Hackmanac Cyber Alerts
Kanalga Telegram’da o‘tish
Ma'lumot yo'q
Obunachilar
-624 soatlar
-567 kun
-15230 kun
Postlar arxiv
🚨Cyberattack Alert ‼️
🇧🇷Brazil - Government of Brazil
Kill Security hacking group claims to have breached the Government of Brazil.
Allegedly, 100 GB of data, including names of individuals and companies, addresses, contact information, CNPJ/CPF numbers, transaction amounts, bank account numbers, and information related to specific services and contracts, were exfiltrated.
Ransom demand: $25,000.
+3
🚨Cyberattack Alert ‼️
🇲🇽Mexico - Grupo Aeroportuario del Centro Norte (OMA)
RansomHub ransomware group claims responsibility for the attack on Grupo Aeroportuario del Centro Norte (OMA).
Allegedly, exfiltrated data includes investment reports, financial documents, sales and accounting data, and shareholder information. Personal information of investors, client lists, assessments, agreements, and personal data of employees and customers—such as addresses, contacts, passport scans, confidential internal correspondence, passwords, credentials, and SQL databases—were also compromised.
Additionally, the group makes bold claims, stating they have evidence of some employees collaborating with cartels.
Ransom deadline: 2nd Nov 2024.
🚨Cyberattack Alert ‼️
🇺🇸USA - Value City Furniture NJ
Fog hacking group claims to have breached Value City Furniture NJ.
Allegedly, exfiltrated data include human resources files, customer contacts, medical documents, login credentials, SSNs, and employee phone numbers.
🚨Cyberattack ‼️
🇯🇵Japan - LY Corporation (LINEヤフー株式会社)
On August 27, 2024, LINE identified unauthorized logins targeting LINE Business IDs, resulting in the hijacking of several official LINE accounts. The attack used a credential-stuffing technique, where attackers exploited previously leaked email and password combinations.
In total, 12 LINE Business IDs in Japan and 156 globally were compromised. Attackers accessed official LINE accounts, sending suspicious messages and viewing some user information. The affected users were notified, and measures such as password resets and session invalidations were implemented. The attack mainly targeted LINE Business IDs that had not enabled two-factor authentication.
LINE advises users to remain cautious of phishing attempts and suspicious messages linked to these compromised accounts.
Source:
https://www.lycorp.co.jp/ja/privacy-security/announcement/009487/
🚨Cyberattack Alert ‼️
🇺🇸USA - Legacy Treatment Services
Interlock hacking group claims to have breached Legacy Treatment Services.
Allegedly, 170 GB of data, including internal documents, patient records, and a large SQL database, were exfiltrated.
🚨 Cyberattack Alert ‼️
🇮🇹 Italy - SMEG
Interlock ransomware group claims responsibility for the cyberattack at SMEG.
Allegedly, 820 GB of corporate documents were exfiltrated, including a dump of mailboxes from all employees, company developments, and personal data of employees.
SMEG suffered a cyberattack on September 27, 2024, which disrupted its internal network systems. The attack affected critical areas such as production, logistics, human resources, and accounting software. As a precautionary measure, SMEG halted operations to prevent further damage, including the potential loss of sensitive data.
🚨Lazarus Group Exploits Google Chrome Zero-Day Vulnerability (CVE-2024-4947) to Control Infected Devices Targeting Individuals in the Cryptocurrency Sector. 🚨
https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
🚨Zero-day Update 🚨
Fortinet Discloses Zero-Day Exploited by UNC5820 in Active Attacks Since June, Reports Mandiant
Fortinet has finally disclosed a zero-day vulnerability, CVE-2024-47575, affecting FortiManager, which had been actively exploited in the wild.
Dubbed "FortiJump" by researcher Kevin Beaumont, the vulnerability allows remote code execution and the theft of sensitive data, including IP addresses, credentials, and device configurations. Attackers need a valid certificate from Fortinet devices to connect to FortiManager via the FGFM protocol.
Mandiant reported that threat actor UNC5820 has been exploiting FortiManager devices since June 27, 2024, compromising FortiGate configuration data and hashed passwords prior to Fortinet’s disclosure.
🚨Cyberattack Alert ‼️
🇮🇱🇺🇸 Picsolve - Pomvom
Cactus ransomware group claims to have breached Picsolve, a company that merged with Pomvom in 2020.
Picsolve is a leading digital content capture partner for visitor attractions, and Pomvom is a Tel Aviv-based artificial intelligence (AI) company.
Allegedly, 620 GB of data were exfiltrated, including personally identifiable information, actual database backups, corporate confidential data and correspondence, customer data, contracts, financial documents, and more.
🚨Cyberattack Alert ‼️
🇬🇧United Kingdom - BCL Legal
Cactus hacking group claims to have breached BCL Legal.
Allegedly, 829 GB of data were exfiltrated, including personally identifiable information, database backups, corporate confidential data and correspondence, customer contracts, financial documents, and personal data.
⚠️DDoS
🇺🇸USA - Georgia’s Secretary of State’s office successfully repelled a cyberattack this month, believed to have originated from a foreign entity, targeting the absentee ballot request website.
With the help of Cloudflare, the attack, which flooded the site with traffic from hundreds of thousands of IP addresses, was mitigated, preventing any disruption to the voting process.
The attackers likely aimed to probe the state’s election defenses, though no votes or systems were compromised. The FBI and US Cybersecurity and Infrastructure Security Agency were involved in the aftermath of the attack.
Source: CNN
🚨Data Breach Alert ‼️
🇺🇸USA - ELife
The threat actor Intelbroker, in cooperation with EnergyWeaponUser, claims to have compromised ELife, a vehicle hiring service that connects airports to hotels.
According to a post on a hacking forum, the breach occurred in October 2024, affecting 170,000 users. Compromised data includes full names, airport check-ins, email addresses, phone numbers, flight numbers, flight arrival times, and drop-off locations.
The confirmation or denial of these claims has yet to be verified
🚨Cyberattack Alert ‼️
🇮🇳India - Doctor 24x7
Kill Security hacking group claims to have breached Doctor 24x7.
Allegedly, exfiltrated data include patient names, age, gender, patient registration numbers, billing details, laboratory results, and doctor credentials.
Ransom deadline: 01st Nov 24.
🚨Cyberattack Alert ‼️
🇮🇳India - Prince Pipes and Fittings
Ra World hacking group claims to have breached Prince Pipes and Fittings, one of India's largest PVC pipe manufacturers & multi polymer processors.
Allegedly, 1.056 TB of data, including legal documents, financial documents, department documents, employee documents, business contracts, and other files, were exfiltrated.
🚨Cyberattack Alert ‼️
🇹🇼Taiwan - Walsin Technology Corporation
RansomHub hacking group claims to have breached Walsin Technology Corporation, a manufacturing company with nearly $3 billion in revenue.
Allegedly, 150 GB of data, including technical designs, agreements, and certificates, were exfiltrated.
Ransom deadline: October 31, 2024.
🚨🚨Cyberattack Alert ‼️
🇺🇸USA - Wayne County
Interlock ransomware group claims responsibility for the cyberattack on Wayne County.
Allegedly, 7.7 TB of data, including 130 SQL databases, a large collection of confidential criminal investigation files, and personal data of residents, were exfiltrated.
According to our database, the Wayne County government in Detroit was hit by a ransomware attack on October 3, 2024, disrupting multiple services. The attacker has demanded a ransom. Critical systems, including those at the Wayne County Sheriff’s Office, the Treasurer’s Office, and the Register of Deeds Office, were affected, halting operations such as inmate bonding, online tax payments, and real estate records processing.
🚨Data Breach Alert ‼️
🇯🇵Japan - Slow Village Co., Ltd (スローヴィレッジ)
Slow Village Co., Ltd.'s online shop suffered a data breach caused by a third-party attacker who exploited a vulnerability in the payment system.
As a result, the personal data of 32,345 customers was leaked, including potentially 4,494 credit card records. The breach occurred between February 4, 2021, and May 28, 2024. The attacker manipulated the payment application, and there were also 23,466 random number combinations entered into the credit card input field, although none were successfully processed.
Source:
https://shop.slow-village.jp/Page/owabi.aspx
🚨🚨Data Breach Alert 🚨🚨
Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection
More details:
https://www.infostealers.com/article/largest-retail-breach-in-history-350-million-hot-topic-customers-personal-and-payment-data-exposed-as-a-result-of-infostealer-infection/
🚨Fake Crypto Game Hides Chrome Zero-Day CVE-2024-4947 Attack by Lazarus APT 🚨
https://securityonline.info/fake-crypto-game-hides-chrome-zero-day-cve-2024-4947-attack-by-lazarus-apt/
🚨Cyberattack Alert ‼️
🇺🇸USA - Goshen Central School District
Fog hacking group claims to have breached Goshen Central School District.
Allegedly, 10 GB of data were exfiltrated, including internal correspondence, personal contacts, human resources, medical documents, and SSNs.
According to our database, the Goshen Central School District experienced a ransomware attack on July 10, 2024, which disabled its computer services, phones, and email systems.
