Cybersecurity & Privacy
The Good, the Bad and the Ugly in Cybersecurity – Week 43 Europol dismantled the SIMCARTEL operation, a major cybercrime-as-a-service network that facilitated over 3,200 fraud cases and caused €4.5 million in damages using 1,200 SIM-box devices and 40,000 SIM cards. Separately, the Jingle Thief threat group targets cloud environments for large-scale gift card fraud by stealing Microsoft 365 credentials, while the PhantomCaptcha campaign used spearphishing to deploy a RAT targeting Ukrainian government and humanitarian organizations.
Shutdown Sparks 85% Increase in US Gov’t Cyberattacks The US government shutdown has led to an 85% increase in cyberattacks against federal employees, with threat actors exploiting financial anxieties. The Department of Veterans Affairs (VA) and the Department of Justice (DoJ) are the most targeted agencies, particularly among essential employees who continue to work despite the risks.
Everest Ransomware Claims AT&T Careers Breach with 576K Records – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More The Everest ransomware group claims to have breached AT&T Careers, potentially exposing 576,686 personal records of applicants and employees. The data listing is password-protected, with a deadline for AT&T to respond before public release, and AT&T has not yet officially commented on this specific incident.
Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation The Smishing Triad, a China-linked group, has been linked to over 194,000 malicious domains since January 2024 in a global phishing operation, generating over $1 billion in the last three years by impersonating services like toll violations and package misdeliveries. This sophisticated operation utilizes a decentralized infrastructure, rapidly registering and churning through domains to evade detection, with a significant portion hosted on U.S. cloud services.
AI Dataset for Detecting Nudity Contained Child Sexual Abuse Images The NudeNet dataset, used for training AI nudity detection, has been found to contain child sexual abuse material (CSAM) by the Canadian Centre for Child Protection (C3P). This discovery highlights ethical concerns regarding data collection in AI development, similar to previous findings with the LAION-5B dataset.
Every Formula 1 driver on the grid just had their passport and license details leaked - but it could have been so much worse | TechRadar Security researchers discovered a significant bug in the FIA website, granting them access to the personally identifiable information of all Formula 1 drivers, including passport and license details. Although the vulnerability has since been fixed and there’s no indication of malicious access, the incident highlights the ongoing cybersecurity risks even in highly funded sports.
Ransomware recovery perils: 40% of paying victims still lose their data | CSO Online A recent survey reveals that 40% of businesses paying ransoms for ransomware recovery still fail to regain their data, with only 60% achieving partial or full recovery. Modern attacks often involve double or triple extortion, and paying the ransom does not guarantee data restoration or prevent data leaks, highlighting the critical need for robust preparation and cyber resilience.
Toys ‘R’ Us Canada Customer Information Leaked Online - SecurityWeek Toys “R” Us Canada experienced a data breach where a threat actor stole and leaked customer information, including names, addresses, email addresses, and phone numbers, on the dark web. The company is notifying customers and authorities, but no sensitive information like passwords or credit card details was compromised.
GlassWorm Malware Targets Developers Through OpenVSX Marketplace – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More The GlassWorm malware targets developers using Visual Studio Code extensions on the OpenVSX marketplace, spreading by hijacking trusted extensions and stealing credentials. It hides its malicious payload using invisible Unicode variation selectors and communicates through the Solana blockchain and Google Calendar.
Meta boosts scam protection on WhatsApp and Messenger | Malwarebytes Meta has enhanced scam protection on WhatsApp and Messenger with new safeguards to protect users, especially the elderly, from scammers. Scams targeting the elderly have increased, with losses reaching $4.8 billion in 2024.