Security
Shell latest victim in Cl0p MOVEit hacking spree
Shell Global has confirmed to Cybernews that some of their systems were impacted by the latest spree of cyber attacks involving a flaw in the MOVEit file transfer system.
Read more about Shell latest victim in Cl0p MOVEit hacking spree
US gov agencies slammed by MOVEit hack
Multiple US government agencies have been breached by the Cl0p ransom gang’s global hacking campaign exploiting a zero-day bug in the MOVEit file transfer platform.
Read more about US gov agencies slammed by MOVEit hack
Workers regularly post sensitive data into ChatGPT
A new study found 15% of employees regularly post company data into ChatGPT – and over a quarter of that data is considered sensitive information – putting their employers at risk of a security breach.
Read more about Workers regularly post sensitive data into ChatGPT
3CX data exposed, third-party to blame
A third-party vendor of 3CX, a popular Voice over Internet Protocol (VoIP) comms provider, left an open server and exposed sensitive 3CX data. The issue went under the company’s radar, even though it was recently targeted by North Korean hackers.
Read more about 3CX data exposed, third-party to blame
BreachForums is back – for real this time
The cybercrime marketplace BreachForums appears to have finally been resurrected with help from its former second in command – as the federal case against its former founder heats up. But will fears of FBI entrapment keep users away?
Read more about BreachForums is back – for real this time
Temp Mail leaves systems wide open
Temp Mail, a popular disposable email provider, left its systems publicly open for over three months, risking potential breaches and large-scale malware spread.
Read more about Temp Mail leaves systems wide open
UPS latest Anonymous Sudan target, Microsoft time-out
Following a week-long attack on Microsoft, the pro-Russian hacktivist gang Anonymous Sudan has claimed global shipping giant United Parcel Service (UPS) as the latest target in an ongoing campaign against the US.
Read more about UPS latest Anonymous Sudan target, Microsoft time-out
Unveiling the Balada injector: a malware epidemic in WordPress
Learn the shocking truth behind the Balada Injector campaign and find out how to protect your organization from this relentless viral invasion.
Read more about Unveiling the Balada injector: a malware epidemic in WordPress
Hackers have been sitting on MOVEit bug for 2 years
Cl0p hackers have been sitting on a zero-day vulnerability in the MOVEit Transfer application for two years, cybersecurity analyst Kroll claims.
Read more about Hackers have been sitting on MOVEit bug for 2 years
Prestigious Russian university puts student data at risk
Bauman University, the second oldest educational institution in Russia, had its internal system exposed, putting student data at risk
Read more about Prestigious Russian university puts student data at risk
Pflegia leaks sensitive job seeker info
Pflegia, a German healthcare recruitment platform, has exposed hundreds of thousands of files with sensitive user data such as names, home addresses, and emails.
Read more about Pflegia leaks sensitive job seeker info
Microsoft Outlook hackers threaten ChatGPT next
The pro-Russian hackers – who claim to have taken down Microsoft Outlook in an ongoing targeted campaign against the US – warn OpenAI’s ChatGPT is the next victim on their list.
Read more about Microsoft Outlook hackers threaten ChatGPT next
NASA website flaw jeopardizes astrobiology fans
A flaw in NASA’s website dedicated to astrobiology could have tricked users into visiting malicious websites by disguising a dangerous URL with NASA’s name.
Read more about NASA website flaw jeopardizes astrobiology fans
Microsoft Outlook down after reported hack
Microsoft Outlook is down for thousands of American users after pro-Russian hacktivists Anonymous Sudan claim a new campaign to disrupt US companies and infrastructure.
Read more about Microsoft Outlook down after reported hack
Apple flaw left iTunes users vulnerable on Microsoft
Apple iTunes had a vulnerability when used on Microsoft Windows that could have allowed threat actors to hijack an affected device’s operating system.
Read more about Apple flaw left iTunes users vulnerable on Microsoft
California-based workforce platform leaks drivers licenses and medical records
Prosperix, a US-based workforce management platform, has leaked nearly 250,000 files exposing job seekers’ sensitive data.
Read more about California-based workforce platform leaks drivers licenses and medical records
SAS faces new $3m ransom demand to halt ongoing attack
Anonymous Sudan, the hacktivist gang targeting SAS Airlines for five days now, has upped their latest ransom demand from $175,000 to a whopping $3 million.
Read more about SAS faces new $3m ransom demand to halt ongoing attack
Swiss real estate agency fails to put a password on its systems
Neho, a Switzerland-based real estate agency, leaked credentials recently, potentially allowing threat actors to prey on sensitive data about the company and its clients.
Read more about Swiss real estate agency fails to put a password on its systems
FBI: man steals $600K in sports betting website hack
An 18-year-old Wisconsin is busted for hacking a fantasy sports betting website, stealing over half a million dollars, and boasting how much he enjoyed it, the FBI said.
Read more about FBI: man steals $600K in sports betting website hack
China positioned to hack US railways and pipelines
The US State Department warns that China is capable of large-scale cyberattacks targeting critical US infrastructure, including railway systems and fuel pipelines.
Read more about China positioned to hack US railways and pipelines