
Loading summary
Claire Aird
Oracle's health tech division gets hacked and its customers extorted the Italian government admits it used Paragon to Spy on an NGO, a WordPress feature is being abused to silently install malicious plugins, and the Dutch public prosecutor pulls systems offline after a cyber incident. This is the risky bulletin prepared by Catalyn Kim Panu and read by me, Claire aird. Today is the 31st of March and this podcast this podcast episode is brought to you by Kroll. Hackers have breached Oracle's health technology division and stolen medical data. According to Bloomberg, the hack took place in late January and the attackers are extorting US Medical providers with the stolen data. This is the second suspected breach at Oracle after a different hacking group claimed to have hacked the company's cloud service earlier this month. Oracle has not reported any of the breaches to the sec. In other news, the Italian government has admitted it used spyware against members of an NGO that protects refugees crossing the Mediterranean. High ranking intelligence officials told a parliamentary committee that they approved the surveillance on the grounds of national security. Italian officials initially denied the hacks, which came to light in January when Meta warned some activists they'd been targeted. Israeli company Paragon cut off Italy's access to its graphite spyware by but the Italian government has since contracted local firm NEG to provide similar surveillance capabilities. NEG operates a one click spyware platform known as vbis, which has been previously detected in Italy, Malaysia and Kazakhstan. Hackers are abusing a little known WordPress feature to install and hide malware from site administrators. The must use plugins feature was designed for web hosting companies to forcibly and silently install plugins on their users WordPress sites, but hackers are now abusing it to install malicious plugins. GoDaddy's Sucuri team says the feature has been abused since February. The Dutch public prosecution service has taken its IT system offline following a cyber security incident on Friday. The agency has activated its crisis management team. In response, the agency told its staff that the issues would prevent them from communicating with the police and the judiciary. T Mobile will start paying users affected by the company's 2021 data breach in April. The telco will begin distributing $350 million from a class action settlement. More than 76 million customers are eligible for payments of between $25 and $25,000. The US Justice Department has indicted a Canadian man for hacking the Texas Republican Party. Aubrey Cottle allegedly hacked the party's Web server in 2021 and stole files containing party members personal information. The suspect was identified after he took credit for the hack on social media. Cottle was arrested in Canada last week and police found the stolen data on his devices. Apple is adding a new logging feature to macOS that will help security products to detect and stop malware in a new way. The feature will be added to the Transparency, Consent and Control framework on also known as tcc. TCC prompts users for consent whenever an app needs to access their files, passwords or other data. The new TCC event logging feature will allow security products to trace back malware infections to their source and even add new real time detection capabilities for suspicious data access requests. Mobile security firm ThreatFabric has discovered a new Android banking trojan in the wild. The Crocodylus malware can be used for overlay, phishing attacks, keylogging, and for remote access and remote control operations. The new trojan is targeting bank accounts in Spain and Turkey and popular cryptocurrency services. The European Union will invest 1.3 billion euros into local AI, cybersecurity and digital independence over three years. The funds will be available through the Digital Europe Program, an EU fund designed to bring digital technology to businesses, citizens and public administrations. Earlier this month, a coalition of European businesses urged EU lawmakers to invest in local alternatives to US Tech services. US President Donald Trump has issued an executive order instructing federal agencies to end collective bargaining agreements with unions. The White House claims that federal unions damage and hinder national security, intelligence and counter intelligence work. The order applies to 18 agencies, including the DOD, DHS and CISA union representatives executives have called the executive order unlawful and an attack on the civil service. Security researchers have found a backdoor in robot dogs from Chinese robotics company Unitree. The Robot's firmware includes CloudSail, a cloud based network tunneling system for nat traversal. Attackers with Unitree's Cloud Sail API key could SSH into the robots with the default password, which is attackers could then remotely pilot the dog and use its cameras. Unitree has revoked the API key and the researchers urged robot owners to uninstall the cloud sales service. TikTok has taken down a network of more than 28,000 Ukrainian accounts that targeted audiences in Russia, Georgia, Croatia and Belarus. The company said the accounts were created to undermine support for pro Kremlin political figures, stoke anti government protests and incite ethnic hatred. TikTok said the network used generative AI tools for profile avatars and gained more than 300,000 followers. And that is all for this podcast edition. Today's show was brought to you by our sponsor Kroll. Find them@kroll.com cyber thanks for your company.
Risky Bulletin: Oracle's Healthtech Division Hacked, Customers Extorted
Released on March 31, 2025 by risky.biz
Overview:
Oracle faced a significant cybersecurity breach in late January 2025, targeting its health technology division. Hackers successfully infiltrated the system, stealing sensitive medical data and subsequently extorting U.S. medical providers. This incident marks the second suspected breach for Oracle within a short span, following a separate attack on the company's cloud services earlier in the month.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'Oracle has not reported any of the breaches to the sec.'"
Overview:
The Italian government has officially acknowledged deploying spyware against members of a non-governmental organization (NGO) dedicated to protecting refugees crossing the Mediterranean. This admission follows revelations in January after Meta alerted activists about targeted surveillance.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'Italian officials initially denied the hacks, which came to light in January when Meta warned some activists they'd been targeted.'"
Overview:
Cybercriminals are exploiting a lesser-known feature of WordPress to clandestinely install malicious plugins on websites. This tactic involves abuse of the "must-use plugins" feature, originally intended for web hosting companies to enforce essential plugins on user sites.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'GoDaddy's Sucuri team says the feature has been abused since February.'"
Overview:
The Dutch public prosecution service experienced a cybersecurity incident on Friday, leading to the temporary shutdown of its IT systems. In response, the agency activated its crisis management team to address the breach.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'The agency has activated its crisis management team.'"
Overview:
T-Mobile has announced plans to compensate users affected by its 2021 data breach. The telecommunications giant will commence the distribution of $350 million from a class action settlement in April 2025.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'More than 76 million customers are eligible for payments of between $25 and $25,000.'"
Overview:
The U.S. Justice Department has formally charged a Canadian national, Aubrey Cottle, for unauthorized access and theft of data from the Texas Republican Party’s web server in 2021.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'Cottle was arrested in Canada last week and police found the stolen data on his devices.'"
Overview:
Apple is set to introduce a novel logging feature in macOS aimed at bolstering malware detection and prevention. This enhancement is part of the Transparency, Consent, and Control (TCC) framework.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'The new TCC event logging feature will allow security products to trace back malware infections to their source.'"
Overview:
Mobile security firm ThreatFabric has identified a new Android banking trojan named Crocodylus. This malware is designed for overlay and phishing attacks, keylogging, and enabling remote access and control.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'The Crocodylus malware can be used for overlay, phishing attacks, keylogging, and for remote access and remote control operations.'"
Overview:
The European Union has pledged a substantial investment of €1.3 billion over three years to bolster local artificial intelligence (AI), cybersecurity, and digital independence. These funds are channeled through the Digital Europe Program.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'The funds will be available through the Digital Europe Program, an EU fund designed to bring digital technology to businesses, citizens and public administrations.'"
Overview:
President Donald Trump has signed an executive order directing federal agencies to terminate collective bargaining agreements with unions. The administration asserts that federal unions impede national security and intelligence operations.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'Federal unions damage and hinder national security, intelligence and counter intelligence work.'"
Overview:
Researchers have discovered a vulnerability in the firmware of robot dogs produced by Chinese robotics company Unitree. The flaw involves the CloudSail network tunneling system, which can be exploited to gain unauthorized remote control of the robots.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'Attackers with Unitree's Cloud Sail API key could SSH into the robots with the default password.'"
Overview:
TikTok has dismantled a network comprising over 28,000 Ukrainian accounts that were strategically targeting audiences in Russia, Georgia, Croatia, and Belarus. These accounts aimed to influence public opinion and incite unrest.
Key Points:
Notable Quote:
"[00:04] Claire Aird: 'The company said the accounts were created to undermine support for pro Kremlin political figures, stoke anti government protests and incite ethnic hatred.'"
Conclusion
The March 31, 2025 episode of Risky Bulletin, hosted by Claire Aird, provided a comprehensive overview of the latest cybersecurity threats and developments. From significant breaches at major corporations like Oracle to governmental misuse of spyware and the emergence of sophisticated malware, the bulletin underscored the evolving landscape of cyber threats. Additionally, it highlighted responses from tech giants, governmental bodies, and international organizations aiming to bolster digital security and integrity.
Notable Quote from Conclusion:
"[00:04] Claire Aird: 'And that is all for this podcast edition.'"
This summary was prepared based on the transcript of the Risky Bulletin podcast episode and is intended to provide an informative overview for those who have not listened to the original broadcast.