Skip to main content
News

Cyber News Rundown: Hive ransomware takes down Costa Rican Social Security Fund

Cyber News Rundown: Hive ransomware takes down Costa Rican Social Security Fund
Forum|alt.badge.img+7
  • Threat Research Analyst
  • 4 replies

Officials at the Costa Rican Social Security Fund (CCCS) discovered their systems were being encrypted by a Hive ransomware attack. Employees were told to disconnect their devices from the network to prevent any further spread of the infection. However, there isn’t a timeline for a return to normal work operations. Unfortunately, the Hive attack comes just weeks after the Conti ransomware group targeted a substantial portion of the Costa Rican government’s organizations, including the Social Security Fund.

Turkish airline compromises 6.5TB of internal data

Researchers have found a misconfigured Amazon Web Services (AWS) bucket belonging to an internally developed software by Pegasus Airlines, based in Turkey. The bucket contained nearly 6.5TB of sensitive customer and employee data, including flight plans and personally identifiable information (PII) that could be used to initiate further malicious attacks. Shortly after being contacted by the research team, the IT staff at Pegasus Airlines were able to properly secure the servers. However, it remains unclear if any malicious actors accessed the data while it was vulnerable.

International law enforcement operation takes control of FluBot

The combined efforts of several international law enforcement agencies and coordination by Europol have led to the takeover of the Android malware known as FluBot. Active since December 2020, FluBot has disguised itself as a wide variety of simple apps on the Google Play store. This form of malware has stolen the login credentials of its unsuspecting users and racked up millions of downloads.

Phishing campaign disguised as RuneScape account change email

Security researchers have identified a new phishing campaign that is disguising itself as an email regarding account changes from the publisher, MMORPG RuneScape, Jagex Ltd. The campaign is orchestrated to warn potential victims through email of account changes that require a user to enter their credentials to cancel or verify the change. Once collected, the credentials are transferred to a connected Discord server, where an attacker attempts to access and take total control of the account before the victim knows what is happening.

Third-party breach exposes Australian National Disability data

Staff of the client management system, CTARS, have revealed they suffered a data breach in mid-May that affected several clients, including the Australian National Disability Insurance Scheme (NDIS). While the company does acknowledge the breach, they have not been able to confirm if the data being posted to the Dark Web is legitimate or issued a statement in response to the breach.

 

Did this help you find an answer to your question?

5 replies

kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • June 9, 2022

Wait. Runescape still exists? This is the game all my middleschoolers played when I used to teach 15 years ago.


tasystems
New Voice
Forum|alt.badge.img+8
  • New Voice
  • 156 replies
  • June 10, 2022

A phone system installed at a client that nobody knew about… running windows 7, and the phone supplier when installing setup up a Draytek router for port forwarding… 3389… to this computer… and guess what happened… Thankfully all other computers on network had Webroot protection, but not this sucker….  Check for any rogue computers on your network, supplied by others!

!!! ALL YOUR FILES ARE ENCRYPTED !!!

All your files, documents, photos, databases and other important files are encrypted.

You are not able to decrypt it by yourself! The only method of recovering files is to purchase an unique private key.
Only we can give you this key and only we can recover your files.

To be sure we have the decryptor and it works you can send an email: woodpeker@tutanota.com and decrypt one file for free.
But this file should be of not valuable!

Do you really want to restore your files?
Write to email: woodpeker@tutanota.com
Reserved email: dealinfrm@cock.li

Your personal ID: D45-804-059


Companies are been forced more and more to increase the personal in their securities departments


Forum|alt.badge.img+1
  • New Voice
  • 86 replies
  • June 15, 2022

Always be wary when suppliers come to install stuff. Isolate devices if possible.


Forum|alt.badge.img+1
  • New Voice
  • 86 replies
  • June 15, 2022

I'm catching up on reading all the news. It remains interesting and current.


Reply