Security News

Hacker leak payment data from defunct WeLeakInfo breach site
2021-03-16 19:03

The now-defunct WeLeakInfo data breach site has suffered its own data breach after a threat actor leaked the service's payment information and customer info. Last Thursday, a threat actor released an archive of payment processing data used by WeLeakInfo when processing payments through Stripe.

Hackers leak payment data from defunct WeLeakInfo breach site
2021-03-16 19:03

The now-defunct WeLeakInfo data breach site has suffered its own data breach after a threat actor leaked the service's payment information and customer info. Last Thursday, a threat actor released an archive of payment processing data used by WeLeakInfo when processing payments through Stripe.

As attacks on Exchange servers escalate, Microsoft investigates potential PoC exploit leak
2021-03-15 13:00

Microsoft Exchange servers around the world are still getting compromised via the ProxyLogon and three other vulnerabilities patched by Microsoft in early March. A. Human operated ransomware attacks are utilizing the Microsoft Exchange vulnerabilities to exploit customers.

WSJ: Microsoft Probing Possible PoC Exploit Code Leak
2021-03-12 21:04

Software giant Microsoft Corp. has launched an investigation to determine whether one of its flagship information-sharing programs sprung a leak that led to the widespread exploitation of Exchange server deployments around the world. According to a bombshell report in the Wall Street Journal, Redmond is looking closely at its Microsoft Active Protections Program to figure out if an anti-malware partner in China leaked proof-of-concept code ahead of the availability of security updates.

Intel CPU interconnects can be exploited by malware to leak encryption keys and other info, academic study finds
2021-03-08 01:00

Doctoral student Riccardo Paccagnella, master's student Licheng Luo, and assistant professor Christopher Fletcher, all from the University of Illinois at Urbana-Champaign, delved into the way CPU ring interconnects work, and found they can be abused for side-channel attacks. "It is the first attack to exploit contention on the cross-core interconnect of Intel CPUs," Paccagnella told The Register.

Dutch Research Council (NWO) confirms ransomware attack, data leak
2021-02-25 18:30

The recent cyberattack that forced the Dutch Research Council to take its servers offline and suspend grant allocation processes was caused by the DoppelPaymer ransomware gang. Since NWO does not cooperate with cybercriminals, DoppelPaymer published proof of the stolen internal data on their leak site.

Health Website Leaks 8 Million COVID-19 Test Results
2021-02-25 17:34

Another human-related error - this time a flaw in a health department website in the state of Bengal, India - has exposed the confidential results of COVID-19 tests as well as personally identifying information for an entire geographic region's population. Test results related to more than 8 million people potentially were exposed before the agency fixed the error, according to a security researcher.

Hackers Leak Data Stolen From Jet Maker Bombardier
2021-02-24 13:44

Just as the cybercriminals behind the Clop ransomware operation made public information supposedly stolen from Canadian business jet manufacturer Bombardier, the company confirmed suffering a data breach. In a Thursday statement, the jet maker revealed that an unauthorized party was able to access and steal data by exploiting a vulnerability in "a third-party file-transfer application." While the company did not say which third-party software was compromised, the general characteristics of the incident suggest it was Accellion's FTA service.

Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet
2021-02-23 21:22

The Clop ransomware gang claims to have stolen documents from aerospace giant Bombardier's defense division - and has leaked what appears to be a CAD drawing of one of its military aircraft products, raising fears over what else they've got. Bombardier confirmed its security had been breached, putting out a public statement only minutes after The Register grilled the Canadian business jet maker on the Clop gang's claims.

Chinese hackers used NSA exploit years before Shadow Brokers leak
2021-02-22 16:26

Chinese state hackers cloned and started using an NSA zero-day exploit almost three years before the Shadow Brokers hacker group publicly leaked it in April 2017. "To our surprise, we found out that this APT31 exploit is in fact a reconstructed version of an Equation Group exploit called 'EpMe'," Check Point said.