Blog
-
DOJ: Kremlin and RT Collaborated on Bot Farm to Spread Social Media Disinformation
The Justice Department says that it has taken down a bot farm run by RT for disinformation campaigns, seizing two domain names and 968 X accounts used to spread these posts.
-
Twilio Backup Carrier Exposed “SMS-Related” Data Via Public Amazon Bucket
A backup carrier for cloud-based communications platform Twilio was found to have an AWS S3 bucket open to the internet for several days, exposing “SMS-related” data including millions of one-time client passwords.
-
Hacking Group Released 39,000 More Print-At-Home Concert Tickets as Ticketmaster Hack Continues to Expand
Hackers responsible for the Ticketmaster hack has released 39,000 more print-at-home concert tickets, and has promised to release millions more if not paid a ransom. Some 166,000 concert tickets for the extremely popular Taylor Swift tour has already been leaked last month.
-
Indonesian National Data Center on the Road to Recovery After “Magnanimous” Provision of Ransomware Decryptor by Hackers
Following a refusal by the Indonesian government to pay an $8 million ransom demand, Brain Cipher has provided the ransomware decryptor along with a request for donations.
-
Authy Data Breach Confirmed by Twilio, Another Unsecured API Endpoint to Blame
Shinyhunters has offered 33 million stolen phone numbers for sale. Twilio has since confirmed the Authy data breach and that the leak occurred due to an improperly secured API endpoint.
-
Optus Data Breach Penalties Hang in the Balance as ACMA Hones in on API Access Control Coding Error
If ACMA had its way, penalties could go as high as $900 million for the Optus data breach. All of that will hinge on a court’s decision on the company’s handling of a coding error in the access control of an API that lingered for years before being exploited.
-
AI Models Under Threat From “Skeleton Key” Attacks That Create Universal Jailbreak Ability
The skeleton key approach gets its moniker from its ability to work across multiple LLMs, with the same jailbreak statement or one that is only slightly modified. The ball is now in the courts of the developers of AI models to stop it.
-
New OpenSSH Vulnerability Could Be Exploited for RCE
The current OpenSSH vulnerability is the discovery of security researchers and not yet in the wild, but it is expected that threat actors will figure it out before long. The issue would provide an attacker with RCE ability and should be addressed immediately.
-
Teamviewer Security Breach Update: Russian APT Group Behind SolarWinds Named as Suspect
Teamviewer has now confirmed that a Russian APT group is the likely culprit in a security breach that impacted the “corporate environment” of its company.
-
US Federal Reserve Wasn’t Hacked? LockBit’s Stolen Data Was Taken From a Single Bank
Without juicy US Federal Reserve stolen data on offer, this appears to be a more run-of-the-mill breach, albeit one that does look to contain sensitive financial information. The silver lining is that such an audacious lie points to LockBit being on the ropes.










