Security News

Kevin Mitnick Hacked California Law in 1983
2023-01-27 20:19

Early in his career, Kevin Mitnick successfully hacked California law. The setup is that he just discovered that there's warrant for his arrest by the California Youth Authority, and he's trying to figure out if there's any way out of it.

CISA: Federal agencies hacked using legitimate remote desktop tools
2023-01-25 21:18

CISA, the NSA, and MS-ISAC warned today in a joint advisory that attackers are increasingly using legitimate remote monitoring and management software for malicious purposes. More worryingly, CISA discovered malicious activity within the networks of multiple federal civilian executive branch agencies using the EINSTEIN intrusion detection system after the release of a Silent Push report in mid-October 2022.

Over 4,500 WordPress Sites Hacked to Redirect Visitors to Sketchy Ad Pages
2023-01-25 16:11

A massive campaign has infected over 4,500 WordPress websites as part of a long-running operation that's been believed to be active since at least 2017. According to GoDaddy-owned Sucuri, the infections involve the injection of obfuscated JavaScript hosted on a malicious domain named "Track[.]violetlovelines[.]com" that's designed to redirect visitors to unwanted sites.

Riot Games hacked, delays game patches after security breach
2023-01-21 19:54

Riot Games, the video game developer and publisher behind League of Legends and Valorant, says it will delay game patches after its development environment was compromised last week. Riot Games also added that the breach directly impacted its ability to publish patches for its games.

T-Mobile hacked to steal data of 37 million accounts in API data breach
2023-01-19 22:19

T-Mobile disclosed a new data breach after a threat actor stole the personal information of 37 million current postpaid and prepaid customer accounts through one of its Application Programming...

MailChimp discloses new breach after employees got hacked
2023-01-18 21:11

Email marketing firm MailChimp suffered another breach after hackers accessed an internal customer support and account administration tool, allowing the threat actors to access the data of 133 customers. MailChimp says the attackers gained access to employee credentials after conducting a social engineering attack on Mailchimp employees and contractors.

Serious Security: Unravelling the LifeLock “hacked passwords” story
2023-01-17 19:59

As opening paragraphs go, this one is pretty straightforward, and contains uncomplicated if potentially time-consuming advice: someone other than you probably knows your Norton account password; they may have been able to peek into your password manager as well; please change all passwords as soon as you can. In LastPass's case the stolen passwords weren't of direct and immediate use to the attackers, because each user's password vault was protected by a master password, which wasn't stored by LastPass and therefore wasn't stolen at the same time.

Hacked Cellebrite and MSAB Software Released
2023-01-16 12:14

Cellebrite is an cyberweapons arms manufacturer that sells smartphone forensic software to governments around the world. Someone has released software and documentation from both companies.

Canada's largest alcohol retailer's site hacked to steal credit cards
2023-01-14 14:16

The Liquor Control Board of Ontario, a Canadian government enterprise and the country's largest beverage alcohol retailer, revealed that unknown attackers had breached its website to inject malicious code designed to steal customer and credit card information at check-out.LCBO revealed on Wednesday that third-party forensic investigators found a credit card stealing script that was active on its website for five days.

Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL
2023-01-09 21:16

The Kinsing malware is now actively breaching Kubernetes clusters by leveraging known weaknesses in container images and misconfigured, exposed PostgreSQL containers. "Recently, we identified a widespread campaign of Kinsing that targeted vulnerable versions of WebLogic servers," reads a report by Microsoft security researcher Sunders Bruskin.