TRELLO DATA BREACH: PRECAUTIONARY STEPS FOR AFFECTED VICTIMS

In other news, a popular project management tool from Atlassian, Trello, just experienced a serious data breach. According to reports from Hackread.com, the hacker whose alias is “Emo” recently leaked this data on a cybercrime platform called “Breach Forums,” where it was confirmed that a staggering 21.1GB of customer information was lost in this breach. …

The ClickFix Social Engineering Tactic

In May 2024, a new social engineering tactic called ClickFix emerged which involves displaying fake error messages in web browsers to deceive users into copying and executing a given malicious PowerShell Command. According to Proofpoint researchers[1], who named this tactic ClickFix, they reported that the initial access broker TA571 leveraged it in email phishing campaigns …

Calgary Public Library’s Cyber Attack

What happened? On Oct 11th 2024 all 22 locations of public libraries across Calgary was shut down amid a cyber-attack. The early news suspected it to be the ransomware attack endangering public’s crucial data at the hands of attackers. Why was library targeted? “Libraries are a rich target, and the reason that they’re rich target …

Iranian Cyber Actors Target Critical Infrastructure Sectors

Brute force attacks are currently on the rise and constantly evolving. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and more, released an advisory on October 16, 2024, warning several large organizations and most especially critical infrastructure sectors on the ongoing brute force attacks being carried out by some Iranian cyber …

Generative AI used in developing malwares

“OpenAI says it has disrupted 20-plus foreign influence networks in past year”[4] It was about time when analysts and researchers will find AI-generated malware in the wild. Last month, a report published by HP wolf Security[5] highlighted the malicious code has been detected in the recent targeted email campaigns to French users to deliver AsyncRAT …

France’s Grand Palais discloses cyberattack during Olympic games

France’s Grand Palais discloses cyberattack during Olympic gamesOn Saturday night, August 3, 2024, the Grand Palais Réunion des musées nationaux (Rmn) in France fell victim to a cyberattack, raising concerns about the security of cultural institutions amid ongoing digital threats. The Grand Palais Rmn is a significant institution responsible for managing various museums and cultural …

RPKI Insecurity 

Recently, a team of researchers from Germany released a paper outlining the vulnerabilities of Resource Public Key Infrastructure (RPKI), the primary framework used to provide security for the Border Gateway Protocol (BGP) [2]. BGP is used for routing, and it is an alternative to Open Shortest Path First (OSPF). OSPF is generally used for routing …

UDP-WG

Hello everybody! I’m proud to announce the completion of my Project: UDP-WG. It’s a heavily documented C++ codebase that implements both the UDP Network Protocol, and the WireGuard VPN protocol. These implementations are used to create the main program, which allows instances to communicate with each other using either of these two protocols! The repository …

The XZ Backdoor: A 10.0 CVSS Exploit We Just Barely Avoided

Introduction The beginning of the calendar year is an important time for the Linux Ecosystem, as it sees the release of many important projects and distributions. Perhaps most important is the coordinated release of the prolific GNOME desktop environment, who’s biannual release cycle sees a new version in March and September (1), and the Ubuntu …

Cybercriminals attacked and stole records from BBC pension database

A security breach at the BBC Pension Scheme’s cloud-based service compromised the personal data of around 25,000 members in the last week of May 2024. Read more to know the details. BBC has suffered a major data breach, exposing the personal information of approximately 25,000 current and former employees. The broadcaster has one of the …