News

Hi folks,

I hope this particular newsletter finds you well :-) My last exam was a success, I made it through the gaunlet, and now I can focus on regular work again! Just in time for the holidays ^^

This week is a doozy, lot's of interesting articles to share, but I've tried to keep it as short as possible. It feels like most reporters and researchers are pushing stuff out the door before a two-week vacation :-)

Enjoy the read, and enjoy the upcoming holidays!

Cheers,

Dieter







Quick stories

  • DOJ indicts 14 North Koreans who fraudulently earned $88 million working for US firms: link.
  • CISA urges switch to Signal-like encrypted messaging apps after telecom hacks: link.
  • Kali Linux 2024.4 released with 14 new tools, deprecates some features: link.

Breaches and leaks

  • Texas Tech University System data breach impacts 1.4 million patients: link.
  • ConnectOnCall breach exposes health data of over 910,000 patients: link.
  • Rhode Island governor warns residents of cyberattack on state benefits system: link.
  • Namibia’s state telecom provider says hackers leaked data after it refused to pay ransom: link.
  • Auto parts giant LKQ says cyberattack disrupted Canadian business unit: link.
  • Japanese game and anime publisher reportedly pays $3 million ransom to Russia-linked hackers: link.
  • South Carolina credit union says 240,000 impacted by recent cyberattack: link.
  • Ireland fines Meta $264 million over 2018 Facebook data breach: link.
  • BeyondTrust says hackers breached Remote Support SaaS instances: link.
  • Chainalysis: $2.2 billion stolen from crypto platforms in 2024 cyberattacks: link.

Crime doesn't (always) pay

Maybe a fun section to include once every while :-)

  • Raccoon Stealer malware operator gets 5 years in prison after guilty plea: link.
  • Romanian Netwalker ransomware affiliate sentenced to 20 years in prison: link.

Issues and fixes

  • Fortinet warns of FortiWLM bug giving hackers admin privileges: link.
  • Citrix shares mitigations for ongoing Netscaler password spray attacks: link.
  • Windows kernel bug now exploited in attacks to gain SYSTEM privileges: link.
  • Over 25,000 SonicWall VPN Firewalls exposed to critical flaws: link.
  • New critical Apache Struts flaw exploited to find vulnerable servers: link.
  • Cleo urges customers to ‘immediately’ apply new patch as researchers discover new malware: link.