Ukraine Arrests Hackers for Selling 100 Million Email, Instagram Accounts

0
[ad_1]
Ukraine Arrests Hackers for Selling 100 Million Email, Instagram Accounts

Ukrainian police seized a massive trove of 100 million stolen email and Instagram accounts – Three individuals were arrested for hacking and selling the data on the dark web – This major cybercrime bust highlights the importance of strong passwords and two-factor authentication (2FA) to protect your online accounts.

The Ukrainian Cyber Police, working alongside investigators from the national police, have pulled off a major win in the fight against cybercrime. They successfully arrested three individuals accused of hacking and selling a staggering 100 million email and Instagram accounts on the dark web.

Authorities believe the group used a brute-force attack technique, essentially bombarding accounts with numerous password combinations until they cracked the login credentials. These stolen accounts were then compiled into a database and offered for sale on dark web marketplaces and hacking forums, where malicious hackers could purchase them for fraudulent activities.

It is worth mentioning that currently, some of the most active and popular hacker and cybercrime forums include Breach Forums and a Russian language platform called XSS. Cybercriminals utilize these forums to sell stolen data through escrow deals, while others opt to leak it for free. Additionally, Telegram serves as a significant platform for criminals to announce data breaches and either leak or sell data.

According to Cyber Police’s press release, the buyers used the stolen accounts to launch various scams, including the notorious “Friend Asks for a Loan” scheme where compromised accounts are used to target the victim’s friends and family with fabricated requests for money.

Additionally, law enforcement officers conducted 7 searches at the residences and registered addresses of individuals involved in Kyiv, Odesa, Vinnytsia, and Ivano-Frankivsk, as well as in the regions of Kyiv, Donetsk, and Kirovohrad. During these searches, over 70 pieces of computer equipment, 14 phones, bank cards, and cash, totalling more than $3,000, were seized. A petition has been submitted to the court to request the seizure of the confiscated property.

Law enforcement officers conducted 7 searches at the residences and registered addresses of individuals involved in Kyiv, Odesa, Vinnytsia, Ivano-Frankivsk, as well as in the regions of Kyiv, Donetsk, and Kirovohrad. During these searches, over 70 pieces of computer equipment, 14 phones, bank cards, and cash, totaling more than $3,000, were seized. A petition has been submitted to the court to request the seizure of the confiscated property.
Seized equipment (Image credit: Ukraine Cyber Police)

The ages of the arrested suspects range from 20 to 40. They now face charges of unauthorized interference in information systems and networks, a serious offence in Ukraine punishable by up to 15 years in prison.

The investigation isn’t over yet, however. Authorities suspect the group may have collaborated with foreign entities, particularly those with interests aligned with Russia. Investigators are looking into the possibility that some of the stolen accounts were used specifically to benefit Russian interests, though the exact nature of this potential collaboration remains unclear.

Commenting on this, Jamie Akhtar, CEO and Co-Founder at CyberSmart said: “Following the takedown of LockBit in February, this is another heartening story. It demonstrates that cybercriminals can be caught and brought to justice. However, we shouldn’t rest on our laurels, for each of these groups that is shut down another will spring up in its place and those still at large will learn from how their peers were caught.”

This arrest goes on to show the importance of taking cybersecurity measures. Using strong and unique passwords for all online accounts is crucial, and enabling multi-factor authentication (MFA) whenever possible adds an extra layer of security. The Ukrainian cyber police also recommend these practices to help protect yourself from falling victim to similar account hijacking schemes.

While the full extent of the data breach remains under investigation, it’s a significant development and a win for law enforcement. The stolen accounts could have been used for a wide range of malicious activities, and their seizure disrupts a major operation within the cybercriminal underworld.

  1. Two hackers arrested after a decade of selling malware
  2. 10 years prison for hacking 200 firms, sold data on Dark Web
  3. Ukraine Busts Hackers Who Stole 30M Accounts of EU Citizens
  4. 360m WhatsApp Records Shared Freely on Telegram, Dark Web
  5. DeepDotWeb admin pleads guilty to money laundering, kickbacks

[ad_2]
Source link

Some Galaxy Z Flip 6 models could include an Exynos SoC

0
[ad_1]

According to a new report, some Galaxy Z Flip 6 models could include an Exynos SoC, instead of a Snapdragon one. In other words, Samsung could use the Exynos 2400 in some variants, instead of the Snapdragon 8 Gen 3.

Some Galaxy Z Flip 6 models could end up using the Exynos 2400 SoC

This information comes from Revegnus, a tipster. He doesn’t seem to be fully convinced it’ll happen, however. He said that he wouldn’t “be surprised even if the Exynos is included in this year’s Flip 6”.

So, it’s not set in stone. Samsung has a tendency to stick to Snapdragon processors in its Fold and Flip models. The Galaxy Z Flip 5 and Flip 5 are both fueled by the Snapdragon 8 Gen 2 for Galaxy chip.

The Galaxy Z Fold 6 and Galaxy Z Flip 6 are expected to ship with the Snapdragon 8 Gen 3 for Galaxy SoC. If this rumor ends up being true, however, units in Europe, for example, could end up sporting the Exynos 2400.

The Galaxy Z Fold 6 was not mentioned in this report

The tipster did mention the Galaxy Z Flip 6 in specific, not the Galaxy Z Fold 6. So the Galaxy Z Fold 6 will hopefully avoid the same fate. The Exynos 2400 is a much better SoC than its predecessor, but the Snapdragon 8 Gen 3 reigns supreme.

Both the Galaxy Z Fold 6 and Galaxy Z Flip 6 are expected to launch in July. July 10 has been tipped as the launch date, as the two phones are expected to launch in Paris, France.

Samsung usually launches its ‘Fold’ and ‘Flip’ foldables later on, but due to the Olympic Games that kick off on July 26 in the same city, the company decided to move up the launch of its new foldables.

Samsung did not officially confirm that date just yet, however. We’ll have to wait to be sure.


[ad_2]
Source link

DeepMind co-founder Mustafa Suleyman now leads Microsoft AI

0
[ad_1]

In the world of artificial intelligence, big brands are searching for people to head their AI divisions. For example, Apple recently purchased a company called Darwin AI and brought over some of its workers to head its AI division. Well, Microsoft just established Microsoft AI, and it hired DeepMind co-founder Mustafa Suleyman.

This is another example of large companies hiring top minds from their competitors. Back in 2010, Suleyman founded DeepMind. After leaving the company several years later and joining Google, he then co-founded Inflection AI in 2019.

Microsoft hires Mustafa Suleyman to head Microsoft AI

With AI being such a major subject with big companies, many Enterprises are finding themselves shuffling their business structures and adding full AI divisions where none existed. It’s obvious that Microsoft has gone all in on AI. So, it has a large team dedicated to pushing AI forward. Now, according to a new report, the company has a new AI division called Microsoft AI.

It brought on Suleyman as the CEO of Microsoft AI. So, he will oversee Copilot, Bing, and Edge. He will definitely be a higher-up, as he will be reporting directly to Satya Nadella, the CEO of Microsoft. So, the future of  Microsoft’s AI Endeavors will rest In His Hands.

However, he will not be alone. Fellow inflection AI co-founder Karén Simonyan will also join the team. He’ll take on the role of Chief scientist. Suleyman stated that several Inflection AI employees have also joined Microsoft. However, it appears that that might not be the case. Reports say that Microsoft may have hired the majority of Inflection AI’s staff, which doesn’t sound great for the company.

Inflection AI made a blog post explaining what the company wants to do going forward. The company is going to focus more on its AI Studio business. It appears that Inflection AI wants to focus more on this product as a business tool rather than a consumer tool. The company’s work so far makes it “uniquely well placed to be the AI platform for businesses around the world.”

Also, the company is currently searching for a new CEO. So, hopefully, Inflection AI doesn’t suffer any significant losses because of the shake-up. If you are a person who follows Inflection AI, you’ll be happy to know that it will host Inflection 2.5 on Microsoft Azure sometime down the road.

As for Microsoft, we are still in the dark as to what will change, what will improve, and what will be made worse. So, we’re just going to have to wait to find out what this new Microsoft AI division will bring.


[ad_2]
Source link

WordPress Plugin Flaw Exposes 40,000+ Websites to Cyber Attack

0
[ad_1]

A popular WordPress plugin, Automatic (premium version), developed by ValvePress, has been found to harbor critical security vulnerabilities that put over 40,000 websites at risk.

This plugin, known for its capability to create posts from various sources, including YouTube, Twitter, and virtually any website through scraping modules, has been identified as a gateway for potential cyber-attacks due to these flaws.

Unauthenticated Arbitrary SQL Execution – CVE-2024-27956

The first of the two vulnerabilities, CVE-2024-27956, allows unauthenticated users to execute arbitrary SQL queries on the affected WordPress sites.

This flaw was found in the inc/csv.php file, where an arbitrary SQL query could be supplied to the $q variable and executed.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

Despite checks involving user password trimming and MD5 hashing, attackers could bypass these by simply supplying a whitespace character, enabling full-scale SQL query execution.

Unauthenticated Arbitrary File Download and SSRF – CVE-2024-27954

The second vulnerability, CVE-2024-27954, pertains to arbitrary file downloads and Server-Side Request Forgery (SSRF) attacks.

This flaw in the downloader.php file allows attackers to fetch arbitrary URLs or local files using the $_GET[‘link’] parameter.

Initially, this could be exploited without any authentication, posing a significant risk to the integrity and confidentiality of the WordPress site data.

PatchStack has recently published a technical article highlighting the critical vulnerabilities fixed in the latest version of WordPress Automatic Plugin through security patches.

The Patch

In response to these vulnerabilities, ValvePress has issued updates to mitigate the risks. For CVE-2024-27956, the inc/csv.php file was removed entirely.

To address CVE-2024-27954, a nonce check was introduced, requiring a value only obtainable by privileged users, alongside a validation check on the $link variable.

These measures aim to secure the plugin against unauthorized SQL executions and file downloads.

FofaBot recently tweeted about a critical update to the WordPress Automatic plugin.

The discovery of these vulnerabilities underscores the critical need for rigorous security measures in plugin development, especially those that involve SQL query execution and URL fetching capabilities.

Developers are advised to avoid providing full-scale SQL query features, even to high-privilege users, and to implement permission and nonce checks for URL fetching actions.

For enhanced security, it is recommended that users fetch URLs using WordPress’s wp_safe_remote_* functions.

This incident serves as a reminder of the ever-present risks in the digital landscape and the importance of maintaining up-to-date security practices to protect against potential cyber threats.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

The ‘AT&T breach’—what you need to know

0
[ad_1]

Earlier this week, the data of over 70 million people was posted for sale on an online cybercrime forum. The person selling the data claims it stems from a 2021 breach at AT&T.

Back in 2021, a hacker named Shiny Hunters claimed to have breached AT&T and put the alleged stolen data up for sale for $1 million for a direct sell. Fast forward three years and another threat actor calling themselves MajorNelson has leaked what they say is the same data.

However, AT&T denies (both in 2021 and, now, in 2024) that the data came from its systems, telling BleepingComputer that it’s seen no evidence of a breach. No response was received to a follow-up question on whether the data could come from a third-party provider.

The data posted online includes names, addresses, mobile phone numbers, date of birth, social security numbers, and other internal information. Almost the same set was offered for sale in 2021, but the encrypted date of birth and social security numbers have since been decrypted and added to the set as supplemental files for most records.

Several sources have verified the dataset (or parts thereof) contains valid data.

What to do

AT&T still hasn’t confirmed that the data came from its systems, nor from a third party. However, there are some general actions you can take if you are an AT&T customer:

  • Watch out for people posing as AT&T. Data breaches are great for scammers because they can contact you pretending to be from the (in this case alleged) breached company. If you receive an email, phone call or something similar from someone claiming to be from AT&T be cautious and contact AT&T directly to check it’s real.
  • Take your time. Scammers often use themes that require urgent attention to hurry you into making a decision, filling in a form or giving away personal data. Take a step back and don’t give away any personal or financial information.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Check if your data has been breached

Our Digital Footprint records now include the AT&T data so you can check if your information has been exposed online. Submit your email address (it’s best to submit the one you most frequently use) to our free Digital Footprint scan and we’ll send you a report.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using Malwarebytes Identity Theft Protection.


[ad_2]
Source link

Samsung tops the list of best research & innovation brands in 2024

0
[ad_1]

Samsung has its branding spread across almost everything in the electronics world. Whether it be normal home appliances or smartphones, Samsung has its presence and is even dominating some of the areas. They already secured the tag of the best brand in aspects such as design and innovation in the past. With no surprise, they have now secured the top position in the list of best research and innovation brands for the year 2024.

Samsung is the best research and innovation brand once again

According to Clarivate’s latest list of Top 100 Global Innovators Brands of 2024, Samsung is the best brand for research and innovation. The report lists top one hundred brands for their huge contribution to the field of research and innovation. In the top 5 brands, followed by Samsung, brands such as Canon, Honda, Toyota, and Seiko Epson have secured their positions respectively.

As we look further into the report, we can spot multiple tech brands like Sony, Panasonic, Hitachi, Toshiba, Ericsson, Qualcomm, Toyota, Tencent, Daikin Industries, Zeiss, and a lot more. HONOR has secured the seventh position on the list. Moreover, as many as 38 Japanese-origin brands are there too. It shows how well the Japanese firms are doing in the field of research and innovation.

The United States ranks as the second country with the most contributions, having 17 brands, followed by Taiwan with 11 brands and South Korea with 8 brands, which also includes Samsung.

This is not surprising considering how much Samsung invests into R&D

Well, Samsung being at the top is a very good thing for the brand, but it is not very unexpected either. Samsung boasts a huge team of research and development which focuses on doing innovations each day. The overall portfolio of the brand whether it be patents or standalone research is very huge. Samsung first introduced all, whether it be the first foldable smartphone or innovations such as the first under-display camera in a foldable smartphone i.e., Galaxy Z Fold 3. This shows their research team’s enthusiasm.

The list focuses on tech and electronics as a whole rather than specifically on smartphone research. Samsung Electronics has dominated the list and not any particular division. But when we talk about Samsung Electronics, all the sub-divisions are already included in.


[ad_2]
Source link

DLL Hijacking & PHP Malware

0
[ad_1]

Researchers have discovered the workings of the MalSync malware known as the “DuckTail” or “SYS01”.

The analysis of the malware revealed the infection vectors, command line usage, malware capabilities, and other information.

The malware seems to have a targeted approach to stealing social media credentials and have capabilities of data extraction and detection evasion.

Moreover, the malware communicates with a command-and-control server for updating its configuration and receiving instructions.

MalSync Malware

According to Binary Defense’s reports, the index.php file handles device information collection, scheduled tasks, and data staging before exfiltration.

The analysis started with an alert raised due to suspicious PowerShell command line activity designed to add exclusions to Windows Defender.

Similar to other malware, this command was initiated by a svchost.exe process with elevated privileges.

Further analysis also revealed several executable files in the %AppData% directory. The list of files identified is as follows:

Though these files are used by legitimate installers and malware, the presence of these files in this specific directory raises suspicion.

Attack Chain

In addition, the file creation events in the malware showed a chain of executables which indicates a layered attack strategy.

The first part of the attack chain used an EXE file under the name “IMG_9597_One_Night_Stand_Li_Shaw – Gyeon_Jung_Hee_Studio – By_Gook_Changmin_Photographer.exe” that creates another EXE file “ts.exe”.

Following this, another two EXE files are created under the same name “cgcmpukluosgfec.exe”.

One of these files is a temporary file. After this, three other files are created such as rhc.exe, php.exe, and wdelua.exe alongside all the PHP libraries required for the attack chain.

The final part of the sequence is associated with the creation of a Scheduled search.

This search is used to communicate with the C2 server, download additional malware and create several other scheduled searches based on the C2’s response.

For luring users, the threat actor creates a file “WDSyncService.exe” which is capable of DLL search-order hijacking attack.

This DLL hijacking attack is performed by the use of WDSync.dll in the same directory that is loaded when the WDSyncService.exe is executed.

However, the original malware was found in the file named “updx-v2.5.23-setup.exe” which seems to be downloaded from an external source.

Further analysis of the malware executed through the MalSync’s IonCube PHP components had several other tactics such as identity theft, fraud and espionage activities.

Moreover, the index.php files consist of a large amount of PHP code that handles device information collection, task management, and data staging prior to exfiltration.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Mintlify Confirms Data Breach Through Compromised GitHub Tokens

0
[ad_1]
Mintlify Confirms Data Breach Through Compromised GitHub Tokens

Mintlify data breach exposes GitHub tokens of 91 customers. The software documentation platform experienced a security vulnerability that compromised private code access. Mintlify has taken steps to address the issue and users are advised to change passwords and enable 2FA.

A security breach at a software documentation platform, Mintlify, has allowed unauthorized access to 91 GitHub tokens, raising concerns about the potential exposure of private repositories and the need for improved security measures to protect user data. 

For your information, Mintlify assists developers in creating software documentation by requesting access to customers’ GitHub repositories, including fintech, database, and AI startups.

On March 1st, an email raised security concerns about endpoints’ security, leading to unusual requests from an unrecognized device. Some of these requests targeted sensitive API endpoints. 

Mintlify blames the breach on a vulnerability in its systems, discovered by a bug bounty reporter, which allowed the attackers to gain access to private admin tokens, causing unauthorized entry into the system.

It is worth noting that private tokens on GitHub enable users to share account access with third-party apps such as Mintlify. If stolen, attackers could access source code levels as permitted.

Initial probing revealed that compromised GitHub tokens were used to access a customer’s repository, with no evidence suggesting other repositories were accessed.

The company took immediate action by revoking all GitHub token access, rotating admin access tokens, and implementing stringent security measures to mitigate further unauthorized access. 

Furthermore, the vulnerability that exposed admin access tokens was patched. The company is deprecating private tokens to prevent similar incidents and working with GitHub and customers to determine if any other tokens were used by the attacker.

“The users have been notified, and we’re working with GitHub to identify whether the tokens were used to access private repositories,” the startup’s co-founder Hang Wang noted in the blog post.

The extent of the data breach remains unclear. Nevertheless, Mintlify has collaborated with third-party cybersecurity vendors to conduct a thorough investigation and implemented security measures. This includes improving API endpoint monitoring systems, establishing a robust security policy, launching a bounty program for ethical hackers, and re-auditing its 2024 SOC 2 certification. to prevent unauthorized access and ensure user security.

Mintlify advises users to change their password, enable two-factor authentication (2FA), monitor emails for suspicious activity, and review API key permissions. The incident underscores the need to improve cybersecurity for cryptocurrency exchanges, emphasizing the importance of strong passwords and 2FA.

  1. Malware as Dependabot Contributions Strikes GitHub Projects
  2. Massive Data Breach Exposes Info of 43 Million French Workers
  3. Hacker: I used GitHub 0day to hack US Federal contractor Acuity
  4. GitHub Reports Code-Signing Certificate Theft in Security Breach
  5. Scammers Exploit Crypto Hype with Token Factory, Stealing Millions

[ad_2]
Source link

Galaxy S25 CAD renders are being prepared as we speak

0
[ad_1]

It seems like Samsung is preparing the Galaxy S25 CAD renders as we speak. This information comes from a tipster, @kor_roe. Truth be said, that’s not our usual source of Samsung tips, but it’s easily possible he’s right.

The Galaxy S25 CAD renders are being prepared by the company, it seems

When it comes to smartphone designs, CAD-based renders are what we usually see first. That’s especially true when it comes to high-profile devices. @OnLeaks usually partners up with a publication and shares those renders with the world.

We’ve already seen the Pixel 9 and Pixel 9 Pro renders, for example, and the devices are not expected to launch until October. Considering that the Galaxy S25 series renders are being prepared, we may see those quite early too.

The Galaxy S25 series is not expected to arrive until January next year. Well, if Samsung intends to keep true to its release cycle. The Galaxy S24 CAD renders appeared in September last year almost 4 months ahead of launch.

It’s likely that @OnLeaks will show us the Galaxy S25 CAD renders first

Well, we have a feeling that the Galaxy S25 CAD-based renders could arrive even sooner than that. It remains to be seen, of course. Chances are they’ll once again come from @OnLeaks, though.

We do not have much info about the Galaxy S25 series thus far. An interesting rumor did surface quite recently, though. It claimed that (at least) the vanilla Galaxy S25 will feature a new design. In addition to that, it’s tipped to include a larger display too.

If that phone ends up changing things up in the design department, chances are that the other two will as well. The Galaxy S23 and Galaxy S23+ looked identical, aside from the size difference. The same goes for the Galaxy S24 and Galaxy S24+.

If we had to guess, we’d say that the same will happen with the Galaxy S25 series, but they both could have different designs. It remains to be seen.


[ad_2]
Source link

Samsung patents another rollable display, as the wait continues

0
[ad_1]

Samsung has secured a patent for yet another rollable display tech, as we’re waiting for first devices with rollable display to arrive. Foldable smartphones have been around for quite some time now, but phones with rollable displays, not exactly.

Samsung has patented yet another rollable display

We’ll talk more about that in a minute let’s first focus on this display. If you check out the images below, you’ll get to see some of the sketches included in the patent. This patent has been submitted with the United States Patent and Trademark Office (USPTO).

At the moment, we’re not sure for what it is, though. It could be for a smartphone, tablet, or TV. This is not the first rollable display patent Samsung submitted, not at all. Samsung also submitted a cylindrical roller design with the WIPO a while back, and it’s also worthing on a dual-folding display tech.

Samsung was the first company to release a foldable smartphone. That South Korean tech giant had a number of other firsts in the smartphone industry, and we wouldn’t be surprised if it delivered the first rollable smartphone.

LG was expected to release the first rollable smartphone, but that didn’t happen

LG allegedly had a rollable smartphone ready to go, but the company left the smartphone-making industry right before that. OPPO showed us its rollable smartphone concept a couple of years ago, but it still didn’t release such a product.

It will be interesting to see who will be the first to cross the finish line. Having new form factors on the market is always exciting. They’d provide competition for both regular phones and foldable smartphones alike.

Foldable devices are actually excellent nowadays, so the competition would be fierce. Devices like the OnePlus Open and HONOR Magic V2 really managed to push the ante when it comes to foldable smartphone designs.

We’re still not sure when we’ll see the very first rollable smartphone, but a rumor from last year suggested it will happen in the second half of this year. It remains to be seen.


[ad_2]
Source link