Attacks

Over 45,000 VMware ESXi Servers Reach End-Of-Life

It is critical for organizations to keep their ESXi servers up to date. Vulnerabilities may accumulate, allowing an attacker a variety of opportunities for exploitation. In addition, because ESXi servers host virtual machines, they are a very desirable target for attackers. The compromise of a single ESXi server could lead to the compromise of dozens of production servers hosted within.System administrators can use this resource from VMware to plan a proactive update cycle and avoid…

Read More

CISA Releases Two Industrial Control Systems Advisories

Original release date: October 18, 2022 CISA released two Industrial Control Systems (ICS) advisories on October 18, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-291-01 Advantech R-SeeNet ICSA-21-336-06 Hitachi Energy APM Edge (Update A) This product is provided subject to this Notification and this Privacy & Use policy.

Read More

CISA Releases RedEye: Red Team Campaign Visualization and Reporting Tool

Original release date: October 14, 2022 CISA has released RedEye, an interactive open-source analytic tool to visualize and report Red Team command and control activities. RedEye allows an operator to quickly assess complex data, evaluate mitigation strategies, and enable effective decision making. For more information, CISA encourages users to review RedEye on GitHub and watch CISA’s RedEye tool overview video. This product is provided subject to this Notification and this Privacy & Use policy.

Read More

IOTW: Hacker allegedly hits both Uber and Rockstar

It has been alleged that the hacker who gained unauthorized access to rideshare service Uber’s servers was also responsible for a similar hack into the systems of Rockstar Games, developer of the Grand Theft Auto (GTA) game series. The hack into Rockstar Games was discovered on September 19, 2022 after a user called teapotuberhacker posted on Grand Theft Auto game series fan site GTAForums: “Here are 90 footage/clips from GTA 6. It’s possible I could…

Read More

Ferrari denies breach following 7GB of data posted online

Italian car manufacturer Ferrari has denied being the victim of a cyber-attack after ransomware gang RansomEXX claimed it had stolen 7GB of the company’s data and posted it online. News of the alleged breach was posted by dark web intelligence feed DarkFeed on Twitterwhere it shared screenshots from RansomEXX in which they claimed to be sharing “some internal documents, data sheets [and] repair manuals”. 🌐 RansomEXX #ransomware team added Ferrari To the victim’s list 🚨…

Read More

Former CSO of Uber found guilty of covering up data breach

A federal jury has found Joe Sullivan, former CSO of Uber, guilty of covering up a data breach the company suffered in 2016.  The breach saw 57 million user’s information including full names, email addresses, telephone numbers and driver’s license numbers exposed, and led to Uber paying US$148,000 to settle civil litigation. Sullivan was convicted on October 5 of obstruction of proceedings of the Federal Trade Commission (FTC) and misprision of felony in connection with…

Read More

IOTW: Capital One hacker given probation following cyber attack

Paige Thompson, a former Amazon software engineer known by the online handle ‘erratic’ was sentenced to time served and five years’ probation for seven federal crimes. Thompson’s location and personal computer will also be monitored.  The sentencing was related to her hacks into a number of cloud accounts for both individuals and companies, including the bank Capital One. During the hacks, Thompson stole data and computer power. At the trial, she was found guilty of…

Read More

IOTW: Everything we know about the Optus data breach

Australian telecommunication company Optus suffered a devastating data breach on September 22 that has led to the details of 11 million customers being accessed. The information accessed includes customers’ names, dates of birth, phone numbers, email addresses, home addresses, driver’s license and/or passport numbers and Medicare ID numbers. Payment detail and account passwords were not compromised in the breach. Optus confirmed that it has now contacted all customers to notify them of the cyber-attack’s impact,…

Read More

Suspected Grand Theft Auto 6 hacker arrested by UK police

The person responsible for hacking into Rockstar Games, leaking gameplay and clips from the upcoming Grand Theft Auto 6 game, has been potentially identified and arrested by London police. The hacker, known as teapottuberhacker, was also allegedly responsible for an attack into rideshare platform Uber earlier this month, which saw the hacker take control of Uber’s systems and post a graphic image on the company’s internal sites. They are also said to be a member…

Read More