Today’s cybersecurity landscape is abuzz with activity, from new threats to significant breaches. Here’s a detailed report on the latest developments:
Brand New Threats
Zero-Day Exploits in Ivanti VPN Products: The MITRE Corporation reported a security event linked to Chinese APT group UNC5221. Two zero-day vulnerabilities were exploited, allowing session hijacking and lateral movement across MITRE’s NERVE network.
Brand New Breaches
Frontier Communications: A cyberattack led to unauthorized access to IT systems, causing operational disruptions and compromising personal data.
United Nations Development Programme (UNDP): The 8Base ransomware gang targeted the UNDP, exfiltrating data from a locally hosted server involving human resources and procurement information. The agency has refused to pay the ransom.
Cherry Health: This Michigan-based healthcare provider was hit by a ransomware attack that encrypted vital data and disrupted clinical services.
Tyler Technologies: A ransomware attack by the LockBit group compromised significant data from this third-party provider to Washington D.C.’s Department of Insurance, Securities, and Banking (DISB).
Military Breaches
Phishing Campaign by Fin7: This financially motivated group targeted IT staff within a major America-based automaker company, deploying the Anunak backdoor malware for financial gain and data theft.
Stay informed and stay secure. Remember, in the digital age, vigilance is your best defense.
