Plus récents

Steamship Authority (steamshipauthority.com) Nantucket targeted in attack and Martha's Vineyard passengers may be hit by delays. The United States has experienced a soar in attacks during recent weeks.

boston.cbslocal.com/2021/06/02

Union Community School District publicly silent after threat actors dump files on dark web. In a year when they were already dealing with COVID-19 and then accusations that a teacher had improper emails with students, Union Community School District in Iowa found itself with a third major challenge - a attack. But whereas the district has publicly acknowledged and discussed its response to the first two challenges, they seem to have maintained radio silence about the cybersecurity incident.

databreaches.net/ia-union-comm

Les intrus disent être restés plus d'un mois dans le Système d'Information de la société ExaGrid Systems, Inc (exagrid.com) avant de déclencher la phase finale de leur attaque. Ils ont ainsi obtenu avec brio le paiement net de 2,6 millions de dollars. ExaGrid a construit sa dernière campagne marketing sur le développement d'une fonction « Retention Time-Lock for Ransomware Recovery » permettant d'après elle d'empêcher les pirates informatiques et autres d'effacer des données sensibles protégées.

lemagit.fr/actualites/25250164

Zeppelin : All phones and computers across Waikato DHB (waikatodhb.health.nz) have been taken down by a cyber security incident, leaving clinical services scrambling.

sciencemediacentre.co.nz/2021/

Agrius hacking group has shifted from using purely destructive wiper to a combination of wiper and functionality. Don't be fooled, Agrius intentionally masked their « activity » as a ransomware attack. This group is state-sponsored and it'slikely to be of Iranian origin

assets.sentinelone.com/sentine

The continually increasing frequency and severity of cyberattacks, especially ransomware attacks, have led insurers to reduce cyber coverage limits for certain riskier industry sectors [...] and for public entities and to add specific limits on coverage

The findings come amid a period of unprecedented scrutiny for the , as multimillion-dollar ransoms come to light and cybercriminals appear to target insurers for a list of their clients to extort.

CNA Financial, a major U.S. insurer, paid its digital extortionists $40 million in what some analysts described as a record ransom. Meanwhile, Colonial Pipeline, the main artery for delivering fuel to the East Coast, paid hackers $4.4 million for decryption keys.

cyberscoop.com/cyber-insurance

Une partie des systèmes informatiques et téléphoniques du groupe français Berger-Levrault (berger-levrault.com) partiellement paralysée suite à une attaque informatique avec utilisation de . De grands comptes du secteur industriel, immobilier, transports, santé,.. utilisent quotidiennement les solutions logicielles développées par CARL Software qui, depuis 2018, est devenu CARL Berger-Levrault (carl-software.com), actuel leader européen et n°1 en en GMAO & EAM.

Newly discovered function in variant targets disk partitions - At the time of discovery, FortiGuard Labs researchers believed the ransomware was seeking out partitions to find possible hidden partitions setup by systems administrators to hide backup files. But further analysis confirmed an even more advanced technique. This DarkSide variant seeks out partitions on a multi-boot system to find additional files to encrypt, thereby causing greater damage.

  • DarkSide ransomware code is efficient and well-constructed, indicating that their cybercriminal organization includes experienced software engineers

  • This ransomware variant (NOT the version used to disrupt Colonial Pipeline operations) is advanced in nature and was observed to seek out partitions in a multi-boot environment to create further damage. It also seeks out the domain controller and connects to its active directory via LDAP anonymous authentication.

  • Additional insight on the files used by, and associated with, DarkSide was uncovered by the FortiGuard Incident Response team during recent engagements.

  • The use of a well-known bulletproof host that has been used by a wide variety of malicious actors for numerous nefarious activities over the years, including the 2016 DNC elections attack in the United States.

fortinet.com/blog/threat-resea

Une partie des systèmes informatiques et téléphoniques du groupe français Stelliant (stelliant.com) partiellement paralysée suite à une attaque informatique. Créé en 1987, le Groupe Stelliant est un spécialiste des services à l'assurance. Les assureurs en ligne de mire. Récemment, les opérateurs du a revendiqué une attaque sur une filiale asiatique du groupe international français AXA. Ils auraient exfiltrés plus de 3 téraoctets de données sensibles. Un timing qui fait suite à l'annonce de l'arrêt de la couverture du contrat « risques cyber » portant sur les ransomware.

newsassurancespro.com/cyber-le

, the group that disrupted gasoline distribution across a wide swath of the U.S this week—has gone dark, leaving it unclear if the group is ceasing, suspending, or altering its operations or is simply orchestrating an exit scam.

arstechnica.com/gadgets/2021/0

Toshiba unit hacked by group - more than 740 GiB of information were compromised and included passports and other personal information.

irishtimes.com/business/techno

Avaddon group claimed on their leak site that they had stolen 3 TB of sensitive data from AXA's Asian operations. Avaddon's announcement of the attack on AXA's systems comes roughly a week after AXA had stated that their cyber-insurance policies written in would no longer include reimbursement for ransomware extortion payouts.

bleepingcomputer.com/news/secu

El Ayuntamiento de Oviedo ha puesto en conocimiento del Centro Nacional de Inteligencia lo sucedido para buscar Lo que se denomina ransomware es un tipo de ciberataque que logra colocar en un equipo un programa que encripta los datos e impide su acceso a ellos. Se trata, según confirmaron fuentes municipales, de un ciberataque con , del mismo tipo del que sufrió hace dos meses el SEPE.

elcomercio.es/oviedo/ciberataq

A reported attack on MedNetwoRX has impeded some customers' access to their Aprima electronic record systems for more than two weeks.

healthcareitnews.com/news/repo

On March 22, 2021, ATC discovered that it was the target of a attack in which an unauthorized actor used to encrypt certain servers.

atctransportation.com/noticeof

CISA is aware of a recent successful cyberattack against an organization using a new variant, which CISA refers to as FiveHands. Threat actors used publicly available penetration testing and exploitation tools, FiveHands ransomware, and SombRAT remote access trojan (RAT), to steal information, obfuscate files, and demand a ransom from the victim organization.

us-cert.cisa.gov/ncas/analysis

CISA is aware of a recent successful cyberattack against an organization using a new variant, which CISA refers to as FiveHands. Threat actors used publicly available penetration testing and exploitation tools, FiveHands ransomware, and SombRAT remote access trojan (RAT), to steal information, obfuscate files, and demand a ransom from the victim organization.

us-cert.cisa.gov/ncas/analysis

U.S. defense contractor BlueForce (blueforceinc.com) has apparently been hit in a attack, according to a Conti ransomware chat and Hatching Triage sample.

searchsecurity.techtarget.com/

Plus anciens