Category: Uncategorized
-
Misconfigured Firebase Instances Expose 125 Million User Records Ionut Arghire
A weakness in a Firebase implementation allowed researchers to gain access to names, phone numbers, email addresses, plaintext passwords, confidential messages, and more. The post Misconfigured Firebase Instances Expose 125 Million User Records appeared first on SecurityWeek. Read More
-
Mintlify Data Breach Leads to Exposure of Customer GitHub Tokens Ionut Arghire
Mintlify announces vulnerability disclosure program after a data breach exposed 91 customer GitHub tokens. The post Mintlify Data Breach Leads to Exposure of Customer GitHub Tokens appeared first on SecurityWeek. Read More
-
Aiohttp Vulnerability in Attacker Crosshairs Eduard Kovacs
A recently patched Aiohttp vulnerability tracked as CVE-2024-23334 is being targeted by threat actors, including by a ransomware group. The post Aiohttp Vulnerability in Attacker Crosshairs appeared first on SecurityWeek. Read More
-

New Phishing Attack Uses Clever Microsoft Office Trick to Deploy NetSupport RAT [email protected] (The Hacker News)
A new phishing campaign is targeting U.S. organizations with the intent to deploy a remote access trojan called NetSupport RAT. Israeli cybersecurity company Perception Point is tracking the activity under the moniker Operation PhantomBlu. “The PhantomBlu operation introduces a nuanced exploitation method, diverging from NetSupport RAT’s typical delivery mechanism by leveraging OLE (ObjectRead More
-

E-Root Marketplace Admin Sentenced to 42 Months for Selling 350K Stolen Credentials [email protected] (The Hacker News)
A 31-year-old Moldovan national has been sentenced to 42 months in prison in the U.S. for operating an illicit marketplace called E-Root Marketplace that offered for sale hundreds of thousands of compromised credentials, the Department of Justice (DoJ) announced. Sandu Boris Diaconu was charged with conspiracy to commit access device and computer fraud and possession…
-
UnitedHealth Says It Has Made Progress on Recovering From Massive Cyberattack Associated Press
UnitedHealth is testing the last major system it must restore from last month’s Change Healthcare cyberattack, but it has no date yet for finishing the recovery. The post UnitedHealth Says It Has Made Progress on Recovering From Massive Cyberattack appeared first on SecurityWeek. Read More
-

New DEEP#GOSU Malware Campaign Targets Windows Users with Advanced Tactics [email protected] (The Hacker News)
A new elaborate attack campaign has been observed employing PowerShell and VBScript malware to infect Windows systems and harvest sensitive information. Cybersecurity company Securonix, which dubbed the campaign DEEP#GOSU, said it’s likely associated with the North Korean state-sponsored group tracked as Kimsuky. “The malware payloads used in the DEEP#GOSU represent aRead More
-
Exploitation activity increasing on Fortinet vulnerability
Post ContentRead More
-
UK Government Releases Cloud SCADA Security Guidance Eduard Kovacs
UK’s NCSC releases security guidance for OT organizations considering migrating their SCADA solutions to the cloud. The post UK Government Releases Cloud SCADA Security Guidance appeared first on SecurityWeek. Read More
-
Fujitsu Data Breach Impacts Personal, Customer Information Ionut Arghire
Fujitsu says hackers infected internal systems with malware, stole personal and customer information. The post Fujitsu Data Breach Impacts Personal, Customer Information appeared first on SecurityWeek. Read More
