"Staples Confirms Cyberattack Behind Service Outages, Delivery Issues"

"Staples Confirms Cyberattack Behind Service Outages, Delivery Issues"

American office supply retailer Staples took down some of its systems on November 27th after a cyberattack to contain the breach's impact and protect customer data.  Staples operates 994 US and Canada stores and 40 fulfillment centers for nationwide product storage and dispatch.  The company noted that the response measures disrupted its business operations, specifically the backend processing and product delivery.

Submitted by Adam Ekwall on

"US Sanctions Cryptocurrency Mixer Sinbad for Aiding North Korean Hackers"

"US Sanctions Cryptocurrency Mixer Sinbad for Aiding North Korean Hackers"

The US Department of the Treasury recently announced sanctions against cryptocurrency mixer Sinbad for laundering stolen cryptocurrency for the North Korean state-sponsored hacking group Lazarus.  Sinbad, the Treasury says, is the preferred mixing service for Lazarus and is responsible for laundering millions of dollars in stolen cryptocurrency for the nation state threat actor.  Sinbad operates on the Bitcoin blockchain, and the mixer obfuscates illicit transactions' origin, destination, and counterparties.

Submitted by Adam Ekwall on

"Black Basta Ransomware Group Makes $100m Since 2022"

"Black Basta Ransomware Group Makes $100m Since 2022"

According to researchers at Corvus Insurance, a prolific Russian-speaking ransomware group has made over $100m from dozens of victims since April 2022.  The researchers used the Elliptic Investigator blockchain forensics tool to lift the lid on the Black Basta group.  The tool helped the researchers uncover patterns in the group’s online activities, which enabled them to trace a large number of Bitcoin ransoms with a high degree of certainty.  The researchers found that Black Basta has received at least $107m in ransom payments since early 2022 across more than 90 victims.

Submitted by Adam Ekwall on

"Thousands of Dollar Tree Staff Hit By Supplier Breach"

"Thousands of Dollar Tree Staff Hit By Supplier Breach"

A major data breach at IT provider Zeroed-In Technologies has impacted nearly two million end users, including thousands of Dollar Tree and Family Dollar employees.  The data breach affected 1,977,486 users on August 7-8, 2023.  Zeroed-In Technologies stated that the investigation determined that an unauthorized actor gained access to certain systems between August 7, 2023, and August 8, 2023.  The company found that the threat actor stole names, dates of birth, and Social Security numbers.

Submitted by Adam Ekwall on

"Defending Your Voice Against Deepfakes"

"Defending Your Voice Against Deepfakes"

Computer scientists led by Ning Zhang, assistant professor of computer science and engineering at the McKelvey School of Engineering at Washington University in St. Louis, created AntiFake, a tool to protect voice recordings from unauthorized speech synthesis. Recent advancements in generative Artificial Intelligence (AI) have accelerated progress in realistic speech synthesis.

Submitted by grigby1 CPVI on

"North Korean Software Supply Chain Attack Hits North America, Asia"

"North Korean Software Supply Chain Attack Hits North America, Asia"

A recent North Korean attack on a Taiwanese company spreads malware to the United States, Canada, Japan and Taiwan. Microsoft discovered that a hacker gang known as Diamond Sleet gained access to a Taiwan software company CyberLink Corporation producers of audio, video, and photo editing software. They added malware to the application installer and managed to get their modified version signed with a CyberLink certificate and hosted on a valid update system. The code checks to see if security software from CrowdStrike, FireEye, or Tanium is present before running the malicious code.

Submitted by grigby1 CPVI on

"DJVU Ransomware's Latest Variant 'Xaro' Disguised as Cracked Software"

"DJVU Ransomware's Latest Variant 'Xaro' Disguised as Cracked Software"

The latest variant of DJVU ransomware, codenamed Xaro, is distributed in the form of cracked software. The DJVU variant appends the .xaro extension to affected files and demands a ransom for a decryptor. It has been observed infecting systems along with other commodity loaders and infostealers. DJVU, which is a variant of the STOP ransomware, typically masquerades as legitimate services or applications. It is also delivered as a SmokeLoader payload. This article continues to discuss the new variant of the DJVU ransomware.

Submitted by grigby1 CPVI on

"POCs for Critical Arcserve UDP Vulnerabilities Released"

"POCs for Critical Arcserve UDP Vulnerabilities Released"

Tenable researchers have released proof-of-concepts (POCs) for now-patched critical security vulnerabilities in Arcserve's Unified Data Protection (UDP) solution. Arcserve UDP is a widely used enterprise data protection, backup, and disaster recovery solution that helps organizations improve resiliency against ransomware attacks. This article continues to discuss the potential exploitation and impact of the vulnerabilities affecting Arcserve UDP.

Submitted by grigby1 CPVI on

"Japanese Space Agency JAXA Hacked in Summer Cyberattack"

"Japanese Space Agency JAXA Hacked in Summer Cyberattack"

The Japan Aerospace Exploration Agency (JAXA) was hacked in a cyberattack over the summer, which may have put sensitive space-related technology and data at risk.  The security breach was discovered this Fall when law enforcement authorities alerted Japan's space agency that its systems were compromised.  Chief Cabinet Secretary of Japan Hirokazu Matsuno revealed that attackers gained access to the agency's Active Directory (AD) server, a crucial component overseeing JAXA's network operations.

Submitted by Adam Ekwall on
Subscribe to