Tire manufacturer launches a comprehensive investigation after a limited cyber incident affects operations at multiple plants. Bridgestone Americas has confirmed that a cyberattack has impacted manufacturing facilities across North America, including two plants in Aiken County, South Carolina. The tire manufacturing giant disclosed the cyber incident on Thursday, stating that it has launched a comprehensive […]
Tire manufacturing giant Bridgestone Americas has confirmed it is responding to a cyberattack that disrupted operations at some of its manufacturing facilities this week.
In a statement, the company asserted that the incident has been contained and that business is now operating normally, though a full investigation into the breach is ongoing.
Bridgestone acknowledged that it identified a “limited cyber incident” that impacted its production capabilities. “We have launched a comprehensive forensic analysis and believe we contained the incident early,” the company stated.
The disruption directly impacted plant workers. At facilities including the company’s two plants in Aiken County, South Carolina, employees whose normal duties were halted were reportedly given a choice: stay on-site to perform preventive maintenance and receive a full day’s pay, or opt to go home without pay.
While Bridgestone’s official statements characterize the incident as “limited,” reports from local officials suggest a potentially more widespread event. Pierre-Luc Bellerose, Mayor of Joliette, Quebec, where Bridgestone operates a large plant, told local media that he believes the attack affected all of the company’s factories in North America.
Mayor Bellerose, who contacted company executives after being alerted to the situation, noted that an internal memo was sent to employees. The Joliette plant alone employs an estimated 1,400 people.
A primary concern in any cyberattack is data security. On this front, Bridgestone has moved to reassure its stakeholders, stating, “it doesn’t believe any customer data was affected in the incident.” Mayor Bellerose echoed this sentiment after his conversations with the company. “No information has been compromised, either for employees or customers,” he said. “I’ve been reassured on that front.”
This event marks the second major cybersecurity challenge for Bridgestone in recent years. The company suffered a significant ransomware attack in 2022 that also forced production to a halt and was attributed to the LockBit hacking group.
As the forensic investigation continues, the exact nature of this new cyber incident and the full scope of its impact remain under review. In a written statement, Bridgestone Americas reiterated that it is “continuing its investigation” while maintaining that business is proceeding as usual.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
A sophisticated threat actor known as NoisyBear has emerged as a significant concern for Kazakhstan’s energy sector, employing advanced tactics to infiltrate critical infrastructure through weaponized ZIP files and PowerShell-based attack chains.
This newly identified group has been orchestrating targeted campaigns against KazMunaiGas (KMG), the country’s national oil and gas company, using highly crafted phishing emails that mimic legitimate internal communications about salary schedules and policy updates.
The attack methodology demonstrates remarkable precision in social engineering, with threat actors compromising legitimate business email accounts within KazMunaiGas to lend authenticity to their malicious communications.
These emails contain ZIP attachments disguised as urgent HR-related documents, creating a false sense of legitimacy that encourages employee interaction.
The campaign’s sophistication extends beyond simple phishing, incorporating multi-stage payload delivery systems that leverage trusted system binaries and PowerShell execution environments to maintain stealth throughout the infection process.
Seqrite researchers identified this threat group’s activities beginning in April 2025, with active campaigns intensifying throughout May 2025.
The researchers noted that NoisyBear’s operational patterns suggest Russian origins, evidenced by Russian language comments within malicious code, utilization of sanctioned hosting services, and targeting patterns consistent with geopolitical interests in Central Asian energy resources.
Infection Chain (Source – Seqrite)
The group’s infrastructure analysis reveals connections to Aeza Group LLC, a sanctioned hosting provider, indicating deliberate attempts to operate within jurisdictions that complicate attribution and takedown efforts.
The malware’s impact extends beyond simple data theft, incorporating advanced persistence mechanisms and defense evasion techniques that allow prolonged network access.
Victims face potential exposure of sensitive corporate communications, strategic planning documents, and operational data critical to Kazakhstan’s energy infrastructure.
The campaign’s focus on energy sector entities raises concerns about potential disruption to critical national infrastructure and economic stability.
Infection Mechanism and Technical Analysis
The NoisyBear infection chain begins with malicious ZIP files containing three critical components: a decoy document bearing the official KazMunaiGas logo, a README.txt file providing execution instructions, and a weaponized LNK file named “График зарплат.lnk” (Salary Schedule.lnk).
The malicious shortcut file employs PowerShell as a Living Off The Land Binary (LOLBIN) to execute sophisticated download operations.
Upon execution, the LNK file initiates a PowerShell command that retrieves a malicious batch script named “123.bat” from the remote server “77.239.125.41:8443”.
The downloaded script is strategically placed in the C:\Users\Public directory, a location chosen for its accessibility and reduced security scrutiny.
The batch script serves as a secondary loader, downloading PowerShell scripts dubbed “DOWNSHELL” by researchers.
These loaders demonstrate advanced Anti-Malware Scan Interface (AMSI) bypass techniques, using reflection to manipulate the System.Management.Automation.AmsiUtils class.
The malware sets the “amsiInitiFailed” flag to convince PowerShell that AMSI initialization has failed, effectively disabling real-time scanning capabilities for subsequent malicious operations.
The final payload involves process injection techniques targeting explorer.exe, utilizing classic CreateRemoteThread injection methods.
The malware employs OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread API calls to inject Meterpreter reverse shell capabilities, establishing persistent backdoor access for data exfiltration and remote command execution.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
The threat actor known as NoisyBear has launched a sophisticated cyber-espionage effort called Operation BarrelFire, using specially designed phishing lures that imitate internal correspondence to target Kazakhstan’s energy sector, particularly workers of the state oil and gas major KazMunaiGas. Security researchers at Seqrite Labs first observed the campaign in April 2025 and noted its rapid […]
ESET security researchers have uncovered a sophisticated cyber threat campaign targeting Windows servers across multiple countries, with attackers deploying custom malware tools designed for both remote access and search engine manipulation. Cybersecurity experts at ESET have identified a previously unknown threat group dubbed GhostRedirector, which has successfully compromised at least 65 Windows servers primarily located in […]
Wilmington, United States, September4th, 2025, CyberNewsWire: Veteran email security leader to expand MSP and VAR partnerships and accelerate DMARC adoption. Sendmarc today announced the appointment of Rob Bowker as North American Region Lead. Bowker will oversee regional expansion with a focus on growing the Managed Service Provider (MSP) partner community, developing strategic Value-Added Reseller (VAR) […]
Wilmington, United States, September4th, 2025, CyberNewsWire: Veteran email security leader to expand MSP and VAR partnerships and accelerate DMARC adoption.
Sendmarc today announced the appointment of Rob Bowker as North American Region Lead.
Bowker will oversee regional expansion with a focus on growing the Managed Service Provider (MSP) partner community, developing strategic Value-Added Reseller (VAR) partnerships, and broadening the enterprise customer base.
Bowker brings more than two decades of experience in email infrastructure, deliverability, and security.
He has helped organizations implement and scale Domain-based Message Authentication, Reporting and Conformance (DMARC), Sender Policy Framework (SPF), and DomainKeys Identified Mail (DKIM) to protect email ecosystems and improve deliverability.
In his new role, Bowker will lead Sendmarc’s North American growth by forging partner-led routes to market and accelerating DMARC adoption across enterprise and mid-market organizations, while empowering MSPs with tools to protect small and medium-sized businesses (SMBs).
He will also expand the regional team to execute the company’s partner-first strategy.
“What excites me most about Sendmarc is our ability to pair an enterprise-class platform with a globally distributed team of experts. Customers don’t just get the best DMARC platform – they get support that spans time zones, cultures, and perspectives. I’m looking forward to helping Sendmarc accelerate growth across North America, working alongside MSPs, resellers, and enterprises to strengthen email security where it’s needed most,” said Bowker.
“Rob’s knowledge of the email and DMARC landscape and his ability to turn strategy into execution make him an invaluable leader for our North American operations,” said Jason Roos, Chief Sales Officer at Sendmarc.
“We’re excited to see the impact he’ll make as he continues building strong relationships with our partners and customers.”
About Sendmarc
Sendmarc is a global leader in safeguarding email communications through DMARC. Built with a partner-first approach, its platform empowers MSPs and VARs to deliver trusted protection against impersonation, phishing, and other email-based threats.
In addition to preventing fraud, Sendmarc improves email deliverability, ensuring legitimate business communications reach their intended recipients.
Trusted by partners worldwide, Sendmarc provides the tools and expertise needed to help customers achieve full DMARC compliance quickly and effectively.
A newly identified hacking group, dubbed “GhostRedirector” by cybersecurity researchers, has compromised at least 65 Windows servers across the globe, deploying custom malware designed to manipulate search engine results for financial gain.
According to a new report from ESET, the threat actor utilizes a malicious module for Microsoft’s Internet Information Services (IIS) to conduct a sophisticated SEO fraud scheme, primarily benefiting gambling websites.
The attacks, which have been active since at least August 2024, employ two previously undocumented custom tools: a passive C++ backdoor named “Rungan” and a malicious native IIS module called “Gamshen.”
While Rungan provides the attackers with the ability to execute commands on a compromised server, Gamshen is the core of the operation, designed to provide “SEO fraud as-a-service.”
GhostRedirector Hacks Windows Servers
Researchers explain that Gamshen functions by intercepting web traffic on the infected server. The module is specifically configured to activate only when it detects a request from Google’s web crawler, Googlebot.
For regular visitors, the website functions normally. However, when Googlebot scans the site, Gamshen modifies the server’s response, injecting data from its own command-and-control server.
GhostRedirector Hackers Compromise Windows Servers
This technique allows the attackers to create artificial backlinks and use other manipulative SEO tactics, effectively hijacking the compromised website’s reputation to boost the page ranking of a target website.
ESET believes the primary beneficiaries of this scheme are various gambling websites targeting Portuguese-speaking users. ESET researchers have attributed the campaign with medium confidence to a previously unknown, China-aligned threat actor.
This assessment is based on several factors, including the use of a code-signing certificate issued to a Chinese company, hardcoded Chinese language strings within the malware samples, and a password containing the Chinese word “huang” (yellow) used for rogue user accounts.
The victimology indicates an opportunistic approach rather than a targeted campaign against a specific industry.
Compromised servers span sectors such as healthcare, retail, transportation, education, and technology, with the majority located in Brazil, Thailand, and Vietnam.
Additional victims were identified in the United States, Peru, Canada, and parts of Europe and Asia.
GhostRedirector Hackers Compromise Windows Servers
GhostRedirector’s attack chain begins with what is believed to be an SQL injection vulnerability for initial access. Once inside, the attackers use PowerShell or CertUtil to download their arsenal from a staging server.
To gain full control, they employ publicly known privilege escalation exploits like “EfsPotato” and “BadPotato” to create new administrator-level user accounts on the server.
These rogue accounts provide persistent access, ensuring the attackers can maintain control even if their primary backdoors are discovered and removed.
The group’s toolkit also includes other custom utilities, such as “Zunput,” a tool that scans the server for active websites and drops multiple webshells to provide alternative methods of remote access.
The shared code libraries and infrastructure across these tools allowed ESET to cluster the activity and attribute it to a single group.
While the immediate impact on website visitors is minimal, participation in the SEO fraud scheme can severely damage the compromised host’s reputation by associating it with black-hat SEO tactics.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Armis Labs has uncovered ten critical security flaws collectively named “Frostbyte10” in Copeland’s E2 and E3 building management controllers. These devices, which handle refrigeration, HVAC, lighting, and other essential functions, could allow remote attackers to execute code, change settings, disable systems, or steal sensitive data. A firmware update is available now, and affected organizations are […]
A new cyber-attack, dubbed “Grokking,” is exploiting features on the social media platform X to spread malicious links on a massive scale.
Scammers are manipulating the platform’s advertising system and its generative AI, Grok, to bypass security measures and amplify harmful domains. This technique turns X’s own tools into unwilling accomplices in a widespread malvertising scheme.
According to GuardioSecurity researcher Nati Tal, the attack begins with malware promoting “video card” posts, which often use explicit or sensational “adult” content to lure users.
While X’s policies aim to combat malvertising by disallowing links in promoted content, these attackers have found a critical loophole.
The malicious link is not placed in the main body of the post but is instead embedded in the small “From:” field located beneath the video player.
X’s automated security scans seem to miss this area. As a result, posts can spread widely and get anywhere from 100,000 to over 5 million paid impressions.
The second stage of the attack leverages the platform’s AI assistant, Grok. Curious users, seeing the often anonymous and intriguing videos, frequently turn to Grok to ask for the source.
In its effort to provide a helpful answer, the AI scans the post for information and extracts the domain name from the “From:” field.
Grok then presents this malicious link directly to the user in its reply. For instance, when asked about a video’s origin, Grok has been observed responding with links to suspicious domains, Nati Tal said.
This process effectively “Grokks” the malicious link, not only delivering it to inquisitive users but also amplifying its visibility and perceived legitimacy.
By having the platform’s own AI reference the domain, the scammers may benefit from enhanced SEO and a strengthened reputation for their harmful sites, making them seem more trustworthy to unsuspecting users.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.