NY Business Council discloses data breach affecting 47,000 people

Picus Blue Report 2025

The Business Council of New York State (BCNYS) has revealed that attackers who breached its network in February stole the personal, financial, and health information of over 47,000 individuals. As the state’s largest statewide employer association, BCNYS represents over 3,000 member organizations, including chambers of commerce, professional and trade associations, and other local and regional … Ler mais

O novo Android Attack tem como alvo os usuários indianos com subsídio gratuito de eletricidade para instalar malware

New Android Attack Targets Indian Users with Free Electricity Subsidy to Install Malware

A newly identified Android phishing campaign is aggressively targeting Indian users by masquerading as the legitimate PM Surya Ghar: Muft Bijli Yojana, a government initiative approved in February 2024 that offers subsidies for solar rooftop installations, covering up to 60% of costs for systems under 2kW and 40% for those up to 3kW. Os invasores … Ler mais

Os hackers Kimsuky norte -coreanos usam o Github para atingir embaixadas estrangeiras com malware Xenorat

North Korean Kimsuky Hackers Use GitHub to Target Foreign Embassies with XenoRAT Malware

O Centro de Pesquisa Avançado da Trellix expôs uma operação de espionagem ligada à RPDC atribuída ao grupo Kimsuky (APT43), visando missões diplomáticas na Coréia do Sul. Entre março e julho, pelo menos 19 e-mails de spear-phishing representavam contatos diplomáticos confiáveis, entregando malware por meio de arquivos ZIP protegidos por senha hospedados no Dropbox e … Ler mais

Zero-Day Exploit in WinRAR File – Schneier on Security

A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups: The vulnerability seemed to have super Windows powers. It abused alternate data streams, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that … Ler mais

South Yorkshire Police Deletes 96,000 Pieces of Digital Evidence

South Yorkshire Police Deletes 96,000 Pieces of Digital Evidence

The UK’s data protection regulator has reprimanded South Yorkshire Police (SYP) after it deleted 96,000 pieces of evidence from officers’ bodycams. The Information Commissioner’s Office (ICO) highlighted multiple failings related to backup, record keeping and data management. After an IT upgrade in May 2023, the centralized Digital Evidence Management (DEMS) system to which officers uploaded … Ler mais

O zagueiro da Microsoft AI pode detectar credenciais de texto simples no Active Directory

Microsoft Defender AI Can Detect Plaintext Credentials in Active Directory

A Microsoft revelou um novo recurso de segurança movido a IA que aborda uma das vulnerabilidades mais persistentes da cibersegurança: credenciais de texto simples armazenados nos sistemas do Active Directory. O recurso aprimorado do Microsoft Defender usa inteligência artificial sofisticada para detectar credenciais expostas com precisão sem precedentes, ajudando as organizações a eliminar um vetor … Ler mais

Blocos Pypi Expired Domínio Acesso para impedir ataques de ressurreição

PyPI Blocks Expired Domain Access to Prevent Resurrection Attacks

O Python Package Index (PYPI) implementou novas medidas de segurança para proteger contra ataques de ressurreição de domínio, uma ameaça sofisticada da cadeia de suprimentos em que os invasores compram domínios expirados para seqüestrar contas de usuário por meio de mecanismos de redefinição de senha. Desde o início de junho de 2025, a plataforma não … Ler mais

Australian ISP iiNet Suffers Breach of 280,000+ Records

Australian ISP iiNet Suffers Breach of 280,000+ Records

Australia’s second-largest ISP has revealed a major data breach impacting hundreds of thousands of customers. Parent company TPG Telecom notified the Australian Securities Exchange of the incident today. It said an “unknown third party” managed to gain unauthorized access to an order management system at subsidiary iiNet, in a breach discovered on Saturday. “Upon confirmation … Ler mais

Lockbit Linux Esxi Ransomware Variante revela técnicas de evasão e processo de criptografia de arquivo

Lockbit Linux ESXi Ransomware Variant Reveals Evasion Techniques and File Encryption Process

Uma análise recente de engenharia reversa de uma variante de ransomware Lockbit, direcionada aos servidores ESXi baseada em Linux, descobriu várias técnicas sofisticadas de evasão e detalhes operacionais. O malware, documentado pela primeira vez em 2022, emprega a chamada do sistema PTRACE para detectar ambientes de depuração, tentando anexar ao seu processo pai. Se isso … Ler mais

Allianz Life security breach impacted 1.1 million customers

Hackers leak 2.8M sensitive records from Allianz Life in Salesforce data breach

Allianz Life security breach impacted 1.1 million customers Allianz Life breach exposed data of most of its 1.4M customers; HIBP lists 1.1M impacted, though the insurer hasn’t confirmed exact figures. In July, Allianz Life disclosed a breach where hackers stole data from a cloud database, affecting most of its 1.4M customers and staff. Now, the … Ler mais