IT Security Newsletter

IT Security Newsletter - 1/8/2025

Written by Cadre | Wed, Jan 8, 2025

UN's aviation agency confirms attack on recruitment database

The International Civil Aviation Organization (ICAO), the United Nations' aviation agency, has confirmed to The Register that a cyber crim did indeed steal 42,000 records from its recruitment database. Yesterday, we reported claims from an atacker that they had illegally accessed tens of thousands of documents. In response to our questions, the agency confirmed the haul pertained to particulars collected between April 2016 and July last year. READ MORE...

Thousands Impacted by Casio Data Breach

Japanese electronics giant Casio has completed its investigation into the data breach caused by a recent ransomware attack and found that thousands of individuals are impacted. The company revealed in early October 2024 that some systems had failed and some services had been disrupted as a result of unauthorized access to its network. A few days later it confirmed that it had been targeted in a ransomware attack that resulted in personal information and confidential corporate files getting stolen. READ MORE...

PowerSchool hack exposes student, teacher data from K-12 districts

Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat actor to steal the personal information of students and teachers from school districts using its PowerSchool SIS platform. PowerSchool is a cloud-based software solutions provider for K-12 schools and districts that supports over 60 million students and over 18,000 customers worldwide. READ MORE...

AI-supported spear phishing fools more than 50% of targets

One of the first things everyone predicted when artificial intelligence (AI) became more commonplace was that it would assist cybercriminals in making their phishing campaigns more effective. Now, researchers have conducted a scientific study into the effectiveness of AI supported spear phishing, and the results line up with everyone's expectations: AI is making it easier to do crimes. READ MORE...

First Android Update of 2025 Patches Critical Code Execution Vulnerabilities

Google on Monday announced the first set of Android security updates for 2025, which include patches for 36 vulnerabilities, including five critical-severity bugs in the System component. As usual, the update is divided into two parts, with the first arriving on devices as the 2025-01-01 security patch level and containing fixes for 24 vulnerabilities in Android's Framework, Media Framework, and System components. READ MORE...

PhishWP Plug-in Hijacks WordPress E-Commerce Checkouts

A malicious plug-in found on a Russian cybercrime forum turns WordPress sites into phishing pages by creating fake online payment processes that convincingly impersonate trusted checkout services. Masquerading as legitimate e-commerce apps such as Stripe, the malware proceeds to steal customer payment data. Called PhishWP, the WordPress plug-in was designed by Russian cybercriminals to be particularly deceptive. READ MORE...

Ransomware Targeting Infrastructure Hits Telecom Namibia

The telecommunications provider for the African nation of Namibia suffered a significant ransomware attack late last year, becoming a visible symbol of the merging of two trends in the region: increasing attacks on critical infrastructure and the growing threat of ransomware. Last month, Telecom Namibia alerted customers that a successful attack by the ransomware-as-a-service (RaaS) group Hunters International led to users' information being leaked online. READ MORE...

Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackers

CISA has added Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic Server (CVE-2020-2883) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Mitel MiCollab is a popular enterprise collaboration suite. CVE-2024-41713 and CVE-2024-55550 are both path traversal vulnerabilities. The former is exploitable without authentication, and may allow an attacker to gain access "to provisioning information including non-sensitive user and network information." READ MORE...

  • ...in 1790, President George Washington delivers the first State of the Union address in New York City.
  • ...in 1935, rock singer and 20th century icon Elvis Presley is born in Tupelo, MS.
  • ...in 1942, English theoretical physicist and author Stephen Hawking is born in Oxford.
  • ...in 1947, musician David Robert Jones (who changed his name to David Bowie to avoid confusion with the Monkees singer) is born in London.