HamsterBoomer

29 Followers
44 Following
3.4K Posts
Session: 05ea022edb3590d9b75f62b53b628748623e0128295341cd5714f1de3d5c86543a
(Only for the ones which understand)
Cybersecurity, Test automation, IT information
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376

Russian APT exploits a critical XSS flaw in Zimbra, tracked as CVE-2025-66376, running scripts via HTML emails to target users in Ukraine.

Security Affairs

Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), exploited a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.

https://www.bleepingcomputer.com/news/security/russian-apt28-military-hackers-exploit-zimbra-flaw-in-ukrainian-govt-attacks/

Russian hackers exploit Zimbra flaw in Ukrainian govt attacks

Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities.

BleepingComputer

The US - and I cannot stress this enough - is the bad guy in virtually every situation.

No empire in world history has ever held this much power.

#Zambia #Africa @blackvoices

#DonaldTrump #EpsteinClass #IsraelFirst

#StraitOfHormuz = #Iran #Sanctions

#news #socialmedia #uspol #ireland #politics #mastodon #usa #protest @politics @socialmedia #humanrights #war #resistance #gaza #middleeast #freepalestine #StopGenocide #icc #europe #health #HIV

Starbucks data breach impacts 889 employees

Starbucks disclosed a breach after phishing attacks on its employee portal led to unauthorized access to Partner Central accounts.

Security Affairs
Ukraine's Armed Forces have liberated almost all of Dnipropetrovsk region, with three small settlements remaining to be taken and two to be cleared, General Staff operations chief Maj. Gen. Oleksandr Komarenko announced. The operation is carried out by air assault units supported by mechanized brigades. #Ukraine

We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

Microsoft warns of ClickFix campaign exploiting Windows Terminal for Lumma Stealer

Microsoft warns of ClickFix campaign using Windows Terminal to deliver Lumma Stealer via social engineering attacks.

Security Affairs
In recent years, the built-in password managers in browsers and operating systems have come a long way. https://www.eff.org/deeplinks/2026/02/how-pick-your-password-manager
How to Pick Your Password Manager

Phishing and data breaches are a constant on the internet. The single best defense against both is to use a password manager to generate and automatically fill a unique password for every site. There are free options, and even ones built into your operating system or browser. We can help you choose.

Electronic Frontier Foundation
Amazing, this one is up. For now.