KLM, Air France passenger data was improperly secured, and vulnerable to data theft

A large amount of personal data belonging to airline passengers who flew on KLM and Air France was not properly secured, and was somewhat readily available for theft, according to NOS and information technology security researcher Benjamin Broersma. The security Read More …

A Log4Shell Retrospective – Overblown and Exaggerated

Two years ago, CVE-2021-44228 sent the security industry into a panic. The vulnerability, better known as Log4Shell, had security professionals working overtime through the holidays hunting down vulnerable log4j libraries. At the time, there was fear and confusion around what Read More …

Xfinity discloses a data breach but doesn’t say how many users are affected

Xfinity is notifying customers of a “data security incident” it says resulted in the theft of customer information, including usernames, passwords, contact information, and more. In a notice on Monday, Xfinity says “there was unauthorized access” to its systems from Read More …

Coverage Advisory for CVE-2023-50164: Apache Struts Path Traversal and File Upload Vulnerability

CVE-2023-50164 is a path traversal flaw that allows a remote attacker to upload malicious files to vulnerable servers. After successful exploitation, an attacker can achieve Remote Code Execution (RCE) on the target server. An attacker exploiting such a vulnerability can Read More …

#StopRansomware: Play Ransomware

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) are releasing this joint CSA to disseminate the Play ransomware group’s IOCs and TTPs identified through FBI investigations Read More …

Israeli-linked hacker group behind major cyber-attack on Iran’s petrol stations

An Israeli-linked hacker group claims to have carried out a major cyber-attack on Iranian petrol stations, knocking 70 per cent of them offline on Monday. Predatory Sparrow, or “Gonjeshke Darande” in Persian, said it launched the “controlled” attack in response Read More …

Europol: Online Jihadist Propaganda – 2022 in review

This report is the fifth edition of the annual review of online jihadist propaganda. It analyses the major trends and developments in the propaganda of the most prominent Sunni jihadist organisations – the self-proclaimed Islamic State (IS) and al-Qaeda (AQ) Read More …

Defense Contractor Austal USA Confirms a Cyber Attack by Hunters International Ransomware Group

Australian-based American defense contractor Austal USA has confirmed a cyber attack after the Hunters International ransomware group listed the company and shared samples of the stolen data as proof. Austal USA is a Contractor for the US Department of Defense Read More …

Snatch ransomware attack claims probed by Kraft Heinz

U.S. multinational food and beverage company Kraft Heinz has launched an investigation into the Snatch ransomware gang’s recently emerged claims of an August attack even though there has been no indication of any systems compromise. Despite admitting responsibility for the Read More …