<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 7/17/2025

SHARE

Top News

China's Salt Typhoon Hacked US National Guard

Chinese state-sponsored hackers compromised the network of a state's Army National Guard unit, collected configuration information, and tapped into its communication with other units, a Department of Defense report shows. The nation-state threat actor, tracked as Salt Typhoon, was previously accused of hacking US telecommunications giants AT&T and Verizon, along with Lumen Technologies and other service providers in the US and abroad, to compromise wiretap systems. READ MORE...

Breaches

Compumedics Ransomware Attack Led to Data Breach Impacting 318,000

Compumedics was recently targeted in a ransomware attack that resulted in the personal information of hundreds of thousands of individuals getting stolen. Compumedics makes medical technologies for the diagnosis of sleep and neurological disorders. The company's global headquarters are in Australia, but it also has a presence in the United States and Europe. The company informed customers in a data security notice that its systems were accessed by hackers between February 15 and March 23, 2025. READ MORE...


DragonForce hackers claim responsibility for Belk data breach

DragonForce, a cyber criminal group connected to a series of attacks against retail firms in recent months, is claiming credit for an attack on the North Carolina-based department store chain Belk. The group claimed on its leak site that it has approximately 156 gigabytes of data stolen from the company. Researchers have linked DragonForce to an April attack on Marks & Spencer, one of the first breaches in a months-long attack spree linked to Scattered Spider. READ MORE...

Hacking

Amazon warns 200 million Prime customers that scammers are after their login info

Amazon has sent out an alert to its 200 million customers, warning them that scammers are impersonating Amazon in a Prime membership scam. In the email, sent earlier this month, Amazon said it had noticed an increase in reports about fake Amazon emails: "Scammers are sending fake emails claiming your Amazon Prime subscription will automatically renew at an unexpected price. The scammers might include personal information in the emails [...] in an attempt to appear legitimate." READ MORE...


Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

A 21-year-old former Army soldier pleaded guilty Tuesday to charges stemming from a series of attacks and extortion attempts last year on telecommunications companies, including AT&T. Cameron John Wagenius, who identified himself as "kiberphant0m" and "cyb3rph4nt0m" on online criminal forums, conducted extensive malicious activity for years, including while he was on active duty, the Justice Department said. READ MORE...

Malware

Hackers exploit a blind spot by hiding malware inside DNS records

Hackers are stashing malware in a place that's largely out of the reach of most defenses-inside domain name system (DNS) records that map domain names to their corresponding numerical IP addresses. The practice allows malicious scripts and early-stage malware to fetch binary files without having to download them from suspicious sites or attach them to emails, where they frequently get quarantined by antivirus software. READ MORE...


Police disrupt "Diskstation" ransomware gang attacking NAS devices

An international law enforcement action dismantled a Romanian ransomware gang known as 'Diskstation,' which encrypted the systems of several companies in the Lombardy region, paralyzing their businesses. The law enforcement operation codenamed 'Operation Elicius' was coordinated by Europol and also involved police forces in France and Romania. Diskstation is a ransomware operation that targets Synology Network-Attached Storage (NAS) devices. READ MORE...


North Korean XORIndex malware hidden in 67 malicious npm packages

North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems. The packages collectively count more than 17,000 downloads and were discovered by researchers at package security platform Socket, who assess them to be part of the continued Contagious Interview operation. Socket researchers say that the campaign follows threat activity detected since April. READ MORE...

Information Security

Catastrophic cyber event could cause widespread disruptions to global infrastructure, study suggests

A global malware attack could infect approximately one-quarter of the world's computer systems, according to a new report from CyberCube and Munich Re. Such an attack would likely result in 15% being fully compromised. The study also predicted that a major cloud security outage could last for up to 72 hours, with a single-day outage of the major providers costing companies approximately 1% of their annual revenue. READ MORE...

On This Date

  • ...in 1790, Congress declares Washington, D.C. the new capital.
  • ...in 1945, at 5:29:45 a.m., the Manhattan Project comes to an explosive end as the first atom bomb is successfully tested in Alamogordo, New Mexico.
  • ...in 1951, J.D. Salinger's only novel, "The Catcher in the Rye", is published.
  • ...in 1969, Apollo 11 is launched from the Kennedy Space Center in Merritt Island, FL.