Topic: sector targeting
-
Europe’s Tech Infrastructure Faces Rising Cyber Threats
Europe’s digital infrastructure faces escalating, interconnected cyber threats driven by cybercrime and state-sponsored espionage, with DDoS attacks and unauthorized access comprising the majority of incidents. Public administration is the most targeted sector, suffering disproportionately from D...
Read More » -
Iranian Hackers Target US Critical Infrastructure Networks
U.S. authorities warn of an active, state-sponsored Iranian cyber campaign targeting critical industrial control systems, specifically from manufacturers like Rockwell Automation, across vital sectors including manufacturing and energy. The attackers exploit known vulnerabilities and weak passwor...
Read More » -
Microsoft Thwarts Ransomware Attack on Teams Users
Microsoft invalidated over 200 fraudulent digital certificates to disrupt a ransomware campaign that used fake Teams installers, blocking the Rhysida ransomware's distribution network in early October. The attack, orchestrated by the Vanilla Tempest group, involved malvertising and spoofed websit...
Read More » -
Gambling Network Exposed as Major Criminal Front
A criminal network operating for 14 years, previously seen as a gambling fraud scheme, is now assessed to be a likely nation-state-sponsored front for espionage targeting U.S. and European organizations. The group uses a massive infrastructure of hijacked and purchased domains to host illegal gam...
Read More » -
US Offers $10M Reward for Russian FSB Hackers Info
The U.S. State Department is offering up to $10 million for information on three Russian FSB officers accused of orchestrating cyberattacks against American critical infrastructure, including government bodies and energy firms. These officers, part of the FSB's Center 16, targeted over 500 energy...
Read More » -
Bolster Defenses Against Scattered Spider Attacks, Experts Warn
The Scattered Spider hacking group poses a severe threat to businesses by using sophisticated methods like social engineering and ransomware, requiring immediate improvements in identity management, security processes, and third-party risk management. Their attack strategy often starts with vishi...
Read More » -
SonicWall VPN Hackers Bypass MFA Due to Incomplete Patches
Threat actors exploited incomplete patches for CVE-2024-12802 on SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication, using brute-forced credentials to gain access and deploy ransomware tools within 30-60 minutes. The vulnerability remains exploitable even after firmware updat...
Read More »