Hijacked subdomains of major brands used in massive spam campaign
A massive ad fraud campaign named "SubdoMailing" is using over 8,000 legitimate internet domains and 13,000 subdomains to send up to five million emails per day to generate revenue through scams and malvertising.
The campaign is called "SubdoMailing, as the threat actors hijack abandoned subdomains and domains belonging to well-known companies to send their malicious emails.
As these domains belong to trusted companies, they gain the benefit of being able to bypass spam filters and, in some cases, take advantage of configured SPF and DKIM email policies that tell secure email gateways that the emails are legitimate and not spam.
Some notable brands that fell victim to this domain hijacking campaign include MSN, VMware, McAfee, The Economist, Cornell University, CBS, NYC.gov, PWC, Pearson, Better Business Bureau, Unicef, ACLU, Symantec, Java.net, Marvel, and eBay.
#SubdoMailing
FBI, CISA warn US hospitals of targeted BlackCat ransomware attacks
Today, the FBI, CISA, and the Department of Health and Human Services (HHS) warned U.S. healthcare organizations of targeted ALPHV/Blackcat ransomware attacks.
Link
Pharmaceutical giant Cencora says data was stolen in a cyberattack
The Company had $262.2 billion in revenue for fiscal year 2023 and employs approximately 46,000 people. In a Form 8-K filing with the SEC, Cencora disclosed they suffered a cyberattack that led to data theft. "On February 21, 2024, Cencora, Inc. (the "Company"), learned that data from its information systems had been exfiltrated, some of which may contain personal information," reads the SEC filing.
Link
Rhysida ransomware wants $3.6 million for children’s stolen data
The Rhysida ransomware gang has claimed the cyberattack on Lurie Children's Hospital in Chicago at the start of the month. Lurie is a leading pediatric acute care institution in the U.S. that provides care to over 200,000 children annually.
The cyberattack forced the healthcare provider to take its IT systems offline and postpone medical care in some cases. Email, phone, access to MyChart, and on-premises internet were all impacted. Ultrasound and CT scan results were rendered unavailable, patient service prioritization systems were taken down, and doctors were forced to switch to pen and paper for prescriptions.
Link
Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
We've obtained intelligence about an ongoing supply chain attack affecting XZ Utils versions 5.6.0 and 5.6.1. This activity has been assigned CVE-2024-3094. XZ Utils is a data compression software that may be included in Linux distributions. The malicious code could potentially allow unauthorized access to impacted systems.
We recommend downgrading XZ Utils to an uncompromised version, such as XZ Utils 5.4.6 Stable.
https://t.me/InformationTechnologySecurity
Why remote desktop tools are facing an onslaught of cyber threats
Hackers are increasingly targeting remote desktop tools in their attacks, new research reveals, prompting warnings for enterprises globally
Link
Meta deepens AI push with 'Superintelligence' lab, source says
CEO #MarkZuckerberg has reorganized the company's artificial intelligence efforts under a new division called Meta Superintelligence Labs, according to a source on Monday.
The division will be headed by Alexandr Wang, former CEO of data labeling startup #ScaleAI. He will be the chief AI officer of the new initiative at the social media giant, the source said.
The high-stakes push follows senior staff departures and a poor reception for Meta's latest open-source Llama 4 model, challenges that have allowed rivals including #Google, #OpenAI and China's #DeepSeek to seize momentum in the #AI race.
Zuckerberg hopes the new lab will fast-track work on artificial general intelligence - machines that can outthink humans - and help create new cash flows from the #MetaAI app, image-to-video ad tools and smart glasses.
Over the past month, Zuckerberg personally led an aggressive talent raid, floating offers for startups including OpenAI co-founder Ilya Sutskever's Safe Superintelligence (SSI) and courting prospects directly on #WhatsApp with million-dollar pay packages.
Earlier this month, the #Facebook and #Instagram parent invested $14.3 billion in Scale AI.
Apart from Wang and some Scale AI staff, the new division will reportedly include SSI's co-founder and CEO, Daniel Gross.
Now Google’s Gemini AI is ready to fill in those empty cells in your spreadsheet
#Google is launching a new #AI function in #GoogleSheets to help you generate text to fill out parts of your spreadsheet. The feature, powered by #Gemini, can reference specific cells to create text, summarize information, or categorize your data.
In the example shared by Google, you can use the new AI function to generate and tailor copy for an advertisement based on the different target audiences listed in your spreadsheet. To do this, you would highlight the cells where you want the AI copy to appear and then use this function (but make sure to change the target range to match your spreadsheet):
=AI(“Write a formal ad copy for the product. Cater copy to the objective and target audience.”, A2:C2).
Another example includes using the AI function to summarize the feedback of customers listed in a group of cells, which you could perform by typing this:
=AI(“For the customer, write a one sentence summary of their feedback.”, A2:D2)
You can also categorize a customer inquiry as a compliment, exchange request, or return request, or even use it to classify restaurants by location. You can check out a range of different examples for the AI function on Google’s support page.
________
https://t.me/InformationTechnologySecurity
Ingram Micro outage caused by SafePay ransomware attack
An ongoing outage at IT giant #IngramMicro is caused by a #SafePay ransomware attack that led to the shutdown of internal systems.
Ingram Micro is one of the world's largest business-to-business technology distributors and service providers, offering a range of solutions including hardware, software, cloud services, logistics, and training to resellers and managed service providers worldwide.
Since Thursday, Ingram Micro's website and online ordering systems have been down, with the company not disclosing the cause of the issues.
https://t.me/InformationTechnologySecurity
OpenAI to release web browser in challenge to Google Chrome
#OpenAI is close to releasing an #AI-powered web #Browser that will challenge #Alphabet's opens new tab market-dominating #Google #Chrome, three people familiar with the matter told Reuters.
The browser is slated to launch in the coming weeks, three of the people said, and aims to use artificial intelligence to fundamentally change how consumers browse the web. It will give OpenAI more direct access to a cornerstone of Google's success: user data.
https://t.me/InformationTechnologySecurity
Outlook takes another sick day
Millions of users disrupted, mailbox infrastructure blamed
#Microsoft's #Outlook was down for the count in a major outage affecting millions of users worldwide for the more than 11 hours.
The troubles, according to Microsoft's service status page, began at 2220 UTC on July 9 when it confirmed "users may be unable to access their mailbox using any connection methods."
This included Outlook.com, Outlook Mobile, and the Outlook desktop client.
"We've determined that a portion of mailbox infrastructure isn't performing as efficiently as expected, resulting in impact. We're investigating this further to better understand the issue and help inform our next troubleshooting steps," Microsoft stated.
https://t.me/InformationTechnologySecurity
#Office365
Gmail’s new tab is made for unsubscribing from emails
#Google is introducing a new #Gmail feature for those feeling overwhelmed by an onslaught of subscription emails in their inboxes. The Manage subscriptions view shows a list of emails delivered through active subscriptions, automatically sorted with the most frequent senders at the top, next to individual one-click links that will unsubscribe you from their mailing lists.
You can find the new feature by clicking the navigation bar in the top left corner of your Gmail inbox and selecting Manage subscriptions from the menu that appears. If you don’t see it yet, it’s being introduced on the web version of Gmail starting today, the #Android mobile app starting on July 14th, and the #iOS app starting on July 21st, but it could take a couple of weeks for it to show up for all users. It will be available for all personal Google accounts, #GoogleWorkspace customers, and Workspace Individual Subscribers in “select countries.”
https://t.me/InformationTechnologySecurity
Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware!
TL;DR - An investigation of a single “verified” color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge...
If you think a Chrome extension with #Google’s verified badge, 100,000+ installs, 800+ reviews, and featured placement on the store is trustworthy? Think again... Meet “Color Picker, Eyedropper — Geco colorpick”, an extension that perfectly demonstrates how sophisticated threat actors are exploiting the trust signals we rely on. This isn’t some obvious scam extension thrown together in a weekend. This is a carefully crafted trojan horse that delivers exactly what it promises (a functional color picker) while simultaneously hijacking your browser, tracking every website you visit, and maintaining a persistent command and control backdoor. Not only that, but it remained legitimate for years before becoming malicious through a version update.
If that is not enough, meet the RedDirection campaign. Our investigation into the Color Picker extension revealed it was just the tip of the iceberg. By analyzing the command and control infrastructure and tracking similar code patterns, we uncovered what we’re calling the RedDirection campaign, a sophisticated cross-platform network of eighteen malicious extensions spanning both #Chrome and #Edge stores, all sharing the same hijacking functionality. Combined, these eighteen extensions have infected over 2.3 million users across both browsers, creating one of the largest browser hijacking operations we’ve documented.
These extensions masquerade as popular productivity and entertainment tools across diverse categories: emoji keyboards, weather forecasts, video speed controllers, #VPN proxies for #Discord and #TikTok, dark themes, volume boosters, and #YouTube unblockers. Each provides legitimate functionality while secretly implementing the same browser surv
Microsoft links Sharepoint attacks to Chinese hacking groups
Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain.
They used this exploit chain (dubbed "ToolShell") to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers.
"Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers," Microsoft said in a Tuesday report. "In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities. Investigations into other actors also using these exploits are still ongoing."
https://t.me/InformationTechnologySecurity
TransUnion says hackers stole 4.4 million customers’ personal information
Credit reporting giant TransUnion has disclosed a data breach affecting more than 4.4 million customers’ personal information.
In a filing with Maine’s attorney general’s office on Thursday, TransUnion attributed the July 28 breach to unauthorized access of a third-party application storing customers’ personal data for its U.S. consumer support operations.
TransUnion claimed “no credit information was accessed,” but provided no immediate evidence for its claim. The data breach notice did not specify what specific types of personal data were stolen.
In a separate data breach disclosure filed later on Thursday with Texas’ attorney general’s office, TransUnion confirmed that the stolen personal information includes customers’ names, dates of birth, and Social Security numbers.
https://t.me/InformationTechnologySecurity
US chip exports deepen AI ties with Saudi Arabia and the UAE
🔘 The US cleared exports of up to 35,000 Nvidia Blackwell AI chips to G42 and Humain.
🔘 The move deepens US–Gulf AI ties despite some lawmakers’ concerns.
The US Commerce Department has approved the export of advanced #AI chips to two firms in #SaudiArabia and the #UAE. The authorization covers the equivalent of up to 35,000 #Nvidia Blackwell chips, which are central to large-scale AI training.
The two buyers — G42 in #AbuDhabi and Humain in Saudi Arabia — are working on major data center projects in their countries. The timing of the approval matched the return of Saudi Crown Prince #MohammedBinSalman to the #US for the first time since 2018. It also signalled US support for the two governments’ AI ambitions.
In its statement, the Commerce Department said both companies can buy up to 35,000 Blackwell chips, though the total value can vary. A full batch would be worth about $1 billion. The agency said the approvals come with “rigorous security and reporting requirements.”
Earlier in the day, Humain said it plans to buy 600,000 Nvidia AI chips. Humain is also working with #ElonMusk’s #xAI to develop large-scale data centers in Saudi Arabia, including a planned 500-megawatt site.
The UAE praised the US decision. Ambassador Yousef Al Otaiba said the approval reflects ongoing talks between the two governments and shows their trust in each other on technology and security.
G42 aims to build one of the largest data center hubs in the world using US technology. Nvidia, #OpenAI, #Cisco, #Oracle and #SoftBank are involved in its first phase, called Stargate UAE, which is set to go live in 2026.
https://t.me/InformationTechnologySecurity
Instagram denies breach amid claims of 17 million account data leak
#Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online.
"We fixed an issue that allowed an external party to request password reset emails for some Instagram users," a Meta spokesperson said.
"We want to reassure everyone there was no breach of our systems and people's Instagram accounts remain secure. People can disregard these emails and we apologize for any confusion this may have caused."
A media frenzy over an alleged Instagram data breach began after Malwarebytes warned its customers that cybercriminals had stolen data from 17.5 million accounts.
https://t.me/InformationTechnologySecurity
#Snowflake’s #OpenIA deal signals enterprises will hedge across model vendors to balance cost, performance, and governance as #AI moves from pilots into production
▶️ more
https://t.me/InformationTechnologySecurity
Iran-linked hackers tied to a cyberattack on U.S. company Stryker
A hacktivist group with links to #Iran's intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of #Ireland, Stryker's largest hub outside of the #US, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at Stryker's main U.S. headquarters says the company is currently experiencing a building emergency.
https://t.me/InformationTechnologySecurity