Friday 21st February 2025

Friday 21st February 2025

Good morning, a very happy Friday to you all and thank you for joining me for the latest edition of Cyber Daily. In today’s edition, Microsoft is forcing IT teams into the cloud, a new ransomware strain is creeping through European hospitals, and Chinese hackers just pulled off a telecom heist so massive, the FBI is calling it “indiscriminate.”

Enjoy the read!

NailaoLocker: A New Ransomware Threat in Europe’s Healthcare Sector

A fresh ransomware strain, NailaoLocker, has been spotted targeting European healthcare organisations, with attacks running from June to October 2024. Hackers exploited a vulnerability in Check Point Security Gateway (CVE-2024-24919) to infiltrate networks and deploy malware associated with Chinese state-sponsored groups.

While NailaoLocker isn’t the most sophisticated ransomware—lacking security evasion features and network scanning—it still managed to encrypt files using AES-256-CTR encryption. Victims received a bizarrely long ransom note filename, directing them to contact an anonymous ProtonMail address for decryption.

Researchers speculate this could be a Chinese espionage operation moonlighting for extra cash. Unlike North Korean actors, Chinese-backed groups haven’t historically used ransomware for profit—making this a concerning tactical shift.

Microsoft to End WSUS Driver Sync—Time to Go Cloud?

Microsoft is pulling the plug on Windows Server Update Services (WSUS) driver synchronisation on April 18, 2025, urging IT admins to shift to cloud-based alternatives like Windows Autopatch, Azure Update Manager, and Microsoft Intune.

After the deadline, drivers will still be available via the Microsoft Update Catalog, but they won’t be importable into WSUS. Organisations sticking with on-prem updates will need to rely on Device Driver Packages or transition to cloud-based services.

Microsoft previously announced WSUS deprecation, meaning no new features—but for now, the system will still receive updates. The move follows Microsoft’s retirement of NTLM authentication, signaling a broader shift toward modernized security and update management.

TL;DR: If your enterprise relies on WSUS, it’s time to rethink your update strategy before April rolls around.


FBI Sounds Alarm on Massive Chinese Hack Targeting U.S. Telecoms

A cyberattack on major U.S. telecom companies, attributed to Chinese state-backed hackers Salt Typhoon, was “indiscriminate” in its scope, according to the FBI. The breach, which vacuumed up call records, law enforcement data, and even information on children, showcases China’s aggressive ambitions in cyberspace, said Cynthia Kaiser, deputy assistant director of the FBI’s cyber division.

China can now store and analyse this data forever, potentially using it for future espionage or influence campaigns. The sheer scale of the operation has reignited calls for the U.S. to launch offensive cyber operations in retaliation.

Salt Typhoon’s global hacking spree is ongoing, and the U.S. has already sanctioned a Chinese national and a cybersecurity company for their role. With bipartisan support growing for stronger cyber defenses, this breach may push Washington to take a more aggressive stance in digital warfare.

Matt Rosenthal

CEO at Mindcore | Cybersecurity & IT Services for Business Owners

1 周

Cyber threats are evolving fast, and these updates prove just how critical proactive security is. Ransomware targeting healthcare, telecom breaches, and shifts in IT infrastructure all reminders that businesses must stay ahead, not just react. Thanks for keeping the community informed on these crucial developments!

回复

要查看或添加评论,请登录

Aidan Dickenson的更多文章

  • Saturday 1st March 2025

    Saturday 1st March 2025

    Good morning everyone, happy Saturday. It's finally Spring! If you’ve ever rolled your eyes at CAPTCHAs, imagine…

  • Friday 28th February 2025

    Friday 28th February 2025

    Good morning everyone and a very happy Friday to you all. Cybercriminals are getting bolder, state-sponsored hackers…

  • Thursday 27th February 2025

    Thursday 27th February 2025

    Good morning everyone and thank you for joining me for the latest instalment of Cyber Daily. If ransomware gangs had a…

  • Wednesday 26th February 2025

    Wednesday 26th February 2025

    Good morning. In today’s edition: Chinese cyber spies are still hanging out in global telecom systems, but instead of…

  • Monday 24th February 2025

    Monday 24th February 2025

    Good morning everyone and thank you for joining me for the latest instalment of Cyber Daily. The U.

  • Saturday 22nd February 2025

    Saturday 22nd February 2025

    Good morning. This week, Apple pulled its Advanced Data Protection feature in the UK after refusing to give law…

  • Thursday 20th February 2025

    Thursday 20th February 2025

    Good morning. In today’s edition: - PAN-OS firewalls are under attack as hackers chain vulnerabilities to break in.

    9 条评论
  • Wednesday 19th February 2025

    Wednesday 19th February 2025

    Good morning everyone, thank you for joining me for the latest instalment of Cyber Daily. If cybercriminals put as much…

    1 条评论
  • Monday 17th February 2025

    Monday 17th February 2025

    Good morning everyone, a very happy Monday and thank you for joining me for the latest instalment of Cyber Daily. If…

    2 条评论
  • Sunday 16th February 2025

    Sunday 16th February 2025

    Good morning. If you thought pirates were only after gold, think again—this week, they went for your passwords.