Symantec researchers report details about the activities of a cybercrime group they track as Bluebottle, revealing significant similarities to the TTP gang OPERA1ER.
Symantec researchers report details about the activities of a cybercrime group they track as Bluebottle, revealing significant similarities to the TTP gang OPERA1ER.
Auth0 fixed an RCE vulnerability in the popular open source library JsonWebToken, which was used in more than 22,000 projects and downloaded more than 36 million times a month on NPM.
Air France and KLM have informed Flying Blue customers about a cyber incident that resulted in their accounts being compromised and personal information being disclosed.
K7 Security Labs resellers have discovered a campaign by an unknown actor, presumably based in China, who uses Windows Problem Reporting (WerFault.exe ) to launch remote administration tools.
Automakers in pursuit of active and passive safety at the time would like to think about information.
While BMW, Mercedes, Toyota and other popular manufacturers were engaged in crash tests of their cars, cybersecurity researcher Sam Curry and his colleagues discovered many vulnerabilities in cars and services implemented by automotive solution providers.
The corporate communication and collaboration platform Slack reported a cyber incident that occurred during the holidays and affected some of its repositories on GitHub, about which the company notified customers.
The Taiwanese NAS manufacturer Synology has eliminated the vulnerability of the maximum (10/10) severity in VPN routers, as well as vulnerabilities that were probably recently used at the Pwn2Own hacking contest.
On New Year's Eve, the Poles put some cranberry infosec under the Christmas tree.
So, on December 30, gov.pl published news about Russian cyberattacks on Polish information resources.
Well, hello in 2023!
It's time to get down to business again!
The year has just begun, and a lot of events have already happened, to which our publications will be devoted in the coming days.
On Christmas Day, Portugal's third largest port was subjected to a cyberattack.
The Portuguese authorities did not specify details. Everything became obvious when the Port of Lisbon ended up on DLS LockBit, which demanded about $ 1.5 million in ransom.
Cryptoplatform 3Commas has recognized a cyber incident, as a result of which API keys were stolen.
Recently, an anonymous user on Twitter published a set of 10,000 API keys used by 3Commas to interact with crypto exchanges and to perform automatic investment and trading actions on behalf of users.
Netgear has fixed a serious vulnerability affecting Wi-Fi routers and advised customers to update the software on their devices as soon as possible.
The largest medical facility in Lake Charles (LCMHS), Louisiana was attacked by ransomware, resulting in a leak of information about almost 270 thousand patients.
A fairly indicative practice has been formed to resolve violations in the field of confidentiality.
Royal Ransomware claimed responsibility for the cyberattack on the telecommunications company Intrado.