BleepingComputer.com

"TeamViewer links corporate cyberattack to Russian state hackers."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 28 June 2024, 1516 UTC.

Content and source:  https://www.bleepingcomputer.com/

Please click link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

TeamViewer links corporate cyberattack to Russian state hackers

  • RMM software developer TeamViewer says a Russian state-sponsored hacking group known as Midnight Blizzard is believed to be behind a breach of their corporate network this week.

  • Hacker prison
     

Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator

  • The recent large scale supply chain attack conducted via multiple CDNs, namely Polyfill.io, BootCDN, Bootcss, and Staticfile that affected up to tens of millions of websites has been traced to a common operator. Researchers discovered a public GitHub repository with leaked API keys helping them draw a conclusion.

  • Security Cybersecurity
     

Hit your summer goals with $465 off a cybersecurity training bundle

  • Career training is a year-round goal for IT pros, and the summer is the perfect time to practice for exams and build skills. This five-course cybersecurity bundle helps you hit your summer targets for $69.97, $465 off the $535 MSRP, now through 11:59 PM PST on July 21st.

    • BLEEPINGCOMPUTER DEALS
    •  
    • JUNE 28, 2024
    •  
    • 07:12 AM
    •  
    • Comment Count 0
  • Clinic
     

Former IT employee accessed data of over 1 million US patients

  • Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance, an IT services provider contracted by the organization.

  • Black Suit BlackSuit hacker
     

BlackSuit ransomware gang claims attack on KADOKAWA corporation

  • The BlackSuit ransomware gang claimed a recent cyberattack on KADOKAWA corporation and is now threatening to publish stolen data if a ransom is not paid.

  • Cluster bomb
     

New Unfurling Hemlock threat actor floods systems with malware

  • A threat actor tracked as Unfurling Hemlock has been infecting target systems with up to ten pieces of malware at the same time in campaigns that distribute hundreds of thousands of malicious files.

  • Justice
     

U.S. indicts Russian GRU hacker, offers $10 million reward

  • The U.S. indicted Russian national Amin Timovich Stigal for his alleged role in cyberattacks targeting Ukrainian government computer networks in an operation from the Russian foreign military intelligence agency (GRU) prior to invading the country.

  • TeamViewer
     

TeamViewer's corporate network was breached in alleged APT hack

  • The remote access software company TeamViewer is warning that its corporate environment was breached in a cyberattack yesterday, with a cybersecurity firm claiming it was by an APT hacking group.

  • Microsoft
     

Get certified this summer with $369 off this Microsoft training bundle

  • Getting certified in Microsoft products can help you advance your IT career. This 11-course Microsoft certification training bundle gets you started for $59.97, $369 off the  $429 MSRP, now through 11:59 PM PST on July 21st.

    • BLEEPINGCOMPUTER DEALS
    •  
    • JUNE 27, 2024
    •  
    • 02:09 PM
    •  
    • Comment Count 0
  • Windows 11
     

Microsoft pulls Windows 11 KB5039302 update causing reboot loops

  • Microsoft pulled the June Windows 11 KB5039302 update after finding that it causes some devices to restart repeatedly.

  • GitLab
     

Critical GitLab bug lets attackers run pipelines as any user

  • A critical vulnerability is affecting certain versions of GitLab Community and Enterprise Edition products, which could be exploited to run pipelines as any user.

  • EC-Council to Decrease AI Chasm with Free Cyber AI Toolkit for Members
     

EC-Council to Decrease AI Chasm with Free Cyber AI Toolkit for Members

  • EC-Council, creator of the Certified Ethical Hacker (CEH) credential, is introducing a Cyber AI Toolkit free for all of its certified members. The Cyber AI Toolkit equips members with cutting-edge AI-enabled cybersecurity courses at no cost, helping them be better prepared for today's cybersecurity landscape in the advent of AI.

  • Get storage and style with $50 off this slim portable hard drive
     

Get storage and style with $50 off this slim portable hard drive

  • Extra data storage is always handy, but it's even better when it adds a little pop of color. This gradient-style 1TB portable hard drive gives you plenty of space while taking up less room for $59.99, $50 off the $109 MSRP.

    • BLEEPINGCOMPUTER DEALS
    •  
    • JUNE 27, 2024
    •  
    • 07:16 AM
    •  
    • Comment Count 0
  • Supply Chain Attack
     

Polyfill claims it has been 'defamed', returns after domain shut down

  • The owners of Polyfill.io have relaunched the JavaScript CDN service on a new domain after polyfill.io was shut down as researchers exposed it was delivering malicious code on upwards of 100,000 websites.. The Polyfill service claims that it has been "maliciously defamed" and been subject to "media messages slandering Polyfill."

  • Cloudflare
     

Cloudflare: We never authorized polyfill.io to use our name

  • Cloudflare, a lead provider of content delivery network (CDN) services, cloud security, and DDoS protection has warned that it has not authorized the use of its name or logo on the Polyfill.io website, which has recently been caught injecting malware on more than 100,000 websites in a significant supply chain attack.

  • Hackers ransomware
     

Chinese Cyberspies Employ Ransomware in Attacks for Diversion

  • Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft.

  • Federal Reserve
     

LockBit lied: Stolen data is from a bank, not US Federal Reserve

  • Recently-disrupted LockBit ransomware group, in a desperate attempt to make a comeback, claimed this week that it had hit the Federal Reserve, the central bank of the United States. Except, the rumor has been quashed.

  • Shield
     

Train for your CISSP certification with $384 off this course bundle

  • Earning a CISSP credential can open doors in your career and expand your cybersecurity skills. This eight-course CISSP training bundle helps you pass the exam for $39.99, $384 off the $424 MSRP.

    • BLEEPINGCOMPUTER DEALS
    •  
    • JUNE 26, 2024
    •  
    • 02:11 PM
    •  
    • Comment Count 0
  • CISA
     

CISA: Most critical open source projects not using memory safe code

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are susceptible to memory flaws.

  • Fortra
     

Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released

  • The Fortra FileCatalyst Workflow is vulnerable to an SQL injection vulnerability that could allow remote unauthenticated attackers to create rogue admin users and manipulate data on the application database.

VIEW MORE

Comments

Popular posts from this blog

The Cyberwire Daily Briefing

BleepingComputer.com

SecurityWeek Briefing