Stolen Data of 533 Million Facebook Users Leaked Online

Stolen Data of 533 Million Facebook Users Leaked Online

The personal data of over 500 million Facebook users has been posted online in a low-level hacking forum. The data includes phone numbers, full names, location, email address, and biographical information. Security researchers warn that the data could be used by hackers to impersonate people and commit fraud. See more stories on Insider’s business page….

North Korean .Gov Hackers Back With Fake Pen-Test Company

North Korean .Gov Hackers Back With Fake Pen-Test Company

A North Korean government-backed APT group has been caught using a fake pen-testing company and a range of sock puppet social media accounts in an escalation of a hacking campaign targeting security research professionals. The notorious hacking group, first exposed by Google earlier this year, returned on March 17th with a website for a fake…

VMware Patches 2 Flaws in vRealize Operations

VMware Patches 2 Flaws in vRealize Operations

Governance & Risk Management , IT Risk Management , Patch Management If Exploited, Flaws Could Open Door to Theft of Admin Credentials Prajeet Nair (@prajeetspeaks) • April 1, 2021     VMware has issued patches for two critical vulnerabilities in its IT operations management platform, vRealize Operations, which, if exploited, could allow attackers to steal…

(ISC)2 calls for greater collaboration off the back of UK Cyber Security Council launch

(ISC)2 calls for greater collaboration off the back of UK Cyber Security Council launch

The UK’s new Cyber Security Council is being urged not to “squander the opportunity” provided by the new organisation. Commissioned by the Department for Digital, Culture, Media and Sport (DCMS), the Cyber Security Council was set up by the members of the Cyber Security Alliance. It’s aim is to serve as a single governing voice…

CVE-2020-9147 – Alert Detail – Security Database

CVE-2020-9147 – Alert Detail – Security Database

Executive Summary Informations Name CVE-2020-9147 First vendor Publication 2021-04-01 Vendor Cve Last vendor Modification 2021-04-01 Security-Database Scoring CVSS v3 Cvss vector : N/A Overall CVSS Score NA Base Score NA Environmental Score NA impact SubScore NA Temporal Score NA Exploitabality Sub Score NA   Calculate full CVSS 3.0 Vectors scores Security-Database Scoring CVSS v2 Cvss…

Booking.com Fined €475,000 For Late Data Breach Reporting

Booking.com Fined €475,000 For Late Data Breach Reporting

The Dutch Data Protection Authority (AP) has imposed a €475,000 fine on Booking.com for reporting a data breach to the AP too late. Cybercriminals exfiltrated the personal data of more than 4,000 customers and they were also able to obtain the credit card details of nearly 300 victims. Source Hackers extracted login credentials of victims’…

OODA Loop – Ubiquiti Shares Dive After Reportedly Downplaying ‘Catastrophic’ Data Breach

OODA Loop – Ubiquiti Shares Dive After Reportedly Downplaying ‘Catastrophic’ Data Breach

New York City- based IoT device maker Ubiquiti recently disclosed a data breach that was downplayed. After news of the catastrophic data breach, the shares of the company fell significantly this week. In January, Ubiquiti informed customers that unauthorized access to some IT systems hosted by a third-party cloud provider occurred. The company said in…

Kansas Man Faces Federal Charges Over Water Treatment Hack

Kansas Man Faces Federal Charges Over Water Treatment Hack

Critical Infrastructure Security , Cybercrime , Fraud Management & Cybercrime DOJ: Wyatt Travnichek Allegedly Accessed Cleaning and Disinfecting System Prajeet Nair (@prajeetspeaks) • April 2, 2021     This is the website of the Ellsworth County Rural Water District in Kansas. The facility was targeted in an attack in 2019, according to the Justice Department….

Scammers steal New Yorkers’ private info for benefits fraud

Scammers steal New Yorkers’ private info for benefits fraud

New York’s Department of Financial Services (DFS) warns of an ongoing series of attacks resulting in the theft of personal information belonging to hundreds of thousands of New Yorkers. The warning follows another alert issued last month describing how this aggressive cybercrime campaign exploits cybersecurity flaws found in public-facing websites to steal Nonpublic Information (NPI). The attacks…

Ubiquiti Shares Dive After Reportedly Downplaying ‘Catastrophic’ Data Breach

Ubiquiti Shares Dive After Reportedly Downplaying ‘Catastrophic’ Data Breach

Shares of New York City-based IoT device maker Ubiquiti (NYSE: UI) fell significantly this week following a report claiming that the recently disclosed data breach was “catastrophic” and that its impact was downplayed. Ubiquiti informed customers in January that it had detected unauthorized access to some IT systems hosted by an unnamed third-party cloud provider….