Infosecurity News
Freecycle Breach May Have Hit Millions of Users
Non-profit urges all users to reset passwords
Python Package Index Targeted Again By VMConnect
ReversingLabs uncovered three additional malevolent packages believed to be part of the campaign
New Attack Technique “MalDoc in PDF” Alarms Experts
JPCERT/CC said it can elude detection by embedding a malicious Word file within a PDF document
Medical Data Breach: Ayush Jharkhand Hacked
According to CloudSEK, the leaked database contains over 320,000 patient records
Sensitive Data about UK Military Sites Potentially Leaked by LockBit
Zaun, the UK’s only manufacturer of fencing systems, saw its IT systems being compromised in early August
Sydney University Suffers Supply Chain Breach
Blast radius appears limited to international students
Four Convicted in $18m Investment Fraud Scheme
The Brittingham Group promised outsized returns to victims
Suffolk High School Forced Offline After Cyber-Attack
Separate research warns of widespread email security failings
Smishing Triad: China-Based Fraud Network Exposed
Resecurity explained the “Smishing Triad” campaign exclusively utilizes iMessages
Open-Source Malware SapphireStealer Expands
Cisco Talos said SapphireStealer has evolved significantly, resulting in multiple variants
Sophisticated Cyber-Espionage Group Earth Estries Exposed
Trend Micro noted that “Earth Estries” employed advanced tactics to infiltrate networks
Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Although the patches for these vulnerabilities have already been released, public attacks are still occurring
BYOD Security Gap: Survey Finds 49% of European Firms Unprotected
Jamf suggested firms enroll employees in a BYOD or Mobile Device Management (MDM) program
New Research Exposes Airbnb as Breeding Ground For Cybercrime
Slashnext unveiled a disturbing arsenal of stealers, cookies and exploits
Facebook Accounts Targeted by Vietnamese Threat Groups
These groups often sell ads to other cybercriminals, either for a fee or a share of the operations
GRU Blamed for Infamous Chisel Malware Targeting Ukraine's Military Phones
Infamous Chisel, which enables unauthorized access to compromised Android devices used by the Ukrainian military, has been linked to Sandworm
Russian APT Intensifies Cyber Espionage Activities Amid Ukrainian Counter-Offensive
The Gamaredon group has ramped up attacks against Ukrainian military entities, with the aim of hindering Ukraine’s counter-offensive operations
Classiscam Spreads: $64.5M Scheme Targets 79 Countries
Group-IB’s analysis showed that between H1 2021 and H1 2023, 251 brands were targeted by Classiscam
Flaw Exposes WP Migration Plugin to Hacks
The vulnerable code was identified by the security research team at PatchStack
Chinese APT Group GREF Use BadBazaar in Android Espionage
ESET said BadBazaar was available via the Google Play Store, Samsung Galaxy Store and various app sites