News & Updates

Identity Thieves Bypassed Experian Security to View Credit Reports

Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureaus. Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian’s website allowed anyone to bypass these questions and go straight to the consumer’s report. All that was needed was the person’s name, address, birthday and Social Security number.
News & Updates

Ransomware attackers steal over 3 million patients’ medical records

A ransomware attack has again put the personal information of innocent parties
at risk after it was revealed that a data breach has potentially exposed the
medical records of more than three million people.

The Californian-based Regal Medical Group says that it suffered a data breach in
December 2022, after malicious hackers accessed information from itself and its
affiliates Affiliated Doctors of Orange County (ADOC) Medical Group, Greater
Covina Medical, and Lakeside Medical Organization.

In

News & Updates

Apple Patches First Zero-Day Flaw Reported in 2023 on iOS and macOS

Apple this week is rolling out patches to iPhone and Mac users to address a new
WebKit flaw that hackers are said to be exploiting in the wild.

The vulnerability, tracked as CVE-2023-23529, is a new type confusion issue in
the web-rendering WebKit engine used by all Apple products.

According to the advisory, the bug can be exploited to compromise vulnerable
iPhones, iPads and Macs by “processing maliciously crafted web content.”

In plain English, an attacker can gain a foothold on the target

News & Updates

Lazarus Group Uses New Mixer to Launder $100 Million in Stolen Crypto Assets

Lazarus Group, the notorious cybercrime gang, has been spotted circumventing US
crypto mixers restrictions by using a newly available service to launder stolen
crypto assets.

According to blockchain analysis company Elliptic, the North Korean cybercrime
posse has obfuscated transfers amounting to roughly $100 million in pillaged
Bitcoin since October.

Crypto mixers, also referred to as tumblers, are a service that blends many
users’ crypto assets, attempting to obfuscate the owners and origins

News & Updates

Hackers who breached grocery service Weee! leak details of over 11 million orders online

Details of over 11 million orders from US-based grocery delivery platform Weee!
Were leaked on the cybercriminal-operated BreachedForums last week.

According to a data broker called ‘IntelBroker,’ the food delivery service was
breached this month, exposing over 1.1 million unique email addresses and order
details including customer names, phone numbers and even delivery notes for
couriers that include residential or office building access codes.

“In approximately February 2023, the Asian and H

News & Updates

‘Al-Toufan’ Hackers Take Down Bahrain International Airport Website

A hacking group known as Al-Toufan has claimed responsibility for attacks on the
websites of Bahrain’s international airport, state news agency and chamber of
commerce.

Al Toufan – “The Flood” in Arabic – took down the Bahrain International Airport
site on Tuesday, along with the sites of the state-run Bahrain News Agency and
the Bahrain Chamber of Commerce, reports
[https://apnews.com/article/technology-persian-gulf-tensions-bahrain-9bd1288487bac78362fe4dca0c19a7f4]
The Associated Press.

The

News & Updates

Microsoft’s February 2023 Patch Tuesday Fixes 3 Actively Exploited Flaws

Microsoft’s monthly security update rollout in February patches 77 flaws
affecting products in its portfolio, including three actively exploited zero-day
vulnerabilities.

Nine of the 77 vulnerabilities are flagged “Critical” in severity, while the
remaining 68 are marked as “Important.” Almost half (37 out of 77) were
classified as Remote Code Execution (RCE) vulnerabilities.

Researchers spotted three zero-day vulnerabilities being exploited in the wild,
namely:

* CVE-2023-21715 (CVSS Score:

News & Updates

Gulp! Pepsi hack sees personal information stolen by data-stealing malware

Towards the end of last year, malicious hackers broke into the systems of Pepsi
Bottling Ventures, the largest privately-owned bottler of Pepsi-Cola beverages
in the USA, and installed malware.

For almost the month the malware secretly exfiltrated personally identifiable
information (PII) from the company’s network.

The first Pepsi Bottling Ventures knew about the unauthorized access to its
network was on January 10 2023, but it took a further nine days until the
organisation completely shut t

News & Updates

What’s love got to do with it? 4 in 5 Valentine’s Day-themed spam emails are scams, Bitdefender Antispam Lab warns

In cybersecurity, Valentine’s Day always heralds one thing: a scam wave washing
across the digital landscape.

Threat actors are always looking to defraud digital citizens ahead of Feb. 14,
some last-minute shopping for a loved one or the need to connect with someone
could turn into a dangerous mash-up.

In 2023, the mid-February celebration of love is preceded by a deluge of
unsolicited correspondence that aims to lure people into giving out personal
information or purchasing a romantic gift fo

News & Updates

City of Oakland Hit by Ransomware

Hackers have infiltrated the IT infrastructure of Oakland, forcing the San
Francisco Bay area metropolis to take systems offline as it works to secure and
restore services, the city government said in a notice.

For now, visitors of oaklandca.gov are greeted with a red banner saying:

“Oakland is experiencing a network outage. Several non-emergency systems
including voicemail within the City of Oakland are currently impacted or
offline. Thank you for your patience while we work to restore servic

Scroll to Top