SOC News | Apr 24 – Full AMMEGA Data Breach Published
Using our CTI SATAYO platform, we identified an artifact belonging to AMMEGA’s data breach.
AMMEGA is a multinational manufacturing company based in the Netherlands with revenues of $1.2 billion. It was the victim of an attack carried out by the Cactus ransomware gang in early March.
The ransomware operators exfiltrated 3 TB of data and initially demanded a ransom of $9 million for all the contents or $90,000 for the file tree. The data contains sensitive business information, including customer and supplier data such as drawings, blueprints, invoices, contracts and orders, or personal employee information such as pay checks, ID cards, dossiers and more.
On April 23, 2024, the data breach was made public on Cactus’ .onion website, accessible via the TOR network. Our Threat Intelligence Platform SATAYO alerted us about it as data belonging to our customers was detected inside. Our analysts are now analyzing the leaked documents to quickly inform our stakeholders and prevent document misuse by third parties.
During the last week of April, our Attacker Centric SOC detected multiple new cyber attacker group websites in the Dark Web. Called Dedicated Leak Sites (DLS), they are widely used by ransomware gangs to publish stolen confidential data when the victim Read More
Cisco Talos identified a previously unknown state-sponsored actor behind ArcaneDoor, a sophisticated cyber espionage campaign targeting the perimeter network devices of several vendors. This actor is now tracked as UAT4356 by Talos and STORM-1849 by the Microsoft Threat Intelligence Center. The Read More
On March 25, 2024, the Cybersecurity & Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The catalog is updated regularly and contains those vulnerabilities most likely to be used in attacks. Organizations should monitor Read More
This article explains how the Cyber Threat Intelligence platform SATAYO serves as a powerful resource to optimize processes and strengthen threat coverage within the Würth Phoenix Attacker Centric SOC. We will analyze the utilization of SATAYO's internal resources for creating Read More
On March 4, 2024, JetBrains released TeamCity version 2023.11.4, which patches two authentication bypass vulnerabilities in the web component of TeamCity. These vulnerabilities were discovered in February by Rapid7’s vulnerability research team and allow a remote unauthenticated attacker to perform Read More