The data breach first emerged in late June when the hacking group ShinyHunters posted a dump of 33 million phone numbers to BreachForums, now confirmed to be taken from an Authy API endpoint.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Twilio said that the data of 125 customers was accessed by the threat actors for some amount of time. Privacy messaging app Signal has indicated that the attackers had some level of access to about 1,900 registered phone numbers.
In the roughly five months that the Okta phishing campaign has been active, it has racked up 9,931 login credentials from about 130 organizations. 5,541 included MFA codes, and 3,120 included the victim's email account.
A massive data breach of video streaming service Twitch has exposed just about everything possible that could be taken. The 125 GB torrent has been confirmed by Twitch and is only the "first part" according to hackers.
The primary concern with Twitter’s zero-day security breach is that authoritarian governments might tie names to the anonymous accounts of activists, political opposition and journalists they are targeting.
Business users' billing information was inadvertently stored in the browser's cache, making it possible for the exposed data to be accessed by users who share computers.
The seemingly odd focus on relative trivialities during the Twitter hack (“OG” usernames and crypto scamming) is due to the culprit being an inexperienced minor.
Twitter hack of high-profile accounts a result of employees tricked into giving up access to support tools that led to compromised accounts posting Bitcoin doubling scam.
Security researchers had matched email addresses to account names, providing an indication that the data leak was legitimate, but Twitter says that the data was gathered via a variety of publicly available sources.
Twitter cites abuse of the text messaging 2FA option by bad actors as the reason for the change in policy. The service will still allow free use of authentication apps or hardware security keys as an additional account security layer.










