Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mailchimp says it was hacked, again

Mailchimp says it was hacked, againPost Views: 86 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Hacked, againMailchimp, a company that specializes in email marketing and newsletters, has announced that it was hacked and that dozens of customers’ data was exposed. This is the second time the company has been hacked in the past six months, with the current incident being almost identical to the previous one.

The company says that its security team detected an intruder on January 11th accessing one of its internal tools used by Mailchimp customer support and account administration.

The hacker targeted Mailchimp’s employees and contractors with a social engineering attack, in which they used manipulation techniques to gain private information, like passwords.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses ​133 Customer accounts compromisedThe hacker then used those compromised employee passwords to gain access to data on 133 Mailchimp accounts, which the company notified of the intrusion. One of the targeted accounts belongs to e-commerce giant WooCommerce.

While WooCommerce states that there is no indication that the stolen data has been misused, threat actors commonly use this type of data for targeted phishing attacks to steal credentials or install malware.
Trending: Common and Uncommon types of SQL Injection Trending: Offensive Security Tool: Freeze MailChimp’sresponseThe marketing company confirmed that this data was being used in phishing emails but declined to share more information about the attacks.

It is not immediately clear who, if anyone, is responsible for cybersecurity at Mailchimp following the departure of its chief information security officer.
Trending: Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: techcrunch.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-5-2-300x150.png Git patches two critical remote code execution security flawsJanuary 18, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-4-2-300x150.png MSI accidentally breaks Secure Boot for hundreds of motherboardsJanuary 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-10-300x150.png PoC exploits released for critical bugs in popular WordPress pluginsJanuary 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-8-300x150.png Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawJanuary 13, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Mailchimp says it was hacked, again first appeared on Black Hat Ethical Hacking.
Dark Reading: Attacks/Breaches
Name That Toon: Poker Hand

Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
The Media Industry Is the Most Vulnerable to Cyber Attacks, Report Shows

The report highlights concerning security stats following two years of extreme tech growth.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SecurityGen Identifies the Cybersecurity Priorities for Mobile Operators in 2023

Open architecture, non-standalone roaming, nation-state attacks, ransomware, and the need for more industry collaboration are among the major 5G security challenges that operators must address in the year ahead.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
KnowBe4 to Offer $10,000 Women in Cybersecurity Scholarship and (ISC) 2 Certification Education Package

KnowBe4 partners with the Center for Cyber Safety and Education to bolster women
in cybersecurity for the fourth consecutive year.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
International Council of E-Commerce Consultants Launches Cybersecurity Essentials Professional Certificate Program on edX

New program enables students and early career professionals to learn critical skills required in today's entry-level cybersecurity field, helping address urgent cyber workforce jobs gap.
Dark Reading: Attacks/Breaches
Ethically Exploiting Vulnerabilities: A Play-by-Play

There's a fine line between a hacker and an attacker, but it pays to be proactive. Consider tests by ethical hackers, a red team, or pen testers, and then bolster your company's defenses against malicious attacks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
New Research From EMA Reveals How Organizations Are Struggling to Develop Secure Software Applications

Research shows that over 50% of organizations performing software development
struggle with fully integrating security into their software development
lifecycle.
Dark Reading: Attacks/Breaches
Cybercriminals Target Telecom Provider Networks

The growing use of mobile devices for MFA and the proliferation of 5G and VoIP in general could result in more attacks in future, experts say.
Dark Reading: Attacks/Breaches
As Social Engineering Tactics Change, So Must Your Security Training

Craft specific awareness training for high-exposure teams like finance, and reinforce other critical awareness training across the organization.
Dark Reading: Attacks/Breaches
Data Security in Multicloud: Limit Access, Increase Visibility

Ensuring that data can be easily discovered, classified, and secured is a crucial cornerstone of a data security strategy.