Voici la sélection des cyberattaques majeures découvertes la semaine passée.
Vous retrouvez ci-dessous les liens directs vers les articles les plus intéressants. Pour information, cette veille est préparée avec un vrai cerveau non artificiel, alors bonne lecture et merci de soutenir le Décodeur !
Les actus sélectionnées cette semaine
Botnet sent millions of emails in LockBit Black ransomware campaign
Since April, millions of phishing emails have been sent through the Phorpiex botnet to conduct a large-scale LockBit Black ransomware campaign.
Des étudiants piratent 1 million de machines à laver
Deux étudiants ont découvert une faille permettant d’utiliser gratuitement plus d’un million de machines à laver connectées. Malgré leurs alertes, l’entreprise CSC ServiceWorks n’a pas réagi, exposant les risques de sécurité liés aux objets connectés.
Banking malware Grandoreiro returns after police disruption
The banking trojan « Grandoreiro » is spreading in a large-scale phishing campaign in over 60 countries, targeting customer accounts of roughly 1,500 banks.
Black Basta Ransomware Victim Count Tops 500
Affiliates of prolific Black Basta ransomware group have breached over 500 global organizations
Windows Quick Assist Exploited in Ransomware Attacks
Microsoft warned Storm-1811 started vishing attacks in April to gain access to target devices
E-prescription provider MediSecure impacted by a ransomware attack
Electronic prescription provider MediSecure in Australia suffered a ransomware attack likely originate from a third-party vendor.
UK Councils Warn of Data Breach After Attack on Medical Supplier
Multiple UK councils have warned that residents’ personal data may have been compromised following a ransomware attack on NRS Healthcare
Russian Actors Weaponize Legitimate Services in Multi-Malware Attack
Recorded Future details a novel campaign that abuses legitimate internet services to deploy multiple malware variants for credential theft
Russian hackers use new Lunar malware to breach a European govt’s agencies
Security researchers discovered two previously unseen backdoors dubbed LunarWeb and LunarMail that were used to compromise a European government’s diplomatic institutions abroad.
Pro-Russia hackers targeted Kosovo government websites
Pro-Russia hackers targeted government websites in Kosovo in retaliation for the government’s support to Ukraine with military equipment.
Kinsing Hacker Group Exploits More Flaws to Expand Botnet for Cryptojacking
Kinsing cryptojacking group evolves again, targeting new vulnerabilities to expand its botnet.
Cyberattaque à Pau : aéroport et école de commerce touchés – Le Monde Informatique
Intrusion, Hacking et Pare-feu : Une attaque informatique a frappé plusieurs infrastructures à Pau à savoir l’aéroport, le campus numérique ainsi que l’école de commerce Eklore (ex…
North Korea-linked Kimsuky APT attack targets victims via Messenger
North Korea-linked Kimsuky APT group employs rogue Facebook accounts to target victims via Messenger and deliver malware.
Ukrainian, Latvian TV Hijacked to Broadcast Russian Celebrations
At least 15 television channels were interrupted in Ukraine alone, which, reportedly, is not out of the norm in this « information war. »
INC ransomware source code selling on hacking forums for $300,000
A cybercriminal using the name « salfetka » claims to be selling the source code of INC Ransom, a ransomware-as-a-service (RaaS) operation launched in August 2023.
FCC reveals Royal Tiger, its first tagged robocall threat actor
The Federal Communications Commission (FCC) has named its first officially designated robocall threat actor ‘Royal Tiger,’ a move aiming to help international partners and law enforcement more easily track individuals and entities behind repeat robocall campaigns.
UK NCSC Launches New Hacking Alert System for Politicians
The U.K. government launched a cyber defense system for alerting political parties and candidates to cyberthreats amid concerns over increased nation-state hacking.
UK engineering firm Arup falls victim to £20m deepfake scam
Hong Kong employee was duped into sending cash to criminals by AI-generated video call
400k Linux Servers Hacked to Mine Cryptocurrency
The botnet, operated by the threat group behind the Ebury malware, has been active since at least 2009 but has evolved over the past decade.
Turla APT Group Attacking European Ministry of Foreign Affairs
The well-known advanced persistent threat (APT) group Turla, which is based in Russia, is said to be going after the European Ministry.