Security News > 2023 > April

FBI seizes stolen credentials market Genesis in Operation Cookie Monster
2023-04-04 20:18

The domains for Genesis Market, one of the most popular marketplaces for stolen credentials of all types, were seized by law enforcement earlier this week as part of Operation Cookie Monster. While authorities have yet to publish press releases about the takedown, accessing the Genesis Market domains shows a banner saying that the FBI has executed a seizure warrant.

Einstein tilings – the amazing “Hat” shape that never repeats!
2023-04-04 18:59

As you can see, square tiles form what's known as a periodic pattern, meaning that the pattern repeats itself every so often. Unlike periodic tilings, which repeat every so often, aperiodic tilings never repeat, no matter how carefully you choose the next piece to place, and where to place it.

Rockstar fixes Red Dead Redemption 2 game broken by Windows update
2023-04-04 17:28

Microsoft says Rockstar Games has addressed a known issue affecting its launcher, causing the Red Dead Redemption 2 game to no longer launch on some Windows 11 systems. The issue affects only gamers who launch RRD2 via the Rockstar Games Launcher on Windows 11 21H2 systems after installing the KB5023774 March 2023 optional preview update.

ALPHV ransomware exploits Veritas Backup Exec bugs for initial access
2023-04-04 15:43

An ALPHV/BlackCat ransomware affiliate was observed exploiting three vulnerabilities impacting the Veritas Backup product for initial access to the target network. Mandiant tracks the ALPHV affiliate as 'UNC4466' and notes that the method is a deviation from the typical intrusion that relies on stolen credentials.

New Rorschach ransomware is the fastest encryptor seen so far
2023-04-04 14:13

Following a cyberattack on a U.S.-based company, malware researchers discovered what appears to be a new ransomware strain with "Technically unique features," which they named Rorschach. Among the capabilities observed is the encryption speed, which, according to tests from the researchers, would make Rorschach the fastest ransomware threat today.

North Korea Hacking Cryptocurrency Sites with 3CX Exploit
2023-04-04 14:10

Researchers at Russian cybersecurity firm Kaspersky today revealed that they identified a small number of cryptocurrency-focused firms as at least some of the victims of the 3CX software supply-chain attack that's unfolded over the past week. Kaspersky declined to name any of those victim companies, but it notes that they're based in "Western Asia.".

Sorting Through Haystacks to Find CTI Needles
2023-04-04 13:51

CTI systems are confronted with some major issues ranging from the size of the collection networks to their diversity, which ultimately influence the degree of confidence they can put on their signals. To illustrate the collection networks' size & variety point, without naming anyone in particular, let's imagine a large CDN provider.

UK data watchdog fines TikTok £12.7M for failing to protect kids
2023-04-04 13:42

Fresh off the back of an embarrassing "Grilling" by US Congress on national security grounds, TikTok has received a more concrete reprimand from the UK's Information Commissioner's Office - a fine of £12.7 million for "Misusing children's data." Despite TikTok's own rules disallowing children under the age of 13, the video-sharing app's whirlwind success has meant that some 1.4 million kids in the UK used it in 2020 by the ICO's estimates.

Rorschach Ransomware Emerges: Experts Warn of Advanced Evasion Strategies
2023-04-04 13:16

Cybersecurity researchers have taken the wraps off a previously undocumented ransomware strain called Rorschach that's both sophisticated and fast. "What makes Rorschach stand out from other ransomware strains is its high level of customization and its technically unique features that have not been seen before in ransomware," Check Point Research said in a new report.

New Rilide Malware Targeting Chromium-Based Browsers to Steal Cryptocurrency
2023-04-04 13:07

Chromium-based web browsers are the target of a new malware called Rilide that masquerades itself as a seemingly legitimate extension to harvest sensitive data and siphon cryptocurrency. "Rilide malware is disguised as a legitimate Google Drive extension and enables threat actors to carry out a broad spectrum of malicious activities, including monitoring."