Cyware Weekly Threat Intelligence - October 03–07

Weekly Threat Briefing • October 7, 2022
Weekly Threat Briefing • October 7, 2022
The 'International Cybersecurity Awareness Month' kicked off this week, with several federal agencies and organizations taking a pledge to improve their defenses against cyberattacks. Highlighting the importance of the program, the Department of Homeland Security has encouraged private-public sector collaboration for threat-sharing and streamlining cybersecurity efforts. In other developments, the CISA has mandated that all federal agencies are to share their findings on vulnerable systems that need to be patched.
Ransomware attacks are running rampant, wreaking havoc on businesses. This week, the Italian luxury sports car manufacturer Ferrari was allegedly hacked by the RansomEXX group that stole around 6.99GB of internal data. In another incident, the Vice Society ransomware group leaked more than 248,000 files belonging to the Los Angeles Unified School District (LAUSD) on the dark web. CommonSpirit Health is also inspecting a cybersecurity incident that is believed to be the work of ransomware attackers.
Active exploitation of unpatched vulnerabilities continues to explode as the CISA released a new advisory with a list of the top 20 vulnerabilities exploited by Chinese state-sponsored threat groups. New and old infostealers were also observed this week in multiple campaigns that targeted users worldwide. While LilithBot was found to be distributed via a dedicated Telegram group and a Tor link, the variants of Agent Tesla and njRAT were propagated via legitimate websites.