Become Cyber Safe – 16th November

Table of Contents

[fusion_builder_container type=”flex” hundred_percent=”no” equal_height_columns=”no” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” background_position=”center center” background_repeat=”no-repeat” fade=”no” background_parallax=”none” parallax_speed=”0.3″ video_aspect_ratio=”16:9″ video_loop=”yes” video_mute=”yes” border_style=”solid” margin_top=”1px” flex_align_items=”center” flex_justify_content=”flex-start”][fusion_builder_row][fusion_builder_column type=”1_1″ layout=”1_1″ background_position=”left top” border_style=”solid” border_position=”all” spacing=”yes” background_repeat=”no-repeat” margin_top=”0px” margin_bottom=”0px” animation_speed=”0.3″ animation_direction=”left” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” center_content=”no” last=”true” hover_type=”none” first=”true” background_blend_mode=”overlay” min_height=”” link=””][fusion_text]

Welcome to the latest edition of the Cyber Safe Cyber Threats, a weekly series in which we bring attention to the latest cyber attacks, scams, frauds, and malware including Ransomware, to ensure you stay safe online.

Here are the most prominent threats which you should be aware of:


‘CitrixBleed’ Linked to Ransomware Hit on China’s State-Owned Bank

A major ransomware attack recently targeted the Industrial and Commercial Bank of China (ICBC), the world’s largest bank, revealing a potential link to a critical Citrix vulnerability known as “CitrixBleed” (CVE-2023-4966).

This vulnerability affects various Citrix NetScaler platforms, allowing attackers to steal sensitive information and hijack user sessions. Despite Citrix releasing updates in October, threat actors began exploiting the flaw in August, leading to an ongoing surge in attacks.

Security researchers identified over 5,000 organisations that have yet to patch the vulnerability, with at least four organised threat groups actively targeting it. The ICBC ransomware incident, attributed to LockBit ransomware cyber hackers, underscored the real-world consequences of unpatched vulnerabilities.

In response to the widespread exploitation, the US Cyber Security and Infrastructure Security Agency (CISA) issued urgent guidance for organisations to update their Citrix appliances to mitigate the threat promptly.

Australian Ports Resume Operation After Crippling Cyber Disruption


Over the weekend, four major ports in Australia experienced a cyber-induced downtime, disrupting operations for Dubai-based international shipping and logistics company DP World. The affected ports included critical locations in Sydney, Melbourne, Brisbane, and Fremantle. It reached national news and Government level clearance, as Clare O’Neil, Australia’s cyber security and home affairs minister, underscored the magnitude of the attack, noting that DP World manages approximately 40% of the country’s freight.

The details of the cyber attack are yet to be fully disclosed, with the company indicating that a critical focus of the ongoing investigation is understanding the nature of data access and potential theft. While some speculation points towards ransomware involvement, conflicting reports suggest that the incident may have been characterised by unauthorised access rather than ransomware. Cyber threat researcher Kevin Beaumont has suggested a link to Citrix Bleed, a vulnerability in Citrix NetScaler devices, although details remain unconfirmed.

DP World proactively shut down local systems throughout the weekend to contain the attack’s impact. This decision, however, resulted in delays for around 30,000 shipping containers.

Notably, despite the disruption, the cyber security incident primarily affected landside operations, with DP World cranes continuing to load and unload ships at Fremantle. Another company operating at the same port reported uninterrupted functions.

As of Monday afternoon, the affected ports have resumed normal function. Nevertheless, Australia’s national cyber security coordinator, Darren Goldie, cautioned on Twitter that the incident’s resolution does not imply its conclusion. Ongoing remediation efforts and lingering supply chain concerns underscore the broader impact of such cyber incidents on critical infrastructure and national logistics.

BlackCat ransomware group says it stole 35TB of sensitive data from Henry Schein’s network

The BlackCat ransomware group has asserted responsibility for a significant cyber threat against Henry Schein, a prominent U.S. healthcare solutions provider, resulting in the theft of 35 terabytes of sensitive data from the company’s network. Henry Schein disclosed the cyber attack in a security incident notice on its website, revealing that it identified the security breach on October 14, impacting sections of its manufacturing and distribution operations.

In response, the company initiated an investigation with third-party cybersecurity experts to comprehend the incident’s nature and extent. As a precautionary measure, portions of its internal network were taken offline, causing temporary disruptions to some business operations.

Despite the cyber security incident, Henry Schein assured that its clients’ practice management software remained unaffected. However, the BlackCat/ALPHV ransomware group claimed responsibility for the attack, listing Henry Schein as a victim on its data leak site and demanding a ransom by November 3. The threat actors alleged that, despite ongoing discussions, Henry Schein had not shown a commitment to prioritising the security of clients, partners, and employees.

In response to the healthcare provider’s perceived lack of cooperation, the ransomware group announced its intention to publish a portion of Henry Schein’s internal payroll data and shareholder folders on its collections blog. The group declared its intent to release more data daily, further escalating the cyber threat.

This incident follows the BlackCat/ALPHV ransomware group’s involvement in a major cyber attack on MGM Resorts International in September, where they claimed responsibility for disrupting 31 MGM property websites and the company’s mobile rewards app. The group highlighted the ease with which they compromised MGM Resorts, citing a 10-minute conversation with an employee they identified on LinkedIn.

—————————————————————————————————————————–

Contact Neuways to help your business become

Cyber Safe

If you need any assistance with cyber security assistance, then please contact Neuways and we will help you where we can. Just get in touch with our team today.

[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]

Want to keep up with our blog?

Get our most valuable tips right inside your inbox every Friday!

Latest IT News & Insights
VPN
SonicWall VPNs under attack: What businesses need to know  
Cybercriminals are always adapting, and the latest surge in activity from the Akira ransomware group...
Read More
Ransomware on the rise
Ransomware on the rise: Meet Akira & Lynx 
Ransomware continues to be one of the most disruptive cyber threats facing businesses today. As defences...
Read More
What is Ransomware
Ransomware: What is it and how to stay protected 
You’ve probably seen the term “ransomware” pop up in the news more often over the past few years, and...
Read More
ring-doorbell
What to know about the supposed Ring doorbell security breach in May 2025
In July 2025, Ring users across social media platforms raised alarm bells after spotting what appeared...
Read More
Heading-12
Windows 10 support ends in 2025: What your business needs to know
Microsoft has officially announced that support for Windows 10 will end on 14th October 2025. If your...
Read More
browser
The hidden danger of browser extensions: Are your staff putting your business at risk?
Browser extensions represent a serious business risk Browser extensions are often seen as harmless add-ons,...
Read More
Legacy systems
Legacy systems: The silent security liability
When thinking about cyber security, it’s easy to focus on the latest threats: phishing, ransomware, or...
Read More
Captchas
CAPTCHAs: A security tool that can be used against you
We’re all used to CAPTCHAs, those little tests that make you pick out traffic lights or type in squiggly...
Read More
Neuways logo

Frequently Asked Questions

As a leading IT and technology provider, we offer three core services, all of which have additional add-ons. We offer Managed IT Support, Business Central implementation and consultation, as well as Managed Cyber Security. Call us on 01283 753333 if you are interested in any of our services.

Contact us

Support: 01283 753300

Business Development: 01283 753333

Purchasing: 01283 753322

Admin and Accounts: 01283 753311

Email: hello@neuways.com

Managed IT support is a comprehensive solution where an expert IT provider, like Neuways, handles your technology infrastructure. This includes proactive monitoring, maintenance, cyber security, and support.

Yes we do. Your business needs Cyber Security due to the increasing number of cyber threats that are affecting businesses in all industries. If your business has data and technology systems implemented, you will need Managed Cyber Security.

We can help you conduct Cyber Audits to assess whether your business would gain Cyber Essentials and Cyber Essentials Plus Certification. Our dedicated departments work with your team to assess how much work is required before you gain Cyber Essentials Plus certification. We will then provide advice and consultation on what aspects you need to change within your business before providing a quote on how we can assist your company become Cybersafe.

Yes we can. We have our own dedicated Microsoft Dynamics 365 Business Central teams who work to ensure that we can implement the right systems and solutions into your website that are absolute right for you. Our experienced business consultants have worked all over the world for organisations operating on a global scale. 

Exclaimer Pro is a dynamic email signature that helps clients to switch and change around email signatures so that clients are able to advertise different offers and brands to a variety of email recipients. Administrators can also manage user emails internally, meaning the user does not have to touch their own email signature.

We offer Managed Security Training to help employees spot email phishing attacks, spear phishing attacks and vishing attacks. We also help train clients on how to use the various pieces of software we provide to clients, like Exclaimer Pro, Business Central and Cybersafe software.

We are a Managed IT Support provider based in Derby, East Midlands. However, we cover so many areas including the whole of the UK, Europe, and America. We are always willing to travel and send our expert technicians to ensure you have the best experience. 

Got a question?

Reach out
& Connect

Name