Security News > 2023 > June

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier
2023-06-30 23:17

Following claims by ransomware gang LockBit that it has stolen data belonging to TSMC, the chip-making giant has said it was in fact one of its equipment suppliers, Kinmax, that was compromised by the crew, and not TSMC itself. The crooks said TSMC has an August 6 deadline to cough up.

The Week in Ransomware - June 30th 2023 - Mistaken Identity
2023-06-30 21:33

A case of mistaken identity and further MOVEit Transfer data breaches continue dominated the ransomware news cycle this week. A new report by VMware's Carbon Black team sheds light on the 8Base ransomware operation, illustrating how they use the Phobos ransomware in attacks.

Friday Squid Blogging: See-Through Squid
2023-06-30 20:58

Doryteuthis opalescens is known as the market squid, and was critical in the recent squid RNA research. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered.

Hackers exploit zero-day in Ultimate Member WordPress plugin with 200K installs
2023-06-30 19:49

Hackers exploit a zero-day privilege escalation vulnerability in the 'Ultimate Member' WordPress plugin to compromise websites by bypassing security measures and registering rogue administrator accounts. Ultimate Member is a user profile and membership plugin that facilitates sign-ups and building communities on WordPress sites, and it currently has over 200,000 active installations.

Cops told: Er, no, you need a wiretap order if you want real-time Facebook snooping
2023-06-30 19:40

New Jersey cops must apply for a wiretap order - not just a warrant - for near-continual snooping on suspects' Facebook accounts, according to a unanimous ruling by that US state's Supreme Court. "We also find that the nearly contemporaneous acquisition of electronic communications here is the functional equivalent of wiretap surveillance and is therefore entitled to greater constitutional protection."

Twitter now forces you to sign in to view tweets
2023-06-30 19:38

BleepingComputer did not reach out to Twitter because the media contact email has been set up to auto-reply with a crappy emoji after Elon Musk acquired the company in October and took over as CEO. Back in April, Twitter disabled the search field for unregistered users and only showing several suggested tweets when going to the homepage. Twitter also capped its free API in early February, asking for at least $100 per month when requesting write or read access to large amounts of tweets.

Surfshark VPN Review (2023): Features, Pricing, and More
2023-06-30 19:15

TechRepublic's review of VPN software Surfshark looks at pricing, features and pros and cons of the product. This comprehensive review delves into the latest Surfshark VPN software examining its pricing and notable features as well as its pros and cons.

New proxyjacking attacks monetize hacked SSH servers’ bandwidth
2023-06-30 18:47

Attackers behind an ongoing series of proxyjacking attacks are hacking into vulnerable SSH servers exposed online to monetize them through proxyware services that pay for sharing unused Internet bandwidth. Like cryptojacking, which allows attackers to use hacked systems to mine for cryptocurrency, proxyjacking is a low-effort and high-reward tactic of leeching compromised devices' resources.

Gigamon’s Cloud Security Report Shares Insights on Undetected Breaches & Deep Observability
2023-06-30 17:47

Findings in network intelligence firm Gigamon's Hybrid Cloud Security Survey report suggest there's a disconnect between perception and reality when it comes to vulnerabilities in the hybrid cloud: 94% of CISOs and other cybersecurity leaders said their tools give them total visibility of their assets and hybrid cloud infrastructure, yet 90% admitted to having been breached in the past 18 months, and over half fear attacks coming from dark corners of their web enterprises. Key to understanding hybrid cloud security Must-read security coverage Google offers certificate in cybersecurity, no dorm room required The top 6 enterprise VPN solutions to use in 2023 EY survey: Tech leaders to invest in AI, 5G, cybersecurity, big data, metaverse Electronic data retention policy.

Free Akira ransomware decryptor helps recover your files
2023-06-30 16:45

Cybersecurity firm Avast has released a free decryptor for the Akira ransomware that can help victims recover their data without paying the crooks any money. Akira on Windows encrypts files only partially for a speedier process, following a different encryption system depending on the file size.