Tag: data-breach
-
Enthüllungen zur Ransomware Black-Basta zeigen erhebliche Sicherheitslücken
Ein kürzliches Datenleck hat die internen Chat-Protokolle der Ransomware-Gruppe Black-Basta offengelegt und zeigt alarmierende Sicherheitslücken in Unternehmensnetzwerken auf. Die geleakten Informationen bieten seltene Einblicke in die Angriffstaktiken der Gruppe und verdeutlichen gravierende Schwachstellen, die von Cyberkriminellen gezielt ausgenutzt werden. Zielgerichtete Angriffe auf bekannte Schwachstellen und Fehlkonfigurationen Black-Basta nutzt systematisch ungeschützte RDP-Server, schwache Authentifizierungsmechanismen sowie […]…
-
DeepSeek Data Leak Exposes 12,000 Hardcoded API Keys and Passwords
A sweeping analysis of the Common Crawl dataset”, a cornerstone of training data for large language models (LLMs) like DeepSeek”, has uncovered 11,908 live API keys, passwords, and credentials embedded in publicly accessible web pages. The leaked secrets, which authenticate successfully with services ranging from AWS to Slack and Mailchimp, highlight systemic risks in AI…
-
Cyberattack on Australia’s Genea: Stolen Patient Data Hits the Dark Web
The Termite ransomware group has allegedly leaked sensitive patient data following the Genea cyberattack, targeting one of Australia’s leading fertility providers. On February 26, 2025, the Termite ransomware group claimed responsibility for breaching Genea Pty Ltd’s systems. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/genea-cyberattack/
-
5 things to know about ransomware threats in 2025
Tags: access, attack, authentication, awareness, backup, breach, ciso, cloud, control, credentials, cyber, dark-web, data, data-breach, defense, detection, encryption, exploit, extortion, finance, fraud, group, healthcare, identity, incident response, infrastructure, Internet, iot, law, leak, mfa, monitoring, network, password, ransom, ransomware, risk, scam, service, software, sophos, supply-chain, technology, threat, tool, update, vpn, vulnerability, zero-day2. Mid-size organizations are highly vulnerable: Industry data shows mid-size organizations remain highly vulnerable to ransomware attacks. “CISOs need to be aware that ransomware is no longer just targeting large companies, but now even mid-sized organizations are at risk. This awareness is crucial,” says Christiaan Beek, senior director, threat analytics, at Rapid7.Companies with annual revenue…
-
Millions of WordPress Websites Vulnerable to Script Injection Due to Plugin Flaw
A critical security vulnerability in theEssential Addons for Elementorplugin, installed on over 2 million WordPress websites, has exposed sites to script injection attacks via malicious URL parameters. The flaw, tracked as CVE-2025-24752 and scoring 7.1 (High) on the CVSS scale, allowed attackers to execute reflected cross-site scripting (XSS) attacks by exploiting insufficient input sanitization in the plugin’s password reset…
-
2,850+ Ivanti Connect Secure Devices Exposed to Potential Cyberattacks
Tags: cyber, cyberattack, cybersecurity, data-breach, exploit, flaw, government, infrastructure, ivanti, network, risk, vpn, vulnerabilityA sweeping cybersecurity alert has emerged as researchers identify 2,850+ unpatched Ivanti Connect Secure devices worldwide, leaving organizations vulnerable to exploitation through the critical flaw designated CVE-2025-22467. The findings, published by cybersecurity watchdog Shadowserver Foundation, reveal systemic risks to virtual private network (VPN) infrastructures relied upon by enterprises and government agencies for secure remote access. Vulnerability Scope and…
-
US Employee Background Check Firm Hacked, 3 Million Records Exposed
DISA Global Solutions, a Houston-based provider of employee background checks and workplace safety services, disclosed a significant cybersecurity incident exposing the personal information of over3.3 million individuals, including 15,198 Maine residents. The breach occurred on February 9, 2024, but was not detected until April 22, 2024, according to a data breach notification filed with the…
-
Have I Been Pwned adds 284M accounts stolen by infostealer malware
The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-284m-accounts-stolen-by-infostealer-malware/
-
Intelligence mined from exposed Black Basta internal chats
First seen on scworld.com Jump to article: www.scworld.com/brief/intelligence-mined-from-exposed-black-basta-internal-chats
-
HHS Slaps Warby Parker With $1.5M Penalty Over Data Breach
First seen on scworld.com Jump to article: www.scworld.com/brief/hhs-slaps-warby-parker-with-1-5m-penalty-over-data-breach
-
House Dems say DOGE is leaving publicly exposed entry points into government systems
A letter from a trio of lawmakers says the group has “left multiple government agencies vulnerable to cyberattacks” from foreign entities. First seen on cyberscoop.com Jump to article: cyberscoop.com/house-dems-say-doge-is-leaving-publicly-exposed-entry-points-into-government-systems/
-
Background check, drug testing provider DISA suffers data breach
DISA Global Solutions, a Texas-based company that provides employment screening services (including drug and alcohol testing and background checks) for over 55,000 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/02/25/background-check-drug-testing-provider-disa-suffers-data-breach/
-
US drug testing firm DISA says data breach impacts 3.3 million people
DISA Global Solutions, a leading US background screening and drug and alcohol testing firm, has suffered a data breach impacting 3.3 million people. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-drug-testing-firm-disa-says-data-breach-impacts-33-million-people/
-
US drug testing firm says data breach impacted 3.3 million people
DISA Global Solutions, a leading US background screening and drug and alcohol testing firm, has suffered a data breach impacting 3.3 million people. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/disa-global-says-data-breach-impacted-33-million-people/
-
Background check and drug testing provider DISA Global Solutions reports data breach
Houston-based employee screening company DISA Global Solutions says a 2024 data breach exposed the information of more than 3.3 million people. First seen on therecord.media Jump to article: therecord.media/background-check-company-disa-data-breach
-
Southern Water takes the fifth over alleged $750K Black Basta ransom offer
Leaked chats and spilled secrets as AI helps decode circa 200K private talks First seen on theregister.com Jump to article: www.theregister.com/2025/02/25/southern_water_black_basta_leak/
-
Warby Parker slapped with $1.5M penalty over data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/warby-parker-slapped-with-1-5m-penalty-over-data-breach
-
Chinese cybersecurity firm’s involvement in surveillance, censorship exposed by data leak
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-cybersecurity-firms-involvement-in-surveillance-censorship-exposed-by-data-leak
-
Leaked Black Basta Chats Expose Ransomware Secrets Infighting
Leaked Black Basta chat logs expose ransomware secrets, key members, and internal conflicts, revealing new insights into cybercrime operations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/black-basta-ransomware-leak-chat-logs/
-
What defenders are learning from Black Basta’s leaked chat logs
The ransomware syndicate’s internal chats exposed a wide swath of the group’s inner workings. First seen on cyberscoop.com Jump to article: cyberscoop.com/black-basta-internal-chat-leak/
-
Smart Bed Security Flaw Lets Hackers Access Other Network Devices
Tags: access, backdoor, credentials, cyber, data-breach, flaw, hacker, Internet, iot, network, service, vulnerabilityA security researcher has uncovered critical vulnerabilities in Eight Sleep’s internet-connected smart beds, revealing exposed Amazon Web Services (AWS) credentials, remote SSH backdoors, and potential access to users’ entire home networks. The findings underscore growing concerns about IoT device security as consumers increasingly adopt connected appliances for everyday use. Researcher Discovers AWS Keys and Remote…
-
Leaked Black Basta chat logs reveal the gang’s operations
Leaked Black Basta chat logs reveal internal conflicts, exposing member details and hacking tools as the gang reportedly falls apart. An unknown actor, named ExploitWhispers, leaked Matrix chat logs of the Black Basta ransomware gang revealing internal conflicts, and exposing member details and hacking tools as the gang reportedly collapses. ExploitWhispers first uploaded the chat…
-
LockBit Ransomware Strikes: Exploiting a Confluence Vulnerability
Tags: attack, cvss, cyber, data-breach, exploit, lockbit, malicious, ransomware, remote-code-execution, vulnerability, windowsIn a swift and highly coordinated attack, LockBit ransomware operators exploited a critical remote code execution vulnerability (CVE-2023-22527) in Atlassian Confluence servers, targeting an exposed Windows server. This vulnerability, rated CVSS 10.0, enabled unauthenticated attackers to execute arbitrary commands by injecting malicious Object-Graph Navigation Language (OGNL) expressions into improperly sanitized template files. The attack commenced…
-
Change Healthcare’s Mega Attack: 1 Year Later
Ransomware Attack Taught Lessons on Health Sector Resiliency, Vendor Redundancy. It’s been one year since hackers attacked IT services provider Change Healthcare, quickly shutting down critical processes for thousands healthcare entities, triggering a data breach affecting 190 million people. So what top lessons are emerging from that massive disruption and data compromise? First seen on…
-
Leaked chat logs expose inner workings of secretive ransomware group
Researchers are poring over the data and feeding it into ChatGPT. First seen on arstechnica.com Jump to article: arstechnica.com/security/2025/02/leaked-chat-logs-expose-inner-workings-of-secretive-ransomware-group/
-
Purported Black Basta internal communications exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/purported-black-basta-internal-communications-exposed
-
Leaked Files Tie Chinese Cybersecurity Firm to Government Censorship
TopSec data leak: 7000+ documents expose potential Chinese government surveillance and censorship practices. Learn about the key findings… First seen on hackread.com Jump to article: hackread.com/leaked-files-chinese-cybersecurity-firm-govt-censorship/
-
Leaked Black Basta Chat Logs Show Banality of Ransomware
‘He Is an Idiot,’ Dissatisfied Hacker Writes of Boss. Two hundred thousand internal chat messages from the Russian ransomware group Black Basta have been leaked online, supposedly in reprisal for the operation targeting Russian banks. The partial logs, spanning 13 months, detail negotiations with victims, ransoms paid, internal disagreements and more. First seen on govinfosecurity.com…
-
A huge trove of leaked Black Basta chat logs expose the ransomware gang’s key members and victims
A leaker allegedly published the leaked internal messages after the group allegedly targeted Russian banks First seen on techcrunch.com Jump to article: techcrunch.com/2025/02/21/a-huge-trove-of-leaked-black-basta-chat-logs-expose-the-ransomware-gangs-key-members-and-victims/

