Category: Breach Reports

  • ALPHV/BlackCat Hacker Group Claims Responsiblity for MGM Resorts Ransomware Attack

    MGM Resorts is currently scrambling to recover from a powerful ransomware attack that happened last Monday, causing a substantial amount of network systems to go down. Company websites as well as many crucial systems are currently offline, including the MGM app, which facilitates reservations, acts as a digital key to unlock rooms, and allows users…

  • Protecting Your MSSQL Databases: Defending Against the FreeWorld Ransomware Threat

    A new cyberattack campaign named “DB#JAMMER” has emerged, specifically targeting exposed Microsoft SQL Server (MSSQL) databases. The implications of this campaign are nothing short of severe, especially for organizations relying on this technology, as DB#JAMMER is no ordinary cyberattack; it’s a well-choreographed assault that employs intricate tactics, including relentless brute-force attacks aimed at breaching MSSQL…

  • Critical Vulnerability in Hikvision Surveillance Cameras Points to Greater Issue Within the IoT

    Security researchers from Cyfirma recently discovered that over 80,000 Hikvision surveillance cameras are still susceptible to a critical vulnerability that was patched in a security update over 2 years ago. CVE-2021-36260, which was added to the National Vulnerability Database in January of 2022, allows attackers to exploit Hikvision cameras due to their lack of input…

  • Overview: Phish Tale of the Week Phishing attempts can often target specific groups that can be exploited by malicious actors and come in many different forms. In this instance, we see a phishing scam targeting PayPal users with what appears to be a link that’s supposed to “reactivate your account.” PayPal says that our account…

  • Voice Synthesis: The Growing Threat of Vishing with AI Technology

    A few months ago, a song called “Heart on My Sleeve” went viral on social media: a collaboration between artists Drake and The Weeknd. It was quickly met with excitement from hip-hop fans, not only because of the song’s impressive vocal performances or the catchy lyrics from both artists, but because it was entirely AI-generated.…

  • Lapsus$: The teenager-run cybercriminal gang targeting Fortune 500 companies.

    Earlier this week, IT giant Microsoft and identity management firm Okta reported that their organizations had suffered data breaches from Lapsus$. Lapsus$ is a relatively new hacking group, with indications of their activity being first reported against Samsung and NVIDIA at the end of 2021. The hacking group announced a Telegram channel on March 22nd,…

  • Log4J: The Minecraft found, Java fueled nightmare.

    On December 9th, the greater information security community had its world turned upside down when a newly uncovered zero-day vulnerability was found in Apache’s Java logging library Log4J. Within hours of this news, every major software company was in disaster mode, attempting to determine how their products were affected and how to fix a patch…

  • Sinclair Broadcast Group Ransomware Attack: How it happened and what this means.

    Last week, millions of television viewers were shocked when a nationwide shutdown occurred, targeting local television stations owned by Sinclair Broadcast Group. Sinclair is one of the largest telecommunications conglomerates in the country, owning 294 stations and covering 100 different markets, giving them about 40% coverage of all American households. Sinclair acknowledged the breach last…

  • NEW Cooperative Ransomware Attack: How it happened and what this means.

    Over the weekend, NEW Cooperative Inc., a Fort Dodge, Iowa-based agricultural services firm was crippled by a ransomware attack. The outside threat group BlackMatter has stated that they are responsible for this attack and have demanded a ransom of $5.9 million to release the data they have locked. BlacMatter released additional information detailing that the…

  • T-Mobile Data Breach: What Happened and What We Do Next.

    Telecommunications company T-Mobile reported Monday that they are investigating the specifics of a data breach that hackers claim may have leaked the personally identifiable information (PII) of over 100 million customers. The majority of the data is said to contain social security numbers, addresses, dates of birth, security PINs, and other sensitive information unique to…