Infosec News

InfoSec News 20230202

  • Publicado: Qui, 02/02/2023 - 13:44

Top News


  • US Cellular customer data allegedly up for grabs on the dark web

"A treasure trove of customer data, allegedly stolen from mobile carrier US Cellular, has been offered up for free on the dark web.
A dark web hacker claims to have obtained the stolen data belonging to 144 thousand US Cellular mobile customers and is now offering it up for free on the popular black market leak site BreachForums.

InfoSec News 20230201

  • Publicado: Qua, 01/02/2023 - 13:11

Top News


  • PoS malware can block contactless payments to steal credit cards

"New versions of the Prilex point-of-sale malware can block secure, NFC-enabled contactless credit card transactions, forcing consumers to insert credit cards that are then stolen by the malware.
On a payment terminal, contactless transactions use NFC (Near Field Communication) chips embedded in credit cards and mobile devices to conduct close-proximity payments via credit cards, smartphones, or even smartwatches. 

InfoSec News 20230131

  • Publicado: Ter, 31/01/2023 - 14:45

Top News


  • GitHub revokes code signing certificates stolen in repo hack

"GitHub says unknown attackers have stolen encrypted code-signing certificates for its Desktop and Atom applications after gaining access to some of its development and release planning repositories.
So far, GitHub has found no evidence that the password-protected certificates (one Apple Developer ID certificate and two Digicert code signing certificates used for Windows apps) were used for malicious purposes.

InfoSec News 20230130

  • Publicado: Seg, 30/01/2023 - 14:08

Top News


  • Microsoft survey says people are ready for AI tools at workplace

"Microsoft is seemingly preparing to introduce more artificial intelligence (AI) features into its toolkit. Results of a new survey suggest the majority of Western business leaders want to automate daily tasks.

InfoSec News 20230127

  • Publicado: Sex, 27/01/2023 - 12:59

Top News


  • Microsoft urges admins to patch on-premises Exchange servers

"Microsoft urged customers today to keep their on-premises Exchange servers patched by applying the latest supported Cumulative Update (CU) to have them always ready to deploy an emergency security update.
Redmond says that the Exchange server update process is "straightforward" (something that many admins might disagree with) and recommends always running the Exchange Server Health Checker script after installing updates.

InfoSec News 20230126

  • Publicado: Qui, 26/01/2023 - 15:51

Top News


  • Yandex denies hack, blames source code leak on former employee

"A Yandex source code repository allegedly stolen by a former employee of the Russian technology company has been leaked as a Torrent on a popular hacking forum.
Yesterday, the leaker posted a magnet link that they claim are 'Yandex git sources' consisting of 44.7 GB of files stolen from the company in July 2022. These code repositories allegedly contain all of the company's source code besides anti-spam rules."

InfoSec News 20230125

  • Publicado: Qua, 25/01/2023 - 13:11

Top News


  • Microsoft 365 outage takes down Teams, Exchange Online, Outlook

"Microsoft is investigating an ongoing outage impacting multiple Microsoft 365 services after customers have reported experiencing connection issues.
"We're investigating issues impacting multiple Microsoft 365 services. We've identified a potential networking issue and are reviewing telemetry to determine the next troubleshooting steps," the Microsoft 365 team said in a Twitter thread.

InfoSec News 20230124

  • Publicado: Ter, 24/01/2023 - 14:10

Top News


  • Apple iOS 16.3 arrives with support for hardware security keys

"Apple released iOS 16.3 today with long-awaited support for hardware security keys to provide extra protection against phishing attacks and unauthorized access to your devices.
Hardware security keys are small physical devices that resemble thumb drives and support USB-C (using an adapter) or Near-field communication (NFC) to connect to a Mac or iPhone.

InfoSec News 20230123

  • Publicado: Seg, 23/01/2023 - 13:02

Top News


  • Riot Games hacked, delays game patches after security breach

"July. Cisco Talos observed threat actors reacting to these changes by moving away from malicious macros as an initial access method in favor of other types of executable attachments.
Riot Games, the video game developer and publisher behind League of Legends and Valorant, says it will delay game patches after its development environment was compromised last week.

InfoSec News 20230120

  • Publicado: Sex, 20/01/2023 - 15:21

Top News


  • PayPal accounts breached in large-scale credential stuffing attack

"PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data.
Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites.

Páginas