On September 14, 2023, the BlackCat ransomware group, also known as APLHV, claimed responsibility for a cyberattack that affected MGM Resorts' operations. The group announced that they had breached MGM's infrastructure on September 8, 2023, encrypted over 100 ESXi hypervisors, exfiltrated data from the network, retained access to portions of MGM's infrastructure, and threatened to conduct future assaults unless a ransom deal was made. Cybersecurity researcher vx-underground was the first to announce that threat actors related to the ALPHV ransomware campaign had infiltrated MGM using a social engineering attack. The threat actor behind the breach has been tracked by various cybersecurity companies under various names, including Scattered Spider (Crowdstrike), 0ktapus (Group-IB), UNC3944 (Mandiant), and Scatter Swine (Okta), and the same group is believed to be responsible for breaching Caesars Entertainment's network as well, with reports indicating a ransom demand of thirty million dollars and receiving a ransom payment of fifteen million dollars. In their statement, BlackCat noted that MGM Resorts had not responded on the provided communication channel, indicating a reluctance to negotiate a ransom payment. Despite MGM's attempt to disconnect Okta Sync servers, the hackers maintained access to the network, with super administrator privileges on MGM's Okta environment and global administrator permissions for the company's Azure tenant. Furious with MGM's lack of involvement, BlackCat launched the ransomware attack, threatening to reveal stolen data unless an agreement was made and pledging to utilize their present access for subsequent attacks to put pressure on the firm.
Researchers at 0patch recently uncovered an unpatched flaw in the Windows Remote Access Connection Manager (RasMan) service while examining a separate vulnerability that had alread...
A high-risk vulnerability has been identified in the Windows Remote Access Connection Manager (RasMan) service that allows local attackers to escalate privileges and execute arbitr...
Security analysts have uncovered an ongoing wave of phishing activity targeting multiple industries across Russia, with a strong focus on financial and administrative departments. ...