In a major blow to cybercrime, an international law enforcement coalition has seized the dark web data leak site of the notorious BlackSuit ransomware group. The operation, led by U.S. Homeland Security Investigations and involving 17 agencies, aims to disrupt ransomware operations targeting organizations worldwide and signals increasing global cooperation in the fight against ransomware syndicates.
Source: Security Affairs
Allianz Life Data Breach Impacts Over 1 Million Customers
Insurance giant Allianz Life has confirmed that the personal data of the majority of its 1.4 million customers was exposed in a significant breach earlier this month. The breach compromised sensitive customer and employee information, raising concerns about the potential for identity theft and prompting calls for enhanced cybersecurity in the insurance sector.
Source: Bleeping Computer
Microsoft SharePoint Attacks Linked to Information Leak
Researchers are pointing to a leak in Microsoft’s MAPP program as the root cause enabling attackers to exploit unpatched SharePoint vulnerabilities, leading to remote code execution incidents. Despite Microsoft's July software updates, the bugs were not fully resolved, leaving organizations at continued risk of takeovers of on-premises servers.
Source: The Register
FBI Issues New Warning to Android and iPhone Users About ‘Phantom Hacker’ Scam
The FBI has issued an urgent alert to all smartphone users about sophisticated ‘Phantom Hacker’ scams capable of draining victims’ life savings. The Bureau emphasizes that ignoring these warnings could have devastating financial consequences, underlining the need for heightened vigilance and updated security practices on mobile devices.
Source: Forbes Security
Congress Introduces Legislation to Ban AI-Driven Pricing Surveillance
New U.S. legislation aims to outlaw the use of AI surveillance tools that dynamically adjust prices and wages based on personal data. The bill, introduced by two Democratic lawmakers, targets increasingly popular but controversial AI practices in industries such as airlines, stirring debate around privacy and ethical technology use.
Source: The Register
Arizona Woman Sentenced for Assisting North Korean IT Job Fraud in U.S.
An Arizona woman has been sentenced to more than 8 years in prison for facilitating a North Korean-led scheme that infiltrated 309 U.S. firms through fraudulent IT job applications. The case highlights an ongoing trend of nation-state actors circumventing sanctions and gaining access to sensitive infrastructure through identity fraud and insider threats.
Source: Security Affairs
Post SMTP Plugin Flaw Puts 200,000+ WordPress Sites at Risk
A critical vulnerability in the popular Post SMTP plugin is exposing over 200,000 WordPress sites to site hijacking attacks. Attackers exploiting the bug can gain admin-level control, underscoring the importance of rapid patching and scrutiny of third-party components in widely used content management systems.
Source: Bleeping Computer
You May Also Be Interested In... UK's New Online Safety Act: What Consumers Need to Know
Dating Safety App Tea Breached, Exposing 72,000 User Images
Microsoft to stop using China-based teams to support Department of Defense