Skip to main content
News

Cyber News Rundown: Malicious QR codes used in new phishing campaign

Cyber News Rundown: Malicious QR codes used in new phishing campaign
Forum|alt.badge.img+7
  • Threat Research Analyst
  • 4 replies

Researchers have been monitoring a new phishing campaign that uses malicious QR codes to infiltrate business emails by avoiding typical security protocols. Of the 1,000 identified phishing emails, 29% of them were focused on a single US energy provider, with the remainder targeting several other industries. Victims of this campaign initially receive an email asking to update their Microsoft 365 settings and are given a QR code to scan that allegedly verifies their account but contains an embedded URL redirect to a phishing site.

Data breach impacts 1.47 million dental patients

Officials for Alberta Dental Service Corporation (ADSC) have confirmed a 2-month long data breach of their systems that has exposed sensitive patient data for 1.47 million individuals. The breach was first identified on July 9th, roughly 2 months after the attackers gained access to the system and began deploying info stealing malware and partially encrypting stored patient data. Fortunately, ADSC has begun contacting the many affected individuals, and are working to improve their security and identify how the attackers were able to gain entry to their network.

MOVEit attack exposes Colorado Department of Health Care Policy & Financing (HCPF)

Following the MOVEit data transfer attack that affected IBM, officials for Colorado Department of Health Care Policy & Financing (HCPF) have confirmed that personally identifiable information (PII) of 4 million Colorado residents has been compromised. Fortunately, IBM has verified that only data from the MOVEit application was impacted by the security incident and no other IBM systems were accessed maliciously.

TripAdvisor complaint emails used to spread Knight Ransomware

Researchers have spotted a new spam campaign that uses fake TripAdvisor complaint emails to distribute the newly renamed Knight ransomware. What started as the Cyclops ransomware-as-a-service in May of 2023 has now been rebranded as Knight ransomware, but retains the encryptors for Windows, MacOS, and Linux that were created for Cyclops. The email campaign disguises itself as a TripAdvisor complaint form that contains a malicious ZIP file which launches a fake browser screen and scares the victim with the threat of account suspension for their complaint. Upon final execution, the encryption process begins, appends files with a ‘.knight_l’ extension, and leaves a ransom note demanding $5,000 in Bitcoin for the decryptor.

Cyberattack takes Clorox production offline

At the start of the week, officials for cleaning manufacturer Clorox were forced to take their production systems offline for several days after identifying suspicious activity on their network. While the investigation is still on-going, it is believed that a ransomware group is behind the attack, though it has not been confirmed if any encryption occurred or data was stolen.

Did this help you find an answer to your question?

9 replies

kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • August 21, 2023

Thanks for the rundown, Connor!

I feel like there’s some irony to Clorox being ransomed. I think Clorox works better as a ransomware gang name.


ProTruckDriver
Moderator

Thank you Connor.


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 8934 replies
  • August 21, 2023

Thanks Connor!


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Thank you Connor.


russell.harris
Popular Voice
Forum|alt.badge.img+5

Thanks as always @ConnorM 


Robis
New Member
Forum|alt.badge.img+1
  • New Member
  • 74 replies
  • August 22, 2023

Thanks a lot Connor.


tasystems
New Voice
Forum|alt.badge.img+8
  • New Voice
  • 156 replies
  • August 22, 2023

As I have posted many times before, placing your medical and financial records onto systems that are proving to be easy to hack is really beyond worrying. I wonder when we go back to the old pen and paper to do everything and keep it all safe locked up and secure in a thick steel safe…

 


Forum|alt.badge.img+1
  • New Member
  • 56 replies
  • August 22, 2023

Cheers connor 


Martin.1
Popular Voice
Forum|alt.badge.img+4
  • Popular Voice
  • 424 replies
  • August 24, 2023

Thank you Connor 


Reply