Mathspace discloses data breach affecting over 1 million people

Over 1 Million People’s Data Stolen in Mathspace Breach, with Attackers Linked to ShinyHunters Extortion Gang Mathspace, a popular online maths learning platform used by thousands of schools across Australia, New Zealand, and other countries, has disclosed a massive data breach that exposed the personal information of over 1 million students, staff, and parents. The … Read more

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A sophisticated phishing-as-a-service framework called BigBear 2.0 has been used to compromise the security of 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication (MFA). Researchers at CloudSEK gained access to the control panel of this malicious service and found that it was targeting Microsoft 365 users with a configuration called … Read more

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento’s StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoor, Leaving Thousands of Sites Vulnerable A severe security vulnerability known as StyleSmuggler has been discovered affecting all versions of Magento and Adobe Commerce. This zero-day exploit allows attackers to deploy a backdoor on compromised servers, leaving thousands of websites exposed. According to e-commerce security company Sansec, the … Read more

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

As a sophisticated threat actor, PEEP has managed to turn Chrome and Edge browsers into post-compromise backdoors for executing malicious commands on compromised systems. The technique exploits vulnerabilities in these popular web browsers, allowing hackers to secretly maintain access to infected machines even after they’ve been cleaned or reinstalled. At the heart of this exploit … Read more

Trezor data breach impact now reaches 81,000 customers

A major cryptocurrency hardware wallet maker has revealed that a recent data breach at its shipping and logistics provider has affected an additional 67,000 U.S. customers, bringing the total number of impacted individuals to 81,000. The incident highlights the need for companies to prioritize data protection and vigilance in their supply chains. The breach occurred … Read more

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A Sophisticated Phishing Service Bypasses MFA at Hundreds of Organizations A recent cybersecurity investigation has uncovered a highly sophisticated phishing-as-a-service (PhaaS) framework called BigBear 2.0, which has been used to compromise Microsoft 365 accounts at an astonishing 258 organizations worldwide. Researchers at CloudSEK discovered that the service exploited a vulnerability in multi-factor authentication (MFA), allowing … Read more

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento E-commerce Platform Hit with Zero-Day Vulnerability, Linux Backdoor Deployed In a worrying development for e-commerce security, a zero-day vulnerability dubbed “StyleSmuggler” has been exploited to deploy a Linux backdoor on websites running Magento and Adobe Commerce. The vulnerability affects all versions of the popular open-source e-commerce platform, which is installed on over 160,000 websites … Read more

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

A string of recent security incidents has highlighted a disturbing trend in cyberattacks, where attackers exploit identity exposure to unlock active attack paths and wreak havoc on unsuspecting organizations. The alarming rate at which this is happening underscores the need for businesses and individuals alike to take immediate action to shore up their defenses. One … Read more

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

**Phantom IT Calls Pose Serious Threat to Executives in Microsoft 365 Data Theft and Extortion Attacks** In a disturbing trend, cyberattackers have started targeting high-ranking executives with fake IT support calls, compromising their sensitive data and extorting them for ransom. This insidious tactic has been observed in attacks on Microsoft 365 users, where attackers exploit … Read more

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

**Critical Vulnerability in Telerik UI Components Exposes Millions to Remote Code Execution** A devastating security flaw has been discovered in the widely-used Telerik UI components, leaving millions of websites and applications vulnerable to remote code execution (RCE). The bug, known as a “padding oracle” vulnerability, allows attackers to chain it with other vulnerabilities to gain … Read more