Cencora Admits Data Breach in February Cyberattack
Pharmaceutical supplier Cencora has revealed that sensitive personal and health information was compromised during a cyberattack that occurred in February. This confirmation came in an updated report filed with the Securities and Exchange Commission on July 31. The breach involved data managed by a Cencora subsidiary specializing in patient support services. The SEC filing did not disclose the number of individuals affected or the name of the subsidiary. InfoSecurity Magazine reports that there is no current evidence suggesting that the stolen data has been published or exploited by the attackers.
Learn to Hack Chips with a $500 Open-Source Laser Tool
At next week’s Black Hat conference, Sam Beaumont and Larry “Patch” Trowell from NetSPI will introduce an innovative laser-based hacking tool named RayV Lite. This device, intended for open-source release, is designed to enable users to perform advanced reverse engineering of chips, uncovering vulnerabilities and secrets previously accessible only to researchers in elite labs and government entities. The presentation aims to demonstrate that chip hacking is achievable for a broader audience and highlights the need for enhanced security in chip design.
New Mandrake Android Malware With Enhanced Capabilities
The Mandrake malware, which has been active since 2016, has resurfaced in a revamped form on five apps with a combined 32,000 downloads from Google Play. The updated version performs various malicious functions such as data collection, screen recording, command execution, and file management. It can also trick users into installing additional harmful applications through deceptive notifications that mimic Google Play alerts.
Senate Committee Advances Three Cybersecurity Bills
This week, a Senate committee approved three significant cybersecurity bills for further consideration. The proposed legislation includes:
- A measure to standardize federal cyber regulations, simplifying requirements for the private sector.
- The Healthcare Cybersecurity Act, which directs CISA to collaborate with the Department of Health and Human Services to enhance cyber defenses in the healthcare sector.
- The Federal Cyber Workforce Training Act, which mandates the national cyber director to establish a centralized training resource for developing the federal cybersecurity workforce, involving private sector and academic institutions.
Sophisticated Phishing Attack Targets OneDrive Users
Trellix Advanced Research Center has issued a warning about a sophisticated phishing scheme aimed at OneDrive users. The attack involves deceptive emails with HTML attachments that falsely claim a DNS issue needs fixing. These attachments contain a dialog box that, when interacted with, downloads malicious scripts compromising users’ systems. The phishing campaign has primarily targeted U.S. users, with additional victims in South Korea, Germany, and India.
Eriakos Ecommerce Scam Targets Facebook Users
Recorded Future has flagged a sophisticated scam network, Eriakos, which deceives Facebook users into visiting fraudulent online stores through malicious ads. This scam focuses on mobile device users and utilizes transient ad campaigns to bypass Facebook’s security filters. The ads create a sense of urgency to prompt immediate purchases and have been traced back to operations based in China.
Argentina to Use AI for Crime Prediction
Argentina’s security forces are set to adopt artificial intelligence for crime forecasting, reminiscent of the “Minority Report” concept. Spearheaded by President Javier Milei, the initiative involves using machine learning to analyze historical crime data for future crime predictions. The program will also deploy facial recognition technology, monitor social media, and scrutinize real-time security camera footage to identify suspicious activities.



