Search results

  1. Carding

    Schrodinger's GitLab — just vulnerable or already hacked? It is better not to check

    Update your installations as soon as possible to avoid attacks on the supply chain. released GitLab security updates to address a critical vulnerability that allows attackers to run pipelines on behalf of other users through scheduled security policies. The vulnerability was identified as...
  2. Carding

    Snowden vs Marvell: The story of one Backdoor

    Are you ready for more revelations from Snowden? Cavium, a semiconductor manufacturer acquired by Marvell in 2018, was allegedly identified in documents leaked in 2013 by Edward Snowden as a supplier of semiconductors with backdoors for US intelligence. Marvell denies that it or Cavium...
  3. Carding

    XWorm Trojan examined under the microscope: does it pose a real threat?

    The use of a resident proxy by researchers made it possible to "expose" the mysterious malware. Since its first appearance in 2022, XWorm has become one of the most annoying Remote Access Trojans (RAT). The analytical group ANY. RUN decided to conduct a detailed analysis of the latest version...
  4. Carding

    Underground bookmakers used satellites for illegal betting

    Bribes, satellites, double payouts - everything is perfect in this campaign. The Spanish police, together with Europol, Interpol, the Spanish Tax Service and the Romanian police, have successfully completed an operation to detain suspects suspected of organizing illegal betting and manipulating...
  5. Carding

    MGM and Caesars are not the only victims of the most high-profile cyber attacks of the month

    3 more companies were affected by the actions of ALPHV and Scattered Spider. Who are they? In the past few weeks, hackers who broke into the systems of major casinos and hotels of MGM Resorts International and Caesars Entertainment companies have attacked three other organizations in the fields...
  6. Carding

    Hidden Threat: Code Assistants Know More than They Think

    All developer secrets will be revealed through the code auto-completion feature. A team of researchers from the Chinese University of Hong Kong and Sun Yat-sen University has discovered that AI-based automated code completion tools, such as GitHub Copilot and Amazon CodeWhisperer, can...
  7. Carding

    Cyber war of global giants: China accuses the US of attacking Huawei

    It seems that the history of cyber espionage has just become even more interesting. Almost a decade after leaked documents from Edward Snowden revealed that the US National Security Agency (NSA) hacked the servers of Chinese telecommunications giant Huawei, Beijing has officially acknowledged...
  8. Carding

    In the hands of the law: a 20-year-old Chelyabinsk resident was detained for trading banking data in Telegram

    He faces up to five years in prison. Investigators of the Federal Security Service of the Chelyabinsk region opened criminal cases against a 20-year-old resident of the region, who was engaged in hacking personal accounts of users of various Internet services, including state institutions and...
  9. Carding

    Australia to build six cyber shields to ensure national security

    By 2030, the state plans to become a world leader in cybersecurity. Australian Home Affairs Minister Claire O'Neill announced the creation of "six cyber shields around the nation" as part of the national cyber security strategy. The strategy includes six key areas, namely: education for...
  10. Carding

    The civil servant spent the money stolen from credit cards on house repairs and a Chanel bag

    An American woman from Northern Kentucky (Ohio) was sentenced to 3.5 years in prison for stealing 185 thousand dollars from a municipal credit card and cards of her colleagues. The Messenger also clarifies that after that, she will serve another three years of probation. Now Allison Donaldson...
  11. Carding

    Финансово мотивированный субъект угрозы UNC3944 смещает фокус на атаки с использованием программ-вымогателей

    Финансово мотивированный субъект угрозы, известный как UNC3944, переходит к развертыванию программ-вымогателей в рамках расширения своих стратегий монетизации, сообщил Mandiant. "UNC3944 продемонстрировал более пристальное внимание к краже больших объемов конфиденциальных данных в целях...
  12. Carding

    Retool становится жертвой фишинг-атаки на основе SMS, затрагивающей 27 облачных клиентов

    Компания-разработчик программного обеспечения Retool сообщила, что учетные записи 27 ее облачных клиентов были скомпрометированы в результате целенаправленной атаки социальной инженерии на основе SMS. Фирма из Сан-Франциско обвинила функцию облачной синхронизации аккаунта Google, недавно...
  13. Carding

    Hook: новый банковский троян для Android, расширяющий наследие ERMAC

    Новый анализ банковского троянца Android, известного как Hook, показал, что он основан на своем предшественнике под названием ERMAC. "Исходный код ERMAC использовался в качестве основы для Hook", - заявили исследователи безопасности NCC Group Джошуа Камп и Альберто Сегура в техническом анализе...
  14. Carding

    Думаете, ваши решения MFA и PAM защищают вас? Подумайте еще раз.

    Когда вы внедряете продукт безопасности, вы предполагаете, что он выполнит свое предназначение. К сожалению, однако, это часто оказывается не так. Новый отчет, подготовленный Osterman Research по заказу Silverfort, показывает, что решения MFA (многофакторная аутентификация) и PAM (Управление...
  15. Carding

    Новая операция по криптоджекингу AMBERSQUID нацелена на необычные сервисы AWS

    Новая облачная операция по криптоджекингу нацелилась на необычные предложения Amazon Web Services (AWS), такие как AWS Amplify, AWS Fargate и Amazon SageMaker, для незаконного майнинга криптовалюты. Вредоносная киберактивность получила кодовое название AMBERSQUID от фирмы Sysdig, занимающейся...
  16. Carding

    Why are we being deceived? The unsightly side of security guides.

    Find out the truth behind the security guidelines. The cybersecurity instructions you receive at work may cause confusion? You are not alone. According to a recent study, there are a number of problems in the wording of these guidelines. The authors suggest simple measures to improve the...
  17. Carding

    Gandalf - a cyber polygon that failed the security test

    The neural network hacking training platform itself has become a privacy threat. The Swiss company Lakera AI, developer of the Gandalf educational platform designed to teach the risks of "prompt injection" attacks in Large Language models (LLM), recently fixed a vulnerability in its system...
  18. Carding

    Xi Jinping's new dangerous game: Students or future spies?

    Chinese students become part of a grandiose antispyware program. In early September, when students were returning to Chinese universities, they were confronted with an unexpected program: spy detection courses. At Tsinghua University, teachers and students were instructed on how to become a...
  19. Carding

    Lazarus malware delivered to South Korean users via supply chain attacks

    $240 Million in 3 Months: Lazarus Fleeces Crypto Platforms One by one Who will be the next victim of North Korean cybercriminals? North Korean hacker group Lazarus has stolen almost $240 million worth of cryptocurrencies over the past 3 months, according to the analytical company Elliptic...
  20. Carding

    Rusty Flag Campaign-Manipulation and stealth in cyber attacks on Azerbaijan

    Who needs to hide behind other cybercriminals for attacks? Cybersecurity researchers from Deep Instinct discovered a new campaign, called Rusty Flag, aimed at Azerbaijani targets. The attacks use a decoy document related to the Karabakh conflict and a new type of malware in the Rust programming...
Top