Infosec In Brief Secrets of the Trump administration may have been exposed after a successful attack on messaging service TeleMessage, which has been used by some officials. Evidence of an attack on administration officials appeared last week on leak site Distributed Denial of Secrets, hosted an archive of messages that included details of over 60 government workers, a White House staffer, and members of the Secret. The leak, first reported by Reuters, isn't as serious as Signalgate - no one was discussing air strikes and possible war crimes - but it's still suboptimal. The White House said that it was "aware of the cyber security incident" but didn't comment further. TeleMessage servers are reportedly closed while an investigation is carried out. Europol had already detailed attempts to take down the Qakbot and Danabot malware groups, and last Friday it announced the disruption of the following five malware crews: Operation Endgame II, a combined operation involving police from the EU, UK, US, and Canada, has now led to 20 arrests and 18 suspects have been added to the EU's most wanted list. In addition a total of €21.2 million has been seized. "This new phase demonstrates law enforcement’s ability to adapt and strike again, even as cybercriminals retool and reorganise," said Catherine De Bolle, Europol executive director. "By disrupting the services criminals rely on to deploy ransomware, we are breaking the kill chain at its source." Two government boffins have proposed a ...
Blue Yonder ransomware termites claim credit
The Register
·Brandon Vigliarolo
·Published Dec 9, 2024
·Updated
Affected Software
3 affected components
Samsung MagicINFO=9
Ivanti Endpoint Manager Mobile=12.5.0.0
TeleMessage Messaging Service
Frequently Asked Questions
1
What recent cyber attack is mentioned in the article?
The article discusses a successful ransomware attack on the messaging service TeleMessage used by some Trump administration officials.
2
What security implications are associated with the attack on TeleMessage?
The attack has potentially exposed sensitive communications and secrets from the Trump administration.
3
Which software or services are affected by this security breach?
Affected services include TeleMessage Messaging Service, Samsung MagicINFO version 9, and Ivanti Endpoint Manager Mobile version 12.5.0.0.
4
Who is behind the ransomware attack mentioned in the article?
The ransomware group Blue Yonder has claimed credit for the attack.
5
What type of data could be at risk due to this incident?
Sensitive messages and information related to Trump administration officials may be at risk of exposure.