Normal view
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
City of Coweta refuses to pay ransom after system-wide cyberattack
City of Coweta hit with system-wide ransomware attack, has backup
-
The Record from Recorded Future News
- Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence
Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence

-
DataBreaches.Net
- Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June. (1)
Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June. (1)
Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
-
The Record from Recorded Future News
- Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents

-
The Record from Recorded Future News
- Anthropic AI agent faked identities, phished real developers in UK government hacking test
Anthropic AI agent faked identities, phished real developers in UK government hacking test

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
Massive supply-chain attack compromises 440 packages under four hours
In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms.Β
The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. The attacker spent the next 30 minutes compromising additional packages controlled by the same maintainer, including cacheable, flat-cache, file-entry-cache.
The attack spread to other maintainers, eventually compromising more than 860 packages with a βcombined total of over 2 billion monthly installs,β Ilyas Makari, malware researcher at Aikido Security, wrote in a blog post.Β
Wiz researchers told CyberScoop it hasnβt observed any new malicious packages since the initial wave moved through a massive footpoint of cloud and code environments in those first four hours.Β
βThis is the most critical initial compromise, with over 155 million weekly downloads on the root packages,β Wiz Research said in an email.Β
Some of the compromised packages, including keyv, flat-cache and file-entry-cache, are present in more than 46% of all cloud environments, according to Wiz. βBy comparison, back in the Shai-Hulud 2.0 campaign the most prevalent packages were only in about 28% of environments,β the company said.Β
βTime will tell whether the eventual cost and impact outpaces past attacks, or whether adoption of hardening mechanisms such as package aging, and the usage of the relatively less aggressive Mini Shai-Hulud code as basis, will defray the final toll here,β Wiz Research added.Β
Researchers from multiple firms sprung into action to monitor the widening attack spree and published indicators of compromise to help potential victims hunt for malicious activity in their systems.Β
The Mini Shai-Hulud variant used in these attacks scoops up a trove of sensitive data, including npm, GitHub, AWS and continuous integration credentials. It also steals AI-related configuration files and cryptocurrency wallets, researchers said.Β
Microsoft, Aikido, Socket and Wiz all said the same payload and pattern was observed across all affected packages, indicating a single attacker or threat cluster was behind the supply-chain attack and using multiple stolen tokens.Β
The malware showcased a few pieces of new functionality, but retained the same core mechanisms that are hallmarks of Mini Shai-Hulud.Β
βThe evolution is consistent with what weβve seen from them in past waves, however we donβt yet have the hard linksβ to confidently attribute the attacks to TeamPCP, Wiz Research said.
The notorious threat actor, which Google previously told CyberScoop it attributes to one core operator that was located in South Africa during at least some of the attacks, compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year.
The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.
-
The Record from Recorded Future News
- Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says

-
DataBreaches.Net
- The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
Ransomware in Italy: RedACT report sheds light on an evolving threat environment
-
DataBreaches.Net
- North Koreaβs Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
North Koreaβs Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
-
The Record from Recorded Future News
- North Korean hackers behind major open-source supply chain attacks, Amazon says
North Korean hackers behind major open-source supply chain attacks, Amazon says

-
DataBreaches.Net
- Crime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent Vector
Crime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent Vector
-
DataBreaches.Net
- HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities
HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities
-
The Record from Recorded Future News
- Laundry Bearβs webmail hackers had more in store after February, report says
Laundry Bearβs webmail hackers had more in store after February, report says

-
The Record from Recorded Future News
- Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
