A big data breach has put the personal information of at least 1.8 million patients at risk. Hackers were in the healthcare network for months from November last year to February. They quietly copied very sensitive files before anyone found out. The stolen data includes medical records, payment info, ID …
Read More »GitHub Internal Source Code Repo Compromised via malicious VSCode extension
GitHub said that about 3,800 internal repositories were hacked because of installing a harmful VS code extension by an employee. “Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response …
Read More »Hackers Exploit Entra ID Accounts to Steal Microsoft 365, Azure Data
Hackers misuse Microsoft Entra ID accounts to steal data from Microsoft 365 and Azure. A very advanced cyberattack by a group called Storm-2949 is aiming at Microsoft Entra ID accounts to take sensitive data from Microsoft 365 and Azure. Storm-2949 used real cloud management tools to get deep access to …
Read More »
CIRT ALERT
New AsyncRAT malware campaign detected in Bangladesh cyber space
BGD e-GOV CIRT found a cyber-attack campaign using AsyncRAT (Asynchronous Remote Access Trojan) aimed at Bangladesh. Threat analysis shows that the website ck44jili[.]com is a main Control Center (C2) for the AsyncRAT malware. The campaign mixes malware, remote access, and fake financial tricks. Attackers hide harmful files as real software …
Read More »NVIDIA reports GeForce NOW breach affecting Armenian users
BleepingComputer reported NVIDIA has confirmed in a statement that GeForce NOW user information has been exposed in a data breach. The big gaming and hardware company said the effect is only in Armenia and happened because a regional partner’s system was compromised. The company added that its own network was …
Read More »Trellix Confirm Source Code repository Breach
Trellix reported a security flaw that impacted part of its source code repository, but the company states there is no evidence of code being used wrongly. It quickly started a probe with experts and informed the law enforcement agency. “Trellix recently identified unauthorized access to a portion of our source …
Read More »Hacker claims to steal Standard Bank 1.2TB data
A hacker claimed that 1.2TB of private data stolen from Standard Bank, including client credit card details, will be shared online in stages. The bank, the largest in South Africa by assets, was breached in late February, with the hacker known as “ROOTBOY” claiming that they spent “just over three …
Read More »10 PB of Data allegedly breach from China’s Tianjin Supercomputer Center
Hackers are claiming that one of China’s most strategically important computing facilities suffered a massive cyber intrusion, with more than 10 petabytes of sensitive information allegedly taken from a state-run supercomputing environment that experts suspect is the National Supercomputing Center in Tianjin. If true, this event might be one of …
Read More »
CERT-EU report
European Commission hack leaks 30 EU entities 90 GB data
The EU’s cybersecurity agency said on Thursday that a recent hack and data leak at the EU was done by a cybercriminal group called TeamPCP. In a new report, CERT-EU said that hackers exfiltrated about 92 gigabytes of data from an Amazon Web Services (AWS) account linked to the European …
Read More »Threat Actor Claims to breach Adobe: Leaking 13M Records
A bad actor named “Mr. Raccoon” claims to breach Adobe leaking 13 million support tickets with personal data, 15,000 employee records, all HackerOne bug bounty reports, and various internal documents, as stated in a report by International Cyber Digest. The threat actor said the intrusion didn’t start inside Adobe. Instead, …
Read More »
InfoSecBulletin Cybersecurity for mankind