Tuesday , September 17 2024

International

Canadian cloud accounting unicorn leaks WordPress admin credentials

A popular accounting software provider with over 30 million users leaked their WordPress admins’ credentials, source code, and server backups, risking threat actors hijacking their website. Founded in 2003, FreshBooks is a Canadian-based company providing invoicing, expenses, payments, and financial reporting services. The company claims to have more than 30 …

Read More »

How the Last Big Breach Will Help You Prepare for the Next Cyber Crisis

Security teams ought to seize on the opportunities of failures of the past to make meaningful change in how we approach incident response, urged Sarah Armstrong-Smith, chief security advisor at Microsoft, during UK Cyber Week 2023. Learning lessons from the past is crucial to developing an effective incident response strategy in …

Read More »

GoAnywhere Zero-Day Attack Hits Major Orgs

More organizations are emerging to confirm impact from the newly disclosed in-the-wild zero-day exploits hitting Fortra’s GoAnywhere managed file transfer (MFT) software. Tracked as CVE-2023-0669, the vulnerability was publicly disclosed in early February alongside zero-day exploitation and a patch was released a week later. Soon after, attacks targeting the security defect were linked to …

Read More »

Western Digital has shut down several of its services after detecting a security breach on its network, the digital storage giant announced on Monday. The service outage, announced on April 2, impacts cloud, proxy, web, authentication, email, and push notification services, including My Cloud, My Cloud Home (Duo), My Cloud OS5, …

Read More »

3CX supply chain attack appears to have been conducted by North Korean hackers with the goal of targeting cryptocurrency firms.

More information has come to light on the recent 3CX supply chain attack, which appears to have been conducted by North Korean hackers with the goal of targeting cryptocurrency companies. Cybersecurity firm Kaspersky has conducted its own analysis of the incident and found links to attacks observed by the company back in …

Read More »

FBI Cracks Down on Genesis Market: 119 Arrested in Cybercrime Crackdown

A coordinated international law enforcement operation has dismantled Genesis Market, an illegal online marketplace that specialized in the sale of stolen credentials associated with email, bank accounts, and social media platforms. Coinciding with the infrastructure seizure, the major crackdown, which involved authorities from 17 countries, culminated in 119 arrests and …

Read More »

Mozilla Foundation Releases New Advisory on Thunderbird Vulnerability

Mozilla Foundation has released a security advisory detailing a high-impact vulnerability fixed in the latest version of their email client, Thunderbird.  According to the advisory, Thunderbird version 102.9.1 fixes a vulnerability, CVE-2023-28427, that could allow a denial-of-service attack for Thunderbird users who use the Matrix chat protocol. The vulnerability was reported by the …

Read More »

British Outsourcing Giant Capita Disrupted by Online Attack

British outsourcing service provider Capita, which has major U.K. healthcare and military contracts, confirmed an online attack is behind ongoing IT failures for some of its customers. Capita “experienced a cyber incident primarily impacting access to internal Microsoft Office 365 applications,” the company said in a statement published by the London Stock …

Read More »