In its assessment, the software giant's incident response team said they were fairly confident the attacker was an initial access broker with ties to the UNC2447, Lapsus$ and Yanluowang threat groups.
At the Black Hat conference on Wednesday, the chair of the Cyber Safety Review Board said its initial review of the Log4j vulnerability “proved the concept” behind the board’s work and promised more action in the coming months.
Roughly 9,000 crypto wallets on the Solana blockchain were reportedly robbed of more than $4 million as spate of attacks target cryptocurrency exchanges and bridge sites.
BleepingComputer reports that email marketing company Klaviyo has been impacted by a data breach last Wednesday that has compromised its internal systems, as well as cryptocurrency customers' marketing lists following a phishing attack that allowed attackers to gain employee credentials.
Salinas Valley Memorial Health will pay the patients impacted by a 2020 email hack $340,000 to resolve a lawsuit alleging the California health system’s poor cybersecurity caused the breach.
Mailing vendor OneTouchPoint informed 30 health plans their patient data was accessed during a ransomware attack; now 326,278 Aetna members have been added to the tally. The incident leads this week’s healthcare data breach roundup.
The Hacker News reports that legitimate applications, including Adobe Reader, Skype, and VLC Player, have been increasingly impersonated by threat actors in social engineering attacks.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.