10th August – Threat Intelligence Report
RoundupNorth Carolina Ports SystemsUNC6671Ryde Scooters PlatformOur summary
Check Point Research reports a significant cyber incident affecting North Carolina Ports, where an intrusion forced manual operations until containment was achieved. The week also featured a major data compromise at Ryde, exposing personal and partial payment details for 4.5 million customers across Scandinavia and Germany, alongside a theft campaign against Coinkite Coldcard wallets that resulted in the loss of approximately $88.6 million in Bitcoin due to a firmware flaw.
On the threat landscape front, researchers uncovered the Shai-Hulud CHAINDROP supply-chain attack on npm packages and identified UNC6671 as the actor behind voice-phishing campaigns targeting US financial firms. Patch releases were issued for critical flaws in Cisco SD-WAN, WordPress 7.0.3, and TP-Link Omada devices.
Below is the opening; the full story is at Check Point Research.
From Check Point Research
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
- North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored.
- Ryde, an electric scooter operator in Scandinavian countries, has disclosed a data breach affecting all 4.5 million customer accounts across Norway, Sweden, Finland, and Germany. Attackers copied phone numbers, email addresses, birth dates, partial payment card numbers, and payment histories. Full card numbers and ride histories were unaffected.
- Canadian hardware wallet maker Coinkite has disclosed a theft campaign exploiting a Coldcard firmware vulnerability, with at least 1,367 bitcoin worth about $88.6 million stolen from thousands of addresses. The company halted affected shipments, destroyed vulnerable inventory, and released patched firmware after confirming exploitation against customer wallets.
- Beacon, a UK provider of customer relationship management software for charities, has disclosed a data breach after attackers compromised an access key. The company notified around 1,500 nonprofit customers that database information, donation records, and stored attachments may have been downloaded. Payment and bank details were not affected.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.