EVENTS
0
EVENTS/DAY
0
EVENTS
0
EVENTS/DAY

The Autumn has begun, and I can finally publish the first timeline of September 2021. Despite we are still far from the highest peaks of activity of this year, in this timeline I have collected 93 events, an increase in comparison with the 78 of the previous timeline. Ransomware continues to dominate the threat landscape, with a percentage similar to the previous period (25.8% vs 24.4% (24 out of 93 events) and with new high-profile victims joining the unwelcome list of the victims.

A trend that is characterizing this year and seems endless is the exploitation of high-profile vulnerabilities. In this timeline you will find multiple events occurred exploiting en-masse software flaws on Confluence (CVE-2021-26084), Zoho (CVE-2021-40539), and the Microsoft MSHTML rendering engine CVE-2021-40444, without considering the dump of 500,000 VPN credentials obtained through the old CVE-2018-13379.

Interestingly enough, this timeline also contains some mega breaches, the worst of which is undoubtedly the leak by the Anonymous collective of 15 million records from Epik, a controversial web hosting provider. Other interesting events happened in Israel and France. I am talking about the leak of the personal data belonging to 7 million Israelis from the CITY4U website, and around 1.4 million people who took COVID-19 tests in the Paris. .

Not so much to mention, numerically, on the cyber espionage front, except maybe the revelation of an attack targeting the United Nations, Other interesting events include a new campaign by Mustang Panda targeting at least ten Indonesian government ministries and agencies, and some APT actors exploiting the above mentioned Zoho vulnerability.

Last but not least, two misinformation campaigns were unearthed in this fortnight respectively pro-Russia and pro-China (how weird!)

Expand for details

Enjoy the interactive timeline, and thanks for sharing it, and supporting my work in spreading the risk awareness across the community. Also, don’t forget to follow @paulsparrows on Twitter, or even connect on Linkedin, for the latest updates.

SUPPORT MY WORK!

BREACHOMETER

The “Breachometer” compares the current number of events/day with the max and min values recorded in the previous 12 months.

12 MONTHS TREND
POPULAR POSTS
  • 1-15 September 2021 Cyber Attacks Timeline

    The Autumn has begun, and I can finally publish the first timeline of September 2021. Despite we are still far from the highest peaks of activity of this year, in this timeline...

  • August 2021 Cyber Attacks Statistics

    During August 2021, I have collected 170 events that I can finally aggregate into (hopefully useful) statistics. This number represents a 10% decrease in comparison to the

  • August 2016 Cyber Attacks Statistics

    It's time to publish the statistics derived from the cyber attacks timelines of August (Part I and Part II), a month particularly active from an Information Security perspective, despite the Summer time. As always, let’s start from the Daily Trend Chart ...

  • 2020 Cyber Attacks Statistics

    As promised, I have pulled together some statistics from the data collected in 2020. The master table is available at the end of the post after the charts.

  • The Biggest Data Breaches of 2021

    With this new project I am going to track the biggest data breaches of 2021 extracted from my cyber attack timelines.

FOLLOW ME ON TWITTER

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.