28 Jul Hacker leaks 386 million user records from 18 companies for free A threat actor is flooding a hacker forum with databases exposing expose over 386 million user records that they claim were stolen from eighteen companies during data breaches. […]
28 Jul Industrial VPN vulnerabilities put critical infrastructure at risk Security researchers analyzing popular remote access solutions used for industrial control systems (ICS) found multiple vulnerabilities that could let unauthenticated attackers execute arbitrary code and breach the environment. […]
27 Jul Office 365 phishing baits employees with fake SharePoint alerts Employees using Microsoft Office 365 are targeted in a phishing campaign that makes use of bait messages camouflaged as automated Sharepoint notifications to steal their accounts. […]
27 Jul Garmin confirms ransomware attack, services coming back online Garmin has officially confirmed that they were victims of a ransomware attack as they slowly bring their Garmin Connect, Strava, and navigation services back online. […]
27 Jul UK and US warn QNAP owners to upgrade firmware to block malware The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre (NCSC) today issued an alert about the risks of infection faced by QNAP NAS devices if QSnatch malware attacks restart. […]
27 Jul Cerberus Android malware source code offered for sale for $100,000 The maintainer of Cerberus banking trojan for Android is auctioning the entire project for a price starting at $50,000 or close the deal for double the money. […]
26 Jul Dave data breach affects 7.5 million users, leaked on hacker forum Overdraft protection and cash advance service Dave has suffered a data breach after a database containing 7.5 million user records was sold in an auction and then released later for free on hacker forums. […]
26 Jul New ‘Meow’ attack has deleted almost 4,000 unsecured databases Dozens of unsecured databases exposed on the public web are the target of an automated ‘meow’ attack that wipes data without any explanation. […]
25 Jul Linux-based malware analysis toolkit REMnux 7 released A new version of REMnux Linux distro is now available for malware researchers, packed with hundreds of tools to dissect malicious executables, documents, scripts, and ill-intended code. […]
24 Jul US govt confirms active exploitation of F5 BIG-IP RCE flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) today published a warning regarding the active exploitation of the unauthenticated remote code execution (RCE) CVE-2020-5902 vulnerability affecting F5 Big-IP ADC devices. […]