Articles

The SEC Files a Lawsuit Against SolarWinds and Their CISO
The SEC has sued IT management company SolarWinds and its CISO Tim Brown, accusing the company of overstating its security posture and downplaying known vulnerabilities in the years leading up to the 2019 Russian-linked espionage attack.

International Law Enforcement Shuts Down Ragnar Locker’s Tor Sites
International law enforcement agencies seized the Tor negotiation and data leak sites run by the Ragnar Locker ransomware group, disrupting its operations in a significant win against organized cybercrime.

Okta’s Data Breach Now Affects 100% of Their Customers
Okta has revealed that a breach originally estimated to affect less than 1% of customers actually impacted all of them, after attackers gained unauthorized access to a support system report containing names, emails, and other sensitive data.

ICBC the World’s Largest Bank Has Been Hit With a Ransomware Attack
ICBC Financial Services, a division of the world’s largest bank by revenue, was hit with a ransomware attack that disrupted specific systems, prompting the unit to isolate affected infrastructure to contain further damage.

Largest DDoS Attack in History Mitigated
Google, Cloudflare, and AWS jointly disclosed a zero-day vulnerability called ‘HTTP/2 Rapid Reset’ behind the largest DDoS attack ever recorded, which peaked at 398 million requests per second before Google Cloud mitigated it.

DarkBeam Experiences Major Data Leak
Digital risk protection firm DarkBeam left an Elasticsearch and Kibana interface unsecured, exposing roughly 3.8 billion records that had originally been compiled to alert customers to prior breaches.

A New Critical Citrix Bug Has Been Exploited as a Zero-Day
A critical Citrix NetScaler vulnerability tracked as CVE-2023-4966 continues to threaten organizations even after patching, since active exploitation dating back to August 2023 means attackers may still hold hijacked sessions that require manual termination.

Boeing Investigates LockBit Ransomware Claim
Boeing is investigating a claim from the LockBit ransomware group that it breached the aerospace giant’s parts and distribution network, though Boeing says the incident has not compromised flight safety.

4.1 Million More Genetic Records Leaked From 23andMe
An additional 4.1 million stolen 23andMe genetic profiles from individuals in Great Britain and Germany have surfaced on a hacking forum, following an earlier leak of data belonging to a million users of Ashkenazi Jewish descent.

23andMe Data Leak Targets Ashkenazi Jews
Data from genetic testing service 23andMe has been compromised and circulated on the dark web in a breach that appears to specifically target close to a million users of Ashkenazi Jewish descent.

Nissan Confirms Ransomware Attack Affecting 100,000 People
Nissan Oceania has confirmed a ransomware attack by the Akira group affecting an estimated 100,000 people, after the automaker’s Australia and New Zealand operations disclosed a systems intrusion in early December 2023.

The Key Differences Between Traditional Penetration Testing and PTaaS
Traditional penetration testing offers a snapshot of security at a single point in time, but that’s no longer enough against today’s threats. This article explains the key differences between traditional pentesting and Penetration Testing as a Service.