Attackers exfiltrated sensitive data from thousands of websites, desktop, and mobile applications in a supply chain attack leveraging typo-squatting in popular NPM packages.
By searching the internet, hackers have begun hijacking smart building access control systems to recruit these IoT devices into botnets for launching DDoS attacks.
Malicious actors are using deepfake videos impersonating YouTube’s CEO to steal users’ credentials in a multi-month phishing campaign. The attackers sent private videos to targeted users via legitimate-looking emails, warning them that YouTube was changing its monetization policies.
The campaign was conducted by malicious hackers who sold the stolen credentials off, with much of the info being put to use in spam and phishing campaigns. The attack simply made use of open-source tools to scan IP ranges for potentially vulnerable Git config files.
The FBI arrested and charged a New York man Connor Brian Fitzpatrick with cybercrime. Connor is alleged to be the hacking forum “BreachForums” owner and operator, Pompompurin.
A leak on a hacking forum that exposed internal AMD data appears to have been confirmed by the company, as it acknowledged that an unnamed third-party vendor involved in product assembly was breached. Questions remain about the extent of the data breach, however.
Okta has about 15,000 clients and provides authentication services for remote logins, usually for employees and students. A known security breach took place in January, but LAPSUS$ says this is something else.
Hacking group ShinyHunters released Pixlr's 1.9 million stolen user credentials on a hacker forum. The data was accessed from an AWS S3 bucket while breaching sister site 123rf.
Imperva reversed the phishing hook to hack the hackers, proving that these 'professionals' are just as susceptible – and in the process reveals some very important anti-hacker lessons.
Russian state-sponsored hackers take 19 mins to break into a network. All of this means that even SMEs need to have a cyber response capable of keeping up with these advanced threat actors.









