Bleeping Computer

AT&T Pays $13 Million FCC Settlement Over 2023 Data Breach

The breach occurred when threat actors gained access to customer data of about 9 million AT&T wireless accounts stored by a vendor. This exposed sensitive customer information like account numbers, phone numbers, and email addresses.

Police Dismantles Phone Unlocking Ring Linked to 483,000 Victims

This scheme was uncovered in 2022 during "Operation Kaerb," involving global enforcement agencies. The criminals mimicked popular mobile platforms to conduct phishing attacks.

Clever 'GitHub Scanner' Campaign Abusing Repositories to Push Malware

A sophisticated campaign is using GitHub repositories to spread the Lumma Stealer malware, targeting users interested in open-source projects or receiving email notifications from them.

Germany Seizes 47 Crypto Exchanges Used by Ransomware Gangs

These exchanges allowed users to trade cryptocurrencies anonymously, creating a safe environment for cybercriminals to launder their proceeds without fear of prosecution.

Update: PKfail Secure Boot Bypass Remains a Significant Risk Two Months Later

Approximately nine percent of tested firmware images use non-production cryptographic keys that are publicly known, making Secure Boot devices vulnerable to UEFI bootkit malware attacks.

Ransomware Gangs Now Abuse Microsoft Azure Tool for Data Theft

Ransomware groups such as BianLian and Rhysida are now exploiting Microsoft Azure tools like Storage Explorer and AzCopy to steal data from compromised networks and store it in Azure Blob storage.

CISA Urges Software Developers to Weed Out XSS Vulnerabilities

The CISA and the FBI recommended software developers to implement rigorous validation, sanitization, and input escaping to prevent malicious script injections and data manipulation.

Chrome Switching to NIST-Approved ML-KEM Quantum Encryption

Google is updating Chrome's post-quantum cryptography to defend against quantum computer attacks. The new encryption system, ML-KEM, replaces Kyber for enhanced security.

D-Link Fixes Critical RCE, Hardcoded Credential Flaws in WiFi 6 Routers

D-Link has addressed critical vulnerabilities in three popular WiFi 6 router models, fixing issues that could allow remote attackers to run arbitrary code or access devices with hardcoded credentials.

Malware Campaign Locks Browser in Kiosk Mode to Steal Google Credentials

The campaign specifically targets Google's login page and prevents users from closing the window or using certain keyboard keys to escape. Once users enter and save their credentials to unlock the computer, the StealC malware steals the credentials.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags