The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques

The Earth Alux APT group’s schemes and tactics have been uncloaked through our relentless monitoring and investigation efforts. The China-linked intrusion set is actively launching cyberespionage attacks against the government, technology, logistics, manufacturing, telecommunications, IT services, and retail sectors. The Read More …

SideWinder targets the maritime and nuclear sectors with an updated toolset

Last year, Kaspersky researchers published an article about SideWinder, a highly prolific APT group whose primary targets have been military and government entities in Pakistan, Sri Lanka, China, and Nepal. In the article, they described activities that had mostly happened Read More …

Cybersecurity and the Role of Trusted TOS Providers

In an era where digital transformation is reshaping the maritime industry, cybersecurity has emerged as a critical concern for port and terminal operators. The adoption of a Terminal Operating System (TOS) is a significant step towards embracing this digital revolution, Read More …

UK’s Morrisons says cyber attack at technology provider hit Christmas sales

British supermarket group Morrisons said a November cyber attack at technology provider Blue Yonder hit its product availability, impacting sales in the Christmas quarter. CEO Rami Baitieh said the attack meant Morrisons had to shut down its warehouse management system, Read More …

Retail outages drag into second week after Blue Yonder ransomware attack

A ransomware attack on supply chain software giant Blue Yonder continues to cause disruption to the company’s customers, almost two weeks after the outage first began. In a brief update to its cybersecurity incident page on Sunday, Arizona-based Blue Yonder Read More …

Italian food delivery app Foodinho eats another privacy fine

Not for the first time, food delivery firm Foodinho has been spanked by Italy’s privacy watchdog. Per Reuters, the Glovo-owned on-demand delivery app has been fined €5 million ($5.20 million) after it was found to have unlawfully processed the data of Read More …

APT41 Has Arisen From the DUST

Recently, Mandiant became aware of an APT41 intrusion where the malicious actor deployed a combination of ANTSWORD and BLUEBEAM web shells for persistence. These web shells were identified on a Tomcat Apache Manager server and active since at least 2023. Read More …

Cyberthreats in the transportation industry

Transportation is a key economic sector. It spans a multitude of diverse companies engaged in logistics, urban transit, land and air cargo and passenger conveyance, and other activities. The transportation system performs critical functions that support nationwide objectives by connecting Read More …

Freight giant Estes confirms data breach, but says it won’t pay ransom

The October 2023 cyberattack against Estes Express Lines was indeed ransomware, but the company has paid no ransom demand as yet. The company confirmed the news in an email recently sent to affected customers. As per the email, sent to Read More …