Security Newsletter

Issue #259 · 19 July 2024

Crowdstrike issue taking down companies around the world. AT&T breach leaking all call logs. Kaspersky shutting down in the US.

Supported by 1Password.

News

Hi friends,

If you've opened up any news reader before seeing this email, you'll probably have seen the Crowdstrike issue going the rounds. Heavy stuff. If you're affected I hope it'll be resolved once the weekend starts, and that you may find peace and quiet when it does :-) Enjoy the read folks.

Cheers,

  • Hackers use PoC exploits in attacks 22 minutes after release: link.
  • Report: Alphabet close to $23 billion deal for cybersecurity startup Wiz: link.
  • Judge tosses out most of SEC cybersecurity case against SolarWinds: link.

Breaches and leaks

  • Massive AT&T data breach exposes call logs of 109 million customers: link.
  • ATT ransom laundered through mixers, gambling services: link.
  • UK national blood stocks in 'very fragile' state following ransomware attack: link.
  • Rite Aid says breach exposes sensitive details of 2.2 million customers: link.
  • Email addresses of 15 million Trello users leaked on hacking forum: link.
  • Yacht giant MarineMax data breach impacts over 123,000 people: link.
  • Over 400,000 Life360 user phone numbers leaked via unsecured API: link.
  • Furniture giant shuts down manufacturing facilities after ransomware attack: link.
  • Indian crypto platform WazirX confirms $230 million stolen during cyberattack: link.

Issues and fixes

  • Vulnerability in Cisco Smart Software Manager lets attackers change any user password: link.
  • Netgear warns users to patch auth bypass, XSS router flaws: link.
  • Critical Exim bug bypasses security filters on 1.5 million mail servers: link.
  • CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks: link.
  • SolarWinds fixes 8 critical bugs in access rights audit software: link.