Share Blog Post
- The FBI released its first-ever public advisory elaborating the behavior of a ransomware affiliate named OnePercent Group, known for its well-structured extortion technique.
- The Ragnarok ransomware gang shut down its operations and released a master key for its victims.
- The U.K is planning on changing data protection and privacy laws, which are anticipated to promote economic growth and innovation. The data adequacy partnership will enable Britain to trade with countries such as the U.S., the Republic of Korea, Australia, and Singapore.
- Post a cybersecurity meeting at the White House, several tech companies, including Microsoft, Google, and Amazon pledged to invest billions to enhance the nation’s cyber resilience.
- A U.S. national living in Turkey admitted to being the primary culprit behind the massive T-Mobile hack that affected at least 50 million customers.
- Indiana-based Eskenazi Health disclosed that a ransomware attack pilfered patient data and leaked the stolen information. In the aftermath, its EHR experienced a downtime.
- Eye & Retina Surgeons suffered a ransomware attack that impacted clinical data, including clinical notes and eye scans of about 73,500 patients.
- A glitch in Palantir—a secretive software program used by the FBI—enabled some employees to gain unauthorized access to confidential data. This went on for more than a year.
- A data breach at Chico State University exposed the personal information of 130 students who requested religious exemptions from COVID-19 vaccination.
- Users of OpenSea, a peer-to-peer marketplace for NFTs, were targeted in an ongoing Discord phishing attack to steal cryptocurrency funds and NFTs.
- The Belgian Police singled out eight Android apps hosting Joker malware. The virus is capable of subscribing the user to payment services without users’ authorization.
- Atlanta Allergy & Asthma informed nearly 9,800 patients of a data breach that blurted out their PHI such as SSNs, financial details, and treatment-related information.
- Cybercriminals swindled nearly $2.3 million from the employees of the Town of Peterborough, New Hampshire, using spoofed email accounts and forged documents, the Town administrator announced in a press release.
- Thousands of web apps laid bare 38 million sensitive records from a number of COVID-19 contact tracing platforms, vaccination sign-ups, job portals, and employee databases.
- The U.S. State Department suspected a breach after an unauthorized actor infiltrated its network. It claimed no significant disruption in its daily operations.
- Financially motivated FIN8 group attempted to compromise the networks of a U.S. financial organization using a new malware - Sardonic.
- A PowerShell script used by the Pysa ransomware shows that the gang is seeking out files containing the financial and personal information of victims. The script includes a list of 123 keywords that helps the threat actors perform manual sweeps of data.
- A U.S.-based computer retail firm was targeted by the new SideWalk backdoor in a recent campaign by a Chinese APT. The backdoor shares multiple similarities with CROSSWALK, another backdoor used by the group.
- A new malware VIPSpace leverages the Discord platform to deploy up to 25 different malware and cripple targeted systems.
- A new espionage campaign, active since July 2020, is targeting public and private companies in South Asian countries. The campaign uses shellcode loaders and the ScrambleCross backdoor.
- A phishing campaign is deploying a new variant of Konni RAT to target users in Russia.
- Several new variants of the PRISM backdoor have managed to fly under the radar for over 3.5 years. One of the variants found is identified as WaterDrop.
- The CISA is warning users about hurricane-related scams that trick victims into handing over their funds and personal details.
- Mirai-based botnet operators were found exploiting a new security flaw in the Realtek SDK, impacting hundreds of thousands of devices.
Posted on: August 27, 2021
More from Cyware
Stay updated on the security threat landscape and technology innovations at Cyware with our threat intelligence briefings and blogs.
Explore Industry Briefs
Cyware for Enterprise
Adopt next-gen security with threat intelligence analysis, security automation...
Cyware for ISACs/ISAOs
Anticipate, prevent, and respond to threats through bi-directional threat in...