A New Hacking Group Hitting Russian Companies With Ransomware

The Hacker News-- As ransomware attacks against critical infrastructure continue to spike in recent months, cybersecurity researchers have uncovered a new entrant that has been actively trying to conduct multistage attacks on large corporate networks of medical labs, banks, manufacturers, and software developers in Russia. The ransomware gang, codenamed "OldGremlin" and believed to be a Russian-speaking … Continue reading A New Hacking Group Hitting Russian Companies With Ransomware

Combining Hadoop and MCollective for total network compromise

InfoSec Write-ups - Medium-- This is the story of how only two insecure configurations allowed us to take down an entire cloud hosted company. It was a gray box pentest for a relatively big client, in which we were tasked with assessing the security of about 5 development endpoints, accessible only using a client certificate. … Continue reading Combining Hadoop and MCollective for total network compromise

Unsecured Microsoft Bing Search Server Exposed User Queries and Location Data

The Hacker News-- A back-end server associated with Microsoft Bing exposed sensitive data of the search engine's mobile application users, including search queries, device details, and GPS coordinates, among others. The logging database, however, doesn't include any personal details such as names or addresses. The data leak, discovered by Ata Hakcil of WizCase on September 12, is … Continue reading Unsecured Microsoft Bing Search Server Exposed User Queries and Location Data

British Hacker Sentenced to 5 Years for Blackmailing U.S. Companies

The Hacker News-- A UK man who threatened to publicly release stolen confidential information unless the victims agreed to fulfill his digital extortion demands has finally pleaded guilty on Monday at U.S. federal district court in St. Louis, Missouri. Nathan Francis Wyatt , 39, who is a key member of the infamous international hacking group … Continue reading British Hacker Sentenced to 5 Years for Blackmailing U.S. Companies

A week in security (September 14 – 20)

Malwarebytes Labs-- Last week on Malwarebytes Labs, we looked at Fintech industry developments, specifically the differences between Europe and the US, and we analyzed how some charities and the advertising industry are tied together. We also told readers about what companies can do to counter domain name abuse. In our Lock and Code podcast we talked … Continue reading A week in security (September 14 – 20)

A Patient Dies After Ransomware Attack Paralyzes German Hospital Systems

The Hacker News-- German authorities last week disclosed that a ransomware attack on the University Hospital of Düsseldorf (UKD) caused a failure of IT systems, resulting in the death of a woman who had to be sent to another hospital that was 20 miles away. The incident marks the first recorded casualty as a consequence of cyberattacks … Continue reading A Patient Dies After Ransomware Attack Paralyzes German Hospital Systems

How I Accidentally Got My First Bounty From Facebook || Facebook Bug Bounty 2020

InfoSec Write-ups - Medium-- How I Accidentally Got My First Bounty From FacebookFacebook Bug Bounty 2020Hello readers,After a very long time I am come back with a new write up. This write up is about how I got my first bounty from Facebook for reporting a functional security issue. So I hope this write up is not … Continue reading How I Accidentally Got My First Bounty From Facebook || Facebook Bug Bounty 2020