Newly-discovered threat group LofyGang has been conducting various hacking operations since beginning its operations more than a year ago, reports SiliconAngle.
More than 200 malicious packages with thousands of installations this year alone have been associated with LofyGang, which has been working not only to target credit card information but also credentials for Disney+, Minecraft, and premium Discord accounts, a Checkmarx report revealed. Software supply chain attacks have also been traced back to LofyGang. The report also showed that LofyGang's hacking tools are being promoted on a page in GitHub. "The surge of recent open-source supply chain attacks teaches us that cyber attackers have realized that abusing the open-source ecosystem represents an easy way to increase the effectiveness of their attacks. Communities are being formed around utilizing open-source software for malicious purposes. We believe this is the start of a trend that will increase in the coming months," said researchers.
Ontario's perinatal, newborn, and child registry Better Outcomes Registry & Network had sensitive data from nearly 3.4 million individuals compromised in late May as a result of the widespread MOVEit hack conducted by the Cl0p ransomware operation, reports BleepingComputer.
New York-based Marymount Manhattan College has agreed to allocate $3.5 million toward cybersecurity measures over the next six years instead of paying a $1 million fine to the state of New York after a data breach two years ago, which compromised almost 200,000 individuals' data, reports EdScoop.
Major U.S. consumer product leasing firm Progressive Leasing has disclosed that some of its systems have been impacted by a cyberattack that resulted in the significant compromise of personally identifiable information belonging to its customers and other individuals, according to The Record, a news site by cybersecurity firm Recorded Future.