Top stories.
- Vishing attacks target hedge funds.
- Cyberattack disrupts North Carolina Ports operations.
- Metabase Cloud breached by zero-day flaw.
Vishing attacks target hedge funds.
Google's Threat Intelligence Group has linked recent cyberattacks targeting hedge funds, private equity firms, and other financial organizations to the UNC6671 extortion group, formerly known as BlackFile. The group is using helpdesk impersonation and voice phishing to compromise Microsoft 365 and Okta accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees’ personal mobile devices.
Reuters cites sources as saying the campaign has targeted Point72, Millennium Management, Two Sigma Investments, Citadel, and several other private-equity firms. Google’s researchers note, "Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands."
Cyberattack disrupts North Carolina Ports operations.
North Carolina Ports is recovering from a cyberattack that disrupted operations across its three port facilities, forcing staff to switch to manual processes, the Record reports. Officials say the breach has been contained, and the Coast Guard and state agencies are investigating the incident. The attack disrupted port operations at Wilmington, Morehead City, and Charlotte. A spokesperson for North Carolina Ports told the Record that the facilities are now following a normal operating schedule, but companies should expect delays as the ports are still relying on manual operations.
Metabase Cloud breached by zero-day flaw.
Metabase yesterday disclosed a security incident involving a zero-day vulnerability that affected some Metabase Cloud customers. The company detected the attack, patched the issue, and began an investigation with external forensic support. Affected customers are being notified and should rotate credentials for connected databases, review admin accounts, and check logs for suspicious activity.
The company stated, “After gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change your application configuration, steal stored credentials for your connected databases, read any data accessible through those connections, and export data.”