A Tallahassee hospital has been forced to divert patients to other facilities and cancel all non-emergency surgical procedures after being hit by a cyberattack that began on Thursday night
They wouldn't say but its likely #ransomware
jon greig
@jgreigj
cybersecurity reporter. formerly
send tips to jonathangreig11@protonmail.com
jon greig’s Tweets
1
2
Much strength and love for Turkey🇹🇷 Every Haitian who lived on January 12, watching the images of Turkey, is not ok this morning. We are not ok.💔
1
13
36
A long-patched vulnerability in VMware's ESXi server application is allowing attackers to install ransomware on systems that haven't been updated.
6
6
Engineering firm Vesuvius Plc confirmed Monday that an incident “involved unauthorized access to our systems,” but the company did not provide further details.
1
7
5
🌐 A new #ransomware attack is spreading like crazy 🚨
Many VMware ESXi servers got encrypted in the last hours with this ransom note 🧐
What's interesting is that the bitcoin wallet is different in every ransom note. No website for the group, only TOX id 👀
27
203
423
Linux version of Royal Ransomware targets VMware ESXi servers -
67
81
Quote Tweet
Group: alphv
Approx. Time: 2023-02-04 23:07:59.162336
Title: Five Guys Enterprises, LLC
8
8
27
🌐Last Week #Ransomware Statistics 🧮
➡️ Top Targeted Countries:
🇺🇸 USA: 22
🇬🇧 UK: 5
🇨🇦 Canada: 4
🇦🇺 Australia: 3
🇲🇽 Mexico: 3
➡️ Top Active Groups:
- Lockbit: 42 💥 (New record in one week)
- Vice: 8
- BlackCat: 5
- Royal: 4
- Play: 2
Total Victims in 7 Days: 59
Hits Map:
3
22
51
With regard to the Nevada ransomware operation, the vulnerabilities they are exploiting are years old. VMware has also recommended disabling SLP for about a decade as part of the Security Configuration Guides. There should be nobody vulnerable to this!
4
16
29
Show this thread
New: Lockbit tells that a ransom has been paid in the case of stricken financial data firm ION — ION itself has declined to comment.
Story on wire.
3
21
27
Show this thread
The Week in Ransomware - February 3rd 2023 - Ending with a mess -
2
18
23
Show this thread
3
4
If you're a GoAnywhere MFT customer, heads up — exploited zero-day vuln, no CVE, no patch (that we can tell). Mitigation available, has to be applied to every node.
1
10
16
A zero-day vulnerability affecting Fortra’s #GoAnywhere MFT managed file-transfer solution is currently being exploited, according to cybersecurity giant #Zeroday
1
4
A zero-day vulnerability affecting Fortra’s #GoAnywhere MFT managed file-transfer solution is currently being exploited, according to cybersecurity giant #Zeroday
1
4
Researchers at confirmed what
said in a private advisory: The company's GoAnywhere MFT solution contains a zero-day vulnerability that's being actively exploited ()
4
4
Fast-evolving Prilex POS malware can block contactless payments
7
5
🚨 On récapitule : un #ransomware semble distribué, depuis ce ~midi, automatiquement à grande échelle sur les serveurs #VMware #ESXi encore aujourd'hui affectés par une vuln de 2021. Ça fait mal, notamment en 🇫🇷
3
47
63
Show this thread
🚨 Right now, at least 115 VMware ESXi servers (and counting) are compromised with this aggressive #Ransomware campaign. Beware!!! 👇
beta.shodan.io/search?query=h
/cc
Quote Tweet
Show this thread
15
217
448
Show this thread
Replying to
LockBit just removed ION Group.
Quote Tweet
ION Group derivatives unit has been breached by LockBit. Bloomberg reported the cyber incident today.
ION software is used by financial institutions and central banks including the European Central Bank.
/iongroup.com
@nytimes @CNBC
#cybersecurity #infosec @business
1
2
4
🚨 This is a massive attack, and as it appears to be automated, all admins are advised to confirm their ESXi servers are firewalled, with no ports exposed to the Internet, until they are patched. 🚨
4
24
51
Show this thread
Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide -
11
297
421
Show this thread
has just released MitreMap notebook, which lets you input a threat report and it infers the most likely MITRE ATT&CK technique(s). This will help identify the motivations and TTPs of TA. You can also add IoCs to the reports. #DFIR
9
247
735
A Tallahassee hospital with 772 patient beds said it is diverting patients to other facilities and cancelling all non-emergency surgeries after being hit by a cyberattack ()
11
8
Researchers at Microsoft say a data leak operation against French satire publication Charlie Hebdo indeed has all the signature tactics of the Iranian group known as Emennet Pasargad or Neptunium.
()
5
3
accused Iran's military of being behind a hack on that involved the leak of personal information from 200,000 subscribers #CharlieHebdo #AliKhamenei #Iran
6
3
#LockBit has listed Redford Township Police Department and the City of Allen Park, claiming to have "hacked into a network where there were two companies." This could imply that the attack was actually on a service provider shared by both the PD and the City. 1/2 #ransomware
1
13
15
Show this thread
French authorities arrested Julius Kivimäki in the high-profile hacking case against Vastaamo, a Finnish psychotherapy center. Kivimäki was prosecuted as a teenager for computer crimes. ()
11
16
The chairmen of two U.S. House committees — and — want more information from the Department about reported Russian hacking activity against three national laboratories last year ()
1
4
1
NEW: The University of Zurich, Switzerland’s largest university, announced on Friday it was the target of a “serious cyberattack,” which comes amid a wave of hacks targeting German-speaking institutions.
14
20
Hardware vendor QNAP said a serious vulnerability discovered by a third-party researcher is "not actively exploited now." But researchers are warning it could be an opportunity for one cybercrime group in particular. ()
3
3
Two apps tied to "pig butchering" schemes — where scammers develop a relationship with victims and get them to deposit money on fraudulent apps — made it onto Apple and Google's app stores.
()
5
3
Another day, another #OneNote maldoc! 📄
We're seeing growing OneNote #maldoc usage lately: crooks leverage different lures, such as #Office365 and blurred documents.
Check a fresh "Legal Notice" maldoc with #Redline as the payload 👇
app.any.run/tasks/b5396b9e
38
67
Muhammad Ali knocks out Cleveland Williams, 1966
106
2,775
38.2K
NEW: We obtained a private intelligence report on the hackers known as "0ktapus" or "Scattered Spider."
After hitting 130 companies last year, the hackers are still active as of January, targeting Riot Games, Roblox, Salesforce, and Mailchimp and others.
2
22
38
Show this thread






















