• Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
MUST READ

Kai West, aka IntelBroker, indicted for cyberattacks causing $25M in damages

 | 

Cisco fixed critical ISE flaws allowing Root-level remote code execution

 | 

U.S. CISA adds AMI MegaRAC SPx, D-Link DIR-859 routers, and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

 | 

CitrixBleed 2: The nightmare that echoes the 'CitrixBleed' flaw in Citrix NetScaler devices

 | 

Hackers deploy fake SonicWall VPN App to steal corporate credentials

 | 

Mainline Health Systems data breach impacted over 100,000 individuals

 | 

Disrupting the operations of cryptocurrency mining botnets

 | 

Prometei botnet activity has surged since March 2025

 | 

The U.S. House banned WhatsApp on government devices due to security concerns

 | 

Russia-linked APT28 use Signal chats to target Ukraine official with malware

 | 

China-linked APT Salt Typhoon targets Canadian Telecom companies

 | 

U.S. warns of incoming cyber threats following Iran airstrikes

 | 

McLaren Health Care data breach impacted over 743,000 people

 | 

American steel giant Nucor confirms data breach in May attack

 | 

The financial impact of Marks & Spencer and Co-op cyberattacks could reach £440M

 | 

Iran-Linked Threat Actors Cyber Fattah Leak Visitors and Athletes' Data from Saudi Games

 | 

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 50

 | 

Security Affairs newsletter Round 529 by Pierluigi Paganini – INTERNATIONAL EDITION

 | 

Iran confirmed it shut down internet to protect the country against cyberattacks

 | 

Godfather Android trojan uses virtualization to hijack banking and crypto apps

 | 
  • Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
  • Home
  • Breaking News
  • Security Affairs newsletter Round 491 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs newsletter Round 491 by Pierluigi Paganini – INTERNATIONAL EDITION

Pierluigi Paganini September 29, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Hackers stole over $44 million from Asian crypto platform BingX
OP KAERB: Europol dismantled phishing scheme targeting mobile users
Ukraine bans Telegram for government agencies, military, and critical infrastructure
Tor Project responded to claims that law enforcement can de-anonymize Tor users
UNC1860 provides Iran-linked APTs with access to Middle Eastern networks
US DoJ charged two men with stealing and laundering $230 Million worth of cryptocurrency
The Vanilla Tempest cybercrime gang used INC ransomware for the first time in attacks on the healthcare sector
U.S. CISA adds new Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalog
Ivanti warns of a new actively exploited Cloud Services Appliance (CSA) flaw
International law enforcement operation dismantled criminal communication platform Ghost
U.S. CISA adds Microsoft Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and Microsoft SQL Server bugs to its Known Exploited Vulnerabilities catalog
SIEM for Small and Medium-Sized Enterprises: What you need to know
Antivirus firm Dr.Web disconnected all servers following a cyberattack
Experts warn of China-linked APT’s Raptor Train IoT Botnet
Credential Flusher, understanding the threat and how to protect your login data
U.S. Treasury issued fresh sanctions against entities linked to the Intellexa Consortium
Broadcom fixed Critical VMware vCenter Server flaw CVE-2024-38812
Remote attack on pagers used by Hezbollah caused 9 deaths and thousands of injuries
Chinese man charged for spear-phishing against NASA and US Government
Data Breach
Qilin ransomware attack on Synnovis impacted over 900,000 patients
D-Link addressed three critical RCE in wireless router models
Apple dismisses lawsuit against surveillance firm NSO Group due to risk of threat intelligence exposure
Hacker tricked ChatGPT into providing detailed instructions to make a homemade bomb
Port of Seattle confirmed that Rhysida ransomware gang was behind the August attack

International Press – Newsletter

Cybercrime  

Samourai and Tornado Cash both pinning hopes on upcoming ruling  

Cyberattack on Kansas water treatment facility investigated by feds  

Modified LockBit and Conti ransomware shows up in DragonForce gang’s attacks  

Inside the Dragon: DragonForce Ransomware Group 

Two Russian Nationals Charged in Connection with Operating Billion Dollar Money Laundering Services  

Telegram’s New Rules Push Criminal Groups to Flee the Platform  

Security Brief: Actor Uses Compromised Accounts, Customized Social Engineering to Target Transport and Logistics Firms with Malware

Administrator account blamed for rail terror message hack  

OFAC and FinCEN target major Russian money laundering services including Cryptex and PM2BTC

Seizure of 7 million euros of crypto currency and 2 crypto currency exchanges offline  

Crypto scammers hack OpenAI’s press account on X     

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

Kuwait Health Ministry restoring systems after cyberattack takes down hospitals, healthcare app  

Wallet Scam: A Case Study in Crypto Drainer Tactics

Malware

How the Necro Trojan infiltrated Google Play, again  

Kryptina RaaS | From Unsellable Cast-Off to Enterprise Ransomware  

Infostealer malware bypasses Chrome’s new cookie-theft defenses

AI-Generated Malware Found in the Wild

“Marko Polo” Navigates Uncharted Waters With Infostealer Empire

Octo2: European Banks Already Under Attack by New Malware Variant  

Hacking

Hacking Kia: Remotely Controlling Cars With Just a License Plate  

4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways  

LLM’s New Achilles Heel: When Prompts Become Exploits  

A collection of Semgrep rules to facilitate vulnerability research

CVEs Targeting Remote Access Technologies

Hezbollah likely to launch retaliatory cyberattack on Israel, expert says          

Rethinking Red Teaming for AI: The new wave of Cybersecurity in the age of AI  

Israeli Group Claims Lebanon Water Hack as CISA Reiterates Warning on Simple ICS Attacks

Attacking UNIX Systems via CUPS, Part I     
Highly Anticipated Linux Flaw Allows Remote Code Execution, but Less Serious Than Expected 

Tosint: Open-source Telegram OSINT tool  

Intelligence and Information Warfare 

GreyNoise Reveals New Internet Noise Storm: Secret Messages and the China Connection  

-=TWELVE=- is back 

Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC  

Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors

‘Get away from Hezbollah’: Has Israel hacked Lebanon’s telecoms networks?  

Iran linked hacker group Handala Hack Team claim pager explosions linked to Israeli battery company  

Norway starts probe into reported links to exploding pagers in Lebanon  

Thousands of Capitol Hill staffers’ info spilled across dark web, security firm says  

Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023  

China-Linked Hackers Breach U.S. Internet Providers in New ‘Salt Typhoon’ Cyberattack  

China’s satellites are dodging US eyes in space 

Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy 

Sophistication of AI-backed operation targeting senator points to future of deepfake schemes 

Three IRGC Cyber Actors Indicted for ‘Hack-and-Leak’ Operation Designed to Influence the 2024 U.S. Presidential Election   

Cybersecurity

Nearly 40% of FAA air traffic control systems need urgent updates, GAO reports  

Telegram Changes Policy, Says It Will Provide User Data to Authorities  

‘Cybersecurity issue’ takes MoneyGram offline for three days – and counting

Kaspersky deletes itself, installs UltraAV antivirus without warning

HP Wolf Security Threat Insights Report: September 2024 

Google & Arm – Raising The Bar on GPU Security

Increased Cybersecurity Essential For NGOs: Help Available  

Firefox tracks you with “privacy preserving” feature  

Cyber house of cards – Politicians’ and staffers’ personal details exposed online 

NATO is testing out this decentralized messenger for communications between member nations  

Kaspersky defends force-replacing its security software without users’ explicit consent  

Threat Actors Continue to Exploit OT/ICS through Unsophisticated Means 

Uniting for Internet Freedom: Tor Project & Tails Join Forces

Microsoft’s more secure Windows Recall feature can also be uninstalled by users

Irish Data Protection Commission fines Meta Ireland €91 million         

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Subscribe to the newsletter for free here:

https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7093942975545667584

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)


facebook linkedin twitter

Cybercrime data breach Hacking hacking news information security news IT Information Security malware Newsletter Pierluigi Paganini Security Affairs Security News

you might also like

Pierluigi Paganini June 26, 2025
Kai West, aka IntelBroker, indicted for cyberattacks causing $25M in damages
Read more
Pierluigi Paganini June 26, 2025
Cisco fixed critical ISE flaws allowing Root-level remote code execution
Read more

leave a comment

newsletter

Subscribe to my email list and stay
up-to-date!

    recent articles

    Kai West, aka IntelBroker, indicted for cyberattacks causing $25M in damages

    Cyber Crime / June 26, 2025

    Cisco fixed critical ISE flaws allowing Root-level remote code execution

    Security / June 26, 2025

    U.S. CISA adds AMI MegaRAC SPx, D-Link DIR-859 routers, and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

    Security / June 26, 2025

    CitrixBleed 2: The nightmare that echoes the 'CitrixBleed' flaw in Citrix NetScaler devices

    Hacking / June 26, 2025

    Hackers deploy fake SonicWall VPN App to steal corporate credentials

    Hacking / June 25, 2025

    To contact me write an email to:

    Pierluigi Paganini :
    pierluigi.paganini@securityaffairs.co

    LEARN MORE

    QUICK LINKS

    • Home
    • Cyber Crime
    • Cyber warfare
    • APT
    • Data Breach
    • Deep Web
    • Digital ID
    • Hacking
    • Hacktivism
    • Intelligence
    • Internet of Things
    • Laws and regulations
    • Malware
    • Mobile
    • Reports
    • Security
    • Social Networks
    • Terrorism
    • ICS-SCADA
    • POLICIES
    • Contact me

    Copyright@securityaffairs 2024

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities...
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
    Non-necessary
    Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
    SAVE & ACCEPT