{"id":8844,"date":"2024-08-12T09:06:18","date_gmt":"2024-08-12T06:06:18","guid":{"rendered":"https:\/\/cyberone.bg\/?p=8844"},"modified":"2024-08-12T09:06:18","modified_gmt":"2024-08-12T06:06:18","slug":"weekly-cybersecurity-report-week-32-2024","status":"publish","type":"post","link":"https:\/\/cyberone.bg\/en\/weekly-cybersecurity-report-week-32-2024","title":{"rendered":"Weekly Cybersecurity Report | Week 32, 2024"},"content":{"rendered":"<p>As your dedicated cybersecurity services provider,<strong>\u00a0<a href=\"https:\/\/cyberone.bg\/\">Cyberone<\/a><\/strong>\u00a0equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.<\/p>\n<h2>Weekly Cybersecurity Report | Week 32, 2024<\/h2>\n<p><b><span data-contrast=\"auto\">Information security updates and events from the past week<\/span><\/b><span data-ccp-props=\"{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559739&quot;:60}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">1 &#8211; An attacker hacked into the Mobile Guardian platform and remotely deleted data of 13,000 students.<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The Mobile Guardian platform provides several capabilities for managing tablets and computer stations in schools and helps with classroom management, control of usage times, content control and more.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">According to the company&#8217;s report, an attacker gained access to the company&#8217;s systems and remotely performed a complete deletion of a small number of positions.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Contrary to the company&#8217;s report, the Ministry of Education in Singapore reports that the attacker deleted information from approximately 13,000 student laptops and tablets&#8230;.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Upon detection of the incident, the company cut off access to the platform and at this point users cannot log in.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.straitstimes.com\/singapore\/politics\/all-devices-affected-by-mobile-guardian-glitch-to-be-fixed-by-aug-16-priority-for-o-level-students\"><span data-contrast=\"none\">https:\/\/www.straitstimes.com\/singapore\/politics\/all-devices-affected-by-mobile-guardian-glitch-to-be-fixed-by-aug-16-priority-for-o-level-students<\/span><\/a><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">2 &#8211; The Grand Palais Rmn organization in France, which manages the activities of several museums in the country, reports that it is suffering from a ransomware attack.<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Following the attack, the organization disabled the computer systems, and a number of museums are experiencing disruptions in activity.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Various reports indicate that the attack was caused after the credentials of one of Grand Palais Rmn&#8217;s partners were stolen using Infostealler.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">\u00a0At this point, no infidel group has claimed responsibility for the attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">3 &#8211; A ransom attack on c-edge technologies led to the shutdown of about 300 banks in India.<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Following a ransom attack on the company c-edge technologies, which provides banks with various technological systems, about 300 banks in India had to stop their activities.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The National Payments Corporation of India (NPCI) has proactively disconnected all c-edge technologies from the country&#8217;s payment system to prevent the spread of the malware.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Cloudsek reports that the Ransomexx ransomware group is responsible for the attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">4 &#8211; ADT company approves data hacking after it leaked customer information on a hacking forum<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">US building security giant ADT has confirmed it suffered a data breach after threat actors leaked allegedly stolen customer data on a popular hacking forum.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">ADT is a public American company specializing in security and smart home solutions for residential and small business customers. The company employs 14,300 people, has annual revenue of $4.98 billion, and serves approximately 6 million customers in 200 locations in the United States.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In a Form 8-K regulatory filing Thursday morning with the Securities and Exchange Commission (SEC), ADT says threat actors hacked some of its databases and stole customer information.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">5 &#8211; The Rhysida Ransomware group claims to have hacked Bayhealth Hospital in Delaware<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Bayhealth Hospital is a not-for-profit health system with nearly 4,000 employees and a medical staff of more than 450 physicians and 200 physicians.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The Rhysida Ransomware group claims to have hacked Bayhealth Hospital and added the hospital to the list of victims on its Tor leak site.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The group claims to have stolen data from the hospital and demands 25 BTC to avoid leaking it. The group leaked screenshots of stolen passports and IDs as proof of the hack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">6 &#8211; A ransomware attack cost Keytronic over $17 million<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Electronics manufacturing services company Keytronic revealed on Friday that the latest ransomware attack resulted in more than $17 million in additional expenses and lost revenue.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The company disclosed the costs associated with the incident in a preliminary financial report for the fourth quarter of fiscal 2024.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">&#8220;Due to this event, the company was required to incur additional expenses of approximately $2.3 million, and it believes it lost approximately $15 million in revenue during the fourth quarter,&#8221; said Keytronic.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">However, he added, &#8220;Most of these orders are refundable and are expected to materialize in fiscal year 2025. Partially offsetting these additional expenses was an insurance gain of $0.7 million that was also recorded during the quarter.&#8221;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The cyber-attack, discovered on May 6, caused disruptions to websites in the United States and Mexico. Activity on these sites was suspended for two weeks due to the incident.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The company first reported in June that it had already incurred about $600,000 in expenses for outside cybersecurity experts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><b><span data-contrast=\"auto\">7 &#8211; Personal and health information was stolen from Cencora<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Healthcare giant Cencora confirmed this week that personally identifiable information (PII) and protected health information (PHI) were stolen in a February 2024 cyber-attack.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The incident was identified on February 21 and disclosed a few days later in a regulatory filing, when the company said that personal information had been leaked from its systems.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In a July 31 filing with the Securities and Exchange Commission (SEC), Cencora said that &#8220;additional data, beyond what was initially identified, has been released.&#8221;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The company has identified and completed its review of most of the data. That review confirmed that the data included personally identifiable information and protected health information about individuals, most of which is maintained by a subsidiary of the company that provides patient support services, Cencora said.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In addition, it stated that the attack did not have a material impact on its activities, and its systems remained fully operational and that no material impact on the financial situation or the result of the activity is expected.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong><em>The attacks highlighted in this report aren&#8217;t just incidents, they&#8217;re blueprints of the adversary&#8217;s arsenal. To protect your business you need the right protection. Cyberone is here to help! Check out our <a href=\"https:\/\/cyberone.bg\/en\/services\">services<\/a>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As your dedicated cybersecurity services provider,\u00a0Cyberone\u00a0equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape. Weekly Cybersecurity Report | Week 32, 2024 Information security updates and events from the past week\u00a0 1 &#8211; An attacker hacked into the [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8606,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[],"class_list":["post-8844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-weekly-cyber-updates"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/comments?post=8844"}],"version-history":[{"count":1,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8844\/revisions"}],"predecessor-version":[{"id":8845,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/posts\/8844\/revisions\/8845"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/media\/8606"}],"wp:attachment":[{"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/media?parent=8844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/categories?post=8844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberone.bg\/en\/wp-json\/wp\/v2\/tags?post=8844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}