Posts

Showing posts with the label Hacking

Nissan North America data breach impacts over 53,000 employees

Image
By Bill Toulas,  Bleeping Computer Nissan North America (Nissan) suffered a data breach last year when a threat actor targeted the company's external VPN and shut down systems to receive a ransom. The car maker discovered the breach in early November 2023 and discovered recently that the incident exposed personal data belonging to more than 53,000 current and former employees. “As shared during the Nissan Town Hall meeting on December 5, 2023, Nissan learned on November 7, 2023, that it was the victim of a targeted cyberattack. Upon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain, and successfully terminate the threat,” the company said in a notification to impacted individuals. Nissan disclosed that the threat actor targeted its external VPN and then shut down certain company systems before asking for a ransom. The company notes that none of its systems were encrypted during the attack. Working with extern...

Dell hacker claims they had access to systems for nearly three weeks

Image
By Solomon Klappholz, IT Pro The hacker trying to sell a Dell database containing 49 million customer records claims he was able to persist on the company’s systems for several weeks The threat actor behind the recent Dell data breach that exposed 49 million customer records claims they were able to access internal systems for weeks before being discovered.  The hacker, Menelik, was reported to be selling access to a database storing 49 million records related to systems purchased from Dell between 2017 and 2024. Dell disclosed the breach on 9 May, notifying customers that their names, addresses, and Dell customer info were exposed, warning them to watch out for social engineering attacks impersonating the technology giant. Menelik told TechCrunch they were able to gain access to the database by registering several accounts on a Dell portal as a partner that resells Dell products and services. According to Menelik, the process of registering and being approved as a partner was re...

Conservative News Websites Hacked, Replaced With Page Leaking Private Information

Image
By Charlie Nash,  Mediaite Two conservative news websites – Human Events and The Post Millennial – were hacked on Thursday evening and replaced with a page leaking private information. Both websites were taken down by unnamed hackers and replaced with a fake coming out letter purported to be written by Post Millennial senior editor Andy Ngo. “Dear Readers of The Post Millennial, I am writing to you today to share something deeply personal and important to me,” the letter opened. “After much soul-searching, I have come to the realization that I am a trans individual, and I would like to officially introduce myself as Angelina Ngo, a woman.” At the end of the letter, the hacker concluded, “P.S. I am also sharing with you all of our mailing lists, our subscriber database and the personal details of all our writers and editors,” along with links to download the private information. The official Twitter accounts for both Human Events and The Post Millennial – which was acquired by ...

Why remote desktop tools are facing an onslaught of cyber threats

Image
By Solomon Klappholz, IT Pro Hackers are increasingly targeting remote desktop tools in their attacks, new research reveals, prompting warnings for enterprises globally In the era of hybrid work, remote desktop tools have become vital business enablers, but due to their pervasiveness on corporate networks they have become a popular entry point for cyber criminals. If successfully exploited, remote access tools can provide hackers with a direct pathway into a system or network, and once access is gained attackers can move laterally within the network, escalating privileges and maintaining persistence. In an investigation into which remote desktop tools are targeted the most, Jonathan Tanner, senior security researcher at Barracuda Networks, explained that remote desktop software poses a particular challenge to IT teams to secure. “Among the security challenges facing IT teams implementing remote desktop software is that there are many different tools available, each using different and ...

LastPass: Hackers targeted employee in failed deepfake CEO call

Image
By Sergiu Gatlan,  Bleeping Computer LastPass revealed this week that threat actors targeted one of its employees in a voice phishing attack, using deepfake audio to impersonate Karim Toubba, the company's Chief Executive Officer. However, while 25% of people have been on the receiving end of an AI voice impersonation scam or know someone who has, according to a recent global study, the LastPass employee didn't fall for it because the attacker used WhatsApp, which is a very uncommon business channel. "In our case, an employee received a series of calls, texts, and at least one voicemail featuring an audio deepfake from a threat actor impersonating our CEO via WhatsApp," LastPass intelligence analyst Mike Kosak said. Deepfake audio LastPass CEO impersonation "As the attempted communication was outside of normal business communication channels and due to the employee’s suspicion regarding the presence of many of the hallmarks of a social engineering attempt (such a...

Senators take aim at future quantum-enabled hacking with new bill

By Patrick Tucker,  American Military News Experts believe quantum computing may render some of the core cybersecurity algorithms at the heart of many modern-day digital experiences—from accessing money via an ATM to sending secure messages—obsolete. A new bipartisan bill pushes the U.S. government to prepare more quickly for that eventuality. The problem is a complex one, literally. The public key encryption standards for everything from bank transactions to secure communications are based on the mathematical principle of factorization. A classical computer would take around 300 trillion years to crack them. But a quantum computer, able to process bits composed of values far more diverse than “1” or “0,” could crack the same encryption standard in seconds. While no quantum computer yet exists that can perform such a trick, the rapidly growing field suggests it’s possible within the decade. And that won’t stop adversaries from attempting to steal encrypted data now for later decodi...

China-Made GPS Tracker is Found to Be Risk for Vehicle Hacking

New research shows problems in trackers used by major companies and governments for fleet management. There’s no known fix.  By Jack Gillum,  Bloomberg Vulnerabilities in a popular GPS tracker made in China and used around the world could allow hackers to disrupt vehicles, cut off their fuel and surveil drivers’ movements, according to new research. Several “severe” flaws in the Micodus MV720 tracker affect customers, private companies and government agencies, creating a “high risk” of personal injury, vehicle disablement and supply-chain disruption, according to Boston-based BitSight Technologies. Researchers believe 1.5 million Micodus devices are in use in more than 160 countries. The US Department of Homeland Security issued several warnings Tuesday about the flaws. Micodus didn’t immediately respond to emails and phone calls seeking comment from Bloomberg News since early Monday. In a statement, Eric Goldstein, executive assistant director for the Cybersecurity Infrastruc...

EU warns of Russian cyberattack spillover, escalation risks

By Sergiu Gatlan,  Bleeping Computer The Council of the European Union (EU) said today that Russian hackers and hacker groups increasingly attacking "essential" organizations worldwide could lead to spillover risks and potential escalation. "This increase in malicious cyber activities, in the context of the war against Ukraine, creates unacceptable risks of spillover effects, misinterpretation and possible escalation," the High Representative on behalf of the EU said Tuesday. "The latest distributed denial-of-service (DDoS) attacks against several EU Member States and partners claimed by pro-Russian hacker groups are yet another example of the heightened and tense cyber threat landscape that EU and its Member States have observed." In this context, the EU reminded Russia that all United Nations member states must adhere to the UN's Framework of responsible state behavior in cyberspace to ensure international security and peace. The EU urged all states ...

US journalists targeted by foreign hackers who show sophisticated understanding of American politics

By Sean Lyngaas, CNN In the days before the January 6, 2021, insurrection, Chinese hackers sent out a flurry of malicious emails to prominent White House correspondents and other journalists at major US news outlets in an apparent intelligence collection effort, US cybersecurity firm Proofpoint said Thursday. As Chinese hackers scrambled to ascertain whether there would be a peaceful transfer of power in the US, they tried to break into the email accounts of high-profile US journalists, who can be softer targets for hackers than officials on US government networks. The newly revealed hacking campaign shows just how valuable a target journalists can be to intelligence services in search of clues about US policy. To try to lure them, the attackers wrote email subject lines about then-President Donald Trump's attempts to overturn the 2020 election, pandemic relief legislation and other enticing issues. It's unclear how successful the hacking campaign was -- Proofpoint said it bloc...

Hackers Attack British Army's Twitter, YouTube And Facebook Accounts

By Murtuza Merchant, Benzinga Crypto scammers briefly hacked the official Twitter, YouTube and Facebook accounts of the British army to promote certain non-fungible token (NFT) collections and phishing scams. The press office of the Ministry of Defense confirmed Monday that it was aware of the breach and that an investigation was underway: "The Army takes information security extremely seriously and is resolving the issue. Until their investigation is complete it would be inappropriate to comment further." The official social media accounts were subsequently restored, while scam and phishing links were deleted. It remains unclear who was behind the breach, how many victims were affected and the quantum of funds lost to phishing schemes. According to screenshots posted by Twitter users, hackers promoted at least two derivates of fraudulent NFT collections of “The Possessed” and “BAPESCLAN.” Hackers also pinned a fake NFT mint of “The Possessed” NFT collection, with phishing li...

North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector

CISA, the Federal Bureau of Investigation (FBI), and the Department of the Treasury (Treasury) have released a joint Cybersecurity Advisory (CSA), North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector, to provide information on Maui ransomware, which has been used by North Korean state-sponsored cyber actors since at least May 2021 to target Healthcare and Public Health (HPH) Sector organizations.  CISA, FBI and Treasury urge network defenders to examine their current cybersecurity posture and apply the recommended mitigations in this joint CSA, which include: Train users to recognize and report phishing attempts. Enable and enforce multifactor authentication. Install and regularly update antivirus and antimalware software on all hosts. See North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector for Maui ransomware tactics, techniques, and procedures, indicators of comp...

Canadian Affiliated With NetWalker Ransomware Group Pleads Guilty to Hacking Charges

By Sophie Webster, Tech Times A Canadian who previously worked as an IT expert for the Canadian government has pleaded guilty to being a high-level hacker. He also admitted to being a member of a Russian cyber-crime group. 

Pro-Russia hackers claim responsibility for 'intense, ongoing' cyberattack against Lithuanian websites

By Sean Lyngaas, CNN An "intense, ongoing" cyberattack has hit the websites of government agencies and private firms in Lithuania, the Baltic country's defense ministry said Monday. A Russian-speaking hacking group, known as Killnet , claimed responsibility for at least some of the hacks, saying they were in retaliation for Lithuania blocking the shipment of some goods to the Russian enclave of Kaliningrad, which is wedged between Lithuania and Poland. Monday's cyberattacks were aimed in part at Lithuania's Secure Data Transfer Network, a communications network for government officials that is built to withstand war and other crises, according to the defense ministry. "Part of the Secure National Data Transfer Network users have been unable to access services, work is in progress to restore it to normal," Lithuania's National Cyber Security Centre (NKSC) said in a statement issued by the defense ministry. "It is highly probable that such, or eve...

Chinese hackers use ransomware as decoy for cyber espionage

By Bill Toulas,  Bleeping Computer Two Chinese hacking groups conducting cyber espionage and stealing intellectual property from Japanese and western companies are deploying ransomware as a decoy to cover up their malicious activities. Threat analysts from Secureworks say that the use of ransomware in espionage operations is done to obscure their tracks, make attribution harder, and create a powerful distraction for defenders. Finally, the exfiltration of the sensitive information is masked as financially-motivated attacks, which isn't the case with Chinese government-sponsored threat groups.

Hackers can bring ships and planes to a grinding halt. And it could become much more common

By Sam Shead, CNBC Armed with little more than a computer, hackers are increasingly setting their sights on some of the biggest things that humans can build. Vast container ships and chunky freight planes — essential in today’s global economy — can now be brought to a halt by a new generation of code warriors. “The reality is that an aeroplane or vessel, like any digital system, can be hacked,” David Emm, a principal security researcher at cyber firm Kaspersky, told CNBC. Indeed, this was proven by the U.S. government during a “pen-test” exercise on a Boeing aircraft in 2019.

Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware

By Bill Toulas,  Bleeping Computer The Ukrainian Computer Emergency Response Team (CERT) is warning that Russian hacking groups are exploiting the Follina code execution vulnerability in new phishing campaigns to install the CredoMap malware and Cobalt Strike beacons. The APT28 hacking group is believed to be sending emails containing a malicious document name "Nuclear Terrorism A Very Real Threat.rtf.". The threat actors selected the topic of this email to entice recipients to open it, exploiting the fear that's spread among Ukrainians about a potential nuclear attack. Threat actors also used a similar tactic in May 2022, when CERT-UA identified the dissemination of malicious documents warning about a chemical attack. The RTF document used in the APT28 campaign attempts to exploit CVE-2022-30190, aka "Follina," to download and launch the CredoMap malware (docx.exe) on a target's device. This vulnerability is a flaw in the Microsoft Diagnostic Tool, exploite...

Meet the Administrators of the RSOCKS Proxy Botnet

Image
By  Krebs On Security Authorities in the United States, Germany, the Netherlands and the U.K. last week said they dismantled the “RSOCKS” botnet, a collection of millions of hacked devices that were sold as “proxies” to cybercriminals looking for ways to route their malicious traffic through someone else’s computer. While the coordinated action did not name the Russian hackers allegedly behind RSOCKS, KrebsOnSecurity has identified its owner as a 35-year-old Russian man living abroad who also runs the world’s top Russian spamming forum. According to a statement by the U.S. Department of Justice, RSOCKS offered clients access to IP addresses assigned to devices that had been hacked: “A cybercriminal who wanted to utilize the RSOCKS platform could use a web browser to navigate to a web-based ‘storefront’ (i.e., a public web site that allows users to purchase access to the botnet), which allowed the customer to pay to rent access to a pool of proxies for a specified daily, weekly, or ...

A Rookie Mistake Shows Hackers Aren't All Geniuses

When a ransomware attacker isn’t up to snuff, the damage might be limited. By Tim Culpan,  Bloomberg For more than two decades, ransomware attacks have been the bane of corporate IT managers and their CEOs, and a source of much research for cybersecurity professionals. An underground market for hacking and encryption tools has helped such incursions proliferate, but thankfully a recent case shows what we can learn when attackers don’t know what they’re doing.  Unlike other cyber nuisances, such as viruses, which replicate and cause mayhem, or denial of service attacks, which bring networks to a grinding halt, ransomware is almost impossible to unwind once it’s been deployed successfully. That’s because they use encryption to lock up the files, with a secret decryption key being the only route out.  Rather than try to undo this encryption, most victims just write off the files and restore their systems using backups. This can take days or weeks, assuming the target ha...

Iranian hack likely set off sirens in Jerusalem, Eilat, say cyber-security experts

Report: The attack targeted municipal alert systems but did not breach essential IDF infrastructure. By  JNS A suspected Iranian cyber attack likely set off rocket-warning sirens in the cities of Jerusalem and Eilat on Sunday, Israeli media reported. Israeli cyber-security authorities said the attack targeted municipal alert systems but did not breach essential IDF infrastructure, according to Ynet. Authorities “instructed local councils to take precautionary steps to secure their alert systems, since they were activated by municipal alert systems and not by the IDF’s Home Front Command,” the report issued on Monday said. The report cited Yoram Cohen, head of the Israel Internet Association, as saying that the hack “did not appear to harm any vital infrastructure,” but that it had once again exposed vulnerabilities in civilian systems. “There is a gap between Israel’s excellent cyber defenses on critical infrastructure compared to non-critical civilian systems,” said Cohen. “This w...

Previously Undiscovered Team of State-Sponsored Chinese Hackers, Has Been Quietly Committing Cyber Espionage in the APAC Region for a Decade

By Scott Ikeda,  CPO Magazine A new advanced persistent threat (APT) group linked to China has been discovered by SentinelLabs, but only after conducting cyber espionage campaigns under the radar since 2013. The Chinese hackers have been given the name “Aoqin Dragon,” appear to specialize in targeting the Asia Pacific region and likes to lure victims with malicious documents that appear to be salacious ads for pornography sites.