Security News

36% of organizations suffered a serious cloud security data leak or a breach in the past year
2021-07-27 05:30

As cloud adoption accelerates and the scale of cloud environments grows, engineering and security teams say that risks-and the costs of addressing them-are increasing. The survey of 300 cloud pros found that 36% of organizations suffered a serious cloud security data leak or a breach in the past 12 months, and eight out of ten are worried that they're vulnerable to a major data breach related to cloud misconfiguration.

Windows “HiveNightmare” bug could leak passwords – here’s what to do!
2021-07-21 18:58

Denoted CVE-2021-36934, this one has variously been nicknamed HiveNightmare and SeriousSAM. The moniker HiveNightmare comes from the fact that Windows stores its registry data in a small number of proprietary database files, known in Microsoft jargon as hives or hive files. These hive files include a trio called SAM, SECURITY and SYSTEM, which between them include secret data including passwords and security tokens that regular users aren't supposed to be able to access.

New Leak Reveals Abuse of Pegasus Spyware to Target Journalists Globally
2021-07-19 20:39

A sweeping probe into a data leak of more than 50,000 phone numbers has revealed an extensive misuse of Israeli company NSO Group's Pegasus "Military-grade spyware" to facilitate human rights violations by surveilling heads of state, activists, journalists, and lawyers around the world. "The Pegasus Project lays bare how NSO's spyware is a weapon of choice for repressive governments seeking to silence journalists, attack activists and crush dissent, placing countless lives in peril," Amnesty International's Secretary-General, Agnès Callamard, said.

Researchers Leak PoC Exploit for a Critical Windows RCE Vulnerability
2021-07-01 21:15

A proof-of-concept exploit related to a remote code execution vulnerability affecting Windows Print Spooler and patched by Microsoft earlier this month was briefly published online before being taken down. The Windows maker addressed the vulnerability as part of its Patch Tuesday update on June 8, 2021.

Tulsa warns of data breach after Conti ransomware leaks police citations
2021-06-23 15:53

The City of Tulsa, Oklahoma, is warning residents that their personal data may have been exposed after a ransomware gang published police citations online. The attack disrupted Tulsa's online bill payment systems, utility billing, and email, as well as the websites for the City of Tulsa, the Tulsa City Council, Tulsa Police, and the Tulsa 311.

ADATA suffers 700 GB data leak in Ragnar Locker ransomware attack
2021-06-21 15:56

The Ragnar Locker ransomware gang have published download links for more than 700GB of archived data stolen from Taiwanese memory and storage chip maker ADATA. A set of 13 archives, allegedly containing sensitive ADATA files, have been publicly available at a cloud-based storage service, at least for some time. On Saturday, the ransomware actor published on their leak site the download links to a new set of ADATA corporate documents, warning interested parties that the links would not survive for long.

Data leak marketplace pressures victims by emailing competitors
2021-06-21 15:13

The Marketo data theft marketplace is applying maximum pressure on victims by emailing their competitors and offering sample packs of the stolen data. The data sold on these sites are obtained through the marketplace's own attacks, from other threat actors, or by collecting data released in other attacks, such as ransomware or website data breaches.

Alibaba suffers billion-item data leak of usernames and mobile numbers
2021-06-16 03:14

Alibaba's Chinese shopping operation Taobao has suffered a data breach of over a billion data points including usernames and mobile phone numbers. Both reports state that a developer created a crawler that was able to reach beneath information available to the human eye on Taobao, and that the crawler operated for several months before Alibaba noticed the effort.

Reality Winner, NSA Contractor in Leak Case, Out of Prison
2021-06-15 13:24

A former government contractor who was given the longest federal prison sentence imposed for leaks to the news media has been released from prison to home confinement, a person familiar with the matter told The Associated Press on Monday. Reality Winner, 29, has been moved to home confinement and remains in the custody of the federal Bureau of Prisons, the person said.

Baby Clothes Giant Carter’s Leaks 410K Customer Records
2021-06-11 18:29

Baby clothes retailer Carter's inadvertently exposed the personal data of hundreds of thousands of its customers, dating back years, according to a new disclosure. The Linc system was delivering customers shortened URLs with Carter's purchase and shipping details without basic security protections.