In the second timeline of October 2024 I collected 120 events (7.5 events/day) with a threat landscape dominated by malware with 26.4%, a value very close to 26.2% of the previous timeline. And once again ransomware ranks at place number two with 16.5% (it was 12.3%) and targeted attacks with 13.2%.
In terms of initial access, phishing emails were still the preferred weapon with 18.5% (vs. 19.8% in the previous timeline), once again ahead of exploitation of vulnerabilities with 12.9% (it was 15.1%) and misconfigurations (5.6%).
Cyber crime led the motivations chart with 65% (it was 71.1%), ahead of cyber espionage (14.2% up from 12.4% of the previous timeline), hacktivism (7.5%, up from 4.1%) and cyber warfare (6.7% up from 4.1%)
Multiple organizations led the targeted sectors chart with 18.6% (down from 22.3%), once again ahead of governments (15% up from 10%) and individuals (13.6% up from 8.5%).
Besides these trends, as always the timeline is rich of interesting events, such as mega breaches (now the corresponding piost is updated with the events occurred in 2024) and attacks against organizations in the fintech space, so my final suggestion does not change: browse the timeline for the details of the events collected in this fortnight.
Feel free to share it to support my work and spread the risk awareness across the community. And last but not least, don’t forget to connect on Linkedin, or even follow @paulsparrows on X (formerly Twitter), psparrows.bsky.social on Bluesky, or @ppasseri@Infosec.exchange on Mastodon for the latest updates.
Geo Map October H2 2024
No Data Found
No Data Found
BE NOTIFIED OF NEW POSTS
SUPPORT MY WORK! MAKE A DONATION
Creating the timelines is a very time-consuming task.
In this first quarter of 2024, threat actors have been particularly busy in exploiting vulnerabilities (0-days but also old unpatched flaws) targeting traditional remote access technologies.
Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.
The first cyber attack timeline of September 2023 reveals a record-breaking 13.93 events/day, a worrying increase from August's downward trend. Ransomware and malware attacks continue to be prevalent, making up 39.7% of the threat landscape, a rise from 34.5%. The impact of vulnerabilities remains vital ...
A one-page visual briefing on August 2026's global cyber attack landscape: 218 confirmed incidents, a rising four-in-five share driven by profit-motivated crime, and a back-to-back spike that delivered 34 attacks in just two days.
The second half of August 2026 brought 110 confirmed cyber incidents, with Cyber Crime once again the dominant motivation at 78% of attacks. Malware remained the weapon of choice, exploitation of public-facing applications (T1190) continued to lead initial access, and Information & Communication emerged as ...
August 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt ...
Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information
The Ukraine’s computer emergency response team (CERT-UA) discover a campaign where unidentified threat actors distribute MeduzaStealer through a Telegram account disguised as a technical support bot for users of the new Ukrainian government app called Reserve+.
Malware
Public admin and defence, social security
Cyber Crime
UA
Instant Messaging App
2
16/10/2024
Since at least January 2023
During January 2023
?
Undisclosed organization(s)
Researchers at Trend Micro discover a ransomware campaign abusing Amazon S3 to steal data with a fake Lockbit encryptor.
Researchers at AhnLab and the National Cyber Security Center (NCSC) of the Republic of Korea, discover Operation Code on Toast, a malicious campaign targeting an unnamed advertising agency in South Korea
Targeted Attack
Information and communication
Cyber Espionage
KR
CVE-2024-38178 Vulnerability
4
16/10/2024
Since 14/10/2024
14/10/2024
?
Novaya Gazeta Europe
The Russian independent media outlet Novaya Gazeta Europe is targeted by several large-scale distributed denial-of-service (DDoS) attacks, temporarily knocking its website offline.
DDoS
Information and communication
Hacktivism
RU
N/A
5
16/10/2024
Since October 2023
Since October 2023
Iranian threat actors
Organizations in the energy, engineering, government, healthcare and public health (HPH), and information technology sectors in the US, Australia, and Canada.
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) warn that Iranian state-sponsored threat actors have been using brute force and other techniques in attacks targeting critical infrastructure organizations, government agencies in the US, Australia, and Canada
Brute Force
Multiple Industries
Cyber Espionage
AU
CA
US
Brute force
6
16/10/2024
Since at least 2023.
During July 2024
IcePeony
Government agencies, academic institutions, and political organizations in India, Mauritius, and Vietnam.
Researchers at nao_sec discover a previously unknown China-nexus APT group, named “IcePeony”, targeting government agencies, academic institutions, and political organizations in countries such as India, Mauritius, and Vietnam.
Targeted Attack
Multiple Industries
Cyber Espionage
IN
MU
VN
Misconfiguration
7
16/10/2024
-
-
Threat actor from North Korea
Undisclosed organization
An undisclosed company is hacked after accidentally hiring a North Korean cyber criminal as a remote IT worker.
Targeted Attack
Unknown
Cyber Espionage
Unknown
Unknown
8
16/10/2024
-
-
RansomHub
DoctorsToYou
The RansomHub ransomware group adds a listing for DoctorsToYou in New York to their leak site. After they realize the organization is non-profit, they claim to return the data and provide a decryptor.
Ransomware
Human health and social work
Cyber Crime
US
Unknown
9
16/10/2024
During June 2024
-
?
Westmoreland County
Municipal Authority of Westmoreland County officials say the water and sewer utility has recovered more than $826,000 that was stolen in what it called a “vendor impersonator scheme.”
Business Email Compromise
Water supply, waste mgmt, remediation
Cyber Crime
US
Social Engineering
10
17/10/2024
During September 2024
During September 2024
Lazarus
Multiple organizations in the cryptocurrency sector
Researchers from eSentire discover a new campaign by the North Korean threat actor Lazarus targeting developers in the cryptocurrency sector via the BeaverTail malware.
Targeted Attack
Fintech
Cyber Crime
>1
Supply Chain Compromise
11
17/10/2024
Since at least late 2023
Since at least late 2023
UAT-5647
Ukrainian government entities and unknown Polish entities
Researchers at Cisco Talos observe a new wave of attacks from a Russian speaking group tracked as “UAT-5647”, against Ukrainian government entities and unknown Polish entities, using an updated version of the RomCom malware tracked as “SingleCamper”.
Targeted Attack
Multiple Industries
Cyber Espionage
PL
UA
Phishing Email
12
17/10/2024
16/10/2024
16/10/2024
?
Radiant Capital
More than $50 million worth of cryptocurrency is stolen from decentralized finance platform Radiant Capital.
Malware
Fintech
Cyber Crime
HK
Unknown
13
17/10/2024
Since August 2024
Since August 2024
?
Multiple organizations
Researchers at Sekoia discover new clusters of ClickFix campaigns using Google Meet lure, phishing emails targeting transport and logistics firms, fake Facebook pages, and deceptive GitHub issues.
Malware
Multiple Industries
Cyber Crime
>1
Fake Pages
Phishing Email
14
17/10/2024
Since June 2024
Since June 2024
?
Over 6,000 sites worldwide
Researchers at GoDaddy discover a new variant of ClickFix (also known as ClearFake) fake browser update malware that is distributed via bogus WordPress plugins compromised via stolen credentials.
Malware
Multiple Industries
Cyber Crime
>1
Stolen Credentials
15
17/10/2024
03/06/2024
05/08/2024
8BASE
Everest
Nidec Corporation
Nidec Corporation informs that threat actors behind a ransomware attack it suffered earlier this year stole data and leaked it on the dark web.
Ransomware
Manufacturing
Cyber Crime
JP
Stolen Credentials
16
17/10/2024
15/10/2024
15/10/2024
Several pro-Russian threat actors, including NoName057(16) and the Cyber Army of Russia
Japan's ruling Liberal Democratic Party (LDP)
Japan's ruling Liberal Democratic Party (LDP) reports that a cyberattack temporarily disrupted its website, coinciding with the start of the country’s general election campaign.
DDoS
Public admin and defence, social security
Hacktivism
JP
N/A
17
17/10/2024
14/10/2024
14/10/2024
Several pro-Russian threat actors, including NoName057(16) and the Cyber Army of Russia
Japanese logistics and shipbuilding firms, and other government and political organizations
Researchers at Netscout reveal that the same groups launched distributed denial-of-service (DDoS) attacks at Japanese logistics and shipbuilding firms — as well as government and political organizations
DDoS
Multiple Industries
Hacktivism
JP
N/A
18
17/10/2024
17/10/2024
17/10/2024
?
Moldova’s parliamentary email servers
Moldova’s parliamentary email servers are hit by a cyberattack just ahead of the country’s presidential election and a referendum on joining the European Union.
Unknown
Public admin and defence, social security
Unknown
MD
Unknown
19
18/10/2024
08/10/2024
08/10/2024
?
Multiple organizations
Unknown threat actors attempt to infect Israeli organizations with wiper malware delivered through phishing emails that impersonated the cybersecurity firm ESET using a compromised partner in Israel.
Malware
Multiple Industries
Cyber Warfare
IL
Phishing Email
20
18/10/2024
-
-
Threat actors from Vietnam
Job seekers and digital marketing professionals
Researchers at Cyble discover a sophisticated multi-stage malware attack orchestrated by a Vietnamese threat actor, specifically targeting job seekers and digital marketing professionals, employing various advanced tactics including the use of Quasar RAT, which allows attackers full control over compromised systems.
Malware
Professional, scientific and technical
Cyber Crime
>1
Phishing Email
21
18/10/2024
'Recently'
'Recently'
?
Multiple organizations
Researchers at Netskope discover a new campaign exploiting the Bumblebee malware loader, more than four months after Europol disrupted it during 'Operation Endgame' in May.
Malware
Multiple Industries
Cyber Crime
>1
Phishing Email
22
18/10/2024
-
-
?
Multiple organizations
Researchers at Phylum discovere a number of suspicious packages published to the npm registry designed to harvest Ethereum private keys and gain remote access to the machine via the secure shell (SSH) protocol.
Malware
Multiple Industries
Cyber Crime
>1
Supply Chain Compromise
23
18/10/2024
Since at least December 2023
During December 2023
Crypt Ghouls
Government agencies, as well as mining, energy, finance, and retail companies located in Russia.
Researchers at Kaspersky link a nascent threat actor known as Crypt Ghouls to a set of cyber attacks targeting Russian businesses and government agencies with ransomware with the twin goals of disrupting business operations and financial gain.
Ransomware
Multiple Industries
Cyber Crime
RU
Stolen Credentials
24
18/10/2024
'Recently'
'Recently'
?
Financial, automotive and healthcare business sectors
Researchers at Forcepoint and Logpoint discover a new Latrodectus campaign.
Malware
Multiple Industries
Cyber Crime
>1
Phishing Email
25
18/10/2024
-
-
RansomHub
Grupo Aeroportuario del Centro Norte
Grupo Aeroportuario del Centro Norte announces that a cyber incident forced its IT team to turn to backup systems. The RansomHub operation claims to be responsible for the incident, and threatens to leak 3 terabytes of stolen data.
Ransomware
Transportation and storage
Cyber Crime
MX
Unknown
26
18/10/2024
18/10/2024
18/10/2024
Several pro-Palestine hacker groups
Cyprus’ critical infrastructure and government websites
Cyprus’ critical infrastructure and government websites are targeted in a series of coordinated cyberattacks claimed by several pro-Palestine hacker groups.
DDoS
Multiple Industries
Hacktivism
CY
N/A
27
18/10/2024
16/10/2024
16/10/2024
?
Johnson & Johnson
Insurance company Johnson & Johnson discloses a data breach impacting the personal information of thousands of people.
Unknown
Finance and insurance
Cyber Crime
US
Unknown
28
18/10/2024
-
18/4/2024
Medusa
Summit Pathology and Summit Pathology Laboratories
Summit Pathology and Summit Pathology Laboratories (“Summit”) in Colorado notify of a breach affecting 1,813,538 patients. The Medusa ransomware gang is allegedly responsible for the breach.
Ransomware
Human health and social work
Cyber Crime
US
Phishing Email
29
18/10/2024
-
-
Threat actor from North Korea
Social
Tapioca DAO suffers a $4.5 million exploit after an attacker compromised its native token's vesting contract.
Account Takeover
Fintech
Cyber Crime
KY
Social Engineering
30
19/10/2024
19/02/2024
16/03/2024
?
National Diagnostic Imaging
Birth Choice of San Marcos notifies patients of a breach at National Diagnostic Imaging.
Unknown
Human health and social work
Cyber Crime
US
Unknown
31
20/10/2024
-
-
?
Multiple organizations
Researchers at Qualys discover a new Lumma Stealer campaign that uses malicious CAPTCHA pages to scam targets into clicking through the "verification" process, triggering the initial malware download.
Malware
Multiple Industries
Cyber Crime
>1
Legitimate Software
Public-facing Applications
32
20/10/2024
-
-
?
The Wayback Machine
The Internet Archive is breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens.
Account Takeover
Information and communication
Cyber Crime
US
Misconfiguration
33
21/10/2024
'Recently'
'Recently'
?
Multiple organizations
Researchers at Trend Micro observe an unknown threat actor abusing exposed Docker remote API servers to deploy the perfctl malware.
Malware
Multiple Industries
Cyber Crime
>1
Misconfiguration
34
21/10/2024
-
-
?
Undisclosed organization(s) in the U.S.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds CVE-2024-9537, a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day.
Unknown
Unknown
Unknown
US
CVE-2024-9537 Vulnerability
35
21/10/2024
03/10/2024
03/10/2024
?
Vocational Training Center, or Berufsbildungszentrum (BBZ)
The Vocational Training Center, or Berufsbildungszentrum (BBZ), in the canton of Schaffhausen is the victim of a ransomware attack.
Ransomware
Education
Cyber Crime
CH
Vulnerability
36
21/10/2024
Mid-September 2024
Mid-September 2024
Spamouflage
Marco Rubio
The covert Chinese information operation known as Spamouflage has renewed its long-running disinformation campaign against Republican Senator Marco Rubio of Florida.
Coordinated Inauthentic Behavior
Public admin and defence, social security
Cyber Warfare
US
N/A
37
21/10/2024
'Recently'
'Recently'
?
Transak
A recent data breach at the crypto payment processor Transak exposes the information of more than 92,000 people after an employee's laptop was accessed.
Account Takeover
Fintech
Cyber Crime
US
Phishing Email
38
21/10/2024
06/08/2024
08/08/2024
Inc Ransom
OnePoint Patient Care
OnePoint Patient Care (OPPC) informs customers about a data breach impacting their personal information. The Inc Ransom ransomware group takes credit for the attack. The impact is bigger than initially believed, with over 1.7 million people affected
Ransomware
Human health and social work
Cyber Crime
US
Unknown
39
21/10/2024
13/09/2024
22/02/2024
Meow Leaks
RansomHub
Trinity
Rocky Mountain Gastroenterology
Rocky Mountain Gastroenterology suffers a triple ransomware attack.
Ransomware
Human health and social work
Cyber Crime
US
Unknown
40
22/10/2024
Since at least 07/10/2024
07/10/2024
?
Undisclosed organizations
Google’s Threat Analysis Group (TAG) warns of a Samsung zero-day vulnerability, tracked as CVE-2024-44068 exploited in the wild.
Unknown
Unknown
Unknown
Unknown
CVE-2024-44068 Vulnerability
41
22/10/2024
-
-
?
Russian-speaking users
Researchers at Cisco Talos reveal that Russian-speaking users are the target of a new phishing campaign that leverages an open-source phishing toolkit called Gophish to deliver DarkCrystal RAT (aka DCRat) and a previously undocumented remote access trojan dubbed PowerRAT.
Malware
Individual
Cyber Crime
RU
Phishing Email
42
22/10/2024
During May 2024
During May 2024
?
Individuals in the U.S.
Researchers at Cofense warned of a phishing campaign with an embedded download link to a virtual hard drive file purporting to be the sender’s tax documents as a way to avoid detection by Secure Email Gateways (SEGs) and ultimately distribute Remcos RAT or XWorm.
Malware
Individual
Cyber Crime
US
Phishing Email
43
22/10/2024
During June and July of 2024
During June and July of 2024
?
Individuals in Canada
Researchers at Cofense warn of a phishing campaign spoofing Canada Post and other postal services to deliver attached .zip archives containing a virtual hard drive file purporting to be a package label photo.
Malware
Individual
Cyber Crime
CA
Phishing Email
44
22/10/2024
During August 2024
During August 2024
?
Spanish-speaking users
Researchers at Cofense warn of a phishing campaign targeting Spanish speaking victims with attached .zip archive files that were purported to be a curriculum vitae for review by the recipient.
Malware
Individual
Cyber Crime
>1
Phishing Email
45
22/10/2024
-
-
?
Undisclosed organization(s) in the U.S.
The U.S. CISA adds CVE-2024-38094, a Microsoft SharePoint Deserialization Vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Unknown
Unknown
Unknown
US
CVE-2024-38094 Vulnerability
46
22/10/2024
'Recently'
'Recently'
?
Multiple organizations
Researchers at Trend Micro observe a malicious actor targeting Docker remote API servers to deploy the SRBMiner cryptominer and mine XRP cryptocurrency.
Malware
Multiple Industries
Cyber Crime
>1
Misconfiguration
47
22/10/2024
Since February 2024
Since February 2024
?
Banking users in Mexico
Researchers at Kaspersky discover a new variants of the banking malware Grandoreiro adopting new tactics in an effort to bypass anti-fraud measures.
Malware
Finance and insurance
Cyber Crime
MX
Phishing Email
48
23/10/2024
Since at least 27/06/2024
27/06/2024
UNC5820
At least 50 organizations worldwide
Fortinet confirms that CVE-2024-47575, a critical zero-day vulnerability affecting its FortiManager network management solution is being exploited in the wild.
Targeted Attack
Unknown
Unknown
Unknown
CVE-2024-47575 Vulnerability
49
23/10/2024
Since April 2024
During August 2024
TA866 (a.k.a. Asylum Ambuscade)
Multiple organizations
Researchers from Cisco Talos discover a new malware family named WarmCookie, also known as BadSpace, actively distributed through malspam and malvertising campaigns since April 2024.
Malware
Multiple Industries
Cyber Crime
>1
Malspam
Malvertising
50
23/10/2024
During July 2024
During July 2024
Embargo
Organizations in the U.S.
Researchers at ESET reveal that the Embargo ransomware group is deploying MS4Killer, a customized Rust-based tool to overcome cybersecurity defenses.
Ransomware
Multiple Industries
Cyber Crime
US
Unknown
51
23/10/2024
Since at least 13/05/2024
13/05/2024
Lazarus
Individuals in the cryptocurrency space
Researchers at Kaspersky reveal that the North Korean Lazarus hacking group exploited a Google Chrome zero-day tracked as CVE-2024-4947 through a fake decentralized finance (DeFi) game targeting individuals in the cryptocurrency space.
Targeted Attack
Fintech
Cyber Crime
>1
CVE-2024-4947 Vulnerability
52
23/10/2024
-
-
?
Undisclosed organization(s)
Cisco addresses multiple vulnerabilities in Adaptive Security Appliance (ASA), Secure Firewall Management Center (FMC), and Firepower Threat Defense (FTD) products, including an actively exploited flaw tracked as CVE-2024-20481.
DDoS
Unknown
Unknown
Unknown
CVE-2024-20481 Vulnerability
53
23/10/2024
Since at least 22/10/2024
22/10/2024
APT29 (tracked as UAC-0215, Midnight Blizzard, Nobelium, Cozy Bear)
Agencies, enterprises, and military entities in Ukraine
The Computer Emergency Response Team of Ukraine (CERT-UA) details a new malicious email campaign targeting government agencies, enterprises, and military entities, containing attachments in the form of Remote Desktop Protocol ('.rdp') configuration files, and mimicking AWS domains. The campaign is later confirmed by Microsoft.
Targeted Attack
Multiple Industries
Cyber Espionage
UA
Phishing Email
54
23/10/2024
'Recently'
'Recently'
?
Undisclosed organization
Researchers at Trend Micro shed light on a new campaign involving a targeted brute-force attack against an unnamed customer to deliver the Prometei crypto mining botnet.
Malware
Unknown
Cyber Crime
Unknown
Brute force
55
23/10/2024
-
-
Cotton Sandstorm
U.S. election-related websites and American media outlets
Researchers at Microsoft reveal that the Iranian group known as Cottom Sandstorm is actively scouting U.S. election-related websites and American media outlets as Election Day nears, with activity suggesting preparations for more "direct influence operations."
Unknown
Information and communication
Cyber Warfare
US
Unknown
56
23/10/2024
-
-
Threat actors from Russia
U.S. election campaign
Researchers at Microsoft disclose that Russian operatives continue to take steps to undermine the U.S. Election campaign with disinformation.
Coordinated Inauthentic Behavior
Individual
Cyber Warfare
US
N/A
57
23/10/2024
-
-
Threat actors from China
U.S. Election Campaign
Researchers at Microsoft disclose that Chinese threat actors are carrying out disinformation campaigns against candidates and members of Congress.
Coordinated Inauthentic Behavior
Individual
Cyber Warfare
US
N/A
58
23/10/2024
13/05/2024
13/05/2024
?
Landmark Admin
Insurance administrative services company Landmark Admin warns that a data breach impacted over 800,000 people from a May cyberattack.
Unknown
Administration and support service
Cyber Crime
US
Unknown
59
23/10/2024
During September 2024
During September 2024
Operation Overload a.k.a. Matryoshka and Storm-1679
2024 U.S. Presidential Election
Researchers at Recorded Future reveal the details of Operation Overload, a Russia-aligned influence operation, targeting the 2024 US presidential election using fake news, fact-checking sites, and AI-generated audio.
Coordinated Inauthentic Behavior
Individual
Cyber Warfare
US
N/A
60
23/10/2024
23/10/2024
23/10/2024
?
Russian Foreign Ministry
The Russian Foreign Ministry is targeted by a severe DDoS attack, coinciding with the major BRICS summit taking place in the country, spokeswoman Maria Zakharova said.
DDoS
Public admin and defence, social security
Unknown
RU
N/A
61
23/10/2024
-
7/9/2024
RansomHub
Cardiology of Virginia
Cardiology of Virginia patient data appears to be up for sale after an alleged RansomHub ransomware attack.
Ransomware
Human health and social work
Cyber Crime
US
Unknown
62
24/10/2024
-
-
Qilin a.k.a. Agenda
Multiple organizations
Researchers at Halcyon discover a new Rust-based version of the Qilin (Agenda) ransomware strain, dubbed 'Qilin.B,' featuring stronger encryption, better evasion from security tools, and the ability to disrupt data recovery mechanisms.
Ransomware
Multiple Industries
Cyber Crime
>1
Unknown
63
24/10/2024
Since at least 11/09/2024
11/09/2024
Tenacious Pungsan, a.k.a. CL-STA-0240 and Famous Chollima.
Multiple organizations in the cryptocurrency sector
Researchers at Datadog discover three malicious packages published to the npm registry found to contain the known malware BeaverTail, a JavaScript downloader and information stealer linked to an ongoing North Korean campaign tracked as Contagious Interview.
Targeted Attack
Fintech
Cyber Crime
>1
Supply Chain Compromise
64
24/10/2024
at least since August 2024
-
UAC-0218
Individuals in Ukraine
The Computer Emergency Response Team of Ukraine (CERT-UA) warns of a mass phishing attack aimed at stealing sensitive personal data of citizens via phishing links purporting to be bills or payment details but actually leads to the download of data stealing malware.
Targeted Attack
Individual
Cyber Espionage
UA
Phishing Email
65
24/10/2024
Since early August 2024
During early August 2024
Akira
Fog
Multiple organizations
Researchers at Arctic Wolf reveal that Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw.
Ransomware
Multiple Industries
Cyber Crime
>1
CVE-2024-40766 Vulnerability
66
24/10/2024
-
23/10/2024
Shooked
Esport North Africa
A threat actor known as “Shooked,” leaks the personal details of over 180,000 Esport North Africa (ESNA) users just one day before the tournament is set to begin in Morocco.
Unknown
Arts entertainment, recreation
Cyber Crime
N/A
Unknown
67
24/10/2024
24/10/2024
24/10/2024
?
U.S. Government
A threat actor appears to have stolen approximately $20 million in stablecoins and ETH from wallets belonging to the U.S. Government.
Unknown
Public admin and defence, social security
Cyber Crime
US
Unknown
68
25/10/2024
During late October 2024
Since at least late October 2024
BlackBasta
Multiple organizations
Researchers at ReliaQuest observe the BlackBasta ransomware operation moving its social engineering attacks to Microsoft Teams, posing as corporate help desks contacting employees to assist them with an ongoing spam attack.
Ransomware
Multiple Industries
Cyber Crime
>1
Malspam
69
25/10/2024
-
-
UAC-001 a.k.a. APT28
Government organizations in Ukraine
The Computer Emergency Response Team of Ukraine (CERT-UA) warns of a ClickFix-style campaign designed to trick users into malicious links embedded in email messages to drop a PowerShell script capable of downloading and launching the Metasploit penetration testing framework.
Targeted Attack
Public admin and defence, social security
Cyber Espionage
UA
Phishing Email
70
25/10/2024
During late October 2024
Since at least late October 2024
TeamTNT
Multiple organizations
Researchers at Aqua Security reveal that the infamous cryptojacking group known as TeamTNT appears to be readying for a new large-scale campaign targeting Docker-based cloud-native environments for mining cryptocurrencies and renting out breached servers to third-parties via the Sliver malware.
Malware
Multiple Industries
Cyber Crime
>1
Misconfiguration
71
25/10/2024
Since 2023
Since 2023
HeptaX
Organizations in the healthcare industry
Researchers at Cyble uncover an ongoing campaign by a persistent threat group dubbed HeptaX, leveraging consistent techniques to gain unauthorized Remote Desktop access on compromised systems, targeting a wide range of users.
Targeted Attack
Multiple Industries
Cyber Espionage
Unknown
Phishing Email
72
25/10/2024
-
-
Chinese Threat Actors
Commercial telecommunication service providers in the U.S.
The FBI and the U.S. Cybersecurity & Infrastructure Security Agency (CISA) disclose that Chinese threat actors breached commercial telecommunication service providers in the United States.
Unknown
Information and communication
Cyber Espionage
US
Unknown
73
25/10/2024
'Over the past couple of months'
'Over the past couple of months'
State-sponsored threat actors from China
Multiple organizations in Canada
The Canadian government announces that state-sponsored threat actors from China have been performing broad network scans over the past couple of months, targeting a wide spectrum of organizations.
Unknown
Multiple Industries
Cyber Espionage
CA
Unknown
74
25/10/2024
-
-
drussellx
Free
Free, a major internet service provider (ISP) in France, confirms that threat actors breached its systems and stole customer personal information.
Unknown
Information and communication
Cyber Crime
FR
Unknown
75
25/10/2024
Since at least 2022
-
Equalize
Sensitive government and police databases in Italy
Four people are arrested in Italy after a business intelligence company called Equalize is accused of hacking sensitive government and police databases to create dossiers for its clients.
Unknown
Public admin and defence, social security
Cyber Crime
IT
Unknown
76
25/10/2024
-
-
Threat actors from China
Republican presidential nominee Donald Trump JD Vance, and people associated with the Democratic campaign of Kamala Harris
Chinese threat actors engaged in a broader espionage operation targeting cellphones used by Republican presidential nominee Donald Trump JD Vance, and people associated with the Democratic campaign of Kamala Harris.
Targeted Attack
Public admin and defence, social security
Cyber Espionage
US
Unknown
77
25/10/2024
-
-
ThreeAM
Carolina Arthritis
ThreeAM adds Carolina Arthritis to its leak site.
Ransomware
Human health and social work
Cyber Crime
US
Unknown
78
28/10/2024
-
-
?
Individuals
Researchers at Proofpoint observe an increase in cryptocurrency fraud that impersonates various organizations to target users with fake job lures.
Scam
Individual
Cyber Crime
>1
Instant Messaging App
Social Media
79
28/10/2024
Since 18/09/2024
18/09/2024
UNC5812
Individuals in Ukraine
Google Threat Intelligence Group discovers UNC5812, a suspected Russian hybrid espionage and influence operation, delivering Windows and Android malware using a Telegram persona named "Civil Defense".
Coordinated Inauthentic Behavior
Malware
Individual
Cyber Warfare
UA
Instant Messaging App
80
28/10/2024
During May 2022
During May 2022
Evasive Panda (a.k.a. BRONZE HIGHLAND, Daggerfly, or StormBamboo)
Taiwanese religious institution
Researchers at ESET discover a newly documented toolset, CloudScout, developed by the advanced persistent threat (APT) group Evasive Panda, targeting a Taiwanese religious institution to infiltrate and extract cloud-based data.
Targeted Attack
Other service activities
Cyber Espionage
TW
Unknown
81
28/10/2024
During February 2023
During February 2023
Evasive Panda (a.k.a. BRONZE HIGHLAND, Daggerfly, or StormBamboo)
Taiwanese government entity
Researchers at ESET discover a newly documented toolset, CloudScout, developed by the advanced persistent threat (APT) group Evasive Panda, targeting a Taiwanese government entity to infiltrate and extract cloud-based data.
Targeted Attack
Public admin and defence, social security
Cyber Espionage
TW
Unknown
82
28/10/2024
Since July 2024
Since July 2024
?
Individuals
Researchers at Perception Point identify a mounting wave of phishing attacks, in which threat actors misuse Eventbrite’s services to steal financial or personal information.
Account Takeover
Individual
Cyber Crime
>1
Phishing Email
83
28/10/2024
28/10/2024
28/10/2024
NoName057(16)
UK councils of Hemel Hempstead, St Albans, Salford, Bury, Trafford, Tameside, Dudley, Portsmouth and Middlesborough
The Russian group NoName057(16) claims responsibility for a DDoS campaign in retaliation for British military support for Ukraine.
DDoS
Public admin and defence, social security
Hacktivism
GB
N/A
84
28/10/2024
-
-
Meow Leaks
Black Suit
The Eye Clinic Surgicenter
Meow Leaks adds The Eye Clinic Surgicenter in Montana to their leak site, after the Black Suit threat actors had added the same medical group to their leak site back in June.
Ransomware
Human health and social work
Cyber Crime
US
Unknown
85
28/10/2024
-
-
?
H&R Block Canada
The Canada Revenue Agency discovers that threat actors had obtained confidential data used by one of the country's largest tax preparation firms, H&R Block Canada.
Account Takeover
Administration and support service
Cyber Crime
CA
Stolen Credentials
86
29/10/2024
28/10/2024
28/10/2024
PSAUX
Multiple organizations
Over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability are mass-targeted in a PSAUX ransomware attack that takes almost all instances offline.
Ransomware
Multiple Industries
Cyber Crime
>1
Vulnerability
87
29/10/2024
Since at least 18/10/2024
18/10/2024
Chenlun
Individuals
Researchers at DomainTools discover an ongoing, sophisticated phishing campaign targeting individuals with text messages impersonating trusted brands like Amazon.
Account Takeover
Individual
Cyber Crime
>1
SMS
88
29/10/2024
Since 2022
-
?
iOS Users
Researchers at ThreatFabric discover an improved version of an Apple iOS spyware called LightSpy that not only expands on its functionality, but also incorporates destructive capabilities to prevent the compromised device from booting up.
Malware
Individual
Cyber Espionage
>1
CVE-2020-9802 Vulnerability
89
29/10/2024
29/10/2024
29/10/2024
Ukrainian Cyber Alliance
Tver Administration's Network
A group with the moniker of Ukrainian Cyber Alliance claims to have taken down the Tver administration's network and to have wiped out “dozens of virtual machines, backup storage, websites, email, and hundreds of workstations.”
Unknown
Public admin and defence, social security
Hacktivism
RU
N/A
90
29/10/2024
From 22/09/2024 to14/10/2024
From 22/09/2024 to14/10/2024
?
Users in Brazil, Spain, Italy, and Russia
Researchers at Kaspersky reveal that web pages hosting fake CATCHA checks are being used to propagate Lumma Stealer and Amadey, as part of a new ClickFix campaign.
Malware
Individual
Cyber Crime
BR
ES
IT
RU
Malvertising
91
29/10/2024
Since 22/10/2024
Since 22/10/2024
APT29 a.k.a. BlueBravo, Cloaked Ursa, Cozy Bear, and Midnight Blizzard
Government, academia, defense, non-governmental organizations, and other sectors.
Researchers at Microsoft observe the Russian threat actor Midnight Blizzard sending a series of highly targeted spear-phishing emails to individuals in government, academia, defense, non-governmental organizations, and other sectors.
Targeted Attack
Multiple Industries
Cyber Espionage
>1
Phishing Email
92
29/10/2024
Since July 2024
Since July 2024
?
International audience on X
A network of 71 suspicious accounts on X is deployed ahead of the UN’s COP29 climate change conference. The accounts aim to give the impression of grassroots support for the Azerbaijan government, according to NGO Global Witness.
Coordinated Inauthentic Behavior
Individual
Cyber Warfare
>1
N/A
93
29/10/2024
29/10/2024
29/10/2024
?
Andy Ayrey's social media account
Threat actors hack Truth Terminal founder Andy Ayrey's social media account to promote a fraudulent token "IB."
Account Takeover
Individual
Cyber Crime
US
Unknown
94
30/10/2024
'Recently'
'Recently'
?
Undisclosed organization
Researchers at Trend Micro observe an attacker exploiting the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network.
Researchers at Palo Alto discover a ransomware incident where the threat actor Jumpy Pisces, tied to North Korea, collaborated with the Play ransomware group.
Ransomware
Unknown
Cyber Crime
Unknown
Stolen Credentials
96
30/10/2024
-
-
?
Android banking users
Researchers at Zimperium discover a new version of the FakeCall malware for Android able to hijack outgoing calls from a user to their bank, redirecting them to the attacker's phone number instead.
Malware
Finance and insurance
Cyber Crime
>1
Phishing Email
97
30/10/2024
Since at least a month
Since at least a month
?
Multiple organizations
Researchers at Bitdefender uncover an ongoing malvertising campaign that abuses Meta's advertising platform and hijacked Facebook accounts to distribute an information stealer known as SYS01stealer.
Malware
Multiple Industries
Cyber Crime
>1
Malvertising
98
30/10/2024
End of October 2024
End of October 2024
?
Organizations in Germany and Spain
Researchers at Cyble uncover a new variation of the Strela Stealer targeting Germany and Spain
Malware
Multiple Industries
Cyber Crime
DE
ES
Phishing Email
99
30/10/2024
Between August and September 2024
Between August and September 2024
?
Multiple organizations
Researchers at Sysdig discover a large-scale malicious operation named "EmeraldWhale" scanning for exposed Git configuration files to steal over 15,000 cloud account credentials from thousands of private repositories.
Account Takeover
Multiple Industries
Cyber Crime
>1
Misconfiguration
100
30/10/2024
-
-
kzoldyck
Interbank
Interbank, one of Peru's leading financial institutions, confirms a data breach after a threat actor who hacked into its systems leaked stolen data online.
Unknown
Finance and insurance
Cyber Crime
PE
Unknown
101
30/10/2024
-
-
?
Crypto users
Researchers at Checkmarx discover a new malicious Python package that masquerades as a cryptocurrency trading tool but harbors functionality designed to steal sensitive data and drain assets from victims' crypto wallets.
U.S. and Israeli cybersecurity agencies attribute the Iranian cyber group Emennet Pasargad to targeting the 2024 Summer Olympics and compromising a French commercial dynamic display provider to show messages denouncing Israel's participation in the sporting event.
Undisclosed US-based Internet Protocol Television (IPTV) streaming company
U.S. and Israeli cybersecurity agencies reveal that the group Emennet Pasargad hacked into the systems of a US-based IPTV streaming company to spread propaganda.
U.S. and Israeli cybersecurity agencies reveal that the group Emennet Pasargad conducted IP camera hacking, mainly targeting devices in Israel, but also in Gaza and Iran.
Unknown
Multiple Industries
Hacktivism
IL
IR
Unknown
105
30/10/2024
29/06/2023
21/07/2023
Alphv a.k.a. BlackCat
Saint Xavier University
Saint Xavier University starts notifying over 210,000 individuals that their personal information was compromised in a data breach in July 2023.
Ransomware
Education
Cyber Crime
US
Unknown
106
30/10/2024
28/10/2024
28/10/2024
?
AEP
German pharmaceutical distributor AEP is hit with a ransomware attack.
Ransomware
Wholesale and retail
Cyber Crime
DE
Unknown
107
31/10/2024
Since 2019
-
?
Individuals
Researchers at Human reveal that more than 1,000 legitimate shopping sites have been compromised to promote fake product listings in a credit card phishing scheme dubbed “Phish ‘n’ Ships,”
Scam
Individual
Cyber Crime
>1
Vulnerability
108
31/10/2024
Since at least July 2024
Since at least July 2024
?
Facebook business and advertising account users in Taiwan
Researchers at Cisco Talos observe an unknown threat actor conducting a phishing campaign targeting Facebook business and advertising account users in Taiwan. The decoy email and fake PDF filenames are designed to impersonate a company's legal department, attempting to lure the victim into downloading and executing malware such as LummaC2 and Rhadamanthys.
Malware
Professional, scientific and technical
Cyber Crime
TW
Phishing Email
109
31/10/2024
Since at least September 2024
Since at least September 2024
?
Individuals in the U.S. and UK, Spain, Australia, and Japan.
Researchers at Netcraft reveal the details of Xiū gǒu, a new phishing kit used in campaigns targeting Australia, Japan, Spain, the U.K., and the U.S. since at least September 2024.
Scam
Individual
Cyber Crime
AU
ES
GB
JP
US
RCS Messages
110
31/10/2024
-
-
Storm-0940
Multiple organizations
Researchers at Microsoft warn that Chinese threat actors use the Quad7 botnet (a.k.a. CovertNetwork-1658 or xlogin), composed of hacked SOHO routers, to steal credentials in password-spray attacks.
Malware
Multiple Industries
Cyber Crime
>1
Vulnerability
111
31/10/2024
Since 2018
Since 2018
Multiple threat actors from China including Volt Typhoon, APT31, and APT41/Winnti
Multiple organizations
Researchers at Sophos reveal that over the past five years, threat actors from China have increasingly used zero-day and known vulnerabilities to target edge networking devices from Fortinet, Barracuda, SonicWall, Check Point, D-Link, Cisco, Juniper, NetGear, Sophos, and many more.
Malware
Multiple Industries
Cyber Espionage
>1
Vulnerability
112
31/10/2024
Since at least April 2024
Since at least April 2024
?
Undisclosed organization(s(
Researchers at GreyNose reveal that threat actors are attempting to exploit CVE-2024-8956 and CVE-2024-8957, two zero-day vulnerabilities in PTZOptics pan-tilt-zoom (PTZ) live streaming cameras used in industrial, healthcare, business conferences, government, and courtroom settings.
Unknown
Unknown
Unknown
Unknown
CVE-2024-8956 and CVE-2024-8957 Vulnerability
113
31/10/2024
31/10/2024
31/10/2024
?
Crypto users
The popular LottieFiles Lotti-Player project is compromised in a supply chain attack to inject a crypto drainer into websites that steals visitors' cryptocurrency.
Crypto drainer
Fintech
Cyber Crime
>1
Supply Chain Compromise
114
31/10/2024
Since the end of October 2024
31/10/2024
?
Multiple organizations
Researchers at Checkmarx, Phylum, and Socket discover independently an ongoing campaign targeting npm developers with hundreds of typosquat versions of their legitimate counterparts in an attempt to trick them into running cross-platform malware. The attack is notable for utilizing Ethereum smart contracts for command-and-control (C2) server address distribution.
Malware
Multiple Industries
Cyber Crime
>1
Supply Chain Compromise
115
31/10/2024
End of October 2024
End of October 2024
?
Multiple organizations
LastPass warns about an ongoing campaign where scammers are writing reviews for its Chrome extension to promote a fake customer support phone number. However, this phone number is part of a much larger campaign to trick callers into giving scammers remote access to their computers.
Scam
Multiple Industries
Cyber Crime
US
Social Engineering
116
31/10/2024
28/10/2024
28/10/2024
?
San Joaquin County Superior Court
The San Joaquin County Superior Court says that nearly all of its digital services are knocked offline due to a cyberattack.
Unknown
Public admin and defence, social security
Cyber Crime
US
Unknown
117
31/10/2024
Mid-October 2024
Mid-October 2024
?
ChatGPT users
Researchers at Barracuda Networks observe a large-scale OpenAI impersonation campaign targeting the credentials of ChatGPT users.
Account Takeover
Individual
Cyber Crime
>1
Phishing Email
118
31/10/2024
-
05/10/2024
?
Mystic Valley Elder Services
Mystic Valley Elder Services suffers a data breach impacting many individuals.
Unknown
Human health and social work
Cyber Crime
US
Unknown
119
31/10/2024
-
-
?
Walt Disney World
A former worker hacked servers at Walt Disney World after being fired in order to manipulate computer menus by changing prices, adding profanities and altering notifications to wrongly declare some items as safe for people with allergies, according to a federal criminal complaint.
Unknown
Arts entertainment, recreation
Cyber Crime
US
Unknown
120
31/10/2024
14/08/2024
27/08/2024
?
Western Sydney University
Australia's Western Sydney University said hackers breached its student management system and data warehouse to steal students' demographic and enrollment information in the third data theft incident of 2024.
These data are the same data as for the 1-15 October section?!
I fixed it. Apologies for any inconvenience.