无数据
订阅者
-624 小时
-567 天
-15230 天
帖子存档
🚨🚨🚨Data Breach Alert‼️
🇦🇪UAE - Dubai Pulse
A potential data breach involving Dubai Pulse has been detected on a hacking forum: 21,912,532 user records are reportedly affected.
According to the post, the data includes information such as names, email addresses, phone numbers, and other personal details.
The confirmation or denial of these claims has yet to be verified.
🚨Cyberattack Alert ‼️
🇺🇸USA - Rent-2-Own
Medusa ransomware group claims to have breached Rent-2-Own.
Ransom demand: $200,000.
Ransom deadline: 18th Jan 25.
🚨Cyberattack Alert ‼️
🇪🇸Spain - GALFER
Akira ransomware group claims to have breached GALFER.
Allegedly, 65 GB of data were exfiltrated, including NDAs, contact numbers and e-mail addresses of employees and customers, employees DNI numbers, and HR confidential information.
🚨Cyber Attack Alert ‼️
🇨🇴Colombia - Permoda
Akira ransomware group claims to have breached Permoda.
Allegedly, 220 GB of data were exfiltrated, including contact numbers and e-mail addresses of employees and customers, internal financial documents, confidential agreements and contracts, certification documents, etc.
🚨Data Breach Alert - OnlineTVRecorder (OTR)
A potential data breach affecting OnlineTVRecorder (OTR) has been detected on a hacking forum: 543,019 user records, including email addresses and plain text passwords, have reportedly been affected.
The confirmation or denial of these claims has yet to be verified.
🚨 DDoS Alert ‼️
🇯🇵Japan: tenki.jp hit by another DDoS
On January 9, 2025, at approximately 7:01 AM, the weather forecasting media platform "tenki.jp" (web version) experienced accessibility issues due to a DDoS attack causing network congestion.
This follows a similar event on January 5, 2025.
Source:
https://www.jwa.or.jp/news/2025/01/25016/
🚨Ivanti 0-day Exploited‼️
Ivanti has disclosed a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure appliances, which has been actively exploited by attackers to install malware.
The flaw, a stack-based buffer overflow, allows unauthenticated remote code execution on devices running vulnerable firmware versions of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways.
While the flaw affects all three products, exploitation has only been observed in Connect Secure appliances.
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-connect-secure-flaw-used-in-zero-day-attacks/
🚨Cyberattack Alert ‼️
🇯🇵Japan - FUKOKU
Space Bears hacking group claims to have breached FUKOKU.
Allegedly, databases, accounting, sales, purchasing, drawings, prototypes, and production cycles were exfiltrated.
Ransom deadline: 18th Jan 25.
🚨Data Breach Alert‼️
🇵🇰Pakistan - Platinum Pharmaceuticals
A potential data breach targeting Platinum Pharmaceuticals has been detected on a hacking forum.
According to the post, on January 3, 2025, the threat actor known as "0mid16B" allegedly exfiltrated 612 GB of data containing "trade secrets ranging from its import, export, sales, clientele, patients, chemists to drug products" and decided to leak them on a hacking forum.
The confirmation or denial of these claims has yet to be verified.
🚨Cyberattack Alert ‼️
🇹🇭Thailand - King Power
Abyss hacking group claims to have breached King Power.
Allegedly, 1.2 TB of data were exfiltrated.
🚨Silent Crow, a hacker group, claims to have breached Russia's state cadastre and cartography agency, allegedly obtaining sensitive real estate data.
The stolen database reportedly includes internal record IDs, owner names (individual or legal entities), dates of birth, passport details, addresses, and sometimes phone numbers, covering entries up to early 2024.
Silent Crow claimed to have stolen 2 billion lines of data, publishing 82 million as proof. Russia’s state register denied the breach and is conducting further checks.
https://kyivindependent.com/hackers-claimed-to-have-hacked-russias-real-estate-database-moscow-denies/
🚨Cyberattack Alert ‼️
🇺🇸USA - Huntington Hotel Group
Termite ransomware group claims to have breached Huntington Hotel Group.
Allegedly, 38.7 GB of data were exfiltrated.
🚨The Packers Pro Shop online store experienced a data breach in September and October 2024, exposing customer information.
Hackers inserted malicious code into the e-commerce website, compromising credit card transactions made between September 23-24 and October 3-23. Information potentially accessed included names, billing and shipping addresses, email addresses, credit card numbers, expiration dates, and verification codes.
The total number of affected customers has not been disclosed.
https://www.greenbaypressgazette.com/story/sports/nfl/packers/2025/01/07/packers-pro-shop-experienced-data-breach-in-fall-2024-green-bay/77514322007/
🚨🚨Orange Finance, a liquidity management protocol on Arbitrum, was hacked, resulting in the theft of approximately $787,000 in cryptocurrency assets.
The attacker exploited the protocol by gaining control of the administrator address, upgrading the contract, and transferring the funds to their wallet.
Users are advised to revoke all contract authorizations and avoid interacting with the compromised protocol.
https://www.binance.com/en/square/post/01-08-2025-orange-finance-suffers-hack-resulting-in-significant-loss-18656672720113
🚨🇯🇵Since August 2024, at least seven Japanese companies and organizations have reported cyberattacks on their e-commerce sites, resulting in the potential leak of over 330,000 pieces of personal information.
The attackers used a sophisticated technique, embedding malicious programs into order forms disguised as legitimate customer orders. Once activated by site administrators, the malware enabled remote access and altered the site to redirect customer input, such as credit card information, to external servers.
Victims include Tully’s Coffee Japan (93,000 records leaked, including 53,000 credit card details), a school bag manufacturer Kyowa, and the National Federation of Fisheries Cooperative Associations.
https://www.tokyo-np.co.jp/article/377828
🚨🇯🇵The Japanese National Police Agency and the Cybersecurity Center of the Cabinet Office have assessed that since around 2019, a cyberattack campaign targeting organizations, businesses, and individuals in Japan has been conducted by the cyberattack group "MirrorFace" (also known as "Earth Kasha").
Investigations by the Kanto Regional Police Bureau, the Tokyo Metropolitan Police Department, and other prefectural police revealed that MirrorFace's campaigns primarily aim to steal information related to Japan's national security and advanced technologies. These attacks are suspected to involve organized efforts linked to China.
Source: National Police Agency
https://www.npa.go.jp/bureau/cyber/koho/caution/caution20250108.html
🚨Data Breach Alert - Vivaia
A potential data breach at Vivaia, a global footwear brand, has been detected on a hacking forum, reportedly affecting 9 million customers.
According to the sample provided, the stolen information includes data such as full names, phone numbers, and email addresses.
The validity of these claims has yet to be verified, but in the meantime, Vivaia customers are advised to remain vigilant against potential phishing attempts.
🚨Cyberattack Alert ‼️
🇹🇷Turkey - Şah Petrol A.Ş.
RansomHub ransomware group claims to have breached Şah Petrol A.Ş.
Allegedly, 94 GB of data were exfiltrated.
Ransom deadline: 18th Jan 25.
🚨🚨🚨Data Breach Alert - Gravy Analytics
Hackers claim to have breached Gravy Analytics, a major player in the location data industry and the parent company of Venntel, which sells location data to U.S. government agencies like the FBI, DHS, and the military.
The hackers reportedly stole a vast amount of sensitive data, including customer lists, industry-related information, and precise smartphone location data showing individuals' movements.
They are now threatening to publish the stolen data publicly.
More details on 404 Media:
https://404media.co/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 01 - 07 January 2025
⚠️296 cyber attacks across 40 countries ⚠️
➡️The most active threat actor this week is NoName057(16) claiming responsibility for 96 cyber attacks.
➡️Poland is the most affected country, accounting for 17.2% of incidents, with 51 cyber attacks.
➡️The Gov / Mil / LE sector is the most impacted, accounting for 17.9% of incidents with 53 cyber attacks.
➡️The estimated Critical cyber attacks account to 10(3.3% of the total).
➡️Overall, the claimed compromised data amounts to approximately 15.7 TB.
Follow the link for list of attacks (claimed or disclosed):
https://hackmanac.com/news/hack-tuesday-week-01-07-january-2025
#Hackmanac #HT #Cybersecurity
