With the chance of payouts on the decline, expect more leaks like this from other groups... Clop now leaks data stolen in MOVEit attacks on clearweb sites https://www.bleepingcomputer.com/news/security/clop-now-leaks-data-stolen-in-moveit-attacks-on-clearweb-sites/ #infosec #CyberSecurity #CSNB
Clop now leaks data stolen in MOVEit attacks on clearweb sites

The Clop ransomware gang is copying an ALPHV ransomware gang extortion tactic by creating Internet-accessible websites dedicated to specific victims, making it easier to leak stolen data and further pressuring victims into paying a ransom.

BleepingComputer
The M on Mario's hat may stand for malware... Trojanized Super Mario game used to install Windows malware https://www.bleepingcomputer.com/news/security/trojanized-super-mario-game-used-to-install-windows-malware/ #infosec #CyberSecurity #CSNB #Cybercrime
Trojanized Super Mario game used to install Windows malware

A trojanized installer for a popular Super Mario Bros game has been infecting unsuspecting players with multiple Windows malware families.

BleepingComputer
It's another home router being targeted by a #maliciousactor bt their #botnet ... New Condi DDoS botnet targets TP-Link Wi-Fi routers https://securityaffairs.com/147683/cyber-crime/condi-botnet.html #CyberSecurity #InfoSec #CSNB
New Condi DDoS botnet targets TP-Link Wi-Fi routers

Researchers discovered a new strain of malware called Condi that targets TP-Link Archer AX21 (AX1800) Wi-Fi routers. Fortinet FortiGuard Labs Researchers discovered a new strain of malware called Condi that was observed exploiting a vulnerability in TP-Link Archer AX21 (AX1800) Wi-Fi routers. “FortiGuard Labs encountered recent samples of a DDoS-as-a-service botnet calling itself Condi. It attempted to spread by exploiting TP-Link […]

Security Affairs
If you have an #Asus #wifi router, you need to check if yours has this #vulnerability and #patch immediately... Asus Patches Highly Critical WiFi Router Flaws - SecurityWeek https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/ #infosec #CyberSecurity #CSNB
Asus Patches Highly Critical WiFi Router Flaws

ASUS patched nine WiFi router security bugs, including a highly critical vulnerability (CVE-2018-1160) that exposes users to code execution attacks

SecurityWeek
On the things you should be checking if they are vulnerabile in your environment this morning list. #Cisco fixes #privilegeescalation bug in Cisco Secure Client https://securityaffairs.com/147217/security/cisco-secure-client-privilege-escalation.html #CyberSecurity #InfoSec #CSNB #vulnerability
Cisco fixes privilege escalation bug in Cisco Secure Client

Cisco addressed a high-severity flaw in Cisco Secure Client that can allow attackers to escalate privileges to the SYSTEM account. Cisco has fixed a high-severity vulnerability, tracked as CVE-2023-20178 (CVSS Score 7.8), found in Cisco Secure Client (formerly AnyConnect Secure Mobility Client) that can be exploited by low-privileged, authenticated, local attacker to escalate privileges to […]

Security Affairs
What did the game companiea do to disserve this... Was it #redfall, well OK they deserve it... #Akamai spotted a new #botnet dubbed #DarkFrost that is used to launch #DDoS attacks against the gaming industry. https://securityaffairs.com/146683/malware/dark-frost-botnet.html #CyberSecurity #InfoSec #CSNB #Cybercrime
Dark Frost Botnet targets the gaming sector with powerful DDoS

Researchers spotted a new botnet dubbed Dark Frost that is used to launch distributed denial-of-service (DDoS) attacks against the gaming industry. Researchers from Akamai discovered a new botnet called Dark Frost that was employed in distributed denial-of-service (DDoS) attacks. The botnet borrows code from several popular bot families, including Mirai, Gafgyt, and Qbot. The Dark Frost botnet was […]

Security Affairs
Oh the story that keeps getting G better, the #lastpass / #GoTo saga only gets better.... LastPass owner GoTo says hackers stole customers' backups • TechCrunch https://techcrunch.com/2023/01/24/goto-customer-backups-stolen-lastpass/ #infosec #CyberSecurity #CSNB #databreach
TechCrunch is part of the Yahoo family of brands

Vulnerabilities in #zoom remind me of early pandemic, but this is more serious with 4 #highseverity #vulnerabilitiesZoom... Rooms was affected by four “high” severity vulnerabilities https://securityaffairs.com/140607/security/zoom-rooms-vulnerabilities.html #CyberSecurity #InfoSec #CSNB
Zoom Rooms was affected by four “high” severity vulnerabilities

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms. Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms. Below are the details for the bugs addressed by the company: CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers. The issue affects Rooms for Windows […]

Security Affairs
Well this isn't good if you are a customer of #Okta... Okta's source code stolen after GitHub repositories hacked https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/ #infosec #CyberSecurity #CSNB #github
Okta's source code stolen after GitHub repositories hacked

In a 'confidential' email notification sent by Okta and seen by BleepingComputer, the company states that attackers gained access to its GitHub repositories this month and stole the company's source code.

BleepingComputer
Uber suffers new data breach after attack on vendor, info leaked online

Uber has suffered a new data breach after a threat actor leaked employee email addresses, corporate reports, and IT asset information stolen from a third-party vendor in a cybersecurity incident.

BleepingComputer