onion news

Onion World News

Covid-19: International Cybercriminals apprehended, charged with business email compromise (BEC) fraud

Covid-19: International Cybercriminals apprehended, charged with business email compromise (BEC) fraud

Twenty-three persons who were involved in the Business Email Compromise (BEC) scheme that scammed companies of about $1.2 million have been apprehended and charged by a collaborative investigation led by Europol.

Employees’ healthcare information exposed in a data breach affecting the US waste management firm

Employees’ healthcare information exposed in a data breach affecting the US waste management firm

The health information of dependants, former and current employees of the United States Waste Management Resources have been exposed after the company noticed some suspicious activities on their database systems.
To verify these claims, the services of forensic experts were deployed to investigate the suspicious activities to know the scope and nature of the malicious operation and subsequently, inform the Federal Bureau of Investigation (FBI) for further investigative action.

StarHub discloses data leak affecting over 57,000 customers

StarHub discloses data leak affecting over 57,000 customers

A major Singaporean telco, StarHub, has disclosed that its data file comprising mobile phone numbers, identity card numbers, and email addresses belonging to 57,191 individual customers who subscribed to its services was exposed and victimized in a data breach.

Three million US elderly citizens’ data compromised

Three million US elderly citizens’ data compromised

Security researchers at WizCase have discovered that the personal data of over three million senior citizens of the United States had been exposed. The discovery was facilitated through a review website, SeniorAdvisor, in a security oversight.
A misconfigured Amazon S3 bucket was discovered that meant that data, including phone numbers, emails, and users’ surnames have been exposed.

Over 2.4million patients and employees records leaked in a Healthcare data breach

Over 2.4million patients and employees records leaked in a Healthcare data breach

United States Healthcare provider, Forefront Dermatology, has announced there is a breach of its network, which may have exposed the medical records and personal data of about 2.4 million patients.

The staff records of the organization based in Wisconsin, have been placed at risk from the breach of its data which made intruders secure unauthorized access to some files on its IT systems that contain the information of employees and patients.

Phishing scam blocked following Irish covid-19 certificate URL typo

Phishing scam blocked following Irish covid-19 certificate URL typo

Fionn Kelleher and Adam Conway, both, citizens of the republic of Ireland, have saved the government of Ireland and millions of its citizens from what that could have been the country’s biggest ever recorded information leak and scammers would have used the medium to obtain personal information of unsuspecting citizens.

UK based Loyalty management tech company launches bug bounty program

UK based Loyalty management tech company launches bug bounty program

A renowned UK-based loyalty Mgt software company, Antavo, has rolled out a bug bounty program with a Hungary-based cybersecurity outfit, Hacktify.
The bug bounty program is designed to collect submissions from professional hackers for any security errors detected in its loyalty management application and reward them for any bug or critical vulnerabilities found.

Chrome’s phishing detection mechanism upgraded

Chrome’s phishing detection mechanism upgraded

The most popular search engine in the world, Google, has come out with another version, Chrome 92. The latest version has been designed to detect phishing scams fifty times faster than the last version of the Chrome browser. 

Decrypting tools website, No More Ransom, helps 600,000 people recover from ransomware attacks

Decrypting tools website, No More Ransom, helps 600,000 people recover from ransomware attacks

No More Ransom, a website that is made up of a collection of powerful ransomware decrypting tools, was set up to assist victims whose data/files have been maliciously compromised and recover them from ransomware attacks. Over 600,000 victims have been assisted by the decryptors in its repository to recover their files without any need to pay cyber criminals that are peddling malware money for data recovery.

US authorities offer $10 million financial reward for information on state-sponsored cyber-attacks

US authorities offer $10 million financial reward for information on state-sponsored cyber-attacks

Following the increasing rate of cyber-attacks, The United States Department of State’s Rewards for Justice (RJF) has come up with a bounty reward of $10 million for anyone who can provide any useful information that can lead to the location and identity of state-sponsored cybercriminals. 

Vulnerabilities in IDEMIA access control devices could give room for remote attacks

Vulnerabilities in IDEMIA access control devices could give room for remote attacks

Security researchers have warned attackers can exploit the vulnerabilities detected in the biometric access control devices that were manufactured by IDEMIA to carry out their nefarious activities.
Three vulnerabilities that affect finger vein/fingerprint-reading MA VP MD devices, fingerprint-reading products SIGMA and MorphoWave, and versions of facial recognition device VisionPass have been detected by researchers. 

In the wake of the Colonial Pipeline attack, the US Department of Homeland Security issues a directive for critical fuel supplies security

In the wake of the Colonial Pipeline attack, the US Department of Homeland Security issues a directive for critical fuel supplies security

 The United States Department of Homeland Security (DHS) has directed that tighter security controls be implemented on critical pipelines following the recent attack on Colonial Pipeline.

Cancer patients’ data exposed at Jefferson Health following a third-party hack

Cancer patients’ data exposed at Jefferson Health following a third-party hack

As incidents of cyberattacks continue to rise in the United States, Jefferson Health, a US healthcare provider, has announced that some information of its patients may have been exposed following a breach on third-party Elekta systems.
Medical record numbers of patients, clinical information related to treatment, patients’ names and dates of birth, and some of patients’ Social Security numbers were included in the data that have been exposed. 

Mozilla’s Firefox 91 to feature HTTPS by default in private browsing mode

Mozilla’s Firefox 91 to feature HTTPS by default in private browsing mode

In its continued efforts to protect its users from threats and attacks, the popular browser, Mozilla, is set to release its latest version of Firefox 91, which has been designed to process HTTPS in Private Browsing mode by default.
This implies that the Firefox browser will first establish a secure, encrypted HyperText Transfer Protocol (HTTP) connection to a website when users click on an insecure link on a web page or when they enter a risky HTTP Url in the address bar.

The bar for printing fraudulent SSL certificates lowers due to downgrading attack on Let’s Encrypt

The bar for printing fraudulent SSL certificates lowers due to downgrading attack on Let’s Encrypt

A team of security researchers based in Germany has discovered a hacking technique that allowed them to bypass the domain validation technology of a non-profit certificate authority that gives owners of domain with SSL certificates used in authenticating sites that use Hypertext Transfer Protocol Secure (HTTPS).

Activist finds potential data leak, erupts dispute between Germany’s CDU and Chaos Computer Club

Activist finds potential data leak, erupts dispute between Germany’s CDU and Chaos Computer Club

An association of hackers based in Germany, the Chaos Computer Club (CCC), has announced that it will withdraw its alliance with Germany’s ruling political party, Christian Democratic Union (CDU), after one of its activists was allegedly threatened with legal prosecution by the latter following a security bug report.

Valve Software fixes gaming wallet funds cheat

Valve Software fixes gaming wallet funds cheat

A security researcher has received a total of $7,500 in bug bounty after he discovered a vulnerability in a popular steam gaming platform. The security flaw could allow gamers to credit their in-game Steam wallet account by increasing the value of deposits artificially.

Developers of Node.js fix a high-risk vulnerability that could open up remote domain hijacking

Developers of Node.js fix a high-risk vulnerability that could open up remote domain hijacking

A discovered vulnerability that could permit an attacker to remotely hijack a domain in Node.js has been fixed.
The JavaScript runtime environment engineers have advised users to protect their applications against series of bugs by updating to the latest version.

Attackers seize control of gym members’ data and payment info due to Unpatched vulnerabilities in the Wodify app

Attackers seize control of gym members’ data and payment info due to Unpatched vulnerabilities in the Wodify app

Three vulnerabilities classified as high risk has been discovered in the popular fitness and gym management application, Wodify. The vulnerabilities could let the unauthorized user modify production data and access sensitive private information.

Following unauthorized access to emails, a US medical imaging center reports a possible data breach

Following unauthorized access to emails, a US medical imaging center reports a possible data breach

A US medical imaging center based in Atlanta, Georgia, Express MRI, has disclosed the medical information of its patients may have been accessed in a data breach.
The data breach which dates back to the 10th of July, 2020 was noticed when unauthenticated emails were sent from the Express MRI email account.

Audiomack launches public bug bounty program for its music streaming platform

Audiomack launches public bug bounty program for its music streaming platform

The renowned music-sharing site, Audiomack, is partnering with Bugcrowd to launch a public bug bounty program in an effort to encourage security researchers to share information in case of suspected vulnerabilities.
The music service is running its new Vulnerability Disclosure Program (VDP) which it had previously for almost one year.

Multiple vulnerabilities detected in Aruba Networks opened up remote code execution on routers

Multiple vulnerabilities detected in Aruba Networks opened up remote code execution on routers

Malicious activities which included Remote Code Execution (RCE) have been carried out in Aruba Network routers due to multiple vulnerabilities that were discovered.
Security researchers discovered eight vulnerabilities in the Aruba Instant software, which allow the settings of Aruba routers to be configured by the administrators.

A complete site takeover possible due to XSS vulnerability in WordPress plugin SEOPress

A complete site takeover possible due to XSS vulnerability in WordPress plugin SEOPress

Security researchers have advised that a cross-site scripting (XSS) vulnerability discovered in a popular WordPress plugin, SEOPress, could give way to an attacker to take total control of a website.
Whenever a user accessed the ‘All Posts’ page, the security defect allowed an attacker to inject arbitrary web scripts on a vulnerable website that would execute anytime.

Allegation of improper access to Indiana Covid-19 survey data denied by UpGuard

Allegation of improper access to Indiana Covid-19 survey data denied by UpGuard

The United States’ Indiana Department of Health has issued a statement stressing that personal data of its citizens, obtained via the Covid-19 contact tracing survey, have been accessed improperly by a security vendor.
The Indiana Department of Health announced it would bring to the notice of about 750,000 of its citizens that its Covid-19 contact tracing data have been improperly accessed.

Following the termination of employment, woman deletes company’s vital information and damages computers

Following the termination of employment, woman deletes company’s vital information and damages computers

A Florida-based woman, Medghyne Calonge, 41, has been found guilty by a unanimous decision of jurists of the US Southern District of New York for having unauthorized access to a protected computer and causing major damage to an organization after her employment was terminated.

Revealed: The Web Application Firewall (WAF) of Fortinet is open to command injection attacks

Revealed: The Web Application Firewall (WAF) of Fortinet is open to command injection attacks

A new finding by Rapid7 has revealed there is a vulnerability that gives attackers a chance to run arbitrary commands on devices and servers running the security software on the web application firewall (WAF) of Fortinet.
Fortinet gives FortiWeb an offering of SaaS as well as hardware Web Application Firewalls with various network capacities while FortiWeb protects web applications from attacks that focus on both unknown and known vulnerabilities

Attackers modify Mozi malware to have more impact on industrial control systems

Attackers modify Mozi malware to have more impact on industrial control systems

A peer-to-peer botnet, Mozi, has been developed by attackers to achieve a lasting presence on network gateways and routers.
The Mozi malware which transmits to the Internet of Things (IoT) by using weak Telnet hash passwords and known vulnerabilities has been in existence for two years. It uses the infected devices to send spam and launch Denial of Service (DoS) attacks.

47,000 citizens affected in the latest New York University data breach

47,000 citizens affected in the latest New York University data breach

Following the disclosure by The Research Foundation for the State University of New York (SUNY) that unauthorized access to its network system was detected earlier this year, It has been discovered that personal information belonging to about 47,000 people has been exposed.

After ransomware attack, Entertainment tech provider, D-Box, recovers

After ransomware attack, Entertainment tech provider, D-Box, recovers

Canadian immersive entertainment technology provider, D-Box, has announced its progressive recovery from a ransomware attack that partially disrupted many of its IT systems a few weeks ago.
It was reported that the major IT systems affected have been restored and the restoration process of the whole system function would be concluded soon.

Swindled through Fake Crypto-mining Android Apps

$350k Swindled through Fake Crypto-mining Android Apps

More than 93,000 unsuspecting users of fake cryptocurrency mining apps have been defrauded to the tune of $350,000. The victims were cleverly conned and made to purchase the apps, pay for fake subscriptions and upgrades through a process that appeared legitimate and convincing.

Website leaks AWS secret keys due to a Flaw in the preprocessor language Less.js.

Website leaks AWS secret keys due to a Flaw in the preprocessor language Less.js.

Researchers have warned that the vulnerability in the popular preprocessor language, Less.js , could be exploited to make remote code execution (RCE) against websites that permit users to input Less.js code.
Less.js converts the source code of a language to valid CSS code and is then applied to facilitate the writing of CSS for websites.

Mozilla’s Firefox becomes the latest browser to support Fetch Metadata request headers

Mozilla’s Firefox becomes the latest browser to support Fetch Metadata request headers

In its quest to further protect users from the high-impact web attacks, Mozilla has announced that Firefox, now supports Fetch Metadata request headers.

Etherpad: Critical vulnerabilities could to lead remote attacks

Etherpad: Critical vulnerabilities could to lead remote attacks

New research reveals that security lapses discovered in an online text editor, Etherpad, can expose victims’ servers and make them prone to cyber-attacks. The defects can allow attackers to compromise the server of their victims and steal sensitive information from them at a remote distance.

Fraudsters apprehended as Eurojust Intercepts €2 million e-commerce fraud operation

Fraudsters apprehended as Eurojust Intercepts €2 million e-commerce fraud operation

Eight members of a criminal gang who defrauded some shoppers online to the tune of €2 million (about $2.4 million) have been apprehended by the Greek and Romanian police.

Microsoft pays $14m bug bounty rewards in 52 weeks

Microsoft pays $14m bug bounty rewards in 52 weeks

Technology powerhouse, Microsoft, has awarded the sum of $13.6 million to security researchers under its bug bounty program in the past 52 weeks.

Vulnerability in Apache Tomcat has been present since 2015

Vulnerability in Apache Tomcat has been present since 2015

Project maintainers have warned that A Hypertext Transfer Protocol (HTTP) request smuggling vulnerability in Apache Tomcat, has been present since 2015. The Apache Tomcat maintainers revealed that the vulnerability was discovered in multiple versions of the software.

Yearn Finance launches bug bounty program worth $200k in payouts

Yearn Finance launches bug bounty program worth $200k in payouts

A bug bounty program initiated by The decentralized finance (DeFi) protocol, Yearn Finance, has been instituted in association with Immunefi.

Binance: Ransomware-linked money laundering operation tracked down using data analytics.

Binance: Ransomware-linked money laundering operation tracked down using data analytics.

The renowned cryptocurrency exchange platform, Binance, has explained how they were able to track down money laundering syndicates involved in series of cybercrime activities, especially ransomware scams.

Phish-and-carding kingpin nabbed

Phish-and-carding kingpin nabbed

A suspect, who was involved in various cybercrime activities, has been arrested by the Moroccan police. His targets were customers of Telecommunication companies, French Bank customers, and contacts of many multinational organizations.