Hardcoded AWS Credentials in 1,800 Mobile Apps Highlight Supply Chain Issues

Symantec has discovered hardcoded AWS credentials in more than 1,800 mobile applications and warned of the potential risks associated with poor security practices.
While Symantec’s threat hunting team has looked at both Android and iOS apps, nearly all… Continue reading Hardcoded AWS Credentials in 1,800 Mobile Apps Highlight Supply Chain Issues

Cybercriminals Apparently Involved in Russia-Linked Attack on Montenegro Government

Montenegro has been targeted in a disruptive cyberattack blamed on Russian hackers, and a known ransomware group may have been involved.
The country’s Agency for National Security announced last week that government servers had been targeted in an ongo… Continue reading Cybercriminals Apparently Involved in Russia-Linked Attack on Montenegro Government

Pwn2Own Offers $100,000 for Home Office Hacking Scenario

Trend Micro’s Zero Day Initiative (ZDI) has announced the targets and prizes for its next Pwn2Own hacking competition, as well as the introduction of a new category that aims to simulate a real world home office environment.
read more Continue reading Pwn2Own Offers $100,000 for Home Office Hacking Scenario

Details Disclosed for OPC UA Vulnerabilities Exploited at ICS Hacking Competition

Software development and security solutions provider JFrog has disclosed the details of several vulnerabilities affecting the OPC UA protocol, including flaws exploited by its employees at a hacking competition earlier this year.
read more Continue reading Details Disclosed for OPC UA Vulnerabilities Exploited at ICS Hacking Competition

DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others

Food delivery company DoorDash revealed on Thursday that customer and employee data has been exposed as a result of a recent breach at a third-party vendor.
DoorDash said hackers abused a third-party vendor’s access to its systems. The attacker abused … Continue reading DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others

CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

A vulnerability affecting industrial automation software from Delta Electronics appears to have been exploited in attacks, and the US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to take action as soon as possible.
re… Continue reading CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks