■□□□□ Data-Leak: Geico data breach exposed customers' driver's license numbers.
https://www.bleepingcomputer.com/news/security/geico-data-breach-exposed-customers-drivers-license-numbers/
https://www.bleepingcomputer.com/news/security/geico-data-breach-exposed-customers-drivers-license-numbers/
BleepingComputer
Geico data breach exposed customers' driver's license numbers
Car insurance provider Geico has suffered a data breach where threat actors stole the driver's licenses for policyholders for over a month.
■□□□□ United States: The US 🇺🇸 government's response groups for dealing with recent SolarWinds and Microsoft Exchange vulnerabilities have reached the end of the road.
https://www.theregister.com/2021/04/19/federal_solarwinds_investigation/
https://www.theregister.com/2021/04/19/federal_solarwinds_investigation/
The Register
Who knew Uncle Sam had strike teams for SolarWinds, Exchange flaws? Well, anyway, they are disbanded
Lessons learned and mission accomplished, apparently
■■■■■ North Korea 🇰🇵: Lazarus APT Hackers are now using BMP images to hide RAT malware.
https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html
https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html
■□□□□ KubiScan - A Tool To Scan Kubernetes Cluster For Risky Permissions.
https://github.com/cyberark/KubiScan
https://github.com/cyberark/KubiScan
GitHub
GitHub - cyberark/KubiScan: A tool to scan Kubernetes cluster for risky permissions
A tool to scan Kubernetes cluster for risky permissions - cyberark/KubiScan
■□□□□ Mobile malware analysis.
https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study
https://blog.nviso.eu/2021/04/19/how-to-analyze-mobile-malware-a-cabassous-flubot-case-study
NVISO Labs
How to analyze mobile malware: a Cabassous/FluBot Case study
This blogpost explains all the steps I took while analyzing the Cabassous/FluBot malware. I wrote this while analyzing the sample and I’ve written down both successful and failed attempts at …
■□□□□ Internal Facebook email reveals intent to frame data scraping as ‘normalized, broad industry issue’.
https://www.zdnet.com/article/facebook-internal-email-reveals-intent-to-frame-data-scraping-as-broad-industry-issue-and-normalized
https://www.zdnet.com/article/facebook-internal-email-reveals-intent-to-frame-data-scraping-as-broad-industry-issue-and-normalized
ZDNET
Internal Facebook email reveals intent to frame data scraping as ‘normalized, broad industry issue’
Updated: More scraping incidents are "expected" in the future.
■■■□□ Pulse Secure VPN zero-day used to hack defense firms, govt organisations.
https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/
https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/
BleepingComputer
Pulse Secure VPN zero-day used to hack defense firms, govt orgs
Pulse Secure has shared mitigation measures for a zero-day authentication bypass vulnerability in the Pulse Connect Secure (PCS) SSL VPN appliance actively exploited in attacks against worldwide organizations and focused on US Defense Industrial base (DIB)…
■■□□□ WhatsApp pink malware demo: https://www.instagram.com/reel/CN2tPWGAcrT/?igshid=u85vi5kfhp9n
■□□□□ School District’s Files Leaked in $40m Ransomware Attack.
https://www.infosecurity-magazine.com:443/news/broward-files-leaked-ransomware/
https://www.infosecurity-magazine.com:443/news/broward-files-leaked-ransomware/
Infosecurity Magazine
School District’s Files Leaked in $40m Ransomware Attack
Hackers leak Florida school district’s files online when their ransom demand isn’t met
■□□□□ Over 750,000 Users Downloaded New Billing Fraud Apps From Google Play Store.
https://thehackernews.com/2021/04/over-750000-users-download-new-billing.html
https://thehackernews.com/2021/04/over-750000-users-download-new-billing.html
■■■■■ Hacker (Unkn0wX) hacks a live website and posts his name in as text file as proof.
Asks hackers / pentesters to try to hack a he did.
PoC for hack: http://www.supply.su.ac.th/notice/log.txt
The website hacked belongs to Silpakorn University, Thailand 🇹🇭: https://wikipedia.org/wiki/Silpakorn_University
Asks hackers / pentesters to try to hack a he did.
PoC for hack: http://www.supply.su.ac.th/notice/log.txt
The website hacked belongs to Silpakorn University, Thailand 🇹🇭: https://wikipedia.org/wiki/Silpakorn_University
■■■□□ BetterXencrypt - A Better Version Of Xencrypt - Xencrypt It Self Is A Powershell Runtime Crypter Designed To Evade AVs.
https://github.com/GetRektBoy724/BetterXencrypt
https://github.com/GetRektBoy724/BetterXencrypt
GitHub
GitHub - GetRektBoy724/BetterXencrypt: A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to…
A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs. - GetRektBoy724/BetterXencrypt
■■■■□ Zero-Day Exploits in SonicWall Email Security Lead to Enterprise Compromise.
http://www.fireeye.com/blog/threat-research/2021/04/zero-day-exploits-in-sonicwall-email-security-lead-to-compromise.html
CVE-2021-20021
CVSS: 9.4
Unauthorized administrative account creation
CVE-2021-20022
CVSS: 6.7
Post-authentication arbitrary file upload
CVE-2021-20023
CVSS: 6.7
Post-authentication arbitrary file read
http://www.fireeye.com/blog/threat-research/2021/04/zero-day-exploits-in-sonicwall-email-security-lead-to-compromise.html
CVE-2021-20021
CVSS: 9.4
Unauthorized administrative account creation
CVE-2021-20022
CVSS: 6.7
Post-authentication arbitrary file upload
CVE-2021-20023
CVSS: 6.7
Post-authentication arbitrary file read
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
■■□□□ Data-Leak: Men's social networking website and online dating application Manhunt has suffered a data breach.
According to a security notice filed with the office of the Washington attorney general on April 1, the 20-year-old site was compromised in a cyber-attack that took place in February 2021.
https://www.documentcloud.org/documents/20615089-mhnextllc2021-04-01
According to a security notice filed with the office of the Washington attorney general on April 1, the 20-year-old site was compromised in a cyber-attack that took place in February 2021.
https://www.documentcloud.org/documents/20615089-mhnextllc2021-04-01
■■■■■ Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock.
https://www.mozilla.org/en-US/security/advisories/mfsa2021-16/#CVE-2021-23998
https://threatpost.com/mozilla-fixes-firefox-flaw/165501/
https://www.mozilla.org/en-US/security/advisories/mfsa2021-16/#CVE-2021-23998
https://threatpost.com/mozilla-fixes-firefox-flaw/165501/
Mozilla
Security Vulnerabilities fixed in Firefox 88
cKure
■□□□□ 📢 A file with interesting name is circulating on darknet. @ckure has obtained the file. It contains images of apparent blueprints. We are investigating the credibility and data classification.
■■■■■ Data-Leak of Apple 🍎 via Quanta (supplier).
REvil ransomware group hits Apple supplier Quanta; warns of data leak.
https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/
● The information about this leak was shared initially at https://t.me/cKure/7679 and data was checked by us for authenticity.
REvil ransomware group hits Apple supplier Quanta; warns of data leak.
https://www.hackread.com/revil-ransomware-gang-hits-apple-supplier-quanta/
● The information about this leak was shared initially at https://t.me/cKure/7679 and data was checked by us for authenticity.
Hackread
REvil ransomware gang hits Apple supplier Quanta; warns of data leak
Like us on Facebook @ /HackRead
cKure
■■■□□ Pulse Secure VPN zero-day used to hack defense firms, govt organisations. https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-govt-orgs/
■■□□□ Zero-Day: SA44784 - 2021-04: Out-of-Cycle Advisory: Pulse Connect Secure RCE Vulnerability (CVE-2021-22893)
https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/SA44784/s
https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html
https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/SA44784/s
https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
■□□□□ 📢 Japan 🇯🇵 accuses Chinese 🇨🇳 military of cyber-attacks on its space agency. China