"Phishing Attack Impacts Over 92,000 Transak Users"

"Phishing Attack Impacts Over 92,000 Transak Users"

Transak, a fiat-to-crypto payment gateway provider, recently reported a security incident that has impacted 92,554 of its users. According to Transak, attackers gained unauthorized access to one of their employee laptops through a sophisticated phishing attack. The firm noted that the attacker used compromised credentials to log in to the system of a third-party KYC vendor that the company uses for document scanning and verification services. The attacker then gained access to user information stored within the vendor's dashboard.

Submitted by Adam Ekwall on

"State Department Offers $10 Million Reward For Info on Russian Propaganda Outlet"

"State Department Offers $10 Million Reward For Info on Russian Propaganda Outlet"

The U.S. government has recently announced a reward of up to $10 million for information about the Russian media organization Rybar and its employees amid allegations it's involved in spreading propaganda aimed at influencing the upcoming U.S. presidential election.  According to the State Department, Rybar has been accused of using its extensive social media reach, with over 1.3 million followers on various channels, to promote pro-Russian and anti-Western sentiments.

Submitted by Adam Ekwall on

"Netskope Reports Possible Bumblebee Loader Resurgence"

"Netskope Reports Possible Bumblebee Loader Resurgence"

According to security researchers at Netskope, the Bumblebee malware loader could have re-emerged months after Europol-led Operation Endgame disrupted it in May 2024.  Researchers have uncovered a new infection chain that deploys Bumblebee malware.  The researchers noted that this was the first occurrence of a Bumblebee campaign since Operation Endgame, a law enforcement operation performed by Europol and partners in May 2024 that disrupted major malware botnets.

Submitted by Adam Ekwall on

"Cyprus Thwarted a Digital Attack Against the Government’s Main Online Portal"

"Cyprus Thwarted a Digital Attack Against the Government’s Main Online Portal"

Cyprus recently announced  that it has successfully thwarted a digital attack to block access to the government's central online portal.   The government noted that the distributed denial-of-service attack, or DDoS, only affected the main government portal gov.cy "for a few minutes" and that no other online government ministry or service website was affected.  The deputy ministry didn't say who was behind the attacks or the possible motive.

Submitted by Adam Ekwall on

"Roundcube Webmail Vulnerability Exploited in Government Attack"

"Roundcube Webmail Vulnerability Exploited in Government Attack"

Security researchers at Positive Technologies recently observed a threat actor attempting to exploit a recent vulnerability in Roundcube Webmail against a governmental organization in a Commonwealth of Independent States (CIS) country.  Tracked as CVE-2024-37383 and described as a cross-site scripting (XSS) issue affecting the way Roundcube was handling SVG animate attributes, the bug was patched on May 19 in Roundcube Webmail versions 1.5.7 and 1.6.7.

Submitted by Adam Ekwall on

"Cisco Confirms Security Incident After Hacker Offers to Sell Data"

"Cisco Confirms Security Incident After Hacker Offers to Sell Data"

Cisco recently confirmed that some of its files have been stolen after a hacker offered to sell information allegedly belonging to the company.  The hacker known as IntelBroker on October 14 announced a “Cisco breach” on a popular cybercrime forum.  IntelBroker claimed to have obtained GitHub and SonarQube projects, source code, hardcoded credentials, certificates, confidential documents, Jira tickets, API tokens, AWS private buckets, encryption keys, and other types of information.

Submitted by Adam Ekwall on

"Cicada3301 Ransomware Targets Critical Sectors in US and UK"

"Cicada3301 Ransomware Targets Critical Sectors in US and UK"

Since its discovery in June 2024, the "Cicada3301" ransomware group has targeted critical sectors in the US and UK. In three months, the group has exposed data stolen from 30 companies on their leak sites. Group-IB recently revealed that Cicada3301's ransomware is written in Rust, thus enabling it to run on Windows, Linux, ESXi, and less common architectures such as PowerPC. The Cicada3301 ransomware uses advanced encryption techniques involving ChaCha20 and RSA encryption with configurable modes, welcoming different levels of encryption.

Submitted by Gregory Rigby on

"Experts Play Down Significance of Chinese Quantum 'Hack'"

"Experts Play Down Significance of Chinese Quantum 'Hack'"

Security experts urge caution regarding Chinese researchers' recently reported work in cracking military-grade encryption using quantum computing technology. In a study titled "Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage," Shanghai University researchers claimed to have used a D-Wave Advantage quantum computer to target Substitution-Permutation Network (SPN) algorithms that are foundational to Advanced Encryption Standard (AES) cryptography.

Submitted by Gregory Rigby on

"Microsoft: macOS Vulnerability Potentially Exploited in Adware Attacks"

"Microsoft: macOS Vulnerability Potentially Exploited in Adware Attacks"

Microsoft warned that a recently patched macOS vulnerability could be used in adware attacks. The flaw enables attackers to bypass the operating system's Transparency, Consent, and Control (TCC) technology and access user data. Apple addressed the bug in macOS Sequoia 15 by removing the vulnerable code. The company also emphasized that only MDM-managed devices are affected. According to Microsoft, the flaw's exploitation involves removing the TCC protection for the Safari browser directory and modifying a configuration file in the directory.

Submitted by Gregory Rigby on

"Tech Giant Nidec Confirms Data Breach Following Ransomware Attack"

"Tech Giant Nidec Confirms Data Breach Following Ransomware Attack"

Nidec Corporation recently announced that hackers behind a ransomware attack it suffered earlier this year stole data and leaked it on the dark web.  The company says the threat actors tried to extort the company and decided to leak the information after their demands were not met.  Nidec noted that the attack did not encrypt files, and the incident is considered fully remediated at this time.

Submitted by Adam Ekwall on
Subscribe to