Two members of Serbian civil society
August 30, 2023
•[ espionage, malware, technology ]
Two members of Serbian civil society receive notification from Apple that their devices could have been compromised by a sophisticated spyware.
Japan Aerospace Exploration Agency (JAXA)
August 30, 2023
•[ hack, espionage, government ]
The Japan Aerospace Exploration Agency (JAXA) reveals it was hacked in a cyberattack over the summer, which may have put sensitive space-related technology and data at risk.
Retool
August 29, 2023
•[ social, phishing, technology ]
Software company Retool says the accounts of 27 cloud customers were compromised following a targeted and multi-stage social engineering attack.
Sovos Compliance
August 23, 2023
•[ leak, sqlinjection, technology ]
Sovos Compliance files a notice of data breach on behalf of several companies after learning to have been affected by the MOVEit vulnnerability.
Data Media Associates
August 23, 2023
•[ hack, misconfiguration, technology ]
Data Media Associates files a notice of data breach after discovering that an unauthorized party was able to access confidential consumer information stored on the MOVEit platform.
CloudNordic
August 22, 2023
•[ ransomware, malware, technology ]
Danish hosting firms CloudNordic and AzeroCloud suffer ransomware attacks, causing the loss of the majority of customer data and forcing the hosting providers to shut down all systems, including websites, email, and customer sites.
Terra Protocol
August 22, 2023
•[ social, phishing, technology ]
Terra announces a temporary shuttering of its website to protect its users from interacting with an ongoing phishing scam on the platform.
Resort Data Processing
August 21, 2023
•[ hack, sqlinjection, technology ]
Resort Data Processing (RDP) files a notice of data breach after discovering that an SQL injection attack enabled an unauthorized user to access confidential information in the company's possession.
auDA
August 18, 2023
•[ ransomware, malware, technology ]
auDA, the organization that manages Australia's internet domain .au denies that it was affected by a data breach, after the NoEscape ransomware gang adds it to their list of victims.
Managed Service Providers (MSPs) worldwide
August 17, 2023
•[ ransomware, finance, technology ]
Researchers from Adlumin reveal that the Play ransomware group is now hitting managed service providers (MSPs) around the globe in a cyberattack campaign to distribute ransomware to their downstream customers: midsized businesses in the finance, legal, software, shipping, law enforcement, and logistics sectors
Southeast Asian gambling industry
August 17, 2023
•[ espionage, malware, technology ]
Researchers from SentinelOne discover a second phase of the Operation ChattyGoblin carried out by a China-aligned APT group known as 'Bronze Starlight', targeting the Southeast Asian gambling industry with malware signed using a valid certificate used by the Ivacy VPN provider.
Alogent Holdings
August 14, 2023
•[ hack, misconfiguration, technology ]
Alogent Holdings files a notice of data breach related to an incident occurred exploiting the vulnerability in MOVEit, resulting in an unauthorized party being able to access consumers' sensitive information, which includes their names, account and routing numbers, addresses, phone numbers, check payees and remittance amounts.
Discord
August 14, 2023
•[ leak, technology ]
The Discord.io custom invite service temporarily shuts down after suffering a data breach exposing the information of 760,000 members.
Precisely Software
August 13, 2023
•[ hack, technology ]
Precisely Software files a notice of data breach after confirming that an unauthorized party was able to gain access to its computer network.
Puntozero
August 11, 2023
•[ hack, technology ]
Puntozero, the company that provides the IT services to the Italian region of Umbria, is hit with a cyber attack.
EMS Management and Consultants
August 9, 2023
•[ hack, sqlinjection, technology ]
EMS Management and Consultants files a notice of data breach after discovering that the vulnerability in the MOVEit file transfer system allowed an unauthorized party to access consumer information.
PlayCyberGames
August 9, 2023
•[ leak, misconfiguration, technology ]
In August 2023, PlayCyberGames which "allows users to play any games with LAN function or games using IP address" suffered a data breach which exposed 3.7M customer records. The data included email addresses, usernames and MD5 password hashes with a constant value in the "salt" field. PlayCyberGames did not respond to multiple attempts to disclose the breach.
Kreacta
August 8, 2023
•[ ransomware, malware, technology ]
The NoEscape ransomware gang claims responsibility for a cyber attack to Kreacta, a consulting company in Italy
Rapattoni
August 8, 2023
•[ ransomware, malware, technology ]
Rapattoni, a real estate property listings in US, confirms to have been hit with a ransomware attack.
Aristocrat
August 7, 2023
•[ ransomware, sqlinjection, technology ]
Aristocrat confirms to have been hit by the Clop ransomware gang exploiting the CVE-2023-34362 vulnerability.