Car rental giant Avis data breach impacts over 299,000 customers

American car rental giant Avis notified customers that unknown attackers breached one of its business applications last month and stole some of their personal information.

According to data breach notification letters sent to impacted customers on Wednesday and filed with California’s Office of the Attorney General, the company took action to stop the unauthorized access, launched an investigation with the help of external cybersecurity experts, and reported the incident to relevant authorities after learning of the breach on August 5.

Read Full Article

Dragos reports resurgence of ransomware attacks on industrial sectors, raising likelihood of targeting OT networks

Industrial cybersecurity firm Dragos disclosed that ransomware attacks significantly rose in the second quarter, as hacker groups recalibrated adversarial strategies. These groups demonstrated significant adaptability by rebranding and adopting new tactics, suggesting they will continue refining their operations using sophisticated methods like zero-day vulnerabilities to enhance their attacks. Data also revealed that the quarter saw a significant rise in the frequency and severity of attacks, reflecting the evolving threat landscape and the persistent risk posed by ransomware groups.

Read Full Article

President Biden Formalizes White House Council on Supply Chain Resilience

On June 14, 2024, President Biden issued an Executive Order on White House Council on Supply Chain Resilience (the “Order”). The Order, with a goal of strengthening US supply chain resilience and building “resilient, diverse, and secure supply chains,” encourages “close cooperation” with allies and partners to “foster collective economic and national security, encourage innovation, and strengthen the capacity to respond to and recover from international disasters and emergencies.”

Read Full Publication

DDoS Attack Triggers New Microsoft Global Outage

A global outage of Microsoft services was started by a Distributed Denial-of-Service (DDoS) attack, the tech giant has revealed.

An error in Microsoft’s DDoS protection measures then amplified the impact of the attack rather than mitigating it, the firm admitted.

During this time customers reported issues with a range of Microsoft platforms, including Outlook, Azure and the video game Minecraft. Microsoft cloud systems Intune and Entura were also impacted.

Read Full Article

AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach

U.S. phone giant AT&T confirmed Friday it will begin notifying millions of consumers about a fresh data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers, a company spokesperson told TechCrunch.In a statement, AT&T said that the stolen data contains phone numbers of both cellular and landline customers, as well as AT&T records of calls and text messages — such as who contacted who by phone or text — during a six-month period between May 1, 2022 and October 31, 2022.

Read Full Article

GAO raises red flags over supply chain issues and delays in DoD space programs

The Pentagon remains sluggish in fielding innovative weapon systems even as security risks intensify, the Government Accountability Office said in its annual assessment of major arms programs released June 17. 

The congressional watchdog’s report examined 70 major weapon systems across the military services. GAO flags several hiccups in Space Force programs, including long-standing issues with the Global Positioning System’s ground control system and user equipment. 

Read Full Article

Biden Issues Executive Order to Bolster Supply Chain Resilience

President Biden issued an executive order today aimed at fortifying America’s supply chains, with a particular emphasis on critical infrastructure (CI).

The order solidifies the establishment of a White House council specifically geared towards bolstering supply chain resilience. A key task for this council is conducting a thorough review of industries critical to national or economic security every four years.

The first report is due no later than Dec. 31.

Read Full Article

Data of 560 million Ticketmaster customers for sale after alleged breach

A threat actor known as ShinyHunters is selling what they claim is the personal and financial information of 560 million Ticketmaster customers on the recently revived BreachForums hacking forum for $500,000.

The allegedly stolen databases, which were first put up for sale on the Russian hacking forum Exploit, supposedly contain 1.3TB of data and the customers’ full details (i.e., names, home and email addresses, and phone numbers), as well as ticket sales, order, and event information.

Read Full Article

Hijack of monitoring devices highlights cyber threat to solar power infrastructure

An attack on remote monitoring devices in Japan underscores an emerging cybersecurity threat to the rapidly growing solar component of the power grid. Inverters used with solar panels could pose a more significant risk. In what might be the first publicly confirmed cyberattack on the solar power grid infrastructure, Japanese media recently reported that malicious actors hijacked 800 SolarView Compact remote monitoring devices made by industrial control electronics manufacturer Contec at solar power generation facilities to engage in bank account thefts.

Read Full Article