vulnu.com <- sign up for my weekly cybersecurity newsletter
We can connect some dots based on what they do as a company.
We can connect some dots based on what they do as a company.
While this is all good advice, it wouldn't have done much to stop this type of attack.
Hacks are just logins in 2025.
While this is all good advice, it wouldn't have done much to stop this type of attack.
Hacks are just logins in 2025.
Claims align with known Medusa TTPs focusing on high-value targets.
Claims align with known Medusa TTPs focusing on high-value targets.
Group has hit 300+ victims in past 4 years per US cyber authorities.
(img: TheHackerNews)
Group has hit 300+ victims in past 4 years per US cyber authorities.
(img: TheHackerNews)
Offer later increased to 25% of what they claimed would be "1% of BBC's total revenue."
Offer later increased to 25% of what they claimed would be "1% of BBC's total revenue."
He played along so we got a look inside their tactic here:
He played along so we got a look inside their tactic here:
@haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold”
Just great life advice in general. Will remember this quote forever.
Oh and @hdm.io and @andrewmorr.is are cool too.
@haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold”
Just great life advice in general. Will remember this quote forever.
Oh and @hdm.io and @andrewmorr.is are cool too.
Original article: www.404media.co/wome...
Original article: www.404media.co/wome...
This is why security and privacy pros hate these ID verification laws that require drivers license uploads - these apps just can't keep this stuff secure.
This is why security and privacy pros hate these ID verification laws that require drivers license uploads - these apps just can't keep this stuff secure.
The app is meant to be basically the "are we dating the same man?" Facebook group in a dating app.
In order to verify that the users are women, they ask for photos and driver's licenses.
The app is meant to be basically the "are we dating the same man?" Facebook group in a dating app.
In order to verify that the users are women, they ask for photos and driver's licenses.
They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public
Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
And now FileFix on top of it...
And now FileFix on top of it...
Artem Baranov did the dang math.
He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
Artem Baranov did the dang math.
He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches.
Keychain creds, browser data, Telegram chats, then push over WebSockets - encrypted channel, tricky for network sensors that ignore non-HTTP(S) traffic
Keychain creds, browser data, Telegram chats, then push over WebSockets - encrypted channel, tricky for network sensors that ignore non-HTTP(S) traffic