• Hackers Target Russian Cybercrime Forums

    Hackers Target Russian Cybercrime Forums Elite cybercrime forum Maza aka MFclub has been taken over by hackers, according to new research by risk intelligence company Flashpoint.The Russian-language forum, which was originally known as Mazafaka, has served thousands of cyber-criminals since its launch in 2003. "Little is known at this time about the attackers who successfully compromised Maza," wrote Flashpoint researchers. But thanks to the data allegedly leaked in the attack, qu
  • US Warns of Fake Unemployment Benefit Websites

    US Warns of Fake Unemployment Benefit WebsitesThe United States Justice Department has warned that cyber-criminals are impersonating state workforce agencies (SWAs) to steal Americans' personal data.In a press release issued March 5, the department said it had received reports that bad actors are creating fake websites that mimic sites genuinely belonging to SWAs. "The fake websites are designed to trick consumers into thinking they are applying for unemployment benefits and discl
  • Failure to Report Breach Costs Mortgage Lender $1.5m

    Failure to Report Breach Costs Mortgage Lender $1.5mAn American mortgage lender has shelled out $1.5m to resolve allegations that it violated the New York Department of Financial Services (NYDFS) Cybersecurity Regulation. Residential Mortgage Services, Inc. (RMS), which is headquartered in South Portland, Maine, was accused of failing to report a data breach that occurred in 2019. The breach was uncovered during an investigation of RMS carried out in July 2020 by the NYDFS. T
  • 'There is no bomb': what I learned taking a polygraph test

    'There is no bomb': what I learned taking a polygraph test
    As the government plans to extend the use of lie detectors to terrorism and domestic abuse, our science editor puts himself in the hot seat“Did you plant the bomb?” It’s not a question I’ve been asked before but I’m comfortable enough denying it. Truth is – I didn’t plant a bomb. I planted a pretend bomb – a shoebox filled with webcams and wires – and I’m relying on my physiology to share the pedantic, but surely relevant, distinction.
  • Advertisement

  • Docker Hub and Bitbucket Resources Hijacked for Crypto-Mining

    Docker Hub and Bitbucket Resources Hijacked for Crypto-MiningSecurity researchers are warning of a resurgent campaign to hijack developer resources for cryptocurrency mining.A team from Aqua Security explained that over the period of just four days, attackers set up 92 malicious Docker Hub registries and 92 Bitbucket repositories to abuse these resources.“The adversaries create a continuous integration process that every hour initiates multiple auto-build processes, and on each build, a Mo
  • Fraudsters Circumvent 3D Secure with Social Engineering

    Fraudsters Circumvent 3D Secure with Social EngineeringCyber-criminals are actively sharing tips and advice on how to bypass the 3D Secure (3DS) protocol to commit payment fraud, according to researchers.A team at threat intelligence firm Gemini Advisory found the discussions on multiple dark web forums, claiming that phishing and social engineering tactics stood a good chance of success in certain situations.Although version two of the protocol, designed for smartphone users, allows individuals
  • SITA Supply Chain Breach Hits Multiple Airlines

    SITA Supply Chain Breach Hits Multiple AirlinesA major aviation IT company has been breached in what appears to be a coordinated supply chain attack affecting multiple airlines and hundreds of thousands of passengers.SITA provides IT and telecoms services to around 400 members in the industry, claiming to serve around 90% of the global airline business.It revealed yesterday that attackers had compromised passenger data stored on its SITA Passenger Service System servers in the US. It said these

Follow @Security_UKnws on Twitter!