Hackmanac Cyber Alerts
Відкрити в Telegram
Немає даних
Підписники
-624 години
-567 днів
-15230 днів
Архів дописів
⚠️Microsoft warns that some Windows devices will boot into BitLocker recovery after installing the July 2024 security updates.
https://www.bleepingcomputer.com/news/microsoft/windows-july-security-updates-send-pcs-into-bitlocker-recovery/
#CrowdStrike - Preliminary Post Incident Review (PIR):
Content Configuration Update Impacting the Falcon Sensor and the Windows Operating System (BSOD)
Details include the incident overview, remediation actions, and preliminary learnings. More to come in our full Root Cause Analysis (RCA).
PIR available at the link below.
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
🚨 #CyberAttack 🚨
🇷🇴 #Romania, Electroalfa
Electroalfa has been listed as a victim by the Akira ransomware group.
The hackers allegedly exfiltrated 10 GB of data, including projects information, clients, and detailed personal employee information.
#Ransomware
🚨 #CyberAttack 🚨
🇺🇸 #USA, Dimbleby Funeral Homes
Dimbleby Funeral Homes, a company offering comprehensive funeral and cremation services in Whitesboro, has been listed as a victim by the DragonForce ransomware group.
The hackers allegedly exfiltrated 163.98 GB of data.
Ransom deadline: 30th Jul 24.
#Ransomware
🚨 #CyberAttack 🚨
🇮🇹 #Italy, Regas
Regas has been listed as a victim by the Monti ransomware group.
Ransom deadline: 20th Aug 24.
#Ransomware
🚨 #CyberAttack 🚨
🇺🇸 #USA, Andersen Tax
Andersen Tax LLC, a tax firm headquartered in San Francisco, has been listed as a victim by the Meow hacking group.
The hackers allegedly exfiltrated SQL databases containing sensitive client data and financial records.
Ransom demand: $300.
#Ransomware
🚨 #CyberAttack 🚨
🇧🇷 #Brazil, NUCLEP - Hackers Demand $500,000
Nuclebrás Equipamentos Pesados S.A. (NUCLEP), a state-owned Brazilian company associated with the Ministry of Mines and Energy, has been listed as a victim by the Meow hacking group.
The hackers allegedly exfiltrated 250 GB of data, including:
- Defense production,
- Production and extraction of nuclear materials,
- Military nuclear submarines,
- AutoCAD designs (3D, DWG, etc.),
- Videos and photos of uranium extraction,
- Oil and gas data,
- Geographic coordinates,
- Employee data (emails, passwords, names, etc.).
Ransom demand: $500,000.
NUCLEP's primary mission is to design, develop, manufacture, and commercialize heavy equipment for various sectors, including nuclear energy, defense, oil and gas, and other industrial applications.
#Ransomware
🚨 #CyberAttack 🚨
🇺🇸 #USA, City of Miami Gardens - Hackers demand $500,000
City of Miami Gardens has been listed as a victim by the Meow hacking group.
The hackers allegedly exfiltrated 80 GB of data, including tax documents, police employee data, insurance records, police employment forms, budgets, personal information, and contracts.
#Ransomware
🚨 #CyberAttack 🚨
🇺🇸 #USA, siParadigm Diagnostic Informatics
siParadigm Diagnostic Informatics has been listed as a victim by the Akira ransomware group.
The hackers allegedly exfiltrated 141 GB of data, including a full pack of personal data such as passports, NDAs, confidential agreements, medical reports, driver licenses, birth certificates, social security numbers and other personal documents, financial info, and clients.
#Ransomware
🚨 #CyberAttack 🚨
🇭🇷 #Croatia, Eurovilla
Eurovilla, Croatia's premier luxury real estate agency, has been listed as a victim by the Dark Vault hacking group.
Ransom deadline: July 30, 2024.
#Ransomware
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 17 - 23 July 2024
🚨 94 victims by 23 hacking groups 🚨
The most active ransomware group this week is LockBit 3.0 with 20 claimed attacks.
The most affected country is the United States, accounting for 49% of the victims, while the Manufacturing sector is the most impacted, accounting for 16% of the claimed targets, followed by the Professional, Scientific and Technical sectors with 15% and Education with 12%.
The average Cyber Risk Factor is 4.1.
#Ransomware #DataBreach #CyberAttack #HT
🚨 #CyberAttack - Win Systems
Win Systems, global technology provider for the gaming and entertainment industry, has been listed as a victim by the Akira ransomware group.
The hackers allegedly exfiltrated 10 GB of data, including lots of passports, DNIs (identification cards), credit cards, and other personal documents of employees, as well as information of clients and casinos, financials, and other internal business data.
#Ransomware
🚨 #CyberAttack 🚨
🇮🇪 #Ireland, Inishowen Gateway Hotel
Inishowen Gateway Hotel has been listed as a victim by the INC Ransom ransomware group.
The hackers allegedly exfiltrated contracts, financial data, confidential data, incident reports, agreements, etc.
#Ransomware
🚨#DataLeak: Uhive - 17K user details, including Ethereum wallets associated with Twitter accounts, allegedly leaked on a hacking forum
A threat actor claims to have stolen and leaked 17K user details from an airdrop sign-up belonging to Uhive.
Among the leaked information are email addresses, full names, Ethereum wallet addresses, and references to the associated X account.
Uhive is a social network that lets users socialize, interact, and find people across the world while earning its own digital currency
#ETH #CyberAttack
🚨 #CyberAttack 🚨
🇮🇳 #India, Byzan Systems
Byzan Systems has been listed as a victim by the RansomHub ransomware group.
The hackers allegedly exfiltrated 120 GB of data.
Ransom deadline: 30th Jul 24.
#Ransomware
🚨🚨🚨 #CyberAttack 🚨🚨🚨
🇺🇸 #USA, LawDepot - Hackers Demand 30 BTC
LawDepot has been listed as a victim by the Rhysida ransomware group.
The hackers allegedly exfiltrated 5.5 TB of data, including:
- Backup of the SQL database
- Full dump of the websites:
lawdepot.com,
lawdepot.co.uk,
documentslegaux.fr,
rechtsdokumente.de,
legalcontracts.com,
lawdepot.ca
- Internal passwords
- Certificates for databases
- Confidential customer information (credit cards, PayPal data, customer legal documents) of several countries
- Internal LawDepot-wiki knowledge base
- Full company internal GitLab.
Ransom demand: 30 BTC (approx. $2,000,000). Ransom deadline: 30th Jul 24.
#Ransomware
List of claimed attacks:
CyberVolk - July 23
- Basque Parliament
shapito666 - July 22
- Constitutional Court of Spain
- Parlamento de Galicia
- Spanish Road Association (AEC)
- Court of Arbitration of Madrid
- General Assembly of the Principality of Asturias
- Basque Parliament
- Spanish Agency for International Development Cooperation
- Ministry of Foreign Affairs, European Union and Cooperation
HackNeT - July 22
- Madrid Court of Arbitration
- Sedigas
NetForceZ - July 22
- Ministry of Foreign Affairs, European Union and Cooperation
RUSSIAN TASK POWER - July 22
- Trablisa
- Nexus Energía, S.A.
- Madrid Regional Transport Consortium
CyberDragon - July 22
- Parlamento de Galicia
- Parlamento de Andalucía
- Ministerio de Hacienda
- La Moncloa
Russian Cyber Army Team - July 22
- National Police of Spain
NoName - July 22
- Huelva Port
- PortCastelló
- Port of Palma de Mallorca
- Port Authority of Vigo
- Port Authority of Cartagena
- Valencia City Council
🚨 #DDoS 🚨
🇪🇸#Spain: Surge in DDoS Attacks: 26 Claims in the Last 24 Hours
Following the arrest of three individuals by Spanish authorities for using the pro-Russian DDoSia platform to attack NATO entities, DDoS attacks by various hacktivist groups have surged, with 26 attacks claimed in the past 24 hour.
Moreover, a new Russian-speaking hacktivist collective called Holy League is calling on other pro-Russian hacker groups to join forces and direct their full capabilities against Spain's internet infrastructure in support of the detained.
Spanish law enforcement video of the devices' seizure during the arrests:
https://www.youtube.com/watch?v=QRW8mwVf2YQ
#CyberAttack
CrowdStrike FORM 8-K with the SEC:
"On July 19, 2024, CrowdStrike Holdings, Inc. (“we” or “us”) released a sensor configuration update for our Falcon sensor software that resulted in outages for a number of our customers utilizing certain Windows systems (the “event”). The event was not caused by a cyberattack.
We urgently mobilized teams to support the security and stability of our customers.
Certain Windows systems that were online when the update was released at 4:09 UTC on July 19 were affected. We identified and isolated the issue and the update was reverted at 5:27 UTC. We continue to work with impacted customers to fully restore their systems. As part of that effort, we have provided remediation information through our customer support portal and published event-related updates accessible through our blog at www.crowdstrike.com/blog.
This is an evolving situation. We continue to evaluate the impact of the event on our business and operations."
#Crowdstirke
🚨 #CyberAttack 🚨
🇨🇳 #China, TCC Group
TCC Group has been listed as a victim by the LockBit 3.0 ransomware group.
Ransom deadline: 01st Aug 24.
#Ransomware
