Security News

Egregor Claims Responsibility for Barnes & Noble Attack, Leaks Data
2020-10-21 15:30

The Egregor ransomware gang has reportedly taken responsibility for the Barnes & Noble cyberattack, first disclosed on Oct. 15. The bookseller warned last week that it had been hacked in emailed notices to customers, noting that a cyberattack happened on Oct. 10, "Which resulted in unauthorized and unlawful access to certain Barnes & Noble corporate systems."

Pharma Giant Pfizer Leaks Customer Prescription Info, Call Transcripts
2020-10-20 16:20

UPDATE. Pharma giant Pfizer has leaked the private medical data of prescription-drug users in the U.S. for months or even years, thanks to an unprotected Google Cloud storage bucket. Some of the transcripts were related to conversations about Advil, which is manufactured by Pfizer in a joint venture with GlaxoSmithKline.

ThunderX Ransomware rebrands as Ranzy Locker, adds data leak site
2020-10-16 16:07

ThunderX has changed its name to Ranzy Locker and launched a data leak site where they shame victims who do not pay the ransom. The ransomware operators quickly fixed their bugs and released a new version of the ransomware under Ranzy Locker name.

Broadvoice Leak Exposes 350M Records, Personal Voicemail Transcripts
2020-10-15 14:46

Because its technology underpins these customers' basic interactions with patients, clients, partners, suppliers and others, plenty of personal data flows through Broadvoice's cloud-based systems. The cache of data included records with personal details of Broadvoice clients' customers, they noted.

Software AG hit with ransomware: Crooks leak staffers' passports, want millions for stolen files
2020-10-09 17:40

Software AG has seemingly been hit by ransomware, with the German IT giant itself telling the Euro nation's stock market it had been "Affected by a malware attack." In a notification to the German stock market published earlier this week, Software AG said: "The IT infrastructure of Software AG is affected by a malware attack since the evening of 3 October 2020.".

85% of COVID-19 tracking apps leak data
2020-09-30 03:30

All 100 apps were analyzed using an array of static application security testing and dynamic application security testing techniques based on the OWASP mobile app security guidelines. The vast majority of medical apps have mishandled and/or weak encryption that puts them at risk for data exposure and IP theft.

Twitter Says Bug Leading to API Key Leak Patched
2020-09-28 08:52

Twitter last week started sending emails to developers to inform them of a vulnerability that might have resulted in the disclosure of developer information, including API keys. Designed to provide developers using the Twitter platform and APIs with access to documentation, community discussion, and other type of information, the portal also offers app and API key management functionality.

Microsoft claims to love open source – this alleged leak of Windows XP code is probably not what it had in mind, tho
2020-09-25 18:39

The source code for Windows XP and other elderly Microsoft operating systems appears to have leaked online as the mega-corp's Ignite developer shindig came to an end. The source of the alleged code leak is unclear; a torrent for the archive popped up on internet armpit 4chan and contains what appears to be Windows XP Service Pack 1, as well as some other past-their-sell-by-date flavours of Microsoft's greatest hits.

Microsoft leaks 6.5TB in Bing search data via unsecured Elastic server. *Insert 'Wow... that much?' joke here*
2020-09-23 13:51

Microsoft earlier this month exposed a 6.5TB Elastic server to the world that included search terms, location coordinates, device ID data, and a partial list of which URLs were visited. The data appears to be generated by the Bing mobile app, which promises users "Getting rewarded is easy, just search with the Bing," and has been downloaded more than 10 million times from Google's Play Store at least.

Unprotected Server Leaks Data of Microsoft Bing Mobile App Users
2020-09-22 17:53

WizCase experts have identified an unprotected Elasticsearch server that contained terabytes of data pertaining to users of Microsoft's Bing mobile application. White hat hacker Ata Hakcil, who identified the leak, was able to confirm that the Elasticsearch server belonged to Microsoft's Bing mobile app by installing the application and running a search for WizCase.