Stay ahead of Active Directory targeting. We teamed with @ASDGovAu and others to provide recommended strategies to prevent and detect malicious actors attempting to access the keys to your network. Read our joint guidance: https://t.co/FeciBYQtvW
#TeamViewer recently updated their statement, noting that they currently attribute the recent cyberattack incident to a group of hackers associated with the Russian Foreign Intelligence Service (#SVR). This group is known under several aliases, including #APT29, #MidnightBlizzard, and COZY BEAR.
APT29, often mentioned in connection with other large-scale cyberattacks, has a long history of conducting complex and well-planned operations. Midnight Blizzard and COZY BEAR are other names for this same group, used in various cybersecurity contexts.
TeamViewer emphasized that the attack aimed to gain access to the company's critical information and resources. This incident is part of a broader cyber espionage campaign conducted by these adversaries, targeting various organizations worldwide.
The company is taking all necessary measures to investigate and mitigate the impact of the attack, as well as to strengthen security measures to prevent similar incidents in the future.
https://t.co/oHZiykuQcM
#CyberSecurity #Breached #Velstadt
The company ANY[.]RUN, which created a cloud sandbox, was compromised through one of its clients. This client sent a phishing email to an Any[.]run employee. It is noted that the employee did not have access to the infrastructure or source code.
#CyberSecurity#CyberAttack #AnyRun
Our deep-dive, IOCs, and exploit for CVE-2023-34992, an unauth command injection as root, effecting #Fortinet#FortiSIEM appliances.
https://t.co/Dn7uVwqmA1
🚨#BREAKING🚨DROPBOX, INC. has filed form 8-K with the SEC due to a cybersecurity incident.
#Ransomware#DarkWebInformer#DarkWeb#Cybersecurity#Cyberattack#Cybercrime#Infosec#CTI#Dropbox
https://t.co/03Ww8797P4
"On April 24, 2024, Dropbox, Inc. (“Dropbox” or “we”) became aware of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. We immediately activated our cybersecurity incident response process to investigate, contain, and remediate the incident. Upon further investigation, we discovered that the threat actor had accessed data related to all users of Dropbox Sign, such as emails and usernames, in addition to general account settings. For subsets of users, the threat actor also accessed phone numbers, hashed passwords, and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication. Based on what we know as of the date of this filing, there is no evidence that the threat actor accessed the contents of users’ accounts, such as their agreements or templates, or their payment information. Additionally, we believe this incident was limited to Dropbox Sign infrastructure and there is no evidence that the threat actor accessed the production environments of other Dropbox products. We are continuing our investigation.
When we became aware of the incident, we launched an investigation with industry-leading forensic investigators to understand what happened and mitigate risks to our users. We have notified and are working with law enforcement. As appropriate, we are also notifying regulatory authorities and users with respect to unauthorized access to personal information.
As of the date of this filing, the incident has not had, and we do not believe it is reasonably likely to have, a material impact on our overall business operations, given our current understanding that this incident is limited to the Dropbox Sign infrastructure. We have not determined that the incident is reasonably likely to materially impact our financial condition or results of operations. We remain subject to various risks due to the incident, including potential litigation, changes in customer behavior, and additional regulatory scrutiny. Our remediation efforts are ongoing."