thenewoil, to Cybersecurity
k0nserv, to random

The Church of Sweden(Svenska Kyrkan) was ransomwared on the 23rd of November. This is now being attributed to BlackCat.

Here's a vulnerable server serving a wildcard cert for *.svenskakyrkan.se, last scanned by Shodan on the 23rd. Probably not related at all

majorlinux, to Citrix
@majorlinux@toot.majorshouse.com avatar

Like I always say, update yo stuff!

Comcast held a virtual door open for thieves to steal data - Desk Chair Analysts

https://dcanalysts.net/comcast-held-a-virtual-door-open-for-thieves-to-steal-data/

thenewoil, to Cybersecurity
avoidthehack, to Cybersecurity

Xfinity data breach affects over 35 million people

A fatality.

Data accessed includes customer usernames and passwords.

In some cases data accessed may include:

  • Last 4 of SSN
  • DOBs
  • Secret Questions / Answers exposed

https://www.theverge.com/2023/12/18/24007082/xfinity-data-breach-hack-notice-citrix

AAKL, to Cybersecurity
@AAKL@noc.social avatar
itnewsbot, to security
@itnewsbot@schleuss.online avatar

Xfinity waited 13 days to patch critical Citrix Bleed 0-day. Now it’s paying the price - Enlarge / A Comcast Xfinity service van in San Ramon, California on Feb... - https://arstechnica.com/?p=1992160 &it

brett, to random

has disclosed a -related data breach which affected 35 million customers. The impacted info included names, contact information, last four digits of social security numbers, dates of birth and secret questions and answers.

@GossiTheDog

https://apps.web.maine.gov/online/aeviewer/ME/40/49e711c6-e27c-4340-867c-9a529ab3ca2c.shtml

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

CTS, a cloud provider for legal firms in the UK, who were late patching , have appeared on Cactus ransomware's portal today.

They're offering downloads of CTS customer data.

jos1264, to random
@jos1264@social.skynetcloud.site avatar
h4sh, to random

we need flyers on the streets now

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

Supply-chain ransomware attack causes outages at over 60 credit unions.

Read more in my article on the Tripwire blog: https://www.tripwire.com/state-of-security/supply-chain-ransomware-attack-causes-outages-over-60-credit-unions

matthewskelton, to security
@matthewskelton@mastodon.social avatar

"Payments to ransomware and extortion groups need to be outlawed. I know, I know, it will be hard and there’s a million reasons to argue against it and lots of vested interests who don’t want this. ... I mean it — ransomware payments to these groups need to be outlawed, internationally." - Kevin Beaumont (aka @GossiTheDog )

https://doublepulsar.com/what-it-means-citrixbleed-ransom-group-woes-grow-as-over-60-credit-unions-hospitals-47766a091d4f

GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

This is a longish read but I really go all in on what I think about the ransomware situation and what CitrixBleed signifies in this: https://doublepulsar.com/what-it-means-citrixbleed-ransom-group-woes-grow-as-over-60-credit-unions-hospitals-47766a091d4f

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Just over 60 credit unions across the US are offline due to ransomware at Ongoing Operations LLC, their cloud provider (also known as Cloudworks).

Ongoing Operations failed to patch for .

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

There’s a pretty incredible situation playing out today where a US MSP who look after hospitals has had ransomware actors in their network for a week via , but they’ve been unable to find anybody who has Netscaler credentials to patch still.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

HTC Global Services hit by AlphV/BlackCat. Entry via Caretech, one of their business units. Unpatched for as of today.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Re - I have evidence that a ransomware group and an APT had the exploit on October 23nd, two days before the AssetNote public write up went live.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Qlin ransomware group have claimed Yanfeng, which is entry via . It's holding up vehicle production of Dodge, Jeep
and Chrysler in the US, they stopped two weeks ago due to Yanfeng being a key supplier.

HT @AlvieriD

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇬🇧 University of Manchester Speaks Out on Summer Cyber-Attack
➝ 🔓 🇺🇸 Hacktivists breach U.S. nuclear research lab, steal employee data
➝ 🔓 👀 Sumo Logic Completes Investigation Into Recent Security
➝ 🔓 🇺🇸 Auto parts giant AutoZone warns of data breach
➝ 🔓 🇨🇦 Canadian government discloses data breach after contractor hacks
➝ 🇦🇫 New 'HrServ.dll' Web Shell Detected in Attack Targeting Afghan Government
➝ 🇬🇧 🇰🇷 UK and South Korea: Hackers use zero-day in supply-chain attack
➝ 🇵🇸 🇮🇱 -Linked Using Rust-Powered SysJoker Against
➝ 🇷🇺 😱 “They are tired of him, but they are afraid”: what is known about the leader of the hacker group Killnet
➝ 🇰🇵 N. Korean Hackers Distribute Trojanized Software in Supply Chain Attack
➝ ▶️ 🛒 Play Goes Commercial - Now Offered as a Service to Cybercriminals
➝ 🇮🇳 Indian Hack-for-Hire Group Targeted U.S., , and More for Over 10 Years
➝ 🇷🇺 Russian hackers use feature and exploit to attack embassies
➝ 🇺🇸 🩺 Releases Cybersecurity Guidance for , Public Health Organizations
➝ 🇬🇧 🙏🏻 Thanking the vulnerability research community with Challenge Coins
➝ 🧅 Network Removes Risky Relays Associated With Scheme
➝ 🇺🇦 👋🏻 fires top cybersecurity officials
➝ 🩹 Johnson Controls Patches Critical in Industrial Refrigeration Products
➝ 🦠 🦀 New WailingCrab Loader Spreading via Shipping-Themed Emails
➝ 🦠 📨 New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks
➝ 🦠 🎠 NetSupport Infections on the Rise - Targeting Government and Business Sectors
➝ 🚫 Google will limit ad blockers starting June 2024
➝ 🐛 ☁️ 3 Critical Vulnerabilities Expose Users to Data Breaches
➝ 🔓 ☁️ Researchers Discover Dangerous Exposure of Sensitive Secrets
➝ 🔓 ☝🏻 New Flaws in Fingerprint Sensors Let Attackers Bypass Hello Login
➝ 🔓 🩸 ‘’ vulnerability targeted by nation-state and criminal hackers: CISA
➝ 🐡 Researchers extract RSA keys from server signing errors

📚 This week's recommended reading is: "How I Rob Banks: And Other Such Places" by FC a.k.a. Freakyclown

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-472023

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Restoring toot - it turns out Fidelity National Financial, Inc. and Fidelity National Information Service merged years ago. Both patched late and now have security incidents involving a ransomware group.

image/jpeg

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

LockBit victims currently running incidents with Citrix Netscaler initial entry, by sector: finance, freight, legal, defence

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog, (edited ) to random
@GossiTheDog@cyberplace.social avatar

A ransomware attack on the Industrial and Commercial Bank of China has disrupted the US Treasury market https://www.ft.com/content/8dd2446b-c8da-4854-9edc-bf841069ccb8

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The world’s largest bank, ICBC, are still trying to recover their US clearing house arm over 2 weeks since LockBit gained access via . HT @metacurity

“Two weeks after the attack, the securities arm was still waiting for the all-clear from its cybersecurity consultants to reconnect to the market and Bank of New York Mellon’s automated settlement platform, which sits in the middle of the transactions.”

https://www.wsj.com/finance/banking/icbcs-entree-onto-wall-street-looked-like-a-bargainuntil-hackers-crippled-its-u-s-unit-a69e58ab

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • GTA5RPClips
  • thenastyranch
  • ethstaker
  • everett
  • Durango
  • rosin
  • InstantRegret
  • DreamBathrooms
  • magazineikmin
  • Youngstown
  • mdbf
  • slotface
  • tacticalgear
  • anitta
  • kavyap
  • tester
  • cubers
  • cisconetworking
  • ngwrru68w68
  • khanakhh
  • normalnudes
  • provamag3
  • Leos
  • modclub
  • osvaldo12
  • megavids
  • lostlight
  • All magazines