This week’s roundup covers major cybersecurity developments, including the Log4j alert being described as a “known security non-finding,” U.S. Bancorp distancing itself from LockBit’s claims, and active credential exposure findings affecting AWS, GitHub, Stripe, OpenAI, and Telegram. It also highlights mobile banking malware expansion, confirmed breach impacts at Paylogix and Manchester Airports Group, Russian cyber training revelations, and new U.S. sanctions on Iranian cyber actors. #Log4j #U.S.Bancorp #LockBit #AWS #GitHub #Stripe #OpenAI #Telegram #Paylogix #Akira #ManchesterAirportsGroup #BaumanUniversity #APT28 #Sandworm #MOIS
Keypoints
- Log4j developers said the reported flaw was overblown and a known security non-finding.
- U.S. Bancorp said LockBit’s claims likely came from a fourth-party provider, not its own systems.
- Researchers found hundreds of active AWS keys and thousands of exposed credentials across public repositories.
- Mobile banking malware is targeting more than 800 apps across 44 EMEA countries.
- Paylogix, Manchester Airports Group, and Russian cyber training ties all featured in this week’s incidents.