IT Security Newsletter - 7/22/2025
Dell scoffs at breach, says miscreants only stole 'fake data'
Dell has confirmed that criminals broke into its IT environment and stole some of its data - but told The Register that it's "primarily synthetic (fake) data." On Monday, WorldLeaks, a rebrand of the Hunters International extortion gang, posted Dell Technologies on its leak site and claimed to have exfiltrated 1.3 TB of data in an attempt to force the computer giant into paying an extortion fee to prevent its release. READ MORE...
Dior Says Personal Information Stolen in Cyberattack
French luxury fashion giant Dior is notifying customers that their personal information was likely compromised in a January 2025 data breach. The incident, the company says, occurred on January 26, 2025, and involved unauthorized access to a database containing information about Dior clients. "The House of Dior recently discovered that an unauthorized external party accessed some of the data we hold for our Dior Fashion and Accessories customers," the company says in a notice on its website. READ MORE...
UK Sanctions Russian Hackers Tied to Assassination Attempts
The UK government announced sanctions against three Russian military intelligence units, 18 of their members, and other individuals involved in malicious cyber operations and assassination attempts. The sanctions target Russian General Staff Main Intelligence Directorate (GRU) Units 29155, 26165, and 74455, which have been linked to numerous cyberattacks against Ukraine, NATO allies, European Union member states, and US targets. READ MORE...
Microsoft Fix Targets Attacks on SharePoint Zero-Day
On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the SharePoint flaw to breach U.S. federal and state agencies, universities, and energy companies. In an advisory about the SharePoint security hole, Microsoft said it is aware of active attacks targeting on-premises SharePoint Server customers READ MORE...
Malicious Implants Are Coming to AI Components, Applications
The next generation of malicious implants may live in the AI application back end. Security researcher Hariharan Shanmugam will publish research next month focused on a security issue he discovered regarding how AI models are uniquely vulnerable to injected code. Though much of security research for AI risks right now concerns prompt injections, Shanmugam's findings join a growing body of research dedicated to more technical flaws in LLM models. READ MORE...
'Car crash victim' calls mother for help and $15K bail money. But it's an AI voice scam
A woman in Florida was tricked into giving thousands of dollars to a scammer after her daughter's voice was AI-cloned and used in a scam. Sharon Brightwell says she received a call from someone who sounded just like her daughter. The woman on the other end was sobbing and crying, telling her mom that she had caused a car accident in which a pregnant woman had been seriously injured. She said she'd been texting and driving and that her phone had now been taken by police. READ MORE...
ExpressVPN bug leaked user IPs in Remote Desktop sessions
ExpressVPN has fixed a flaw in its Windows client that caused Remote Desktop Protocol (RDP) traffic to bypass the virtual private network (VPN) tunnel, exposing the users' real IP addresses. One of the key premises of a VPN is masking a user's IP address, allowing users to stay anonymous online, and in some cases, bypass censorship. Failing to do so is a severe technical failure for a VPN product. READ MORE...
Ring denies breach after users report suspicious logins
Ring is warning that a backend update bug is responsible for customers seeing a surge in unauthorized devices logged into their account on May 28th. On May 28th, many Ring customers reported seeing unusual devices logged into their accounts from various locations worldwide, leading them to believe their accounts had been hacked. Last week, Ring posted to Facebook stating that they are aware "of a bug that incorrectly displays prior login dates as May 28, 2025." READ MORE...
- ...in 1894, the first motor race is held in France between the cities of Paris and Rouen. The winning vehicle's average speed: 11 mph.
- ...in 1933, American aviator Wiley Post returns to Floyd Bennett Field in New York, having flown solo around the world in 7 days, 18 hours, and 49 minutes.
- ...in 1940, "Jeopardy!" host and TV producer Alex Trebek is born in Ontario, Canada.
- ...in 1990, American cyclist Greg LeMond wins his second consecutive Tour de France, and his third overall.