my personal bug bounty to-do itemsContinue reading on Medium » (https://ermclm.medium.com/starting-my-path-to-bug-hunter-16ac700f3084?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mailchimp says it was hacked, again
Mailchimp says it was hacked, againPost Views: 86 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Hacked, againMailchimp, a company that specializes in email marketing and newsletters, has announced that it was hacked and that dozens of customers’ data was exposed. This is the second time the company has been hacked in the past six months, with the current incident being almost identical to the previous one.
The company says that its security team detected an intruder on January 11th accessing one of its internal tools used by Mailchimp customer support and account administration.
The hacker targeted Mailchimp’s employees and contractors with a social engineering attack, in which they used manipulation techniques to gain private information, like passwords.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 133 Customer accounts compromisedThe hacker then used those compromised employee passwords to gain access to data on 133 Mailchimp accounts, which the company notified of the intrusion. One of the targeted accounts belongs to e-commerce giant WooCommerce.
While WooCommerce states that there is no indication that the stolen data has been misused, threat actors commonly use this type of data for targeted phishing attacks to steal credentials or install malware.
Trending: Common and Uncommon types of SQL Injection Trending: Offensive Security Tool: Freeze MailChimp’sresponseThe marketing company confirmed that this data was being used in phishing emails but declined to share more information about the attacks.
It is not immediately clear who, if anyone, is responsible for cybersecurity at Mailchimp following the departure of its chief information security officer.
Trending: Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: techcrunch.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-5-2-300x150.png Git patches two critical remote code execution security flawsJanuary 18, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-4-2-300x150.png MSI accidentally breaks Secure Boot for hundreds of motherboardsJanuary 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-10-300x150.png PoC exploits released for critical bugs in popular WordPress pluginsJanuary 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-8-300x150.png Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawJanuary 13, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Mailchimp says it was hacked, again first appeared on Black Hat Ethical Hacking.
Mailchimp says it was hacked, again
Mailchimp says it was hacked, againPost Views: 86 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Hacked, againMailchimp, a company that specializes in email marketing and newsletters, has announced that it was hacked and that dozens of customers’ data was exposed. This is the second time the company has been hacked in the past six months, with the current incident being almost identical to the previous one.
The company says that its security team detected an intruder on January 11th accessing one of its internal tools used by Mailchimp customer support and account administration.
The hacker targeted Mailchimp’s employees and contractors with a social engineering attack, in which they used manipulation techniques to gain private information, like passwords.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 133 Customer accounts compromisedThe hacker then used those compromised employee passwords to gain access to data on 133 Mailchimp accounts, which the company notified of the intrusion. One of the targeted accounts belongs to e-commerce giant WooCommerce.
While WooCommerce states that there is no indication that the stolen data has been misused, threat actors commonly use this type of data for targeted phishing attacks to steal credentials or install malware.
Trending: Common and Uncommon types of SQL Injection Trending: Offensive Security Tool: Freeze MailChimp’sresponseThe marketing company confirmed that this data was being used in phishing emails but declined to share more information about the attacks.
It is not immediately clear who, if anyone, is responsible for cybersecurity at Mailchimp following the departure of its chief information security officer.
Trending: Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: techcrunch.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-5-2-300x150.png Git patches two critical remote code execution security flawsJanuary 18, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-4-2-300x150.png MSI accidentally breaks Secure Boot for hundreds of motherboardsJanuary 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-10-300x150.png PoC exploits released for critical bugs in popular WordPress pluginsJanuary 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-8-300x150.png Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawJanuary 13, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Mailchimp says it was hacked, again first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
The Media Industry Is the Most Vulnerable to Cyber Attacks, Report Shows
The report highlights concerning security stats following two years of extreme tech growth.
The Media Industry Is the Most Vulnerable to Cyber Attacks, Report Shows
The report highlights concerning security stats following two years of extreme tech growth.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SynSaber Releases ICS Vulnerabilities & CVEs Report Covering Second Half of 2022
ICS/OT cybersecurity firm finds 35% of CVEs in second half of 2022 unpatchable.
SynSaber Releases ICS Vulnerabilities & CVEs Report Covering Second Half of 2022
ICS/OT cybersecurity firm finds 35% of CVEs in second half of 2022 unpatchable.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SecurityGen Identifies the Cybersecurity Priorities for Mobile Operators in 2023
Open architecture, non-standalone roaming, nation-state attacks, ransomware, and the need for more industry collaboration are among the major 5G security challenges that operators must address in the year ahead.
SecurityGen Identifies the Cybersecurity Priorities for Mobile Operators in 2023
Open architecture, non-standalone roaming, nation-state attacks, ransomware, and the need for more industry collaboration are among the major 5G security challenges that operators must address in the year ahead.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
KnowBe4 to Offer $10,000 Women in Cybersecurity Scholarship and (ISC) 2 Certification Education Package
KnowBe4 partners with the Center for Cyber Safety and Education to bolster women
in cybersecurity for the fourth consecutive year.
KnowBe4 to Offer $10,000 Women in Cybersecurity Scholarship and (ISC) 2 Certification Education Package
KnowBe4 partners with the Center for Cyber Safety and Education to bolster women
in cybersecurity for the fourth consecutive year.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
International Council of E-Commerce Consultants Launches Cybersecurity Essentials Professional Certificate Program on edX
New program enables students and early career professionals to learn critical skills required in today's entry-level cybersecurity field, helping address urgent cyber workforce jobs gap.
International Council of E-Commerce Consultants Launches Cybersecurity Essentials Professional Certificate Program on edX
New program enables students and early career professionals to learn critical skills required in today's entry-level cybersecurity field, helping address urgent cyber workforce jobs gap.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Research From EMA Reveals How Organizations Are Struggling to Develop Secure Software Applications
Research shows that over 50% of organizations performing software development
struggle with fully integrating security into their software development
lifecycle.
New Research From EMA Reveals How Organizations Are Struggling to Develop Secure Software Applications
Research shows that over 50% of organizations performing software development
struggle with fully integrating security into their software development
lifecycle.