Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    POCO F7 Launches in Malaysia with Snapdragon 8s Gen 4, Flagship Power, Bold Design, and Early Bird Deals

    Next Galaxy Z foldables to be announced on 9 July

    Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025

      The internet thinks this video from Gaza is AI. Here’s how we proved it isn’t.

      May 30, 2025

      Nvidia CEO hails Trump’s plan to rescind some export curbs on AI chips to China

      May 22, 2025

      AI poses a bigger threat to women’s work, than men’s, report says

      May 21, 2025
    • Business

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025

      Cookie-Bite attack PoC uses Chrome extension to steal session tokens

      April 22, 2025
    • Crypto

      How Plume Drove a 100% Jump in RWA Holders to Overtake Ethereum

      June 24, 2025

      $400 Million SHIB Supply Zone Might Prevent Shiba Inu From Ending Downtrend

      June 24, 2025

      Turkey Overhauls Crypto Regulations to Stop Money Laundering

      June 24, 2025

      What Crypto Whales Are Buying After Israel-Iran Ceasefire Announcement

      June 24, 2025

      Midnight Network Tokenomics Introduces Radically Accessible and Fair Token Distribution Model 

      June 24, 2025
    • Technology

      Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

      June 25, 2025

      Windows 10 gets an extra year of free security updates (with a catch)

      June 25, 2025

      Philps Hue smart lights are already pricey. They’re about to get pricier

      June 25, 2025

      Amazon’s Fire TV Stick 4K drops to its best price of the year

      June 25, 2025

      The state of DTC marketing in 2025: How brands and agencies are leveraging data and automation to fuel ROI

      June 25, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Shop Now
    Tech AI Verse
    You are at:Home»Software and Apps»A brief history of mass hacks
    Software and Apps

    A brief history of mass hacks

    TechAiVerseBy TechAiVerseMarch 12, 2025No Comments7 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    A brief history of mass hacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    A brief history of mass hacks

    Enterprise cybersecurity tools, such as routers, firewalls, and VPNs, exist to protect corporate networks from intruders and malicious hackers, something that is particularly important in today’s age of widespread remote and hybrid working. 

    But while pitched as tools that help organizations stay safe from outside threats, many of these products have time and again been found to contain software bugs that allow malicious hackers to compromise the very networks these products were designed to protect.

    These bugs have been blamed for an explosion in mass-hacking campaigns in recent years, whereby malicious hackers abuse these often easy-to-exploit security flaws to break into the networks of thousands of organizations and steal sensitive company data.

    We’ve put together a brief history of mass hacks, and will update this article when more inevitably come to light. 

    One of the first mass hacks of this decade saw a notorious ransomware crew exploit a vulnerability in Fortra’s GoAnywhere managed file transfer software, a product used by companies to share large files and sensitive datasets over the internet. The prolific Clop ransomware gang exploited the bug to compromise more than 130 organizations and steal the personal data of millions of individuals. The vulnerability was exploited as a zero-day, which means Fortra had no time to fix it before it came under attack. Clop later published data stolen from victim organizations who did not pay the hackers a ransom. Hitachi Energy, security giant Rubrik, and Florida-based health tech organization NationBenefits — which saw the data of more than three million members stolen in the attack — reported intrusions resulting from the buggy software.

    May 2023: MOVEit flaws allowed theft of 60 million people’s data

    The mass hack of MOVEit remains one of the largest mass breaches of all time, with hackers abusing a flaw in another widely used file transfer software, developed by Progress Software, to steal data from several thousand organizations. The attacks were again claimed by the Clop ransomware group, which exploited the MOVEit vulnerability to steal data on more than 60 million individuals, according to cybersecurity company Emsisoft. U.S. government services contracting giant Maximus was the largest victim of the MOVEit breach after confirming that hackers accessed the protected health information of as many as 11 million individuals.

    October 2023: Cisco zero-day exposed thousands of routers to takeovers

    The mass hacks continued into the second half of 2023, with hackers exploiting an unpatched zero-day vulnerability in Cisco’s networking software throughout October to compromise tens of thousands of devices that rely on the software, such as enterprise switches, wireless controllers, access points, and industrial routers. The bug granted attackers “full control of the compromised device.” While Cisco didn’t confirm how many customers had been affected by the flaw, Censys, a search engine for internet-connected devices and assets, says it had observed almost 42,000 compromised devices exposed to the internet.

    Image Credits:Ramon Costa/SOPA Images/LightRocket / Getty Images

    November 2023: Ransomware gang exploits Citrix bug

    Citrix NetScaler, which large enterprises and governments use for application delivery and VPN connectivity, became the latest mass-hack target just one month later in November 2023. The bug, known as “CitrixBleed,” allowed the Russia-linked ransomware gang LockBit to extract sensitive information from affected NetScaler systems at big-name firms. Aerospace giant Boeing, law firm Allen & Overy, and the Industrial and Commercial Bank of China were claimed as victims. 

    January 2024: China hackers exploited Ivanti VPN bugs to breach companies

    Ivanti became a name synonymous with mass hacks after Chinese state-backed hackers began mass-exploiting two critical zero-day vulnerabilities in Ivanti’s corporate Connect Secure VPN appliance. While Ivanti said at the time that only a limited number of customers had been affected, cybersecurity company Volexity found that more than 1,700 Ivanti appliances worldwide were exploited, affecting organizations in the aerospace, banking, defense, and telecoms industries. U.S. government agencies with affected Ivanti systems in operation were ordered to immediately take the systems out of service. Exploitation of these vulnerabilities has since been linked to the China-backed espionage group known as Salt Typhoon, which more recently was found to have hacked into the networks of at least nine U.S. telecommunications companies. 

    In February 2024, hackers took aim at two “easy-to-exploit” vulnerabilities in ConnectWise ScreenConnect, a popular remote access tool that allows IT and support technicians to remotely provide technical assistance directly on customer systems. Cybersecurity giant Mandiant said at the time its researchers had observed “identified mass exploitation” of the two flaws, which were being abused by various threat actors to deploy password stealers, backdoors, and in some cases, ransomware.

    Hackers hit Ivanti customers (again) with fresh bugs

    Ivanti made headlines again — also in February 2024 — when attackers exploited another vulnerability in its widely used enterprise VPN appliance to hack its customers. The Shadowserver Foundation, a nonprofit organization that scans and monitors the internet for exploitation, told TechCrunch at the time it had observed more than 630 unique IP addresses attempting to exploit the server-side flaw, which allows attackers to gain access to devices and systems ostensibly protected by the vulnerable Ivanti appliances.

    November 2024: Palo Alto firewall bugs put thousands of firms at risk 

    Later in 2024, hackers compromised potentially thousands of organizations by exploiting two zero-day vulnerabilities in software made by cybersecurity giant Palo Alto Networks and used by customers around the world. The vulnerabilities in PAN-OS, the operating system that runs on all of Palo Alto’s next-generation firewalls, allowed attackers to compromise and exfiltrate sensitive data from corporate networks. According to researchers at security firm watchTowr Labs, who reverse-engineered Palo Alto’s patches, the flaws resulted from basic mistakes in the development process. 

    December 2024: Clop compromises Cleo customers

    In December 2024, the Clop ransomware gang targeted yet another popular file transfer technology to launch a fresh wave of mass hacks. This time, the gang exploited flaws in tools made by Cleo Software, an Illinois-based maker of enterprise software, to target dozens of the company’s customers. By early January 2025, Clop listed almost 60 Cleo companies that it had allegedly compromised, including U.S. supply chain software giant Blue Yonder and German manufacturing giant Covestro. By the end of January, Clop added another 50 alleged Cleo mass-hack victims to its dark web leak site. 

    Image Credits:Alex Kraus/Bloomberg / Getty Images

    January 2025: New year, new Ivanti bugs under attack

    The new year began with Ivanti falling victim to hackers — yet again. The U.S. software giant alerted customers in early-January 2025 that hackers were exploiting a new zero-day vulnerability in its enterprise VPN appliance to breach the networks of its corporate customers. Ivanti said that a “limited number” of customers were affected, but declined to say how many. The Shadowserver Foundation says its data shows hundreds of backdoored customer systems. 

    Fortinet firewall bugs exploited since December

    Just days after Ivanti’s latest bug was disclosed, Fortinet confirmed that hackers had separately been exploiting a vulnerability in its firewalls to break into the networks of its corporate and enterprise customers. The flaw, which affects the cybersecurity company’s FortiGate firewalls, had been “mass exploited” as a zero-day bug since at least December 2024, according to security research firms. Fortinet declined to say how many customers were affected, but security research firms investigating the attacks observed intrusions affecting “tens” of affected devices.

    SonicWall says hackers are remotely hacking customers

    January 2025 remained a busy month for hackers exploiting bugs in enterprise security software. SonicWall said in late January that as-yet-unidentified hackers are exploiting a newly discovered vulnerability in one of its enterprise products to break into its customer networks. The vulnerability, which affects SonicWall’s SMA1000 remote access appliance, was discovered by Microsoft’s threat researchers and is “confirmed as being actively exploited in the wild,” according to SonicWall. The company hasn’t said how many of its customers have been affected or if the company has the technical ability to confirm, but with more than 2,300 devices exposed to the internet, this bug has the potential to be the latest mass hack of 2025.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleOpen source licenses: Everything you need to know
    Next Article Aiming to accelerate product design with AI, Trace.Space raises a seed round
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Google will stop supporting early Nest thermostats on October 25

    April 27, 2025

    Ex-Meta engineer raises $14M for Lace AI, a revenue generation software startup

    April 22, 2025

    Figma ignores the fear, files paperwork for an IPO

    April 16, 2025
    Leave A Reply Cancel Reply

    Top Posts

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202525 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202521 Views

    Rsync replaced with openrsync on macOS Sequoia

    April 7, 202515 Views

    Arizona moves to ban AI use in reviewing medical claims

    March 12, 202511 Views
    Don't Miss
    Gadgets June 25, 2025

    POCO F7 Launches in Malaysia with Snapdragon 8s Gen 4, Flagship Power, Bold Design, and Early Bird Deals

    POCO F7 Launches in Malaysia with Snapdragon 8s Gen 4, Flagship Power, Bold Design, and…

    Next Galaxy Z foldables to be announced on 9 July

    Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

    Windows 10 gets an extra year of free security updates (with a catch)

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    POCO F7 Launches in Malaysia with Snapdragon 8s Gen 4, Flagship Power, Bold Design, and Early Bird Deals

    June 25, 20250 Views

    Next Galaxy Z foldables to be announced on 9 July

    June 25, 20250 Views

    Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

    June 25, 20250 Views
    Most Popular

    Ethereum must hold $2,000 support or risk dropping to $1,850 – Here’s why

    March 12, 20250 Views

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.