{"id":8748,"date":"2024-05-07T11:46:06","date_gmt":"2024-05-07T08:46:06","guid":{"rendered":"https:\/\/cyberone.bg\/?p=8748"},"modified":"2024-05-07T11:46:06","modified_gmt":"2024-05-07T08:46:06","slug":"weekly-cybersecurity-report-week-17-2024-2","status":"publish","type":"post","link":"https:\/\/cyberone.bg\/en\/weekly-cybersecurity-report-week-17-2024-2","title":{"rendered":"Weekly Cybersecurity Report | Week 17, 2024"},"content":{"rendered":"<p>As your dedicated cybersecurity services provider,<strong> <a href=\"https:\/\/cyberone.bg\/\">Cyberone<\/a><\/strong> equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.<\/p>\n<h2><strong>Weekly Cybersecurity Report | Week 17, 2024<\/strong><\/h2>\n<h4><b><span data-contrast=\"auto\">Information security updates and events from the past week<\/span><\/b><span data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559739&quot;:60}\">\u00a0<\/span><\/h4>\n<h3><b><span data-contrast=\"auto\">1 &#8211; The Dropbox company reports that attackers managed to access the production environment of the Dropbox Sign service and were exposed to sensitive customer information.<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The disclosed information belongs only to customers who use the Dropbox Sign service, designed for digitally signing documents, among the disclosed information: usernames, phone numbers, API keys and more.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service\/\"><span data-contrast=\"none\">Learn more: https:\/\/www.bleepingcomputer.com\/news\/security\/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service\/<\/span><\/a><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">2 &#8211; SynLab reports the shutdown of all company activity in Italy due to a ransomware attack.<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The company operates about 380 laboratories where it performs various tests and now reports that it is forced to disable all computer systems and laboratory tests until the end of the event.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">At this point, no infidel group has claimed responsibility for the attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">3 &#8211; The Qantas app exposed sensitive passenger details to random users<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Qantas Airways confirms that some of its customers were affected by a misconfiguration of its app that exposed sensitive information and boarding passes to random users.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Qantas, Australia&#8217;s flagship airline and the largest airline by fleet size, operates 125 aircraft and serves 104 destinations. Qantas has approximately 23,500 employees and annual revenues of nearly $12.9 billion.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Earlier today, several users of the Qantas app reported on social media that they could view other users&#8217; travel details, including personal identification information, boarding passes for future flights and other account information.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">4 &#8211; London Drugs pharmacy chain closes stores after cyber attack<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Canadian pharmacy chain London Drugs has closed all its retail stores to contain what it described as a &#8220;cyber security incident.&#8221;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The company also hired outside experts to investigate the cyberattack that affected its systems over the weekend.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">&#8220;On April 28, 2024, London Drugs discovered that it was the victim of a cyber security incident. Out of an abundance of caution, London Drugs is closing all stores across Western Canada until further notice,&#8221; London Drugs said in a statement.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">5 &#8211; ICICI Bank exposed credit card data of 17,000 customers<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">ICICI Bank, one of India&#8217;s leading private banks, accidentally disclosed details of thousands of new credit cards to customers who were not the intended recipients.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The bank blocked 17,000 credit cards due to a technical bug in its mobile banking application, &#8216;iMobile&#8217;.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The glitch allowed users to receive card details of other customers. Exposed financial information includes credit card numbers, expiration dates and CVV values.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">6 &#8211; Hackers claim to have penetrated the main security service of Belarus<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">A group of Belarusian hackers claims to have penetrated the network of the country&#8217;s main KGB security agency and accessed personnel files of more than 8,600 employees of the organization, which still goes by its Soviet name.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Authorities did not respond to the claim, but the website of the Belarusian KGB opened with a blank page on Friday that said it was &#8220;under development&#8221;.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">To back up its claim, the Belarusian Cyber-Partisans group published a list of the site&#8217;s administrators, its database and server logs on its page on the Telegram messaging app.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">7 &#8211; LA County Health Services: Patient data exposed in phishing attack<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The Los Angeles County Department of Health Services has disclosed a data breach after thousands of patients&#8217; personal and health information was leaked in a data breach stemming from a recent phishing attack that affected more than 20 employees.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This integrated health system operates the public hospitals and clinics in LA County. (the most populous county in the United States) and is the second largest public health system in the country after NYC Health.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As disclosed in data breach notices sent to potentially affected individuals, 23 employees had their mailboxes hacked after their login information was stolen in an attack in February.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">8 &#8211; The supply of beverages in Sweden was severely affected by a ransomware attack on a logistics company<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Systembolaget&#8217;s Skanlog distributor, the Swedish government-owned retail chain, suffered a ransomware attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Systembolaget has a monopoly on the sale of alcoholic beverages containing more than 3.5% alcohol by volume. It operates stores throughout Sweden and is responsible for the retail sale of wine, spirits and strong beer.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">&#8220;It affects about 15% of our sales volume. Wine and spirits the most,&#8221; Sofia Sioman Waas, press officer at Systembolaget, told Euronews Next.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">9 &#8211; Data breach at Kaiser Permanente could affect 13.4 million patients<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Healthcare provider Kaiser Permanente has disclosed a data security incident that could affect 13.4 million people in the United States.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Kaiser Permanente is an integrated managed care corporation and one of the largest health plans in the United States.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It operates 40 hospitals and 618 medical facilities in California, Colorado, the District of Columbia, Georgia, Hawaii, Maryland, Oregon, Virginia and Washington.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong><em>The attacks highlighted in this report aren&#8217;t just incidents, they&#8217;re blueprints of the adversary&#8217;s arsenal. To protect your business you need the right protection. Cyberone is here to help! Check out our <a href=\"https:\/\/cyberone.bg\/en\/services\">services<\/a>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As your dedicated cybersecurity services provider, Cyberone equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape. Weekly Cybersecurity Report | Week 17, 2024 Information security updates and events from the past week\u00a0 1 &#8211; The Dropbox company [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8615,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[57,65,56],"class_list":["post-8748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-weekly-cyber-updates","tag-cybersecurity","tag-weekly-cybersecurity-report","tag-weekly-update"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/comments?post=8748"}],"version-history":[{"count":1,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8748\/revisions"}],"predecessor-version":[{"id":8749,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8748\/revisions\/8749"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/media\/8615"}],"wp:attachment":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/media?parent=8748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/categories?post=8748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/tags?post=8748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}