
The Cyber Bulletin:
August 2024
Brought to you by DP Solutions
Welcome to DP Solutions' Cyber Bulletin!
This monthly cyber recap, curated by our Cybersecurity Team, lists recent significant cybersecurity events, news, and breaches to keep you in-the-know on current cyber-incidents and provide recommendations.
These articles are meant to be informative, and we encourage everyone to do their own research.
Scroll down to read this month's cyber bulletin! ↓
Subscribe to the Cyber Bulletin
AT&T says nearly all of its cell customers' call and text records were exposed in massive breach
The records of calls and texts of AT&T customers were illegally downloaded from a third-party cloud platform. The data identified the phone numbers that the AT&T number interacted with, but did not include timestamps or content. The investigation is ongoing as of the article's publication.
Over 400,000 Life360 user phone numbers leaked via unsecured API
A threat actor exploited a flaw in Life360's, the leading family location safety app, login API on Android to collect users' phone numbers, names, and email addresses. The data of over 400,000 users was leaked before the flaw was fixed.
Microsoft says massive Azure outage was caused by DDoS attack
A Distributed Denial-of-Service (DDoS) attack was the cause of a nine-hour outage of Microsoft365 and Azure services worldwide on July 30. Microsoft's DDoS protection mechanisms were activated, but a network misconfiguration ended up amplifying the problem before it was mitigated.
Hackers leak 2.7 billion data records with Social Security numbers
Over 2 billion records of personal information were leaked on a hacking forum that was allegedly taken from National Public Data. This information includes names, social security numbers, and physical addresses. It is recommended that you monitor your credit report for any fraudulent activity.
Dispossessor ransomware group shut down by US, European authorities
The criminal ransomware group, Radar/Dispossessor has been shut down by the United States and Germany. This globally active group targeted small to medium-sized companies in healthcare and transport in the US as well as 13 other identified countries. They were able to access IT systems and data through vulnerable computer systems, weak passwords, and lack of MFA.
Fake X content warnings on Ukraine war, earthquakes used as clickbait
Scammers are creating fake posts on X exploiting top news topics, like the Ukraine war and earthquakes in Japan. The posts include a video that displays a content warning forcing users to click on the link to view the content. The URL then redirects users to a scam site with malicious content.