Now he’s got two years behind bars to think about his bad choices. An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer’s computer network after allegedly using his company-issued laptop to watch pornography. Miklos Daniel Brody, 38, of San Francisco,Continue reading “Cloud engineer wreaks havoc on bank network after getting fired.”
Category Archives: Hack
FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.
The FBI has issued guidance for SEC data breach reporting requirements and how disclosures can be delayed. The FBI has issued guidance regarding the data breach reporting requirements of the Securities and Exchange Commission (SEC), providing useful information on how disclosures can be delayed. The SEC announced in late July that it had adopted new cybersecurityContinue reading “FBI Issues Guidance for Delaying SEC-Required Data Breach Disclosure.”
BazarCall attacks abuse Google Forms to legitimize phishing emails.
A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. BazarCall, first documented in 2021, is a phishing attack utilizing an email resembling a payment notification or subscription confirmation to security software, computer support, streaming platforms, and other well-known brands. TheseContinue reading “BazarCall attacks abuse Google Forms to legitimize phishing emails.”
Apache has warned customers of a critical remote code execution (RCE) vulnerability in its popular Struts 2 framework.
Apache Struts 2 is an open-source web application framework for developing Java EE web applications. The new vulnerability, CVE-2023-50164, has been given a maximum severity rating and affects Struts 2.0.0-2.3.37 (EOL), Struts 2.5.0-2.5.32, and Struts 6.0.0-6.3.0. “An attacker can manipulate file upload parameters to enable path traversal and under some circumstances this can lead toContinue reading “Apache has warned customers of a critical remote code execution (RCE) vulnerability in its popular Struts 2 framework.”
10,000 people’s data stolen in genetic testing company Asper Biogene leak.
Personal and health data belonging to approximately 10,000 people has been illegally downloaded from the Tartu-based genetic testing company Asper Biogene’s database, the State Prosecutor’s Office said on Thursday. Those affected are in the process of being notified. A criminal investigation has been launched by the Southern Prefectural Criminal Bureau which is in the processContinue reading “10,000 people’s data stolen in genetic testing company Asper Biogene leak.”
Nissan Restoring Systems After Cyberattack.
Nissan Oceania says it has been working on restoring its systems after falling victim to a cyberattack. Japanese car manufacturer Nissan has disclosed a cyberattack impacting the internal systems at Nissan Oceania. A regional division of the multinational carmaker, Nissan Oceania is responsible for the company’s operations in Australia and New Zealand. Nissan Oceania disclosedContinue reading “Nissan Restoring Systems After Cyberattack.”
Report: 2.6 billion personal records compromised by data breaches in past two years — underscoring need for end‑to‑end encryption.
An Apple study shows that threats to consumer data stored in the cloud have grown dramatically since the last report was published in December 2022. Earlier this week Apple published an independent study conducted by Massachusetts Institute of Technology professor Dr. Stuart Madnick that found clear and compelling proof that data breaches have become anContinue reading “Report: 2.6 billion personal records compromised by data breaches in past two years — underscoring need for end‑to‑end encryption.”
Intelligence forecast sees ransomware, third-party vendors as major 2024 threats.
ZeroFox predicts that attackers will increase their use of initial access brokers, or IABs, to hack into systems. A new intelligence risk forecast from cybersecurity firm ZeroFox predicts that 2024 will be more of the same for ransomware and AI—and that threat actors are likely to focus on third party vendors as access points forContinue reading “Intelligence forecast sees ransomware, third-party vendors as major 2024 threats.”
New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices.
A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS and iOS devices. Tracked as CVE-2023-45866, the issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. “Multiple Bluetooth stacks have authenticationContinue reading “New Bluetooth Flaw Let Hackers Take Over Android, Linux, macOS, and iOS Devices.”
Your mobile password manager might be exposing your credentials.
A number of popular mobile password managers are inadvertently spilling user credentials due to a vulnerability in the autofill functionality of Android apps. The vulnerability, dubbed “AutoSpill,” can expose users’ saved credentials from mobile password managers by circumventing Android’s secure autofill mechanism, according to university researchers at the IIIT Hyderabad, who discovered the vulnerability and presented theirContinue reading “Your mobile password manager might be exposing your credentials.”

You must be logged in to post a comment.