In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Several cybersecurity events were highlighted this week, including a reassessment of the Log4j vulnerability as ‘non-finding,’ a ransomware attack against Paylogix exposing sensitive data, and US sanctions against Iranian cyber actors. Other notable developments included a credential leak study revealing thousands of active AWS keys, a reassessment of the Carhartt breach, and a Russian cyber training pipeline exposure.
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
Developers have downplayed the severity of the Log4j vulnerability, describing it as a ‘known security non-finding’ despite its potential for remote code execution. The vulnerability, similar to the Log4Shell flaw from a few years ago, can have serious impacts.
U.S. Bancorp responded to claims by the LockBit ransomware gang, stating that the alleged attack originated with a fourth-party provider outside the bank’s environment, and there’s currently no evidence of compromise.
A Truffle Security study uncovered over 700 still-active corporate AWS keys granting full control over accounts, alongside 28,000 exposed Git repositories and numerous other credentials. Separately, Intruder found 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens and 17 GitHub PATs, some of which were still active and could provide access to cloud environments and private source code.
Mobile banking malware continues to expand its reach, with Zimperium identifying 30 malware families targeting over 800 banking and fintech apps across 44 EMEA countries, increasingly utilizing AI across the attack chain.
Analysis of the alleged Carhartt breach revealed that approximately half of the 24.8 million email addresses were synthetic TPC-DS benchmark data, significantly reducing the actual amount of real customer data involved.
Paylogix experienced a breach in November, exposing Social Security numbers, financial and health insurance information, medical data, passport numbers and taxpayer IDs, affecting at least 67,789 people in South Carolina, New Hampshire and Vermont. The Akira ransomware group claimed responsibility.
Russian cyber training pipeline exposed: Leaked Bauman University records revealed a program training approximately 250 career and reserve students for Russian military intelligence and cyber operations, covering offensive and defensive cyber techniques, malware analysis, intelligence work and military placements, with graduates linked to units associated with APT28 and Sandworm.
Manchester Airports Group suffered a cyberattack, with hackers accessing personal data belonging to about 8.7 million customers, including email addresses, phone numbers, vehicle registrations and postcodes. The attackers demanded a ransom, but MAG refused to pay, and airport operations, passenger safety and aviation security were not affected.
The US Treasury sanctioned Iranian cyber actors tied to the MOIS, accusing the group of compromising critical infrastructure and conducting financially motivated cyber theft. Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i were designated, alongside four of the 17 Iranian cyber actors charged by the FBI.