<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 10/4/2023

SHARE

Top News

NATO investigating breach, leak of internal documents

NATO is investigating claims by a politically motivated hacktivist group that it breached the defense alliance's computer systems, which, if confirmed, would mark the second time in the last three months that the group known as SiegedSec has broken into NATO systems. SiegedSec, a cybercrime group with a history of politically-motived attacks, claimed on its Telegram channel on Saturday that it had stolen roughly 3,000 NATO documents. READ MORE...

Breaches

Clorox resumes normal plant operations in the wake of cyberattack

Clorox said all of its manufacturing facilities were back up and running following an August cyberattack that led to weeks of disruption and product shortages, according to a Friday update. The Oakland, California-based maker of Pine-Sol and household bleach, said it resumed automated order processing on Sept. 25 and was ramping up the pace of production to restock product inventories. READ MORE...


Sony confirms data breach impacting thousands in the U.S.

Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a cybersecurity breach that exposed personal information. The company sent the data breach notification to about 6,800 individuals, confirming that the intrusion occurred after an unauthorized party exploited a zero-day vulnerability in the MOVEit Transfer platform. The zero-day is CVE-2023-34362, a critical-severity SQL injection flaw that leads to remote code execution. READ MORE...

Hacking

USPS Anchors Snowballing Smishing Campaigns

A cyber campaign by threat actors targeting the US Postal Service (USPS) using smishing and phishing tactics is cresting, with close to 200 different domains used as infrastructure for the attacks. While using tactics such as these is common in the cyber world, the volume of these campaigns has increased significantly in recent weeks. This prompted an investigation by DomainTools, which looked into the domain included at the end of one of the smishing messages. READ MORE...

Trends

FBI: Crippling 'Dual Ransomware Attacks' on the Rise

The FBI has issued a warning about a rising ransomware trend in which separate attacks are conducted just hours or days apart - otherwise known as "dual ransomware attacks." "Ransomware attacks against the same victim occurring within 10 days, or less, of each other were considered dual ransomware attacks," the bureau explained in a Private Industry Notification released last week. "The majority of dual ransomware attacks occurred within 48 hours of each other." READ MORE...

Exploits/Vulnerabilities

Qualcomm says hackers exploit 3 zero-days in its GPU, DSP drivers

Qualcomm is warning of three zero-day vulnerabilities in its GPU and Compute DSP drivers that hackers are actively exploiting in attacks. The American semiconductor company was told by Google's Threat Analysis Group (TAG) and Project Zero teams that CVE-2023-33106, CVE-2023-33107, CVE-2022-22071, and CVE-2023-33063 may be under limited, targeted exploitation. Qualcomm says it has released security updates that address the issues in its Adreno GPU and Compute DSP drivers. READ MORE...

Science & Culture

Actor Tom Hanks Warns of Ad With AI Imposter

Actor Tom Hanks and CBS talk show co-host Gayle King on Monday were warning fans about ads featuring imposters generated by artificial intelligence. "Beware," Hanks said in an Instagram post that evidently showed a copy of an unauthorized digital version of him. "There is a video out there promoting some dental plan with an AI version of me. I have nothing to do with it." READ MORE...

On This Date

  • ...in 1927, sculptor Gutzon Borglum begins carving the heads of four US presidents on Mount Rushmore.
  • ...in 1957, Sputnik I is launched, making it the first artificial satellite to orbit the Earth.
  • ...in 1965, Pope Paul VI arrives in New York, the first Catholic pontiff ever to visit the United States and the Western hemisphere.
  • ...in 2004, SpaceShipOne wins the Ansari X Prize, by being the first privately-funded craft to fly into space.