๐จ ACTIVE EXPLOITATION
- Family phones compromised to send abusive messages via WhatsApp and SMS
Multiple family members' phones on iOS and Android were compromised to impersonate and send abusive messages.
- Targets: iOS and Android phones of multiple family members
- Impact: Sending profane and abusive messages to contacts via WhatsApp and SMS
- Attack details: Impersonation of both male and female family members
- Mitigation attempts: Changing phones, resetting devices and numbers ineffective
- Unknown attack vector and method of compromise ๐ Coverage: reddit.com ยท ๐ via r/cybersecurity
๐ฅ BREACHES & INCIDENTS
- UK Government Investments agency suffers data breach exposing officials' details
UK Government Investments exposed sensitive data and officials' contact info for 40 hours due to staff error.
- Applies to UK Government Investments (UKGI), managing state investments including Channel 4 and Post Office
- High-level management information and names/work emails of 51 government officials were publicly accessible
- Data exposure lasted approximately 40 hours due to staff member failing to follow security policies
- Incident identified within the past financial year and reported to UK Information Commissioner's Office
- External experts recommended strengthening controls and incident preparedness after breach ๐ Coverage: theguardian.com ยท ๐ via @metacurity@infosec.exchange
๐ต๏ธ RESEARCH & DEEP DIVES
-
Facebook Malvertising Campaign Uses C2 Infrastructure for Attacks A malvertising campaign on Facebook uses command and control servers to deliver payloads to users.
- Targets Facebook users exposed to malicious advertisements
- Campaign uses command and control (C2) infrastructure to manage attacks
- Attackers deliver payloads via malvertising on Facebook platform
- No CVE identifiers associated with this campaign have been reported ๐ Coverage: reddit.com ยท ๐ via r/cybersecurity
-
Israel Thwarts Iranian Cyberattacks Targeting Water Infrastructure Israel prevented cyberattacks on water infrastructure attributed to Iranian state-backed actors.
- Applies to Israeli water infrastructure including wastewater treatment plants and pumping stations
- Attackers attempted to manipulate chlorine levels in water supply via industrial control systems
- Attack involved sophisticated tactics to disguise true chlorine levels from operators
- Iranian state-backed actors suspected; attacks linked to geopolitical tensions
- Israel collaborates with US partners amid similar threats to US water sector ๐ Coverage: csoonline.com ยท ๐ Original: i24news.tv ยท ๐ via @metacurity@infosec.exchange