Hackmanac Cyber Alerts
رفتن به کانال در Telegram
🚩 Channel was restricted by Telegram
نمایش بیشتراطلاعاتی وجود ندارد
مشترکین
-624 ساعت
-567 روز
-15230 روز
آرشیو پست ها
🚨Cyberattack Alert ‼️
🇺🇸USA - Vermilion Parish School Board
Rhysida ransomware group claims to have breached Vermilion Parish School Board and is demanding 15 BTC (approx. $1,400,000) in ransom to be paid by December 4, 2024.
On October 7, Vermilion Parish School Board reported being affected by a possible cyberattack, which caused all schools in the network to go offline. The attack disrupted internet and phone services, with schools such as Abbeville High School and LeBlanc Elementary later restoring their phone lines that same day.
🚨Cyberattack Alert ‼️
🇵🇪Peru - Fuero Militar Policial
Cloak ransomware group claims to have breached Fuero Militar Policial and to have sold the exfiltrated data amounting to 221 GB.
The attack had previously been posted on the group's DLS on December 16, but with the victim's name censored.
Someone Made a Dataset of One Million Bluesky Posts for "Machine Learning Research".
As Joseph Cox, the co-founder of 404 Media writes:
"Bluesky may have said it won't use user data to train generative AI, but someone else just published a dataset of million Bluesky posts for 'machine learning research'. Already very popular dataset, your data may be scraped"
https://www.404media.co/someone-made-a-dataset-of-one-million-bluesky-posts-for-machine-learning-research/
🚨Cyberattack Alert ‼️
🇬🇪Georgia - Silknet
The unnamed hacking group behind the data leak site known as "Ransomware Blog" claims to have breached Silknet, a telecommunications company based in Georgia, and is demanding a ransom of $800,000.
Allegedly, 3 TB of data were exfiltrated, including the company email base, customer data, company audit for 2023/24, corporate data, passports, and other information.
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 20 - 26 November 2024
⚠️247 cyberattacks across 44 countries ⚠️
➡️The most active threat actor this week is SafePay claiming responsibility for 27 attacks.
➡️The USA is the most affected country, accounting for 42% of the victims, with 103 cyberattacks.
➡️The Professional, Scientific and Technical sectors are the most impacted, representing 14% of the claimed targets.
➡️Overall, the claimed compromised data amounts to approximately 35 TB.
☣️The average ESIX® (Estimated Severity Index) is 4.5.
Follow the link for list of referred victims:
https://hackmanac.com/news/hack-tuesday-week-20-26-november-2024
#Hackmanac #HT #Cybersecurity
🚨Cyberattack Alert ‼️
🇦🇪UAE - GMG
Lynx ransomware group claims to have breached GMG.
Allegedly, exfiltrated data includes passports, fresh documents, and personal information.
🚨🚨Zero-Day 🚨🚨
RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks
https://thehackernews.com/2024/11/romcom-exploits-zero-day-firefox-and.html
The Russia-aligned threat actor known as RomCom has been linked to the zero-day exploitation of two security flaws, one in Mozilla Firefox and the other in Microsoft Windows, as part of attacks designed to deliver the eponymous backdoor on victim systems.
🚨Cyberattack🚨
🇯🇵Japan - The Fukushima Prefectural Police's email server was exploited to relay approximately 50,000 emails with the subject "Notice" or similar to domestic and international recipients.
https://www.tokyo-np.co.jp/article/369639?rct=national
The attack occurred between 6:00 a.m. and 2:00 p.m. on November 26, 2024. The targeted server was an external-facing server used for public relations and corporate communications, while the internal server for police communication remained unaffected.
🚨Credential Stuffing
🇯🇵Japan - Oisix ra daichi Inc. (オイシックス・ラ・大地)
A credential stuffing attack targeted Oisix[.]com, compromising approximately 97,533 customer accounts between November 24 and 25, 2024.
Unauthorized logins allowed attackers to potentially access sensitive personal data, including names, addresses, phone numbers, email addresses, delivery information, and purchase history. However, no credit card information or sensitive healthcare data was exposed.
Oisix reset passwords for affected accounts on November 25, 2024, and advised customers to use unique, regularly updated passwords.
Source:
https://www.oisixradaichi.co.jp/news/posts/20241126/
🚨Cyberattack Alert ‼️
🇪🇨Ecuador - Reliv
RansomHub ransomware group claims to have breached Reliv.
Allegedly, 30 GB of data were exfiltrated. The sample provided shows sensitive patient data.
Ransom deadline: 06th Dec 24.
🚨Cyberattack Alert ‼️
🇮🇹Italy - SCM Group
Lynx ransomware group claims to have breached SCM Group.
Allegedly, 700 GB of data were exfiltrated, including HR records, customer data, confidential documents, contracts, financial data, and incident reports.
🚨Cyberattack Alert ‼️
🇧🇩Bangladesh - Government of the People's Republic of Bangladesh
Kill Security hacking group claims to have breached the Government of the People's Republic of Bangladesh. Allegedly, agreements, financial data, technical documents, and more were exfiltrated.
Ransom deadline: 13th Dec 24.
🚨Ransomware - Blue Yonder, an Arizona-based software company owned by Panasonic, suffered a ransomware attack on November 21, 2024.
The attack disrupted its private cloud computing services used by clients, including major US and UK grocery chains and Fortune 500 companies, while its public cloud environment remained unaffected.
In the UK, grocery chains Morrisons and Sainsbury reported disruptions to their operations, with Morrisons experiencing delays in the flow of goods and Sainsbury activating contingency plans.
Source:
https://www.wral.com/story/software-company-providing-services-to-us-and-uk-grocery-stores-says-it-was-hit-by-ransomware-attack/21739436/
🚨Data Breach Alert 🚨
🇯🇵Japan - JR West Via Inn Prime Nihonbashi Ningyocho
On November 25, 2024, the Via Inn Prime Nihonbashi Ningyocho in Japan, operated by JR West Group experienced unauthorized access to its Booking[.]com reservation management system.
The attack led to phishing messages being sent to some customers via the system's chat feature, containing links to malicious websites. Additionally, customer data, including names, addresses, and phone numbers, for reservations made through Booking[.]com from November 26, 2023, to September 30, 2025, may have been exposed.
The breach occurred after the attackers stole login credentials via a phishing email targeting the hotel's staff.
Source:
https://www.westjr.co.jp/press/article/items/24112500_pressviainn.pdf
🚨Ransomware - Starbucks forced to pay its baristas manually because of a ransomware attack on third-party software
https://edition.cnn.com/2024/11/25/tech/starbucks-ransomware-attack/index.html
🚨Cyberattack Alert ‼️
🇺🇸USA - STIIIZY
Everest ransomware group claims to have breached STIIIZY, a premium quality cannabis product supplier.
Allegedly, client personal data and IDs, totaling 422,075 personal records, were exfiltrated.
Ransom deadline: 08th Dec 24.
🚨Cyberattack Alert ‼️
🇦🇪UAE - DarDoc
Kill Security hacking group claims to have breached DarDoc, a health-tech startup.
Allegedly, personally identifiable information such as names, birthdates, ID numbers, passport details, and residency information were exfiltrated. The data also includes sensitive medical records, such as hormone test results and COVID-19 PCR test results, as well as employment certifications detailing job history, positions, and durations.
Ransom deadline: 03rd Dec 24.
🚨Cyberattack
🇯🇵Japan - Kumamoto Prefecture Violence Prevention Movement Promotion (熊本県暴力追放運動推進センター)
On November 15, 2024, an employee of the Kumamoto Prefecture Violence Prevention Movement Promotion Center was redirected to a fraudulent support scam website during work, resulting in unauthorized access to their computer.
Although the employee quickly disconnected the device from power and the network, it is possible that personal information used in operations was leaked.
The Kumamoto Prefecture Violence Prevention Movement Promotion Center is a Japanese government agency that provides a confidential helpline for victims of the Yakuza, Japan's infamous organized crime syndicate, and for Yakuza members seeking to escape its control.
Source:
https://www.kumamoto-boutsui.com/
🚨Data Breach - Hackers breach Andrew Tate’s online university.
According to Have I Been Pwned, "The Real World" had 324k email addresses breached.
https://www.dailydot.com/debug/andrew-tate-the-real-world-hack/
🚨Cyberattack Alert ‼️
🇦🇪UAE - Gulf Energy Maritime
Ra World ransomware group claims to have breached Gulf Energy Maritime, a Product/Chemical Tanker company which provides Marine Transportation for the energy markets across the world.
Allegedly, 90 GB of data were exfiltrated, including business contracts, board documents, legal documents, financial documents, customer information, insurance contracts, claims history, bank documents, employment contracts, confidentiality agreements, audit files, passports, departmental data, and other files.
Ransom deadline: 15th Dec 24.
