TeamViewer Credits Network Segmentation for Rebuffing APT29 Attack post, juni 28, 2024juli 3, 2025 Despite warnings from Health-ISAC and the NCC Group, the remote access software maker says defense-in-depth kept customers’ data safe from Midnight Blizzard. In public statements on June 27 (reiterated today), the German maker of remote desktop software said, “[W]e keep all servers, networks, and accounts strictly separate to help prevent unauthorized access… Continue Reading
Chinese Cyberspies Employ Ransomware in Attacks for Diversion post, juni 27, 2024juli 3, 2025 Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft. A joint report from SentinelLabs and Recorded Future analysts presents the case of ChamelGang, a suspected Chinese advanced persistent threat (APT) that… Continue Reading
Microsoft blamed for million-plus patient record theft at US hospital giant post, juni 26, 2024 American healthcare provider Geisinger fears highly personal data on more than a million of its patients has been stolen – and claimed a former employee at a Microsoft subsidiary is the likely culprit. Geisinger on Monday announced the results of a probe into a November computer security breach, placing the blame on Microsoft-owned Nuance… Continue Reading
Most critical open source projects not using memory safe code post, juni 26, 2024juni 27, 2024 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are susceptible to memory flaws. The report, cosigned by CISA, the Federal Bureau of Investigation (FBI), as well as Australian (ASD, ACSC) and Canadian organizations (CCCS), is a follow-up to the… Continue Reading
China-Linked Cyber-Espionage Teams Target Asian Telecoms post, juni 25, 2024februari 24, 2025 In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack. At least three cyber-espionage groups have compromised telecommunications operators in multiple countries in the Asia-Pacific region, placing backdoors inside the communications providers’ networks, stealing… Continue Reading
Indonesia Refuses to Pay $8M Ransom After Cyberattack post, juni 25, 2024juni 26, 2024 More than 200 regional and national government agencies have been impacted by the ransomware attack, and few of them are once again operational. A cybercrime group is demanding $8 million after compromising Indonesia’s national data center — an amount the government is refusing to pay. More than 200 government agencies have… Continue Reading
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021 post, juni 20, 2024februari 24, 2025 Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021. “The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials,” the Symantec Threat Hunter Team,… Continue Reading
Phoenix UEFI vulnerability impacts hundreds of Intel PC models post, juni 20, 2024juni 21, 2024 A newly discovered vulnerability in Phoenix SecureCore UEFI firmware tracked as CVE-2024-0762 impacts devices running numerous Intel CPUs, with Lenovo already releasing new firmware updates to resolve the flaw. The vulnerability, dubbed ‘UEFICANHAZBUFFEROVERFLOW,’ is a buffer overflow bug in the firmware’s Trusted Platform Module (TPM) configuration that could be exploited… Continue Reading
Thousands of Car Dealerships Stalled Out After Software Provider Cyberattack post, juni 20, 2024juni 21, 2024 CDK Global, which makes software for car dealers, experienced a cyber incident that halted vehicle sales and service across the US. A supply chain cyberattack on software provider CDK Global forced thousands of car dealerships to shut down Wednesday, a traditionally busy day for sales with the Juneteenth holiday. Continue Reading
NiceRAT Malware Targets South Korean Users via Cracked Software post, juni 17, 2024 Threat actors have been observed deploying a malware called NiceRAT to co-opt infected devices into a botnet. The attacks, which target South Korean users, are designed to propagate the malware under the guise of cracked software, such as Microsoft Windows, or tools that purport to offer license verification for Microsoft… Continue Reading