AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

Blog Post

InfoSec News Nuggets 10/01/2025

Canadian Airline WestJet Says Hackers Stole Customer Data 

Canadian airline WestJet this week confirmed that customer personal information was stolen in a June 2025 cyberattack. The incident, disclosed on June 13, involved unauthorized access to several internal systems and impacted the availability of WestJet’s application and website. The airline’s operations were not affected by the attack, and WestJet restored access to its application and website roughly two days after the incident. In July, WestJet said the incident had been fully contained and additional security measures were implemented, adding that the hackers were able to steal certain data from its systems. 

 

Chinese APT ‘Phantom Taurus’ Targeting Organizations With Net-Star Malware 

A Chinese state-sponsored hacking group tracked as ‘Phantom Taurus’ has been targeting government and telecommunications organizations for espionage for more than two years, Palo Alto Networks reports. Initially observed in 2023, the APT was only recently linked to Chinese hacking groups through shared infrastructure, as its tactics, techniques and procedures (TTPs) differ from those typically associated with threat actors operating out of China. “These enable the group to conduct highly covert operations and maintain long-term access to critical targets,” says Palo Alto Networks. 

 

NIST Publishes Guide for Protecting ICS Against USB-Borne Threats 

NIST has published a new guide designed to help organizations reduce cybersecurity risks associated with the use of removable media devices in operational technology (OT) environments. NIST Special Publication (SP) 1334 was authored by the National Cybersecurity Center of Excellence (NCCoE) and it focuses on the use of USB flash drives, but also mentions other types of removable media such as external hard drives and CD/DVD drives. USB flash drives are often used in OT environments to conduct firmware updates or to retrieve data for diagnostics purposes, but such devices are also often a source of malware infections. 

 

Cybersecurity Awareness Month: 10 things to know in 2025 

Cyberattacks are on a steep rise. Over the past four years, their average weekly number has more than doubled: from 818 per organization in the second quarter of 2021 to 1,984 in the same period this year. In the last two years alone, the global average number of weekly attacks encountered by organizations grew by 58%. At the same time, the World Economic Forum’s Global Cybersecurity Outlook 2025 points to an increasingly complex threat landscape. From geopolitical tensions to the impact of cybersecurity and AI, businesses’ vulnerabilities are growing rapidly. Adding to this is a widening skills gap impeding their efforts to step up defences. Small businesses are particularly exposed, with seven times more organizations reporting insufficient cyber resilience than in 2022. 

 

North Korea IT worker scheme expanding to more industries, countries outside of US tech sector 

North Korea is rapidly expanding its illicit IT worker scheme beyond the U.S. tech sector, successfully obtaining interviews and potentially employment at companies in dozens of industries across the world. Cybersecurity giant Okta published a report on Tuesday outlining its continuing research into the IT worker campaign, which has seen North Korea illegally place thousands of its citizens in high-paying roles at U.S. companies to circumvent sanctions and earn millions of dollars for Pyongyang’s military. Using fake IDs or stolen documents, North Korea initially focused on getting its citizens hired at cryptocurrency companies and other blockchain-related firms. Before long, most Fortune 500 companies had interviewed or hired a North Korean IT worker. 

 

Related Posts