Sunday , December 22 2024

Daily Cybersecurity update, July-8, 2023

In the realm of healthcare, an unsettling surge of data breaches has put at risk the privacy and security of numerous patient records. The sensitive information of more than 165,000 patients was compromised in a breach that impacted Henry Ford Health. The Phoenician Medical Center experienced a second breach that affected approximately 162,000 patients’ PHI. In a new campaign, FIN8 has resurfaced, this time deploying a redesigned backdoor to unleash the malicious BlackCat ransomware, putting organizations at risk once again.

Read along for more:

For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Mastercard has completed its acquisition of Recorded Future, an AI-based threat intelligence provider. Mastercard has acquired the company for $2.65...
Read More
For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Eight New ICS Advisories released by CISA

CISA has released eight advisories on vulnerabilities in Industrial Control Systems (ICS). These vulnerabilities affect essential software and hardware in...
Read More
Eight New ICS Advisories released by CISA

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their data and funds are secure...
Read More
Authority Denies  Hacker claim ransomware attack on Indonesia’s state bank BRI

London-based company “Builder.ai” reportedly exposed 1.2 TB data

Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million...
Read More
London-based company “Builder.ai” reportedly exposed 1.2 TB data

(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos resolved 3 critical vulnerabilities in Firewall

Sophos has fixed three separate security vulnerabilities in Sophos Firewall.  The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such...
Read More
(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)  Sophos resolved 3 critical vulnerabilities in Firewall

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on "Cybersecurity Awareness and Needs Analysis" was held on Thursday (December 19) at Bangladesh Bank Training Academy...
Read More
“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

CVE-2023-48788
Kaspersky reveals active exploitation of Fortinet Vulnerability

Kaspersky's Global Emergency Response Team (GERT) found that attackers are exploiting a patched SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient...
Read More
CVE-2023-48788  Kaspersky reveals active exploitation of Fortinet Vulnerability

U.S. Weighs Ban on Chinese-Made Router TP-Link: WSJ reports

The US government is considering banning a well-known brand of Chinese-made home internet routers TP-Link due to concerns that they...
Read More
U.S. Weighs Ban on Chinese-Made Router TP-Link:  WSJ reports

Daily Security Update Dated: 18.12.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 18.12.2024

CISA released best practices to secure Microsoft 365 Cloud environments

CISA has issued Binding Operational Directive (BOD) 25-01, requiring federal civilian agencies to improve the security of their Microsoft 365...
Read More
CISA released best practices to secure Microsoft 365 Cloud environments

Henry Ford Health in Detroit experienced a data breach caused by an email phishing scam. This unfortunate incident has put at risk the personal information of approximately 168,000 patients. The compromised data consists of personal information such as name, gender, date of birth, lab results, and medical record numbers.

The Phoenician Medical Center of Arizona recently revealed a significant cybersecurity breach that resulted in the disruption of multiple IT systems. The breach affected the privacy and security of 162,500 patient files. These files contained sensitive information like state identification numbers, medical record numbers, diagnosis details, and treatment information.

VirusTotal unintentionally revealed the names and email addresses of 5,600 individuals from prominent defense and intelligence agencies worldwide, including those from the U.S. Cyber Command, the NSA, Pentagon, FBI, and military branches are all involved in enhancing national security.

A non-password-protected database was found exposing 2.3 million records from multiple dating apps, including explicit images and personal information. Most of the records are related to the 419 Dating – Chat & Flirt platform.

Symantec observed the financially-motivated FIN8 threat group using a reworked version of the Sardonic backdoor to deliver the BlackCat ransomware.

CISA has published an informative factsheet that offers valuable resources and expert advice aimed at empowering network defenders, cybersecurity professionals, and incident response analysts. With these free tools and guidance, they can effectively mitigate the dangers of information exposure, data theft, as well as encryption and extortion attacks.

Rapid7 has issued a warning regarding the active exploitation of two vulnerabilities in Adobe ColdFusion. These vulnerabilities allow hackers to bypass authentication and gain control over servers by executing remote commands to install malicious webshells.

Researchers have recently discovered evidence of a new ransomware operation called NoEscape, which appears to be a revamped version of the previously discontinued Avaddon ransomware. The latter had shut down and issued decryption keys in 2021.

Malicious actors have been found exploiting Android’s WebAPK feature to deceive users into unknowingly installing harmful web applications that can compromise their personal data. The attack starts with victims receiving text messages prompting them to update a mobile banking app.

Netcraft, a leading provider of cybercrime detection and disruption services based in Britain, has recently received a substantial $100 million investment from Spectrum Equity. This significant funding will fuel Netcraft’s rapid growth and ambitious plans for global expansion.

Check Also

Daily Security Update Dated: 04.12.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data …

Leave a Reply

Your email address will not be published. Required fields are marked *