IT Security Newsletter - 6/23/2025
US Braces for Cyberattacks After Bombing Iranian Nuclear Sites
After the US bombed three key nuclear sites in Iran, the regime in Tehran vowed to retaliate. The Department of Homeland Security (DHS) issued a national terrorism advisory system bulletin on Sunday, warning that the Iranian government has publicly condemned the United States' involvement in the conflict and that retaliation could come in several forms. Iran could conduct lethal attacks and commit acts of violence on US soil, but Iranian hackers are also likely to intensify attacks against the United States. READ MORE...
Steel giant Nucor confirms hackers stole data in recent breach
Nucor, North America's largest steel producer and recycler, has confirmed that attackers behind a recent cybersecurity incident have also stolen data from the company's network. The steel giant employs more than 32,000 people in numerous mills across the U.S., Mexico, and Canada and reported a revenue of $30.73 billion last year. Nucor disclosed this incident last month, revealing that it took down some systems to contain the security breach and halted production at some of its facilities. READ MORE...
Looks like Aflac is the latest insurance giant snagged in Scattered Spider's web
Aflac is the latest insurance company to disclose a security breach following a string of others earlier this week, all of which appear to be part of Scattered Spider's most recent data theft campaign. The American insurance giant on Friday said it intends to notify regulators that it spotted the "unauthorized access to its network" on June 12, and "believes that it contained the intrusion within hours." Notably, the intruder didn't infect any Aflac systems with ransomware. READ MORE...
743,000 Impacted by McLaren Health Care Data Breach
Michigan healthcare provider McLaren Health Care is notifying over 743,000 people that their personal information was compromised in a 2024 data breach. The incident, the organization says, was discovered on August 5, 2024, after suspicious activity was identified on computer systems pertaining to McLaren and Karmanos Cancer Institute. In a written notification to the impacted individuals McLaren revealed that ransomware was involved in the attack. READ MORE...
Telecom Giant Viasat Is Latest Salt Typhoon Victim
Viasat is the latest telecom business to fall victim to Salt Typhoon, the notorious cyber-espionage threat group. The breach at the satellite communications company was discovered earlier this year and has been identified as one of the threat group's targets during the 2024 presidential campaign, according to Bloomberg News, which first reported the breach. Following a report of unauthorized access through a compromised device, Viasat launched an investigation. READ MORE...
Hackers Post Dozens of Malicious Copycat Repos to GitHub
Cybercriminals continue to sneak malicious repositories onto GitHub. Typosquatting, dependency confusion, and other types of cyberattacks precipitated through malicious packages are old and common tricks seen constantly on platforms like npm and the Python Package Index (PyPI). According to ReversingLabs, cases have actually been declining precipitously. At the same time, though, threat actors are finding new paths for performing similar kinds of attacks. READ MORE...
Stealthy backdoor found hiding in SOHO devices running Linux
SecurityScorecard's STRIKE team has uncovered a network of compromised small office and home office (SOHO) devices they're calling LapDogs. The threat is part of a broader shift in how China-Nexus threat actors are using Operational Relay Box (ORB) networks to hide their operations. Unlike traditional botnets, which are often noisy and scattershot, ORBs are more targeted. They repurpose everyday devices to move through networks, collect data, or bounce traffic without raising alarms. READ MORE...
- ...in 1868, inventor Christopher Latham Sholes receives a patent for a revolutionary labor-saving (and labor-creating) device: The typewriter.
- ...in 1955, punk and heavy metal singer Glenn Danzig is born in Lodi, NJ.
- ...in 1969, Warren E. Burger is sworn in as Chief Justice of the US Supreme Court by retiring Chief Justice Earl Warren.
- ...in 2013, daredevil Nik Wallenda becomes the first person to successfully walk across the Grand Canyon on a tightrope.