A Europol-headed law enforcement operation has put a serious dent in the dropper malware ecosystem, disrupting the botnets that these dropper systems rely on to function, with over 100 servers and 2,000 domains impacted across about a dozen countries.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Auction house Christie’s is currently notifying customers of a significant data breach after the RansomHub ransomware group threatened to leak the stolen sensitive personal information.
A hacker with the threat group ShinyHunters appears to have confirmed the attack to a security research firm and claims that cloud storage company Snowflake, which is used by numerous major corporations, is the source of the the Ticketmaster data breach.
Prescription management provider Sav-Rx is notifying 2.8 million individuals of a data breach impacting their personal information after an unauthorized party accessed certain non-clinical systems.
The British Broadcasting Corporation (BBC) has notified the UK's Information Commissioner's Office (ICO) and the Pensions Regulator of an employee data breach affecting 25,000 BBC Pension Scheme members.
The attack has been attributed to an older remote access trojan that was able to take out 49% of the modems from the ISP's ASN, in what is believed to be a targeted cyber attack intended to cause a prolonged outage of internet routers.
The situation is very similar to the assorted US bans on TikTok, but concerns about Kaspersky products are not new among federal agencies; the national government banned its civilian agencies from using them in 2017.
A cyber attack on London hospitals that has unfolded over the course of June has had a devastating impact on the city's blood supply, and has caused hundreds of operations to be postponed.
A leak on a hacking forum that exposed internal AMD data appears to have been confirmed by the company, as it acknowledged that an unnamed third-party vendor involved in product assembly was breached. Questions remain about the extent of the data breach, however.
The National Railroad Passenger Corporation is notifying customers of a data breach affecting their Amtrak Guest Rewards accounts. Amtrak believes the threat actor gained access via a credential stuffing attack.










