Security
Hacker sets up Tor-based online shop to sell access to firms
A new threat actor has started selling access to major companies worldwide. What makes Br0k3r stand out, however, is that it’s one of the first to trade access through its own website.
Read more about Hacker sets up Tor-based online shop to sell access to firms
Who is 8BASE? A deep dive into the "newish" ransom gang
A new ransomware group – known as 8BASE – is already making waves this summer following a record number of victims named in May. Cybernews takes you on a deep dive into what we know about the gang so far.
Read more about Who is 8BASE? A deep dive into the "newish" ransom gang
Top 5 cyber threat actors of 2023
Come with us as we peel back the digital curtain, uncovering the operations, techniques, and impact of five highly active and clandestine groups causing significant disruptions across the cyber landscape.
Read more about Top 5 cyber threat actors of 2023
Clop names PWC, Ernst & Young, and Sony in MOVEit hack
The Cl0p ransom gang has released the names of four new victims in the MOVEit hacking spree – including multi-media conglomerate Sony, and two major accounting firms, PricewaterhouseCoopers (PWC) and Ernst & Young (EY).
Read more about Clop names PWC, Ernst & Young, and Sony in MOVEit hack
Google pledges $20M to expand free cybersecurity clinics across US
Google is pledging $20 million to open more hands-on cybersecurity clinics across the US in an effort to help plug the nation’s cybersecurity workforce gap and stay ahead of evolving threats.
Read more about Google pledges $20M to expand free cybersecurity clinics across US
Global development corp IFC hacked near White House
The Russian-allied hacktivist gangs Killnet and Anonymous Sudan have claimed another major financial institution — the International Finance Corporation (IFC) headquartered in Washington DC.
Read more about Global development corp IFC hacked near White House
Minecraft server host Shockbyte puts players at risk
Shockbyte, one of Minecraft’s largest server hosting providers, left a misconfiguration on its systems exposing it to threat actors that could potentially have manipulated Minecraft server code.
Read more about Minecraft server host Shockbyte puts players at risk
Honda ecommerce platform vulnerability: a walkthrough
Honda was exposed to a critical security risk due to a vulnerability in its API. How did the exploit work?
Read more about Honda ecommerce platform vulnerability: a walkthrough
DoJ creates new National Security Cyber Section
The US National Security Division (NSD) now has its own Cyber Section, created so the agency can better respond to highly technical cyber threats.
Read more about DoJ creates new National Security Cyber Section
Compromised ChatGPT accounts are for sale on dark web
Over 100,000 ChatGPT credentials are currently being traded on the dark market. Given that employees increasingly rely on AI to boost productivity, the compromised credentials could lead threat actors to a treasure trove of data.
Read more about Compromised ChatGPT accounts are for sale on dark web
Square Yards data leak: passports, financial data exposed
India’s largest real estate platform has exposed nearly 350M files, including customer and employee passports and financial documents.
Read more about Square Yards data leak: passports, financial data exposed
Third MOVEit flaw identified by CISA, patch now
A new security advisory is warning organizations to immediately patch a third critical vulnerability found in the MOVEit file transfer system.
Read more about Third MOVEit flaw identified by CISA, patch now
Darknet Parliament is now a thing
The newly coined term “Darknet Parliament” has become the latest catchphrase among cybercriminals trying to prove their clout – and security insiders are loving it.
Read more about Darknet Parliament is now a thing
Swiss Financial Center knocked offline by Russian hackers
The pro-Russian hacker group responsible for a string of attacks against Switzerland's critical infrastructure this week has now hit the website of the Geneva financial center.
Read more about Swiss Financial Center knocked offline by Russian hackers
Shell latest victim in Cl0p MOVEit hacking spree
Shell Global has confirmed to Cybernews that some of their systems were impacted by the latest spree of cyber attacks involving a flaw in the MOVEit file transfer system.
Read more about Shell latest victim in Cl0p MOVEit hacking spree
US gov agencies slammed by MOVEit hack
Multiple US government agencies have been breached by the Cl0p ransom gang’s global hacking campaign exploiting a zero-day bug in the MOVEit file transfer platform.
Read more about US gov agencies slammed by MOVEit hack
Workers regularly post sensitive data into ChatGPT
A new study found 15% of employees regularly post company data into ChatGPT – and over a quarter of that data is considered sensitive information – putting their employers at risk of a security breach.
Read more about Workers regularly post sensitive data into ChatGPT
3CX data exposed, third-party to blame
A third-party vendor of 3CX, a popular Voice over Internet Protocol (VoIP) comms provider, left an open server and exposed sensitive 3CX data. The issue went under the company’s radar, even though it was recently targeted by North Korean hackers.
Read more about 3CX data exposed, third-party to blame
BreachForums is back – for real this time
The cybercrime marketplace BreachForums appears to have finally been resurrected with help from its former second in command – as the federal case against its former founder heats up. But will fears of FBI entrapment keep users away?
Read more about BreachForums is back – for real this time
Temp Mail leaves systems wide open
Temp Mail, a popular disposable email provider, left its systems publicly open for over three months, risking potential breaches and large-scale malware spread.
Read more about Temp Mail leaves systems wide open