Morning cyber security summary
Incident: FBI Warns of BADBOX 2.0 Botnet Surge in Chinese IoT Devices
Incident Date: June 7, 2025
Article Date: June 7, 2025
Summary: The FBI alerted that BADBOX 2.0, a China‑based botnet, has infected over one million low-cost Android smart devices worldwide. Infected devices are being used in criminal schemes, prompting warnings for network audits and device sanitisation.
Reference: www.databreachtoday.com/fbi-warns…‑2‑0‑botnet-surge-in‑chinese‑devices
Incident: New RustStealer Info‑Stealer Targets Chromium Browsers
Incident Date: June 7, 2025
Article Date: June 7, 2025
Summary: Security researchers disclosed “RustStealer,” a Rust‑based info‑stealer targeting Chromium browsers on Windows/macOS. It harvests login credentials, cookies and browser data, posing a significant risk to enterprise credential security.
Reference: social.cyware.com/cyber-sec… (item dated June 7, 2025)
Incident: Optima Tax Relief Hit by Chaos Ransomware, Data Leaked
Incident Date: June 7, 2025
Article Date: June 9, 2025
Summary: Optima Tax Relief was targeted by the Chaos ransomware gang using a double‑extortion tactic; encrypted servers and stolen data are now being leaked on dark‑web forums.
Reference: social.cyware.com/cyber-sec… (item dated June 9, 2025)
Incident: Sensata Technologies Ransomware Breach Exposes SSNs and Medical Data
Incident Date: June 7, 2025
Article Date: June 7, 2025
Summary: Sensata, an industrial tech firm, disclosed a ransomware breach exposing personal data—including Social Security and medical records—of unknown quantity, with confirmation to affected individuals underway.
Reference: social.cyware.com/category/… (item dated June 7, 2025)
Incident: Cumberland County Hospital Cyberattack Affects 36,600 Patients
Incident Date: June 8, 2025
Article Date: June 9, 2025
Summary: Cumberland County Hospital confirmed a ransomware incident impacting 36,600 patients, threatening to publish stolen data on June 8 if ransom wasn’t paid.
Reference: www.hipaajournal.com/cumberlan…
Incident: Cisco Talos Reports Roundcube XSS Attack on Infrastructure
Incident Date: June 6, 2025
Article Date: June 9, 2025
Summary: Cisco Talos revealed attackers exploited an XSS flaw in Roundcube webmail, harvesting credentials from a critical infrastructure entity during active exploitation.
Reference: gbhackers.com/hackers-e…