Infosec News

InfoSec News 20220404

  • Publicado: Seg, 04/04/2022 - 14:02

Top News


  • UK Police charges two teenagers for their alleged role in the Lapsus$ extortion group

"The City of London Police charged two of the seven teenagers who were arrested for their alleged role in the LAPSUS$ data extortion gang.
The duo has been released on bail after appearing in the Highbury Corner Magistrates Court court on Friday."

Link

InfoSec News 20220401

  • Publicado: Sex, 01/04/2022 - 12:31

Top News


  • Security Patch Releases for Critical Zero-Day Bug in Java Spring Framework

"The maintainers of Spring Framework have released an emergency patch to address a newly disclosed remote code execution flaw that, if successfully exploited, could allow an unauthenticated attacker to take control of a targeted system.

InfoSec News 20220331

  • Publicado: Qui, 31/03/2022 - 12:40

Top News


  • Hackers Got User Data From Meta With Forged Request

"Facebook owner Meta gave user information to hackers who pretended to be law enforcement officials last year, a company source said Wednesday, highlighting the risks of a measure used in urgent cases.
Imposters were able to get details like physical addresses or phone numbers in response to falsified "emergency data requests," which can slip past privacy barriers, said the source who requested anonymity due to the sensitivity of the matter."

InfoSec News 20220330

  • Publicado: Qua, 30/03/2022 - 11:35

Top News


  • Dona do Continente confirma ataque informático nas últimas horas

"Esta madrugada a Sonae MC, dona das lojas Modelo e dos hipermercados Continente, foi alvo de um ataque informático, já confirmado pela própria empresa. “A MC confirma que se verificou um ataque informático nos sistemas, que está a afetar algumas comunicações nos sites comerciais e alguns serviços em loja”, refere um comunicado citado pela agência Lusa.

InfoSec News 20220329

  • Publicado: Ter, 29/03/2022 - 14:02

Top News


  • Ukrtelecom, a major mobile service and internet provider in Ukraine, foiled a “massive” cyberattack that hit its infrastructure

"On March 29, 2022, a massive cyber attack caused a major internet disruption across Ukraine on national provider Ukrtelecom. According to global internet monitor service NetBlock, real-time network data showed connectivity collapsed to 13% of pre-war levels.
The attack caused the most severe destruction observed since the invasion of the country by Russia."

InfoSec News 20220328

  • Publicado: Seg, 28/03/2022 - 11:44

Top News


  • FCC adds Kaspersky to Covered List due to unacceptable risks to national security

"The Federal Communications Commission (FCC) added multiple Kaspersky products and services to its Covered List saying that they pose unacceptable risks to U.S. national security.

InfoSec News 20220325

  • Publicado: Sex, 25/03/2022 - 09:30

Top News


  • Over 100 Building Controllers in Russia Vulnerable to Remote Hacker Attacks

"A researcher has identified critical vulnerabilities that can allegedly be exploited to remotely hack a building controller predominantly used by organizations in Russia."

Link

TLP1 : Green

InfoSec News 20220324

  • Publicado: Qui, 24/03/2022 - 12:18

Top News


  • Anonymous claims to have hacked the Central Bank of Russia

"The Anonymous hacker collective claims to have hacked the Central Bank of Russia and stole accessed 35,000 documents.
Anonymous continues to target Russian government organizations and private businesses, now it is claiming to have hacked the Central Bank of Russia.
The popular hacker collective claims to have compromised the systems of the Central Bank of Russia and stole 35,000 files, it announced that will leak it it in 48 hours.

InfoSec News 20220323

  • Publicado: Qua, 23/03/2022 - 13:02

Top News


  • A new wave of DeadBolt Ransomware attacks hit QNAP NAS devices

"Internet search engine Censys reported that QNAP devices were targeted in a new wave of DeadBolt ransomware attacks.
Since January, DeadBolt ransomware operators are targeting QNAP NAS devices worldwide, its operators claim the availability of a zero-day exploit that allows them to encrypt the content of the infected systems.

InfoSec News 20220322

  • Publicado: Ter, 22/03/2022 - 13:06

Top News


  • Follow-up: Lapsus$ extortion gang leaked the source code for some Microsoft projects

"(...) On Sunday, the Lapsus$ gang announced to have compromised Microsoft’s Azure DevOps server and shared a screenshot of alleged internal source code repositories.One of the repositories contains the source code for Cortana and other Bing projects (e.g. ‘Bing_STC-SV’, ‘Bing_Test_Agile’, and “Bing_UX’).

Páginas