Security News

California Man Hacked iCloud Accounts to Steal Nude Photos
2021-08-25 11:41

A California man impersonated an Apple customer support technician in a socially engineered email campaign that stole people's iCloud passwords to break into accounts and collected upwards of 620,000 private photos and videos. Hao Kuo Chi, 40, of La Puente, has agreed to plead guilty to four felonies, including conspiracy to gain unauthorized access to a computer, in a scam that ultimately aimed to steal and share nude images of young women, according to court records and a report by the Los Angeles Times.

Microsoft Exchange servers being hacked by new LockFile ransomware
2021-08-21 15:05

A new ransomware gang known as LockFile encrypts Windows domains after hacking into Microsoft Exchange servers using the recently disclosed ProxyShell vulnerabilities. ProxyShell is the name of an attack consisting of three chained Microsoft Exchange vulnerabilities that result in unauthenticated, remote code execution.

US Census Bureau hacked in January 2020 using Citrix exploit
2021-08-18 21:07

US Census Bureau servers were breached on January 11, 2020, by hackers after exploiting an unpatched Citrix ADC zero-day vulnerability, as the US Office of Inspector General disclosed in a recent report. "The purpose of these servers was to provide the Bureau with remote-access capabilities for its enterprise staff to access the production, development, and lab networks. According to system personnel, these servers did not provide access to 2020 decennial census networks," the OIG said.

Video surveillance network hacked by researchers to hijack footage
2021-08-17 18:48

Operated by Chinese smart device company ThroughTek, Kalay is pitched as a cloud-based solution for vendors of home automation devices, including security cameras, smart locks, video doorphones, smart power plugs, and even personal cloud storage hardware such as NAS devices. As you can see, the idea is that instead of creating their own protocol, setting up their own servers and building their own home automation service, home device makers can build the Kalay software into their own firmware, and use the existing Kalay network so their customers can manage and access the devices.

T-Mobile data breach confirmed, servers were hacked
2021-08-16 19:52

T-Mobile has confirmed that threat actors hacked their servers in a recent cyber attack but still investigate whether customer data was stolen.Yesterday, news broke that a threat actor was selling the alleged personal data for 100 million T-Mobile customers after they breached database servers operated by the mobile network.

Devices From Many Vendors Can Be Hacked Remotely Due to Flaws in Realtek SDK
2021-08-16 18:35

A large number of IoT systems could be exposed to remote hacker attacks due to serious vulnerabilities found in software development kits provided to device manufacturers by Taiwan-based semiconductor company Realtek. Firmware security company IoT Inspector said its researchers have identified more than a dozen vulnerabilities in SDKs provided by Realtek to companies that use its RTL8xxx chips.

Microsoft Exchange servers are getting hacked via ProxyShell exploits
2021-08-12 21:24

Threat actors are actively exploiting Microsoft Exchange servers using the ProxyShell vulnerability to install backdoors for later access. ProxyShell is the name of an attack that uses three chained Microsoft Exchange vulnerabilities to perform unauthenticated, remote code execution.

S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast]
2021-08-12 18:28

" Home and small business routers under attack. The Navajo Nation's selfless cryptographic contribution to America.

Chipotle's Email Marketing Account Hacked to Spread Malware
2021-08-02 15:20

All the malicious emails were sent via the Constant Contact mailing service using the compromised account of the United States Agency for International Development. "Analysis of the email headers revealed that the messages originated from Mailgun servers and passed email authentication for chipotle[.]com," says Inky.

Justice Department Says Russians Hacked Federal Prosecutors
2021-08-01 14:21

The Russian hackers behind the massive SolarWinds cyberespionage campaign broke into the email accounts of some of the most prominent federal prosecutors' offices around the country last year, the Justice Department said. The department said 80% of Microsoft email accounts used by employees in the four U.S. attorney offices in New York were breached.