Undisclosed U.S. Company
February 4, 2024
Researchers at Volexity reveal that the Russian state threat actor APT28 breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique called "nearest neighbor attack."
Arab Civil Aviation Organization (ACAO)
February 4, 2024
•[ sql injection, data leak, cyber-espionage ]
Threat actors exploited a vulnerable web application belonging to the Arab Civil Aviation Organization via SQL injection, exfiltrating staff and member credentials and communications. The stolen data, published on dark-web forums on February 4 2024, was identified by Resecurity, which assessed the activity as part of a cyber-espionage campaign targeting aviation-safety specialists across multiple Arab states.
Pennsylvania’s court system
February 4, 2024
•[ DDoS, cyberattack, service disruption ]
Pennsylvanias court system is hit with a distributed denial-of-service (DDoS) attack and experiences disruptions.
Cooper Aerobics
February 3, 2024
•[ hack, misconfiguration, healthcare ]
Cooper Aerobics files a notice of data breach after discovering unauthorized access to its computer network.
Multiple government agencies in the Philippines
February 2, 2024
•[ espionage, government ]
Government agencies in the Philippines announce they had repelled a cyberattack from threat actors suspected to be based in China.
Municipality of Germantown
February 2, 2024
•[ ransomware, malware, government ]
Tennessee's Germantown announces a ransomware attack.
Ukrainian military
February 2, 2024
•[ espionage, malware, government ]
Researchers from Securonix reveal the details of the STEADY#URSA campaign, an ongoing operation carried on by the russia-linked APT group Shuckworm (aka Gamaredon, and Primitive Bear, targeting the Ukrainian military with a new PowerShell backdoor called Subtle-Paws
Municipality of Korneuburg
February 2, 2024
•[ ransomware, malware, government ]
The municipality of Korneuburg in Austria says it was hit by a LockBit ransomware attack, leading to funerals reportedly being canceled and the town hall informing residents its staff can only be reached via telephone.
Municipality of Sant Antoni de Portmany
February 1, 2024
•[ ransomware, malware, government ]
The Municipality of Sant Antoni de Portmany in the Island of Ibiza, suffers a ransomware attack.
Groton Public Schools
February 1, 2024
•[ hack, education ]
Groton Public Schools is the victim of a cyber attack.
Hewlett Packard Enterprise
February 1, 2024
•[ leak, technology ]
Hewlett Packard Enterprise (HPE) is investigating a potential new breach after a threat actor put allegedly stolen data up for sale on a hacking forum, claiming it contains HPE credentials and other sensitive information.
Flydubai
February 1, 2024
•[ hack, ddos ]
Anonymous Sudan claims responsibility for a DDOS attack against the UAEs Flydubai Airline.
Unnamed Lincoln Project vendor
February 1, 2024
•[ financial, phishing, government ]
The anti-Donald Trump super PAC Lincoln Project discloses to have lost $35,000 to a business email compromise (BEC) scam.
Crypto Users
February 1, 2024
•[ financial, malware, finance ]
The threat actors behind the 2022 LastPass breach were able to steal an estimated $5.36 million in crypto assets from over 40 wallet addresses. The wave of attacks is said to have originated from the 2022 incident in the password manager service LastPass.
SurveyLama
February 1, 2024
•[ leak, technology ]
In February 2024, the paid survey website SurveyLama suffered a data breach that exposed 4.4M customer email addresses. The incident also exposed names, physical and IP addresses, phone numbers, dates of birth and passwords stored as either salted SHA-1, bcrypt or argon2 hashes. When contacted about the incident, SurveyLama advised that they had already "notified the users by email".
Telecommunications organizations in Southeast Asia
February 1, 2024
•[ espionage, technology ]
Telecommunications organizations in Southeast Asia have been targeted by a state-sponsored threat actor known as CL-STA-0969 to facilitate remote control over compromised networks.
Palo Alto Networks Unit 42 said it observed multiple incidents in the region, including one aimed at critical telecommunications infrastructure between February and November 2024.
Financial Business And Consumer Solutions
February 1, 2024
•[ data leak ]
Debt Collector Updated Affected Count For 2024 Breach To 4,253,394 Individuals.
Multiple organizations in Japan
January 31, 2024
Researchers from Itochu discover an updated version of a backdoor called LODEINFO, distributed via spear-phishing attacks, and used against targets in Japan from the Chinese threat actor APT10.
Lurie Children’s Hospital
January 31, 2024
•[ ransomware, malware, healthcare ]
Lurie Childrens Hospital suffers a network outage, later confirmed to be a ransomware attack by the Rhysida group demanding a $3.4M ransom.
Encore Bank
January 31, 2024
•[ hack, phishing, finance ]
Encore Bank files a notice of data breach after discovering that an unauthorized party was able to gain access to an employees email account.