Advania, a Nordic IT provider, had a cybersecurity incident affecting at least 60 of its customers in Sweden, including healthcare centers. The company admitted a “security incident” in its public statement. In a statement the company said, “During the afternoon of Tuesday, February 6th, we discovered an anomaly in a …
Read More »U.S. Sanctions 6 Iranian Officials for Cyber Attacks
On Feb. 2, 2024, the United States imposed sanctions on six Iranian officials for cyber-attacks in the US and other countries. The sanctions were in response to the Jan. 28, 2024, attack on a US outpost in northeast Jordan near the border with Syria and Iraq, where three American soldiers …
Read More »
Cloudflare Blog
Cloudflare hacked using auth tokens stolen in Okta attack
Cloudflare disclosed that its internal Atlassian server was breached by a suspected ‘nation-state attacker’. The attacker gained access to Cloudflare’s Confluence wiki, Jira bug database, and Bitbucket source code management system. The attacker first accessed Cloudflare’s self-hosted Atlassian server on November 14, and then accessed the company’s Confluence and Jira …
Read More »Citibank failed to protect customers from fraud
The attorney general’s office in New York state has sued Citibank for not protecting customers from electronic fraud and not reimbursing the victims. This has resulted in millions of dollars in losses for customers in the state. Attorney General Letitia James filed a lawsuit in federal court in Manhattan. She …
Read More »
Pwn2Own Contest Tokyo
Hackers Unearths Dozens of Zero-Day Vulnerabilities
Top ethical hackers are currently competing in Tokyo. They have discovered nearly 40 zero-day vulnerabilities in Tesla and other products. The first car-focused Zero Day Initiative (ZDI) Pwn2Own contest takes place from January 24-26. ZDI is the world’s largest bug bounty program, encouraging ethical hackers to find and report vulnerabilities …
Read More »
Medibank breach
Australia imposes sanctions on Russian hacker
Australia has imposed cyber sanctions on a Russian hacker for his alleged role in a 2022 ransomware attack. This is the country’s first use of this penalty. A cyberattack stole personal data from 9.7 million Medibank customers in Australia. The data includes names, birth dates, medical information, and Medicare numbers. …
Read More »
Swedish customers affected
Akira ransomware hits cloud service Tietoevry
A ransomware attack on a data center run by Finnish IT company Tietoevry has caused widespread outages in Sweden, affecting healthcare, government services, retail outlets, and the largest cinema chain in the country. Tietoevry, a publicly traded company based in Espoo, Finland, reported that an attack occurred over the weekend. …
Read More »Microsoft’s Top Execs’ Emails Breached By Russia-Linked APT Attack
The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor …
Read More »
Mandiant report
“Group UNC3886” exploiting VMware bug since late 2021
Mandiant and VMware Product Security found that the UNC3886 espionage group has been exploiting CVE-2023-34048 since late 2021, even though it was publicly reported and patched in October 2023. Mandiant found new ways that UNC3886 uses to attack computer systems. They focus on technologies that don’t have EDR protection and …
Read More »
BGD e-GOV CIRT Report
Info Stealer Malware surge in Bangladesh
The BGD e-GOV CIRT Cyber Threat Intelligence Unit has noticed a big rise in a type of malware named stealer malware in Bangladesh’s cyberspace. These sneaky programs are good at secretly getting sensitive data like login details, personal information, and secret data from specific systems. This breach puts financial resources …
Read More »