Daily Cybersecurity Roundup, October 05, 2023
by sunj9710 - Friday October 6, 2023 at 07:55 AM
#1
In a digital age where even a diary has a lock, countless databases still lay bare without a password. One of those, belonging to a B2B CRM firm, exposed millions of sensitive records. Job seekers beware! A new scam is circulating, promising crypto earnings while draining your savings. In other news, the PLAY ransomware group added six new victims to its leak site. Read on to know more from the past 24 hours.


01
A non-password-protected database belonging to Really Simple Systems exposed over three million records, including medical records, tax documents, identification numbers, and more.


02
A new scam operation called WebWyrm is targeting job seekers. The scammers have already targeted over 100,000 individuals in 50 countries, potentially earning them over $100 million.


03
A cyberattack hit Mt. Graham Regional Medical Center in Arizona, affecting its communication and information systems. Another one in St. Louis, Missouri, targeted the Metro Call-A-Ride service for people with disabilities.


04
The PLAY ransomware group added six new victims, including Roof Management, Security Instrument Corp, Filtration Control Ltd, Cinépolis Cinemas, CHARMANT Group, and Stavanger Municipality, to its data leak site.


05
A misconfigured Apache2 web server belonging to the Lorenz ransomware group leaked the personal information of individuals who had contacted them through their online contact form, exposing names, email addresses, and subject lines.


06
Group-IB spotted a new Android trojan called GoldDigger that is targeting users of Vietnamese banking apps to steal their credentials and drain their accounts.


07
Cyble discovered threat actors using banned applications in Russia to carry out a phishing campaign, targeting users by mimicking popular apps like ExpressVPN, WeChat, and Skype.


08
The Royal Women’s Hospital, Melbourne, notified 192 patients that their data may have been compromised due to a worker sending details to their personal email account, which was then accessed by cybercriminals.


09
A cyberespionage campaign called Operation Jacana targeted a governmental entity in Guyana, with the use of spear-phishing and a previously unknown implant called DinodasRAT.


10
Identity management company Okta acquired password management app Uno, with the aim of speeding up the launch of its consumer offerings.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  US health system notifies 882,000 patients of August 2023 breach KingDice 0 528 02-09-2025, 08:03 AM
Last Post: KingDice
  Countries Ranked by Internet Privacy (2023) WHOISTHAT 9 1,191 09-21-2024, 02:09 AM
Last Post: gailee8282
  Daily Cybersecurity Roundup, September 11, 2023 sunj9710 2 1,796 06-05-2024, 04:57 PM
Last Post: themanoj
  Daily Cybersecurity Roundup, October 10, 2023 sunj9710 1 2,157 04-05-2024, 12:00 PM
Last Post: delkibrother12
  Daily Cybersecurity Roundup, August 28, 2023 sunj9710 1 1,487 02-10-2024, 05:20 AM
Last Post: bonfire365

Forum Jump:


 Users browsing this thread: 1 Guest(s)