Latest in Digital Security: Election Interference and DDoS Attacks, Dating Apps Expose User Locations, Germany Points to China

Today’s Cybersecurity Highlights

DDoS Attacks Unlikely to Disrupt US Elections

CISA and the FBI have jointly stated that DDoS activities could only potentially hinder access to election information, without affecting the actual results or the ability to cast votes. They emphasized that no evidence supports claims of DDoS attacks compromising election outcomes. They advised against misinformation and recommended consulting official sources for all election-related information, including registration, polling, and mail-in voting details.

(Source: Bleeping Computer)

Dating Apps Exposed Precise User Locations

Researchers from KU Leuven University in Belgium discovered that dating apps such as Badoo, Bumble, Grindr, happn, Hinge, and Hily had a design flaw that allowed for pinpointing users’ locations within 2 meters. This flaw was exploited using a method called “oracle trilateration.” After being notified by the researchers, the app developers modified the location filters to introduce uncertainty ranges from 111 meters to 1 kilometer, significantly reducing the accuracy of location tracking.

(Source: TechCrunch)

Germany Accuses China of Cyberattack

The German government has formally accused Chinese state actors of a cyberattack on its federal cartography agency, summoning the Chinese ambassador for a protest—an action not taken since 1989. Germany’s intelligence services provided credible evidence of Chinese involvement. This move is part of a broader effort to reduce Chinese influence, including limiting Huawei and ZTE equipment in 5G networks and recent arrests related to espionage.

(Source: Reuters)

BingoMod Malware Targets Android Devices

Cleafy researchers have identified a new Android malware named BingoMod, which disguises itself as various mobile security tools. Distributed via smishing campaigns, it requests accessibility features during installation to steal credentials, take screenshots, and reroute SMS messages. The malware can perform on-device fraud using VNC routines, enabling real-time screen monitoring. BingoMod has been linked to thefts of up to €15,000 per transaction and has the capability to wipe devices post-theft to hinder forensic investigations.

(Source: Bleeping Computer)

Delta Airlines Seeks Compensation from CrowdStrike

Delta Air Lines CEO Ed Bastian revealed on CNBC that the company is pursuing legal action against CrowdStrike, seeking $500 million in damages following a major outage. This incident led to the cancellation of over 5,000 flights, surpassing all cancellations in 2019. The outage, which also prompted a US Department of Transportation investigation, caused significant financial losses due to lost revenue and compensation for stranded passengers.

(Source: CNBC)

Current Status of LockBit Ransomware Group

Connor Jones from The Register reported on the decline of the LockBit ransomware group following the UK’s Operation Cronos in February. The group’s activity dropped from attacking 108 organizations in November 2023 to less than 18 by June. Affiliate numbers also fell dramatically. The remaining affiliates are considered lower-level threat actors. With the alleged leader, Dmitry Khoroshev, identified as a Russian national, it remains uncertain if LockBit will rebrand as other disbanded ransomware groups have.

(Source: The Register)

Ransomware Attack Disrupts Blood Donation Center

OneBlood, a non-profit blood donation center, experienced a ransomware attack that impaired its operations, affecting blood collection and distribution services to over 250 hospitals in the Southeastern US. Hospitals were urged to activate critical blood shortage protocols. The center is working with local investigators to restore its services, though the attackers’ identity remains unknown.

(Source: Infosecurity Magazine)

Columbus Ransomware Attack Update

An update on last month’s ransomware attack on Columbus, Ohio, revealed that a sophisticated, overseas threat actor was responsible. The attack disrupted various city services and municipal email systems. Investigators are notifying individuals potentially affected by data exposure, although they haven’t confirmed any data exfiltration. The breach occurred when an employee downloaded a malicious file not delivered via a phishing email.

(Source: Columbus City Update)

More Articles & Posts