Friday , May 9 2025

Daily Cybersecurity Update, June-28, 2023

In January, Atlantic General Hospital underwent a ransomware attack that compromised the PHI of thousands of people. However, according to the latest revelations, the actual number is five times greater than the initially disclosed one. In other news, the LetMeSpy Android stalkerware got hacked, exposing user information. Coming to the topic of ransomware, this relatively new ransomware, 8base, has amassed a good number of victims in just June. Read along to know more.

  • Atlantic General Hospital
    • A ransomware breach at Atlantic General Hospital in Maryland compromised the sensitive data of nearly 137,000 patients. This is five times more than the previously disclosed number of 30,700 victims.
  • LetMeSpy
    • The developer of the Android stalkerware LetMeSpy experienced a cyberattack, resulting in unauthorized access to user data. This includes email addresses, phone numbers, and message content. LetMeSpy was installed on around 10,000 devices.
  • Cl0p ransomware group
    • At least 131 organizations appear to have been impacted by the Cl0p ransomware group’s attacks against MOVEit Transfer. The threat actor listed 108 organizations, including seven U.S. universities.
  • 8Base ransomware group
    • The 8Base ransomware group has experienced a significant increase in activity since June. They have targeted multiple organizations worldwide and engaged in double-extortion attacks. So far, they have listed 35 victims on their extortion site.
  • Triada trojan
    • Check Point discovered a modified version of the Telegram Messenger app that contains the Triada trojan. This trojan can perform various malicious actions, such as stealing login credentials and signing up the user for paid subscriptions.
  • Ukrainian cyber police
    • Ukrainian cyber police raided nine fraudulent call centers involving over 200 operators running vishing campaigns. These operators were impersonating bank and other financial institution employees to obtain credit and debit card data.
  • ThirdEye info-stealer
    • FortiGuard Labs spotted ThirdEye, a new info-stealer that collects information from compromised Windows machines. This information could potentially be used in future cyberattacks.
  • UAE and Israel cybersecurity project
    • The UAE and Israel are collaborating on a cybersecurity project called “Crystal Ball”. This project aims to create a digital platform for sharing information. The project also involves Microsoft, Rafael Advanced Defense Systems, and CPX, with the participation of other countries.
  • Cyera funding round
    • Data security startup Cyera bagged a whopping $100 million in a Series B round led by Accel. Sequoia, Cyberstarts, and Redpoint Ventures also participated in the round.
  • Astrix Security funding round
    • Astrix Security, an access management platform for third-party app integrations, raised $25 million in a Series A funding round led by CRV. Bessemer Venture Partners and F2 Venture Capital also participated in the round.

Microsoft Patches Four Critical Azure and Power Apps Vulns

Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
Microsoft Patches Four Critical Azure and Power Apps Vulns

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

CVE-2025-29824
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
CVE-2025-29824  Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Hacker exploited Samsung MagicINFO 9 Server RCE flaw

Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
Hacker exploited Samsung MagicINFO 9 Server RCE flaw

CISA adds Langflow flaw to its KEV catalog

CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
CISA adds Langflow flaw to its KEV catalog

Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

Check Also

Daily Security Update Dated: 18.12.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data …

Leave a Reply

Your email address will not be published. Required fields are marked *