Largest non-bank lender in Australia warns of a data breach
    May 12, 2024   10:16 AM   0 Firstmac Limited is warning customers that it suffered a data breach a day after the new Embargo cyber-extortion group leaked over 500GB of data allegedly stolen from the firm. Firstmac is a significant player in Australia's financial services industry, focusing primarily on mortgage lending, investment management, and securitization services. Headquartered in Brisbane, Queensland, and employing 460 people, the firm has...
    By AFFA 2024-05-12 16:47:41 0 3
    Citrix warns admins to manually mitigate PuTTY SSH client bug
    May 9, 2024   03:27 PM   0 Citrix notified customers this week to manually mitigate a PuTTY SSH client vulnerability that could allow attackers to steal a XenCenter admin's private SSH key. XenCenter helps manage Citrix Hypervisor environments from a Windows desktop, including deploying and monitoring virtual machines. The security flaw (tracked as CVE-2024-31497) impacts multiple versions of XenCenter for Citrix Hypervisor 8.2 CU1 LTSR, which bundle and use...
    By AFFA 2024-05-10 18:22:51 0 3
    Widely used modems in industrial IoT devices open to SMS attack
    May 10, 2024   04:00 AM   0 Security flaws in Telit Cinterion cellular modems, widely used in sectors including industrial, healthcare, and telecommunications, could allow remote attackers to execute arbitrary code via SMS. A set of eight separate issues, seven of them with identifiers CVE-2023-47610 through CVE-2023-47616 and another that has yet to be registered, were disclosed last November by security researchers at Kaspersky's ICS CERT division....
    By AFFA 2024-05-10 18:21:00 0 5
    Over 50 Thousand Tinyproxy servers vulnerable to critical RCE flaw
    May 7, 2024   01:07 PM   0 Nearly 52,000 internet-exposed Tinyproxy instances are vulnerable to CVE-2023-49606, a recently disclosed critical remote code execution (RCE) flaw. Tinyproxy is an open-source HTTP and HTTPS proxy server designed to be fast, small, and lightweight. It is specifically tailored for UNIX-like operating systems and is commonly used by small businesses, public WiFi providers, and home users. At the start of the month, Cisco...
    By AFFA 2024-05-07 18:31:12 0 9
    FCC fines carriers $200 million for illegally sharing user location
    April 29, 2024   03:41 PM   3 ​The Federal Communications Commission (FCC) has fined the largest U.S. wireless carriers almost $200 million for sharing their customers' real-time location data without their consent. FCC's forfeiture orders finalize Notices of Apparent Liability (NAL) issued against AT&T, Sprint, T-Mobile, and Verizon in February 2020. The fines imposed on Monday include $12 million...
    By AFFA 2024-04-30 17:11:57 0 25
    Collection agency FBCS warns data breach impacts 1.9 million people
    April 29, 2024   10:23 AM   0 Financial Business and Consumer Solutions (FBCS) is warning 1,955,385 impacted individuals in the United States that the company suffered a data breach after discovering unauthorized access to specific systems in its network. FBCS is a nationally licensed debt collection agency in the U.S., specializing in collecting unpaid debts from consumer credit, healthcare, commercial, auto loans and leases, student loans, and utilities....
    By AFFA 2024-04-29 18:50:11 0 21
    Okta warns of "unprecedented" credential stuffing attacks on customers
    April 27, 2024   10:55 AM   0 Okta warns of an "unprecedented" spike in credential stuffing attacks targeting its identity and access management solutions, with some customer accounts breached in the attacks. Threat actors use credential stuffing to compromise user accounts by trying out in an automated manner lists of usernames and passwords typically purchased from cybercriminals. In an advisory today, Okta says the attacks seem to originate from...
    By AFFA 2024-04-27 17:38:38 0 21
    Fake job interviews target developers with new Python backdoor
    April 26, 2024   10:20 AM   1 A new campaign tracked as “Dev Popper” is targeting software developers with fake job interviews in an attempt to trick them into installing a Python remote access trojan (RAT). The developers are asked to perform tasks supposedly related to the interview, like downloading and running code from GitHub, in an effort to make the entire process appear legitimate. However, the threat actor's goal is make their...
    By AFFA 2024-04-26 18:04:42 0 24
    Telegram is down with "Connecting" error
    April 26, 2024   12:38 PM   0 It's not just you: Telegram is down, and users report seeing a "Connecting" alert when they try to open messages, groups, or channels. The "Connecting" alert, typically used during slow internet connections, prevents users from accessing the messages.  BleepingComputer also observed Connecting" error when accessing the Telegram desktop client. We're seeing similar reports from users on X and Reddit....
    By AFFA 2024-04-26 18:02:50 0 25
    Microsoft releases Exchange hotfixes for security update issues
    April 23, 2024   03:50 PM   0 ​Microsoft has released hotfix updates to address multiple known issues impacting Exchange servers after installing the March 2024 security updates. Although the April 2024 HU is optional, it also adds support for ECC certificates and Hybrid Modern Authentication (HMA) for OWA/ECP. If you have installed the March 2024 SU and have not experienced any known issues fixed in the optional update and do not need the new...
    By AFFA 2024-04-24 17:48:03 0 51
    DuckDuckGo launches a premium Privacy Pro VPN service
    April 11, 2024   08:00 AM   2 DuckDuckGo has launched a new paid-for 3-in-1 subscription service called 'Privacy Pro,' which includes a virtual private network (VPN), a personal data removal service, and an identity theft restoration solution. DuckDuckGo started in 2008 as an internet search engine with an emphasis on protecting people's privacy, preventing online tracking, and bursting the bubble of personalized results. Over the years that followed,...
    By AFFA 2024-04-11 15:43:17 0 60
    Malicious PowerShell script pushing malware looks AI-written
    April 10, 2024   12:12 PM   0 A threat actor is using a PowerShell script that was likely created with the help of an artificial intelligence system such as OpenAI's ChatGPT, Google's Gemini, or Microsoft's CoPilot. The adversary used the script in an email campaign in March that targeted tens of organizations in Germany to deliver the Rhadamanthys information stealer. AI-based PowerShell deploys infostealer Researchers at cybersecurity company...
    By AFFA 2024-04-10 17:04:29 0 58
    Critical flaw in LayerSlider WordPress plugin impacts 1 million sites
    April 3, 2024   02:21 PM   1 A premium WordPress plugin named LayerSlider, used in over one million sites, is vulnerable to unauthenticated SQL injection, requiring admins to prioritize applying security updates for the plugin. LayerSlider is a versatile tool for creating responsive sliders, image galleries, and animations on WordPress sites, allowing users to build visually appealing elements with dynamic content on online platforms. Researcher AmrAwad...
    By AFFA 2024-04-04 16:17:28 0 121
    SurveyLama data breach exposes info of 4.4 million users
    April 3, 2024   06:28 PM   2 Data breach alerting service Have I Been Pwned (HIBP) warns that SurveyLama suffered a data breach in February 2024, which exposed the sensitive data of 4.4 million users. SurveyLama is an online platform that rewards registered users for completing surveys. Owned by French firm Globe Media, the platform is praised for high payouts (up to $20), fast payments, and multiple withdrawal options. In early February, HIBP's creator, Troy...
    By AFFA 2024-04-04 16:11:26 0 64
    AT&T faces lawsuits over data breach affecting 73 million customers
    April 3, 2024   12:28 PM   0 AT&T is facing multiple class-action lawsuits following the company's admission to a massive data breach that exposed the sensitive data of 73 million current and former customers. Among the ten lawsuits filed since Saturday, when AT&T confirmed our previous reporting about the breach, one is handled by Morgan & Morgan, representing plaintiff Patricia Dean and similarly situated persons.  This law firm...
    By AFFA 2024-04-03 17:52:40 0 92
More Articles
Citeste mai mult
Google rejected 2.28 million risky Android apps from Play store in 2023
April 29, 2024   12:00 PM   0 Google...
By AFFA 2024-04-29 18:46:17 0 22
Microsoft is killing off the Android apps in Windows 11 feature
March 5, 2024   02:23 PM   6 Microsoft has unexpectedly announced...
By AFFA 2024-03-07 16:29:00 0 123
Google teases a new modern look for sign-in pages, including Gmail
February 8, 2024   06:33 AM   0 Google is on the brink of...
By AFFA 2024-02-08 22:57:27 0 189
Interpol operation Synergia takes down 1,300 servers used for cybercrime
February 2, 2024   07:56 AM   0 An international law enforcement...
By AFFA 2024-02-02 21:23:06 0 181
CoralRaider attacks use CDN cache to push info-stealer malware
April 23, 2024   05:27 PM   0 A threat actor has been using a...
By AFFA 2024-04-24 17:46:32 0 58