News

Hi friends,

We're a bit heavy on breaches and issues this week, I hope you can gently read through the list without having it ruin your day.

Also, if you're like me and you find yourself excited for the launch of ... a cybersecurity consumer label, congratulations, you're old and boring like me. Let's make t-shirts.

Enjoy the read folks ;-)

Cheers,

Dieter




Quick stories

  • Chinese hackers also breached Charter and Windstream networks: link.
  • US sanctions prominent Chinese cyber company for role in Flax Typhoon attacks: link.
  • National cyber director calls for deterrence against China-affiliated cyber threats: link.

Breaches and leaks

  • UN aviation agency confirms recruitment database security breach: link.
  • Largest US addiction treatment provider notifies patients of data breach: link.
  • Massive breach at location data seller: "Millions" of users affected: link.
  • Hackers claim to breach Russian state agency managing property, land records: link.
  • Some Winston-Salem city services knocked offline by cyberattack: link.
  • Education software firm’s hack exposes personal data for students, teachers nationwide: link.
  • School districts in Maine, Tennessee respond to holiday cyberattacks: link.
  • French govt contractor Atos denies Space Bears ransomware attack claims: link.
  • Casio says data of 8,500 people exposed in October ransomware attack: link.
  • Data of more than 8,500 customers breached on Green Bay Packers shopping website: link.
  • Washington state sues T-Mobile over 2021 data breach security failures: link.
  • Cryptocurrency wallet drainers stole $494 million in 2024: link.

Issues and fixes

  • Bad Tenable plugin updates take down Nessus agents worldwide: link.
  • Nuclei flaw lets malicious templates bypass signature verification: link.
  • Vulnerable Moxa devices expose industrial networks to attacks: link.
  • Malicious npm packages target Ethereum developers' private keys: link.
  • CISA warns of critical Oracle, Mitel flaws exploited in attacks: link.
  • SonicWall urges admins to patch exploitable SSLVPN bug immediately: link.
  • Ivanti warns of new Connect Secure flaw used in zero-day attacks: link.
  • Unpatched critical flaws impact Fancy Product Designer WordPress plugin: link.
  • Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens: link.