware brokerage site BreachForums. The action occurred on Wednesday, just days after the site hosted information apparently stolen from Europol’s databases and marks the latest action against the pernicious site. Despite numerous takedowns… Continue Reading
Boeing Confirms Lockbit Hackers Wanted $200 Million Ransom After 2023 Hack post, mei 9, 2024mei 15, 2024 Boeing declined to pay a $200 million ransom in exchange for securing 43GB of data stolen by hackers, the aerospace company confirmed this week. Boeing was hacked in October 2023 by the LockBit ransomware gang, which threatened to release what it said was a “tremendous amount” of sensitive data. LockBit eventually published data from… Continue Reading