-
Surge in Compromised ChatGPT Accounts
Group-IB, a leading cybersecurity company based in Singapore, reported that over the past year it has identified a staggering 101,134 instances of stealer-infected devices with saved ChatGPT credentials. Group-IB’s Threat Intelligence platform made this discovery through analyzing logs of information-stealing malware, which were being traded on illicit dark web marketplaces. The Rising Threat to ChatGPT…
-
Major Data Breach at International Chapter of the P.E.O. Sisterhood Affects Over 94,000 Individuals
The International Chapter of the P.E.O. Sisterhood, a non-profit organization based in Des Moines, Iowa, has announced that it fell victim to a major data breach, potentially affecting 94,200 individuals. On April 14, 2023, the organization’s systems were hit by a ransomware attack, which resulted in a complete shutdown and lockdown of their systems. The…
-
Microsoft’s June Patch Tuesday Addresses 78 Vulnerabilities Including Critical SharePoint Bug
In its latest Patch Tuesday for June 2023, Microsoft has rolled out fixes for 78 security flaws, which includes an alarming 38 remote code execution vulnerabilities. While Microsoft has not reported any of the vulnerabilities being actively exploited, the tech giant has specifically marked several as “more likely to be exploited”. One vulnerability that has…
-
Honda’s Power Equipment eCommerce Platform Compromised Through Vulnerable API
In a significant revelation, Honda’s power equipment, marine, and lawn & garden dealer eCommerce platform has been compromised due to a vulnerable password reset API. The hacker managed to access all data on the platform, including customer orders, dealer websites, dealer users/accounts, dealer emails, and customer emails. The hacker also potentially gained access to the…
-
Password Manager KeePass Patches Vulnerability in Recent Update
Over the weekend, KeePass, an open-source password manager, patched a vulnerability allowing potential attackers to extract the cleartext master password from a memory dump. This critical update came several weeks ahead of schedule, according to an official statement from KeePass. The flaw, tracked as CVE-2023-32784, impacted KeePass 2.x versions. It was connected to a custom-developed…
-
Gigabyte Rolls Out BIOS Updates to Remove Backdoor from Motherboards
Gigabyte, the Taiwanese computer components manufacturer, has released BIOS updates for a number of its motherboards to remove a backdoor that could have been used to gain unauthorized access to the devices. The backdoor was discovered by security researchers at Eclypsium, who found that it was present in the firmware of Gigabyte motherboards dating back…
-
Legal Tech Giant Casepoint Falls Victim to BlackCat Ransomware Attack
Casepoint, a leading litigation technology platform, has been named the latest victim of the notorious ransomware gang, BlackCat, also known as ALPHV. The group has claimed to have stolen over 2 TB of sensitive data from Casepoint, which includes attorney files and other confidential information. The announcement of the breach was made on BlackCat’s dark…
-
Capital One Discloses Data Breach Impacting Over 16,000 Customers
MCLEAN, VA – In a recent development, Capital One has confirmed a data breach that compromised the personal information of 16,779 individuals. The breach was discovered on April 26, 2023, having occurred between February 1 and February 4 of the same year. Adam Cohen, Associate General Counsel at Capital One, submitted a notification of the…