news.mlab.sh
Back to the feed
threat-intel

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

High
Summary

This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands, a ransomware attack forcing a German manufacturer into bankruptcy, a Japanese taxi network outage attributed to a ransomware group (AiLock), a new macOS information stealer (CrashStealer), tracking of US military personnel via advertising metadata, a joint CISA/partner guide on bug bounty programs, an AI vulnerability in WhatsApp allowing code execution, and a ransomware attack against an IT firm in Asia, alongside a leak of data from a German naval defense manufacturer.

This week’s cybersecurity news roundup covers a diverse set of incidents and developments.

Dutch authorities are investigating a potential breach at Odido, a telecom operator, suspecting involvement from local hacking groups.

A cyberattack targeting an external IT service provider for Lidl resulted in the theft of customer data, prompting warning notices for affected consumers in Belgium and the Netherlands. Security teams are working to determine the full scope of the supply chain incident.

A German manufacturing company, ZEGO Textilveredelungszentrum, has filed for insolvency following a cyberattack that forced a six-week production shutdown.

Nihon Kotsu, Japan’s largest taxi operator, took its IT and dispatch systems offline after detecting a cyberattack, with analysts suspecting the involvement of the AiLock ransomware group.

Security researchers have identified a new macOS information stealer called CrashStealer, which disguises itself as a system crash reporter and exfiltrates sensitive user data.

Foreign threat actors linked to Iran are exploiting advertising technology metadata and global cellular roaming protocols to track and target the smartphones of US military personnel.

CISA and its international partners have released a joint guide outlining framework recommendations for establishing a Coordinated Vulnerability Disclosure program.

An AI vulnerability in an OpenClaw AI agent integrated with WhatsApp allows remote code execution on the underlying host system.

A cybercrime group known as The Gentlemen has claimed a hack of Thyssenkrupp Marine Systems (TKMS) and its subsidiary Atlas Elektronik, alleging the exfiltration of over 1TB of data, despite the parent organization stating the impacted environment was segmented from core infrastructure and did not contain classified military records.

Related: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

Read the full article at SecurityWeek