Security News

UPS discloses data breach after exposed customer info used in SMS phishing
2023-06-21 17:43

Multinational shipping company UPS is alerting Canadian customers that some of their personal information might have been exposed via its online package look-up tools and abused in phishing attacks. At first glance, the letters sent by UPS Canada, titled "Fighting phishing and smishing - an update from UPS," seem to be a warning to customers about the dangers of phishing.

Russian APT28 hackers breach Ukrainian govt email servers
2023-06-20 13:00

A threat group tracked as APT28 and linked to Russia's General Staff Main Intelligence Directorate has breached Roundcube email servers belonging to multiple Ukrainian organizations, including government entities. In these attacks, the cyber-espionage group leveraged news about the ongoing conflict between Russia and Ukraine to trick recipients into opening malicious emails that would exploit Roundcube Webmail vulnerabilities to hack into unpatched servers.

Reddit hackers threaten to leak data stolen in February breach
2023-06-18 16:01

The BlackCat ransomware gang is behind a February cyberattack on Reddit, where the threat actors claim to have stolen 80GB of data from the company. On February 9th, Reddit disclosed that its systems were hacked on February 5th after an employee fell victim to a phishing attack.

BlackCat ransomware gang behind Reddit breach from February
2023-06-18 16:01

The BlackCat ransomware gang is behind a February cyberattack on Reddit, where the threat actors claim to have stolen 80GB of data from the company. On February 9th, Reddit disclosed that its systems were hacked on February 5th after an employee fell victim to a phishing attack.

Millions of Oregon, Louisiana state IDs stolen in MOVEit breach
2023-06-16 14:28

Louisiana and Oregon warn that millions of driver's licenses were exposed in a data breach after a ransomware gang hacked their MOVEit Transfer security file transfer systems to steal stored data. The agency says there is no indication that Clop used, sold, shared, or released any of that data, so the stolen data may have been deleted as the ransomware actors promised in their announcement to delete any stolen government data.

Capita faces first legal Letter of Claim over mega breach
2023-06-16 13:04

Capita is facing its first legal claim over the high profile digital burglary in late March that exposed some customer data to intruders and will cost the outsourcing biz around £20 million to clean up. Barings Law, based in England's northwest, says it dispatched a Letter of Claim to Capita last week to outline its clients' case and their list of worries.

NetSPI Breach and Attack Simulation (BAS) platform demo
2023-06-14 02:45

See the NetSPI centralized detective control validation platform in action and learn how it allows companies to create and execute custom procedures using proven technology and expert human penetration testers. Ready to continuously simulate real-world attack behaviors, not just IoCs, and put your detective controls to the test in a way no other organization can? See BAS in action or schedule a 1:1 meeting with the NetSPI BAS team to get started.

Have I Been Pwned warns of new Zacks data breach impacting 8 million
2023-06-12 17:59

Zacks Investment Research has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database now shared on a hacking forum. Data breach notification service Have I Been Pwned listed an additional Zacks breach this weekend after being sent a database containing 8.8 million user records.

Verizon 2023 Data Breach Investigations Report: 74% of breaches involve human element
2023-06-06 12:48

Verizon Business today released the results of its 16th annual Data Breach Investigations Report, which analyzed 16,312 security incidents and 5,199 breaches. Chief among its findings is the soaring cost of ransomware - malicious software that encrypts an organization's data and extorts large sums of money to restore access.

MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…
2023-06-05 19:59

Last week, Progress Software Corporation, which sells software and services for user interface developement, devops, file management and more, alerted customers of its MOVEit Transfer product about a critical vulnerability dubbed CVE-2023-34362. If the backend data is stored in a SQL database, the web server might convert that URL into a SQL command like the one shown below.