Software

Industry

CLickFix Compromises Websites of over 100 US Auto Dealerships

March 17, 2025

Websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. A threat actor infected LES Automotive, a shared video service unique to dealerships. Websites using the video service would serve a ClickFix webpage to their visitors. The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.

read more

Ransomware Attack at Oracle

April 2, 2025

Oracle Corporation confirmed a hacker broke into a computer system and stole old client log-in credentials. An unidentified person began attempting to sell data online that was stolen from Oracle’s cloud servers.

It is the second cybersecurity breach that the software company has acknowledged to clients in the last month. Oracle told customers that the data breach is separate from the hacking incident that it flagged to some healthcare customers last month.

read more

Versa Networks Acknowledges Cybersecurity Incident

April 23, 2025

SASE specialist Versa Networks acknowledges a cybersecurity incident. “Investigation confirmed that the incident only affected this non-production environment and that it had no impact on our production systems, our customers’ data or that of our employees.” The cyber-extortion startup Silent appears to be involved.

read more

Cyberattack Adds Complication to Daily Lives of French Farmers

December 15, 2024

The IT platform hosting Synel and all other animal notification modules in south-west France has been hit by a cyber-attack. Since December 15, approximately 30,000 farmers in 22 departments in the southwest have been affected by a cyberattack. The Synel herd management software used by cattle, sheep and goat farmers is unusable. They have returned to the age of paper declarations.

The Synel software usually ensures the identification of animals by declaring birth, death or sale. Any change affecting the herd must be scrupulously reported within seven days. In the event of failure to comply with these obligations, farmers are exposed to financial penalties during checks.

read more

Hackers Gain Access to Mail Accounts at Microsoft

November 27, 2023

The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.

The investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself.

read more

Anydesk Software Development Systems Hacked

January 27, 2024

Anydesk recently struggled with disruptions, the company now confirms that it is the victim of an IT incident. The company activated its emergency plan.

The company has revoked all security-related certificates. Systems have been repaired or replaced where necessary. The code signing certificate used to date will be withdrawn shortly and the manufacturer has started using a new one. Anydesk systems are not designed to store private keys, security tokens or passwords, Anydesk adds in the statement.

AnyDesk suffered a four-day outage during which the company disabled the ability to log in to the AnyDesk client. On Feburary 1 access was restored.

read more

Ransomware Attack at New Zealand Auxo Software Company

February 13, 2024

Confidential client information has been stolen in a cyberattack and blackmail attempt by overseas hackers against Software company Auxo.
Auxo software is used in 50 per cent of vehicle workshops nationwide, and at 40 per cent of NZ vehicle dealers.

Auxo – which is wholly owned by the Motor Trade Association (MTA) – will not say how many clients may have been affected nor how much the ransom demand was for.

read more

IVC Technologies, a Vibration Monitoring Firm, Suffers Cyberattack

October 28, 2024

Lebanon, Ohio-based IVC Technologies fell victim of a cybersecurity incident this past October that resulted in a threat actor obtaining unauthorized third-party access to certain personal data.
“We recognize that cybersecurity is a significant concern in today’s world, and we know that many individuals have been impacted by other cybersecurity incidents that are completely unrelated to IVC, such as cyberattacks impacting schools, hospitals, and other businesses,” the company said in a letter to the victims.
The company – which provides vibration analysis programs throughout the United States and has the expertise and software to diagnose equipment’s most difficult mechanical and electrical failure modes – said as of right now, there is no evidence any personal data ended up removed from our information systems.

read more

Ransomware Attack at Swiss BKW Building Solutions Group

April 1, 2024

At the beginning of April, the Swisspro companies belonging to the BKW Building Solutions Group became the target of a cyber attack. The company confirmed this when asked by inside-it.ch. “Ransomware was discovered in Swisspro’s old IT environment,” wrote the BKW media office. “The current operational IT environment of both Swisspro and the other BKW companies is not affected. Despite the incident, Swisspro is able to provide services to customers,” it is emphasized.

read more

Cyberattack Impacted Kadokawa’s and its Subsidiary’s Operations.

June 8, 2024

Japanese publisher Kadokawa has confirmed a data leak affecting 254,241 people due to a cyberattack. On June 8, Kadokawa Group subsidiary Niconico suffered a significant ransomware attack that initially compromised its video portal, before affecting the wider Kadokawa Group corporate conglomerate.

This incident has had a ripple effect across the conglomerate, impacting online merchandise orders for stores under the Kadokawa group, as some systems are currently unable to process and ship orders as well as infrastructure related to company-run websites. At one point the perpetrator remotely restarted servers to continue the attack and spread ransomware, forcing staff to physically disconnect power and communications cables from affected servers in order to halt the attack.

The attack halted the flow of orders but also reduced production output and caused delays in physical distribution. The impact is evident in the sudden drop in publication releases as well as the halt in payments to partners. The further shut down of support systems for domestic editing and production of both print and digital publications has compounded the impact of the incident. The ransomware gang BlackSuit claimed responsibility for the attack.

Kyodo News commissioned an investigation and reports on December 12 that $2.98 million in cryptocurrency was paid to BlackSuit on June 13.

read more