{"id":166526,"date":"2024-08-04T08:22:08","date_gmt":"2024-08-04T08:22:08","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=166526"},"modified":"2024-08-04T08:22:10","modified_gmt":"2024-08-04T08:22:10","slug":"security-affairs-newsletter-round-483-by-pierluigi-paganini-international-edition","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/166526\/breaking-news\/security-affairs-newsletter-round-483-by-pierluigi-paganini-international-edition.html","title":{"rendered":"Security Affairs newsletter Round 483 by Pierluigi Paganini \u2013 INTERNATIONAL EDITION"},"content":{"rendered":"
<\/div>\n

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.<\/gwmw><\/h2>\n\n\n\n

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.<\/p>\n\n\n\n

US sued TikTok and ByteDance for violating children\u2019s privacy laws<\/a><\/td><\/tr>
Russia-linked APT used a car for sale as a phishing lure to target diplomats with HeadLace malware<\/a><\/td><\/tr>
Investors sued CrowdStrike over false claims about its Falcon platform<\/a><\/td><\/tr>
Avtech camera vulnerability actively exploited in the wild, CISA warns<\/a><\/td><\/tr>
Over 20,000 internet-exposed VMware ESXi instances vulnerable to CVE-2024-37085<\/a><\/td><\/tr>
Pharma Giant Cencora confirmed the theft of personal and health information<\/a><\/td><\/tr>
Apple fixed dozens of vulnerabilities in iOS and macOS<\/a><\/td><\/tr>
Phishing campaigns target SMBs in Poland, Romania, and Italy with multiple malware families<\/a><\/td><\/tr>
A Fortune 50 company paid a record-breaking $75 million ransom<\/a><\/td><\/tr>
CISA adds VMware ESXi bug to its Known Exploited Vulnerabilities catalog<\/a><\/td><\/tr>
Mandrake Android spyware found in five apps in Google Play with over 32,000 downloads since 2022<\/a><\/td><\/tr>
SideWinder phishing campaign targets maritime facilities in multiple countries<\/a><\/td><\/tr>
A crafty phishing campaign targets Microsoft OneDrive users<\/a><\/td><\/tr>
Ransomware gangs exploit recently patched VMware ESXi bug CVE-2024-37085<\/a><\/td><\/tr>
Acronis Cyber Infrastructure bug actively exploited in the wild<\/a><\/td><\/tr>
Fake Falcon crash reporter installer used to target German Crowdstrike users<\/a><\/td><\/tr>
Belarus-linked APT Ghostwriter targeted Ukraine with PicassoLoader malware<\/a><\/td><\/tr>
French authorities launch disinfection operation to eradicate PlugX malware from infected hosts<\/a><\/td><\/tr><\/tbody><\/table>
<\/gwmw><\/figcaption><\/figure>\n\n\n\n

International Press \u2013 Newsletter<\/strong><\/p>\n\n\n\n

Cybercrime<\/strong>  <\/p>\n\n\n\n

Malicious Inauthentic Falcon Crash Reporter Installer Distributed to German Entity via Spearphishing Website<\/a>      <\/p>\n\n\n\n

Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption<\/a>     <\/p>\n\n\n\n

STARGAZERS GHOST NETWORK<\/a><\/p>\n\n\n\n

Dark Angels ransomware receives record-breaking $75 million ransom<\/a><\/p>\n\n\n\n

UNC4393 Goes Gently into the SILENTNIGHT<\/a><\/p>\n\n\n\n

Three Individuals Sentenced for Massive $88M Business Telephone System Software License Piracy Scheme<\/a>   <\/p>\n\n\n\n

Ransomware Attack Hits OneBlood Blood Bank, Disrupts Medical Operations<\/a> <\/p>\n\n\n\n

Malware<\/strong><\/a><\/p>\n\n\n\n

Unplugging PlugX: Sinkholing the PlugX USB worm botnet<\/a>  <\/p>\n\n\n\n

Mandrake spyware sneaks onto Google Play again, flying under the radar for two years<\/a><\/p>\n\n\n\n

Phishing targeting Polish SMBs continues via ModiLoader<\/a>\u00a0\u00a0<\/p>\n\n\n\n

BingoMod: The new android RAT that steals money and wipes data<\/a>  <\/p>\n\n\n\n

BITS and Bytes: Analyzing BITSLOTH, a newly identified backdoor<\/a><\/p>\n\n\n\n

Hacking<\/strong><\/p>\n\n\n\n

SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining<\/a>  <\/p>\n\n\n\n

Acronis Product Vulnerability Exploited in the Wild<\/a> <\/p>\n\n\n\n

OneDrive Pastejacking: The crafty phishing and downloader campaign<\/a> <\/p>\n\n\n\n

\u201cEchoSpoofing\u201d \u2014 A Massive Phishing Campaign Exploiting Proofpoint\u2019s Email Protection to Dispatch Millions of Perfectly Spoofed Emails<\/a> <\/p>\n\n\n\n

Windows AppLocker Driver LPE Vulnerability \u2013 CVE-2024-21338<\/a>     <\/p>\n\n\n\n

StackExchange Abused to Spread Malicious Python Package That Drains Victims Crypto Wallets<\/a><\/p>\n\n\n\n

WHO KNEW? DOMAIN HIJACKING IS SO EASY<\/a> <\/p>\n\n\n\n

Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft<\/a>  <\/p>\n\n\n\n

A $500 Open Source Tool Lets Anyone Hack Computer Chips With Lasers<\/a> <\/p>\n\n\n\n

Israeli hacktivist group brags it took down Iran’s internet<\/a>  <\/p>\n\n\n\n

Intelligence and Information Warfare<\/strong> <\/p>\n\n\n\n

SideWinder Utilizes New Infrastructure to Target Ports and Maritime Facilities in the Mediterranean Sea<\/a><\/p>\n\n\n\n

North Korean Government Hacker Charged for Involvement in Ransomware Attacks Targeting U.S. Hospitals and Health Care Providers<\/a>  <\/p>\n\n\n\n

U.S. Trades Cybercriminals to Russia in Prisoner Swap<\/a> <\/p>\n\n\n\n

Fighting Ursa Luring Targets With Car for Sale<\/a>  <\/p>\n\n\n\n

Cybersecurity<\/strong><\/p>\n\n\n\n

When Cyberattacks Are Inevitable, Focus on Cyber Resilience<\/a>  <\/p>\n\n\n\n

IBM: Cost of a breach reaches nearly $5 million, with healthcare being hit the hardest<\/a>  <\/p>\n\n\n\n

Attor\u00adney Gen\u00ader\u00adal Ken Pax\u00adton Secures $1.4 Bil\u00adlion Set\u00adtle\u00adment with Meta Over Its Unau\u00adtho\u00adrized Cap\u00adture of Per\u00adson\u00adal Bio\u00admet\u00adric Data In Largest Set\u00adtle\u00adment Ever Obtained From An Action Brought By A Sin\u00adgle State<\/a><\/p>\n\n\n\n

Google Chrome adds app-bound encryption to block infostealer malware<\/a><\/p>\n\n\n\n

UK calls out China state-affiliated actors for malicious cyber targeting of UK democratic institutions and parliamentarians<\/a>        <\/p>\n\n\n\n

Hackers Steal Personal Information From Pharma Giant Cencora<\/a><\/p>\n\n\n\n

CrowdStrike sued by shareholders over global outage<\/a>     <\/a><\/p>\n\n\n\n

Using Threat Intelligence to Predict Potential Ransomware Attacks<\/a><\/p>\n\n\n\n

Justice Department Sues TikTok and Parent Company ByteDance for Widespread Violations of Children\u2019s Privacy Laws<\/a>\u00a0\u00a0<\/gwmw><\/gwmw><\/p>\n\n\n\n

Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/strong><\/a><\/gwmw><\/gwmw><\/p>\n\n\n\n

Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n

(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, newsletter)<\/strong><\/gwmw><\/gwmw><\/gwmw><\/p>\n","protected":false},"excerpt":{"rendered":"

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. US sued TikTok and ByteDance for violating children\u2019s privacy laws Russia-linked APT used a car for sale as […]<\/p>\n","protected":false},"author":1,"featured_media":35167,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3323],"tags":[88,182,4112,9508,9506,10918,30,3529,687,841,1533],"class_list":["post-166526","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-breaking-news","tag-cybercrime","tag-data-breach","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-malware-2","tag-newsletter","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"yoast_head":"\n杭州江阴科强工业胶带有限公司