Network Box Security Response

Network Box Security Response Network Box Headquarters

Internet threats to Network security are a global phenomenon which is why Network Box has established operation centres around the world. With headquarters in Hong Kong and regional operations centres in Europe, Australasia, America and Asia we ‘follow the sun’ twenty four hours a day, seven days a week to ensure our products are kept up to date against the very latest internet security threats.

Healthcare data breach exposes 3.75M patient records. Hackers stole medical records, Social Security numbers, government...
30/08/2026

Healthcare data breach exposes 3.75M patient records.
Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million people had personal information and medical records stolen after hackers gained access to a CareCloud cloud environment earlier this year.

LINK:

The CareCloud data breach exposed Social Security numbers, banking information and medical records belonging to more than 3.75 million people.

Three major UK airports have been hit by a "cyber security incident" in which criminal hackers accessed the data of almo...
27/08/2026

Three major UK airports have been hit by a "cyber security incident" in which criminal hackers accessed the data of almost nine million people and demanded a ransom. Manchester Airports Group (MAG), which owns Manchester, East Midlands and London Stansted airports, said customers' contact details, vehicle registrations and postcodes were obtained by hackers at the weekend. MAG told the BBC the hackers demanded a ransom fee for the return of the data, which the group said it refused to pay. The sum of the ransom fee was not disclosed.

LINK:

About 8.7 million customers had their data accessed and a ransom was demanded.

Kaspersky has disclosed details of two ransomware incidents in Latin America in which attackers combined the use of Micr...
26/07/2026

Kaspersky has disclosed details of two ransomware incidents in Latin America in which attackers combined the use of Microsoft’s BitLocker encryption tool with an unusual tactic: hijacking corporate printers to distribute ransom notes throughout affected organizations.

In the Colombian case, attackers reportedly gained access through an internet-exposed remote access service connected to a server managing an 8 TB storage device containing business-critical data. After taking control of the environment and modifying user credentials, they used BitLocker to encrypt a storage volume that primarily contained financial information, rendering the data inaccessible. The attackers then used the organization’s network printers to print ransom notes demanding payment.

A separate investigation in Mexico found that a group identifying itself as the “XEntry Team” allegedly accessed an organization’s network through a misconfigured Microsoft SQL Server after obtaining login credentials exposed in publicly available source code. Kaspersky said the attackers expanded beyond the database environment, weakened web server protections, and maintained persistent access for several months before the intrusion was discovered.

LINK:

Ransomware Attacks Using Corporate Printers Found in LATAM: Kaspersky has disclosed details of two ransomware incidents in Latin America …

OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them d...
22/07/2026

OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test. The ChatGPT-maker said its agent - an AI system which can operate alone after some human instruction – was being tested in a controlled environment, but found vulnerabilities and managed to escape. They targeted Hugging Face, one of the world's largest hubs for sharing AI models, gaining access to some internal company systems. OpenAI said the incident was "unprecedented", and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was "mind-blowing that all of this happened autonomously".

LINK:

It is one of the first publicly disclosed cyber-attacks carried out by AI without direct human involvement.

Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-20...
21/07/2026

Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-2026-0257, as the consistent initial access vector across multiple June 2026 intrusions investigated by Arctic Wolf Labs.

The campaign moved rapidly from perimeter compromise to domain-wide encryption, with post-exploitation tactics varying between affiliates operating under Qilin’s ransomware-as-a-service model.

CVE-2026-0257 is an authentication bypass affecting the GlobalProtect portal and gateway in PAN-OS, exploitable when authentication override cookies are enabled alongside a specific certificate configuration.

LINK: https://cyberpress.org/qilin-ransomware-exploits-palo-alto-globalprotect-flaw/

Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-2026-0257, as the consistent initial access vector across multiple June 2026 intrusions investigated by Arctic Wolf Labs.

Ernst & Young discloses data breach after attackers accessed clients’ tax documents. Ernst & Young (EY), one of the worl...
18/07/2026

Ernst & Young discloses data breach after attackers accessed clients’ tax documents. Ernst & Young (EY), one of the world’s largest professional services firms, has disclosed a data breach after an unauthorized attacker compromised a third-party system used by the firm.

The accounting giant notified affected individuals through a filing with the California Department of Justice, revealing that attackers gained access to a third-party IT service management platform used to support EY employees working on client tax services.

EY said the incident involved documents that may have contained personal information and financial details related to clients’ tax filings, as support tickets submitted through the platform may include attached documents with sensitive information.

LINK:

Ernst & Young disclosed a data breach after attackers accessed a third-party IT service management platform used for tax support.

SINGAPORE: Personal data of about 70,000 people was compromised following a cybersecurity incident involving the Singapo...
04/07/2026

SINGAPORE: Personal data of about 70,000 people was compromised following a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by its vendor IBM.

In a media release on Friday (Jul 3), SLA said the incident involved unauthorised access to a data set created for vendor development and testing.

IBM manages the development and systems-integration testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). The web-based system allows lawyers, government agencies and authorised individuals to submit documents relating to property transfers and caveats.

LINK:

Names, NRIC numbers and past property addresses were exposed after unauthorised access to a data set created for vendor development and testing.

Shun Hing Group has reported a data breach to the Privacy Commissioner's Office, with more than 920,000 customers' perso...
03/07/2026

Shun Hing Group has reported a data breach to the Privacy Commissioner's Office, with more than 920,000 customers' personal information potentially exposed, the office said.

The breach, reported on March 23, may involve personal data of about 920,000 customers, including names, addresses, phone numbers and email addresses. Personal data of about 1,000 employees, service providers and suppliers – including names, addresses, phone numbers, email addresses, identity document numbers, bank account details and salary information – may also have been leaked.

In addition, the personal data of about 1.05 million individuals – including about 1.045 million customers – may have been maliciously encrypted, the watchdog said.

LINK:

Shun Hing Group has reported a data breach to the Privacy Commissioner's Office, with more than 920,000 customers' personal information potentially exposed, the office said.

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting t...
02/07/2026

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions.

The campaign was dubbed "FortiBleed" due to the large number of exposed credentials and the massive credential-theft operation.

According to the researchers, the operation targeted more than 430,000 FortiGate firewalls worldwide.

LINK:

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions.

Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the wo...
18/06/2026

Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, according to two cybersecurity firms. The widespread hacking campaign, which is ongoing and has been dubbed FortiBleed, appears to not involve abusing any unknown vulnerability in the targeted devices, but rather on a more basic issue: Companies may not be changing passwords to the firewall, nor making sure that the credentials they use for sensitive systems exposed on the internet are not already known by hackers.

LINK:

An alleged Russian-speaking group of cybercriminals is reportedly compromising and targeting several major companies that use Fortinet Firewalls and VPNs through previously known passwords.

Address

16/F Metro Loft, 38 Kwai Hei Street, Kwai Chung
Kowloon

Alerts

Be the first to know and let us send you an email when Network Box Security Response posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Network Box Security Response:

Share