br00t4c, to random
@br00t4c@mastodon.social avatar

Casino cyberattacks put a bullseye on Scattered Spider - and the FBI is closing in

https://go.theregister.com/feed/www.theregister.com/2024/05/23/mandiant_cto_scattered_spider/

br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Kremlin's Sandworm blamed for cyberattacks on US, European water utilities

https://go.theregister.com/feed/www.theregister.com/2024/04/17/russia_sandworm_cyberattacks_water/

simontsui, to vmware

CISA adds CVE-2023-34048 (9.8 critical, disclosed 25 October 2023 by VMware, reported by Mandiant as exploited as a zero-day since 2021) VMware vCenter Server Out-of-Bounds Write Vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
๐Ÿ”— https://www.cisa.gov/news-events/alerts/2024/01/22/cisa-adds-one-known-exploited-vulnerability-catalog

#CVE202334048 #VMware #CISA #KEV #eitw #activeexploitation #Mandiant #UNC3886 #cyberespionage #vCenter #zeroday #vulnerability #cybersecurity

jos1264, to news
@jos1264@social.skynetcloud.site avatar
0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

โž ๐Ÿ”“ ๐ŸŽฝ Halara probes breach after hacker leaks data for 950,000 people
โž ๐Ÿ”“ ๐Ÿ’ฅ 's X Account Was Hacked Using Brute-Force Attack
โž ๐Ÿ”“ ๐Ÿ‡ต๐Ÿ‡พ warns of Black Hunt attacks after Tigo Business
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ธ US SECโ€™s X account hacked to announce fake ETF approval
โž ๐Ÿ”“ ๐Ÿ‡จ๐Ÿ‡ฆ Toronto Zoo: Ransomware attack had no impact on animal
โž ๐Ÿ”“ Mortgage firm loanDepot impacts IT systems, payment portal
โž ๐Ÿ‡ซ๐Ÿ‡ฎ ๐Ÿ’ธ warns of Akira ransomware wiping NAS and tape devices
โž ๐Ÿ‡ฉ๐Ÿ‡ฐ ๐Ÿ‡ท๐Ÿ‡บ probably wasnโ€™t behind Danish critical infrastructure cyberattack, report says
โž ๐Ÿ‡บ๐Ÿ‡ฆ ๐Ÿ‡ท๐Ÿ‡บ Pro-Ukraine hackers breach Russian ISP in revenge for attack
โž ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡บ๐Ÿ‡ธ French Computer Hacker Jailed in US
โž ๐Ÿ‡ณ๐Ÿ‡ฌ โš–๏ธ Nigerian gets 10 years for laundering millions stolen from elderly
โž ๐Ÿ‡น๐Ÿ‡ท Turkish Hackers Exploiting Poorly Secured Servers Across the Globe
โž ๐Ÿ‡น๐Ÿ‡ท ๐Ÿ‡ณ๐Ÿ‡ฑ Turkish Targeting Netherlands
โž โ˜๏ธ ๐Ÿ‡ช๐Ÿ‡บ Lets Cloud Users Keep Personal Data Within to Ease Fears
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡จ๐Ÿ‡ณ is helping US spies catch stealthy Chinese hacking ops, official says
โž ๐Ÿ‡ฑ๐Ÿ‡ง โœˆ๏ธ Beirut Airport Screens Hacked with Anti-Hezbollah Message
โž ๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Ministry exposed sensitive data for 15 months
โž ๐Ÿ‡ฌ๐Ÿ‡ท to Establish New Authority to Counter Cyber-Attacks
โž ๐Ÿฉน , Release First Patch Tuesday Advisories of 2024
โž ๐Ÿ โ˜๏ธ New -based FBot Hacking Toolkit Aims at and Platforms
โž ๐Ÿฆ  ๐Ÿ“บ Videos Promoting Cracked Software Distribute Lumma Stealer
โž ๐Ÿฆ  ๐Ÿง devices are under attack by a never-before-seen worm
โž ๐Ÿฆ  ๐Ÿ‡ณ๐Ÿ‡ฑ Dutch Engineer Used Water Pump to Get Billion-Dollar Into Iranian Nuclear Facility
โž ๐Ÿก ๐Ÿ” DSA removal from
โž ๐Ÿฉน
โž ๐Ÿ› ๐Ÿ”“ Actively exploited 0-days in VPN are letting hackers networks
โž ๐Ÿ”“ ๐Ÿ”ง Hackers can infect network-connected wrenches to install ransomware
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ”“ cracked by , revealing phone number and email address of sender
โž ๐Ÿฉน Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products
โž ๐Ÿ› ๐Ÿ”“ KyberSlash attacks put projects at risk

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-022024

br00t4c, to random
@br00t4c@mastodon.social avatar

Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in

https://go.theregister.com/feed/www.theregister.com/2024/01/13/ivanti_zeroday_mandiant_analysis/

br00t4c, to medical
@br00t4c@mastodon.social avatar
jbzfn, to cryptocurrency
@jbzfn@mastodon.social avatar

โš ๏ธ Mandiant's X Account Was Hacked Using Brute-Force Attack
แ… @thehackernews

ใ€Œ "Normally, [two-factor authentication] would have mitigated this, but due to some team transitions and a change in X's 2FA policy, we were not adequately protected," the threat intelligence firm said in a post shared on X ใ€

https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html

gcluley, to cryptocurrency
@gcluley@mastodon.green avatar

Security firm Mandiant says it didnโ€™t have 2FA enabled on its hacked Twitter account.

I have questions...

https://grahamcluley.com/security-firm-mandiant-says-it-didnt-have-2fa-enabled-on-its-hacked-twitter-account/

cybersecurity

83r71n, to Cybersecurity

Mandiant's X account was compromised through a brute-force password attack by a drainer-as-a-service (DaaS)* group. The account lacked two-factor authentication (2FA), which could have mitigated the attack.

*(DaaS): A Drainer-as-a-Service is a type of cyber attack where hackers sell access to their botnets, which are networks of computers controlled remotely.

https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html

#cybersecurity #mandiant #attack #bruteforce #hack #2fa #daas #botnets

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar
0x58, to Cybersecurity

๐Ÿ“จ Latest issue of my curated and list of resources for week /2024 is out! It includes the following and much more:

โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ–ผ๏ธ MAJOR US SUFFER FALLOUT
โž ๐Ÿ‡ช๐Ÿ‡ธ ๐Ÿ“ก A โ€œridiculously weakโ€œ password causes disaster for โ€™s No. 2 mobile carrier
โž ๐Ÿ”“ ๐Ÿงฌ tells victims itโ€™s their fault that their data was breached
โž ๐Ÿ”“ ๐Ÿ’ธ loses $86 million in the last hack of 2023
โž ๐Ÿ”“ ๐Ÿ…ฟ๏ธ Europeโ€™s Largest Parking App Provider Informs Customers of Data Breach
โž ๐Ÿ’ธ ๐Ÿ™Š wallet founder loses $125,000 to fake airdrop website
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ US Says 19 People Charged Following 2019 Takedown of Cybercrime Marketplace
โž ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ฎ๐Ÿ‡ฑ Palestinian Hackers Hit 100 Israeli Organizations in Destructive Attacks
โž ๐Ÿ”“ โŒ Hacked X Account Abused for Theft
โž ๐Ÿ‡ณ๐Ÿ‡ฌ ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ Nigerian hacker arrested for stealing $7.5M from charities
โž ๐Ÿ‡ฆ๐Ÿ‡ฑ ๐Ÿ“ก Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
โž ๐Ÿ‡บ๐Ÿ‡ธ The FBI is adding more cyber-focused agents to U.S. embassies
โž ๐Ÿ‡บ๐Ÿ‡ธ โš–๏ธ Former admin to be jailed until Jan. 19 sentencing
โž ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ’ฐ DOJ Slams with $10 Million Fine Over Massive Illegal Robocall Operation
โž ๐Ÿ“ท ๐Ÿฅธ Contractor Pays Parents $50 to Scan Their Childrens' Faces
โž ๐Ÿ’ฐ ๐Ÿฅธ Google Settles $5 Billion Lawsuit Over Tracking Users in 'Incognito Mode'
โž ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ—ณ๏ธ to reveal Chinese election interference after Saturdayโ€™s vote
โž ๐Ÿฆ  ๐Ÿ’ฐ Settles Insurance Claim, Leaving Definition Unresolved
โž ๐Ÿฆ  ๐Ÿ‡ฐ๐Ÿ‡ต SpectralBlur: New Backdoor Threat from North Korean Hackers
โž ๐Ÿฆ  ๐Ÿ 3 Malicious Packages Found Targeting with Crypto Miners
โž ๐Ÿฆ  ๐ŸŽ  New Bandook Variant Resurfaces, Targeting Machines
โž ๐Ÿฆ  ๐ŸŽ  UAC-0050 Group Using New Tactics to Distribute Remcos RAT
โž ๐Ÿฆ  ๐Ÿ‡บ๐Ÿ‡ฆ CERT-UA Uncovers New Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
โž ๐Ÿ”“ ๐Ÿฆ  Free Decryptor Released for Ransomware
โž ๐Ÿ› ๐Ÿ“จ Smuggling: New Flaw Lets Attackers Bypass Security and Spoof
โž ๐Ÿฉน warns critical EPM lets hackers hijack enrolled devices
โž ๐Ÿฉน Google Patches Six Vulnerabilities With First Update of 2024
โž ๐Ÿฉน ๐Ÿก Millions still havenโ€™t patched SSH protocol

Subscribe to the newsletter to have it piping hot in your inbox every week-end โฌ‡๏ธ

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-012024

Freemind, to Cybersecurity
@Freemind@mastodon.online avatar

Following the security breach, the cybercriminal created a counterfeit webpage on Mandiantโ€™s account, mimicking the appearance of the official Phantom website.

#X

https://cybersec84.wordpress.com/2024/01/07/hackers-exploit-mandiant-account-x-to-steal-user-data-and-funds/

itnewsbot, to cryptocurrency

Elon Musk drops price of X gold checks amid rampant crypto scams - Enlarge (credit: ALAIN JOCARD / Contributor | AFP)

There's cur... - https://arstechnica.com/?p=1994036 #cyberthreatanalysts #cryptocurrencyscam #cryptocurrency #phishingscam #cloudsek #elonmusk #ethereum #mandiant #twitter #policy #google #hacker #nfts #x

itnewsbot, to news

This Week in Security: Bitwarden, Reverse RDP, and Snake - This week, we finally get the inside scoops on some old stories, starting with the... - https://hackaday.com/2024/01/05/this-week-in-security-bitwarden-reverse-rdp-and-snake/

governa, to random
@governa@fosstodon.org avatar

's X Account Restored After Six-Hour Crypto Scam Hack

https://thehackernews.com/2024/01/mandiants-twitter-account-restored.html

YourAnonRiots, to Cybersecurity Japanese

๐Ÿ“ข The official X (formally Twitter) account of Google-owned cybersecurity firm Mandiant hacked to run a crypto scam luring users into fake airdrop!

https://www.hackread.com/google-mandiant-cybersecurity-x-hacked-crypto-scam/?s=09

br00t4c, to cryptocurrency
@br00t4c@mastodon.social avatar

Mandiant, the security firm Google bought for $5.4 billion, gets its X account hacked

https://arstechnica.com/?p=1993618

itnewsbot, to security

Mandiant, the security firm Google bought for $5.4 billion, gets its X account hacked - Enlarge

Google-owned security firm Mandiant spent several hou... - https://arstechnica.com/?p=1993618 โข

br00t4c, to random
@br00t4c@mastodon.social avatar
itsecbot, to random

Barracuda Urges Replacing โ€” Not Patching โ€” Its Email Security Gateways - Itโ€™s not often that a zero-day vulnerability causes a network security vendor to u... https://krebsonsecurity.com/2023/06/barracuda-urges-replacing-not-patching-its-email-security-gateways/ -2023-2868

0x58, to infosec

๐Ÿ“จ Latest issue of my curated and list of resources for week /2023 is out! It includes, but not only:

โ€ฃ Hackers target vulnerable servers exposed online
โ€ฃ queries for Americansโ€™ digital data drops, yet advocates for surveillance reform remain undeterred
โ€ฃ : Back in After Meeting Watchdog Demands
โ€ฃ Many Public Sites are Leaking Private Data
โ€ฃ CSF 2.0 Core discussion draft released, stakeholder feedback invited
โ€ฃ Attack: New Politically-Motivated Surveillance Campaign in
โ€ฃ version of RTM Locker targets ESXi servers
โ€ฃ New Atomic info-stealing targets 50 crypto wallets
โ€ฃ Gets Court Order to Take Down That Infected Over 670,000 Computers
โ€ฃ restricted in after refusal to supply user data to authorities
โ€ฃ discloses XSS zero-day flaw in server management tool
โ€ฃ Ukrainian arrested for selling data of 300M people to Russians
โ€ฃ Hackers are breaking into AT&T email accounts to steal
โ€ฃ , , join Elite Cyber Defenders Program to secure critical infrastructure
โ€ฃ ATT&CK v13 April Updates
โ€ฃ New Data Sharing Platform Serves as Early Warning System for Threats
โ€ฃ North Korean Hackers Target Mac Users With New โ€˜โ€™ Malware
โ€ฃ New All-in-One "" Stealer for Systems Surfaces on the Dark Web

๐Ÿ“š This week's recommended book is: "This Is How They Tell Me the World Ends: The Cyberweapons Arms Race" by Nicole Perlroth

Subscribe to the to have it piping hot in your inbox every Sunday โฌ‡๏ธ

https://0x58.substack.com/p/infosec-mashup-week-172023

cybercareersblog, to infosec

DOJ Detected SolarWinds Breach Months Before Public Disclosure | WIRED
https://www.wired.com/story/solarwinds-hack-public-disclosure/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • โ€ข
  • megavids
  • thenastyranch
  • magazineikmin
  • ethstaker
  • InstantRegret
  • tacticalgear
  • rosin
  • love
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • cubers
  • DreamBathrooms
  • provamag3
  • mdbf
  • cisconetworking
  • GTA5RPClips
  • modclub
  • khanakhh
  • everett
  • Leos
  • osvaldo12
  • normalnudes
  • tester
  • Durango
  • anitta
  • JUstTest
  • All magazines