LATEST POST

FEATURE

Pro-Russian, anti-Israeli hackers pose biggest cybercrime threats in Germany

Data Breach News
533 views 44 secs

It may not seem inuitively obvious to many people, but Reuters reports that cybercrime in Germany rose to a record level last year, driven by hacker attacks from pro-Russian and anti-Israeli groups. Some 131,391 cases of cybercrime took place in Germany last year and a further 201,877 cases were committed from abroad or an unknown […]

FEATURE

Cartier latest luxury brand hit by consumer data breach

Data Breach News
144 views 51 secs

The Korea Times reports: Luxury jewelry brand Cartier has confirmed a breach of customer data, raising concerns over data security among high-end brands following recent incidents involving Dior and Tiffany. The company sent out an email Tuesday informing its customers that an “unauthorized third party” accessed its systems temporarily and obtained certain customer information. While […]

FEATURE

Security bug at compliance firm Vanta exposed customer data to other users

Vendor News
387 views 40 secs

TechRadar reports: Security and compliance automation company Vanta has confirmed sharing sensitive customer data with other customers by mistake. In a statement (via TechCrunch), the company said a change it had made in the code resulted in a security breach. In it, some sensitive data from a small subset of customers was shared with other customers. […]

FEATURE

Hackers Weaponize Free SSH Client PuTTY to Deliver Malware on Windows

Consumer Alerts
590 views 39 secs

GBHackers reports: OpenSSH has become a standard tool for secure remote management on both Linux and Windows systems. Since its inclusion as a default component in Windows 10 version 1803, attackers have increasingly exploited its presence, leveraging it as a “Living Off the Land Binary” (LOLBIN). This means adversaries use trusted system tools ssh.exe to evade detection […]

FEATURE

0day for vBulletin: PoC is already online, but no one is installing the patch

Vulnerabilities
547 views 29 secs

When criminals note that there is an unpatched vulnerability, expect more attacks to follow. A Russian-language forum recently picked up a report from SecurityLab.ru. It begins (translation): Popular forums on vBulletin have once again been found to have holes through which arbitrary code can be executed directly on the server – without a login and […]

FEATURE

Victim Pays $800,000 in Bitcoin—But the Chat Was Not Private as Claimed by Akira

Data Breach News
618 views 47 secs

Ransomware gangs will swear not to reveal that you were a victim if you pay their ransom demands. SBut if they fail to secure their negotiation chat servers, researchers and intel analysts can discover who their victims are and shoulder-surf any negotiations or payment arrangements. The SuspectFile blog reports on another case like that where […]

FEATURE

Customers questioned top super fund about security weakness before cyberattacks

Data Breach News
522 views 54 secs

Australia’s biggest superannuation fund was questioned by its own clients about a security weakness in its accounts before cybercriminals stole hundreds of thousands of dollars in retirement savings.  ABC Australia reports: Two AustralianSuper customers have told the ABC they had asked for multi-factor authentication (MFA) on their accounts but were rebuffed — one of them […]

FEATURE

FBI investigating efforts to impersonate White House chief of staff Susie Wiles

Data Breach News
594 views 12 secs

Yet another member of President Trump’s staff has been caught up in a data security incident. The Guardian reports: The FBI is investigating an apparent impersonator who pretended to be the White House chief of staff, Susie Wiles, in texts and calls to her contacts, including prominent Republicans. Wiles has privately informed colleagues that the contacts in her personal cellphone […]