Listen to today's episode on the APJONE.UK Daily Briefing podcast.
Ransomware Attacks (48h)
34 victims across 13 groups
- incransom (7): lantisnet.com 🇺🇸 (Technology), Loyalist College 🇨🇦 (Education), TRULITE GLASS & ALUMINUM SOLUTIONS 🇺🇸 (Manufacturing), geleximco.vn 🇻🇳 (Manufacturing), lccgroup.com 🇵🇭 (Professional Services), pushidrosal.id 🇮🇩, ⚠️ Oleoductos del Valle 🇦🇷 (Energy)
- SafePay (9): pradotuylaw.com 🇺🇸, naskdoorinc.com 🇺🇸, southshorerecycling.com 🇺🇸, multiaqua.com 🇺🇸, cpu-ag.com 🇩🇪, new-point.it 🇮🇹, simonrack.com 🇪🇸, azn.co.jp 🇯🇵, hanan-hov.co.il 🇮🇱
- Qilin (5): Galvin Brothers 🇮🇪 (Manufacturing), RUPP Spritzguss 🇩🇪 (Manufacturing), Service Electric 🇺🇸 (Energy), Universitatea De Vest Vasile Goldi Din Arad 🇷🇴 (Education), WD Masonry 🇺🇸
- Anubis (2): ⚠️ Cameron Regional Medical Center 🇺🇸 (Healthcare), Winn-Dixie 🇺🇸 (Retail)
- The Gentlemen (2): Control Concepts Technology 🇺🇸, TopMark Funding 🇺🇸 (Financial)
- Aurora (2): GILDE Handwerk Macrander GmbH & Co. KG 🇩🇪, US Installation Group 🇺🇸
- Play (2): First Tek 🇹🇼 (Technology), Preferred Financial Group 🇺🇸 (Financial)
- Chaos (1): ⚠️ healthcarehighways.com 🇺🇸 (Healthcare)
- krybit (1): cesmac.edu.br 🇧🇷 (Education)
- gunra (1): worldtube 🇰🇷 (Technology)
- akira (1): University SprinklerSystems (Manufacturing)
- dragonforce (1): TUI China 🇨🇳 (Hospitality)
Round Up Security News
- ChainDrop supply chain compromise: Anatomy of a self-propagating worm — Microsoft Security Blog
- AI researchers let models off the leash — they tried to add malware to a FOSS project — The Register
- Pass the Passkey: A Novel Attack Surface in Passwordless Authentication — Unit 42
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks — BleepingComputer
- New XCSSET variant targets macOS devs via compromised Xcode projects — BleepingComputer
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts — BleepingComputer
- IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay — mysk.blog
- 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET — Microsoft Security Blog