---
title: "Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12, 2024] | DuoCircle"
description: "Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/"
---

Quick Answer

Cybersecurity news for the week of August 12, 2024\. Microsoft patched CVE-2024-38213, a Windows SmartScreen Mark-of-the-Web bypass exploited as a zero-day since March via WebDAV files. Maksim Silnikau, the alleged operator of Ransom Cartel and creator of the Reveton trojan, was extradited to the US and faces over 100 years if convicted. A Russian national was sentenced for an OTP and credential-theft operation that compromised 300,000 logins. The 3AM ransomware group claimed a breach of 464,000 Kootenai Health patient records. Researchers also flagged fake X (Twitter) alerts being used as clickbait to spread scams.

Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News \[August 12, 2024\]

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/08/Windows-SmartScreen-Exploited-Ransomware-Leader-Arrested-Russian-Hacker-Sentenced-–-Cybersecurity-News-August-12-2024.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Windows%20SmartScreen%20Exploited%2C%20Ransomware%20Leader%20Arrested%2C%20Russian%20Hacker%20Sentenced%2C%20Cybersecurity%20News%20%5BAugust%2012%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F&title=Windows%20SmartScreen%20Exploited%2C%20Ransomware%20Leader%20Arrested%2C%20Russian%20Hacker%20Sentenced%2C%20Cybersecurity%20News%20%5BAugust%2012%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Windows%20SmartScreen%20Exploited%2C%20Ransomware%20Leader%20Arrested%2C%20Russian%20Hacker%20Sentenced%2C%20Cybersecurity%20News%20%5BAugust%2012%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2024/08/spf-record-check-1.jpg) 

Here we are with [cybersecurity](/) latest with our news bulletin. This week, we’ll share all the info on the **Windows SmartScreen flaw**, the arrest of the Reveton ransomware cartel’s operator, the sentencing of a Russian cybercriminal who stole 300,000 login credentials, the details of the [3AM ransomware breach of Kootenai Health patient data](https://www.bleepingcomputer.com/news/security/3am-ransomware-stole-data-of-464-000-kootenai-health-patients/), and fake alerts on X being used as clickbait. Let’s take a look!

## Windows SmartScreen Flaw Exploited as Zero-Day Since March

Microsoft shared that threat actors were using a [MotW (Mark of the Web)](https://www.darkreading.com/cyberattacks-data-breaches/windows-mark-of-the-web-zero-days-patchless-exploit) security bypass vulnerability to exploit its **SmartScreen protection security** feature. 

The vulnerability ([CVE-2024-38213](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38213)) could be exploited by threat actors **remotely and needed interaction** at the user’s end. Redmond [shared details](https://redmondmag.com/Articles/2024/08/13/10-Zero-Day-Flaw-Fixes.aspx) of the exploit, highlighting that there was increased difficulty for the threat actors since they would need to send malicious files to users and convince them to open it. [Microsoft](/email-security/microsofts-security-services-heading-in-a-new-direction/) has now released a patch to fix the issue, but it was being exploited by [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) since March of this year. _The vulnerability was due to file results in a WebDAV that were being copied locally without the MotW protections_. 

There were also other attacks in March where the attackers **leveraged another vulnerability** (CVE-2024-21412), to deploy malicious payloads that were disguised as Apple iTunes, NVIDIA, and Notion installers. 

## Ransom Cartel and Reveton Ransomware Operator Arrested and Charged in the US

Maksim Silnikau, a Belarusian-Ukrainian national, was [arrested and extradited](https://web.archive.org/web/20240905040545/http://www.nationalcrimeagency.gov.uk/news/suspected-head-of-prolific-cybercrime-groups-arrested-and-extradited) to the US this week on charges of creating the Ransom Cartel operation and running malvertising operations. 

The threat actor has been known by many aliases like **Lansky, xxx, and J.P. Morgan** on different [hacking forums](https://www.securitymagazine.com/articles/100833-nearly-10-billion-stolen-passwords-were-leaked-on-a-hacker-forum). Along with Maksim, the US also charged his co-conspirators-Volodymyr Kadariya and Andrei Tarasov, who distributed [malware](/resources/malware-and-its-defense-mechanism) for many years to innocent individuals around the world and employed malvertising to trick victims. _The Ransom Cartel operation has been around since December 2021 and was created and administrated by Maksim, who offered it as a RaaS (Ransomware as a Service) model to threat actors and recruited attackers from Russian-speaking forums to participate in attacks with him_. All the ransomware payments were transferred via crypto mixers to avoid a money trail. But that’s not all. Maksim was also the creator of the Reveton trojan, which locked Windows users out of their systems until they [paid ransoms](https://www.cybersecuritydive.com/news/white-house-considers-ransom-payment-ban/649673/) via MoneyPak, PaySafeCard, or other digital payment methods. 

The threat actor is potentially facing a sentence of **over 100 years** if he is convicted on all charges, which include wire and computer fraud, computer abuse, access device fraud, and aggravated identity theft. 

## Russian Cybercriminal Sentenced to 40 Months for Selling 300,000 Stolen Credentials

In other news, a Russian national named ​Georgy Kavzharadze was sentenced to 40 months in prison for selling credentials of over 300,000 Slilpp accounts.

\_Slilpp was the largest online marketplace of stolen credentials before it was seized by law enforcement in June 202\_1\. The [US DoJ (Department of Justice)](https://en.wikipedia.org/wiki/United%5FStates%5FDepartment%5Fof%5FJustice) shared how Kavzharadze sold tons of [PII (Personally Identifiable Information)](https://www.ibm.com/topics/pii) and financial data on Slilpp. Kavzharadze worked on the portal from July 2016 to May 2021, where he listed over 626,100 stolen credentials for sale, many of which were linked to **$1.2 million** in fraud transactions. Kavzharadze’s Slilpp account also listed over 240,000 credentials for sale that other threat actors could purchase and use to steal funds from the victim’s online bank portals. 

The DoJ [charged](https://www.justice.gov/usao-dc/pr/russian-citizen-sentenced-40-months-selling-stolen-financial-information-criminal) **Kavzharadze on 24 August** 2021 for [bank fraud](https://www.cbsnews.com/losangeles/news/local-senior-sues-bank-after-losing-over-700k-to-bank-fraud/), access device fraud, and conspiracy to commit bank and wire fraud. He was extradited to the US and pleaded guilty. 

## 3AM Ransomware Breach Exposes Data of 464,000 Kootenai Health Patients

Kootenai Health [disclosed](https://www.kh.org/notice-of-data-security-incident/) a [data breach](/phishing-protection/the-terrible-price-small-businesses-pay-for-a-data-breach/) this week where the personal data of 464,000 patients was stolen by 3AM ransomware. 

_Kootenai Health is based in Idaho and is the largest hospital in the region_. The organization suffered a cyberattack back in March, which disrupted some **IT systems**. There was an ongoing investigation following the attack that revealed that threat actors were able to gain access to organizational systems in the last week of February 2024 and roamed the network for about ten days, making away with [sensitive patient data](https://www.ucl.ac.uk/news/2024/may/female-health-apps-misuse-highly-sensitive-data). Much patient data was stolen during the breach, including full names, birth dates, [SSNs (Social Security Numbers)](https://www.investopedia.com/terms/s/ssn.asp), government ID numbers, driver’s licenses, and medical records, including numbers, treatments, conditions, diagnoses, and [health insurance data](https://www.usnews.com/news/health-news/articles/2022-09-08/health-insurance-coverage-varies-broadly-by-race-income). Kootenai has made it clear that they are unaware of any misuse of the data that was stolen but would offer 1-2 years of identity protection services to its victims, depending on the data that was exposed. 

The 3AM ransomware gang claimed responsibility for the cyber attack and used its darknet portal to leak the stolen data. The **data consists of a 22 GB** archive that’s free, likely meaning that the hospital did not pay the ransom. 

[![Ransomware](https://media.mailhop.org/duocircle/images/2024/08/dkim-validation-2.jpg)](https://media.mailhop.org/duocircle/images/2024/08/dkim-validation-2.jpg)

## Fake X Alerts on Ukraine War and Earthquakes Used as Clickbait

X (formerly Twitter) has had tons of scams throughout the years, **especially in recent months**, but the scammers have started using the war in Ukraine to entice innocent users into clicking fake content warnings that take them to [malicious extensions](https://thehackernews.com/2022/11/this-malware-installs-malicious-browser.html) and adult websites. 

They are also [using posts](https://www.bleepingcomputer.com/news/security/fake-x-content-warnings-on-ukraine-war-earthquakes-used-as-clickbait/) about earthquake warnings in Japan. X is full of posts that are flagged with content warnings **containing new information** about the Ukrainian forces or warnings in Nankai Trough in Japan. _When users click on these posts to view the content, they are redirected through multiple websites, landing on scam or malicious websites at the end_. Many of these scam websites are adult sites, but plenty more lead to tech support scams, affiliate scams, or malicious browser extensions. X is displaying such warnings because it analyzes the content at the posted [URL (Uniform Resource Locator)](https://www.techtarget.com/searchnetworking/definition/URL) when the post is created. 

Much news shared on [social media](/email-security/simple-social-media-security-practices-your-business-should-adopt/) is false or misinterpreted, but scam artists have taken a liking to exploit the **curiosity of innocent individuals** and lead them to malicious websites/extensions. The best way to stay safe from such scams is to avoid clicking on such posts.

## Topics

cyber securityNewsUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Windows%20SmartScreen%20Exploited%2C%20Ransomware%20Leader%20Arrested%2C%20Russian%20Hacker%20Sentenced%2C%20Cybersecurity%20News%20%5BAugust%2012%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcybersecurity-news-update-week-34-of-2024%2F) Copy 

Related Articles

- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/01/spf-permerror.jpg)  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/01/email-smtp-service-7865.jpg)  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2025/03/phishing-protection-5643.jpg)  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)
- [ ![cybersecurity news](https://media.mailhop.org/duocircle/images/2026/03/email-smtp-service-6670.jpg)  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\] News ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

## Related Articles

[  News 6m  Microsoft Cybersecurity Transparency, Chrome Update Required, Google Calendar Phishing, Cybersecurity News \[December 23, 2024\]  Jan 2, 2025 ](/blog/announcements/cyber-security-news-update-week-1-of-2025/)[  News 6m  Trust Wallet Hack, Browser Extension Espionage, Unleash Protocol Loss, Cybersecurity News \[December 29, 2025\]  Jan 5, 2026 ](/blog/announcements/cyber-security-news-update-week-1-of-2026/)[  News 7m  Bybit’s $1.5B Loss, FatalRAT Hits APAC, GitVenom Targets Wallets,, Cybersecurity News \[February 24, 2025\]  Mar 3, 2025 ](/blog/announcements/cyber-security-news-update-week-10-of-2025/)[  News 6m  LastPass Users Phished, Amazon Down US, UK Cybersecurity Boost, Cybersecurity News \[March 02, 2026\]  Mar 9, 2026 ](/blog/announcements/cyber-security-news-update-week-10-of-2026/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12, 2024]","description":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/","datePublished":"2024-08-19T19:48:39.000Z","dateModified":"2025-05-08T13:27:54.000Z","dateCreated":"2024-08-19T19:48:39.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Updates","wordCount":1024,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-record-check-1.jpg","caption":"cybersecurity","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12, 2024]","item":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12, 2024]","description":"Windows SmartScreen Exploited, Ransomware Leader Arrested, Russian Hacker Sentenced, Cybersecurity News [August 12.","url":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/","datePublished":"2024-08-19T19:48:39.000Z","dateModified":"2025-05-08T13:27:54.000Z","dateCreated":"2024-08-19T19:48:39.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cybersecurity-news-update-week-34-of-2024/"},"articleSection":"announcements","keywords":"cyber security, News, Updates","wordCount":1024,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-record-check-1.jpg","caption":"cybersecurity","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
