I think I crashed HostPlus website trying to check my balance
#superannuation
#cybersecurity #cyberattack
I think I crashed HostPlus website trying to check my balance
#superannuation
#cybersecurity #cyberattack
Ready for a fresh day of Cyber horrors? Me neither!
Oh well, here you go: https://opalsec.ghost.io/daily-news-update-wednesday-april-2-2025-australia-melbourne/
Here's a few of the key items to be aware of:
Palo Alto GlobalProtect Scans: Observed a significant spike in scans targeting Palo Alto Network GlobalProtect login portals, possibly prior to new exploit releases. Time to audit those logs!
China as Top Cyber Threat: Gen. Paul Nakasone (former NSA/Cyber Command Head) highlights China's unprecedented cyber activities, including malicious code in critical infrastructure and rapid exploitation of vulnerabilities. It's time to rethink our defense strategies!
North Korean IT Worker Expansion: North Korean "IT warriors" are infiltrating European companies, using fake identities to secure remote work and fund their regime. Stay vigilant and double-check those remote hires!
Identity Flaws in Breaches: A new report indicates 60% of incidents involved an identity attack, with compromised valid accounts being a top initial access vector. Focus on robust MFA, least privilege, and AD security!
Read the full post for all the details and more actionable insights, and if you want all this straight to your inbox, you're in luck! https://opalsec.ghost.io/daily-news-update-wednesday-april-2-2025-australia-melbourne/#/portal/signup
Attackers say they breached the British postal service last month, scooping a whopping 144 gigabytes of data.
#UK #hackers #cyberattack #cybersecurity #datasecurity #dataprivacy
Latest issue of my curated #cybersecurity and #infosec list of resources for week #13/2025 is out!
It includes the following and much more:
➝ DNA of 15 Million People for Sale in #23andMe Bankruptcy,
➝ #Trump administration accidentally texted a journalist its war plans,
➝ Critical Ingress #NGINX controller vulnerability allows RCE without authentication,
➝ #Cyberattack hits Ukraine's state railway,
➝ Troy Hunt's Mailchimp account was successfully phished,
➝ #OpenAI Offering $100K Bounties for Critical #Vulnerabilities,
➝ #Meta AI is now available in #WhatsApp for users in 41 European countries... and cannot be turned off
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end
https://infosec-mashup.santolaria.net/p/infosec-mashup-13-2025
Shocking Cyber Threat at KLIA, MAHB and Nacsa Step In to Protect Systems
#CyberAttack #KLIA #Malaysia #CyberSecurity #Hacking #Ransomware #TechNews #AirportSecurity #DigitalThreats
https://www.techi.com/klia-cyber-attack-mahb-nacsa-security-response/
Satellite Navigation Systems Facing Rising Jamming and Spoofing Attacks – Source:hackread.com https://ciso2ciso.com/satellite-navigation-systems-facing-rising-jamming-and-spoofing-attacks-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Technology #Satellite #Hackread #Maritime #security #Spoofing #Jamming #GNSS #GPS
#Cyberattack takes down Ukrainian state railway’s online services
liberated #Nadiya in #Luhansk oblast
Fire at #oil depot in #Krasnodar Krai continues for 5th day
In #Belgorod region,
took control of #Demidovka, and destroyed 4
helicopters and a bridge in #Nadezhevka
Large fire in #Simferopol Airport, in occupied #Crimea
Fire at #Sudzha gas metering station continues in #Kursk
lost another 1,280 soldiers
railways system failure after a large-scale #cyberattack
What Really Happened With the DDoS Attacks That Took Down X
—@WIRED
「 Kevin Beaumont and other analysts see evidence that some X origin servers, which respond to web requests, weren't properly secured behind the company's Cloudflare DDoS protection and were publicly visible. As a result, attackers could target them directly. X has since secured the servers 」
"Nym today launched NymVPN, a groundbreaking decentralized Virtual Private Network (dVPN) that protects users from government and corporate surveillance, including AI-driven tracking. NymVPN is built on the world’s first Noise Generating Mixnet (NGM), which is designed to protect metadata and patterns of communication, circumvent censorship, guard against cyberattacks, and fill security gaps in crypto transactions and VPN technology."
"Chelsea Manning, privacy advocate and security advisor at Nym, said: “Even in democratic nations, people are faced with unrestricted data collection, hyper-narrow algorithmic feeds and normalized censorship tactics. NymVPN takes an infrastructure-based privacy approach to try to combat this increasingly uncertain and splintered internet.”
Oh really it was Ukraine that took down X on March 10? Not so fast.
Independent security researchers found evidence that some X origin servers were not properly secured behind DDoS protection, and researchers noted they did not even see Ukraine in the breakdown of the top 20 IP address origins involved in the attacks. https://www.wired.com/story/x-ddos-attack-march-2025/ #X #Musk #DDoS #cyberattack #cybersecurity #security #Ukraine #BotNet #Internet
Safepay has been very active in Latin America.
https://www.security-chu.com/2025/03/Safepay-activo-latinoamerica-ransomware.html
Among the files exposed by these cybercriminals:
Funeral Home cali.losolivos.co Among this multitude of files, we found one from customer service. An unsatisfied customer with the service expresses their dissatisfaction with the funeral home through an email sent on February 16, 2022. #databreach #PII
Medical Center JockeySalud.com.pe In the samples exposed by these cybercriminals, there are image files of endoscopy reports of their patients. #databreach #PHI #Safepay
Yale New Haven Health Cyberattack Disrupts Connecticut Hospitals #Healthcare #Hospital #Cyberattack #Connecticut https://dysruptionhub.com/yale-new-haven-health-cyberattack-ct/
Swiss critical sector faces new 24-hour cyberattack reporting rule
Switzerland's National Cybersecurity Centre (NCSC) has announced a new reporting obligation for critical infrastructure organizations in the country, requiring them to report cyberattacks to the agency within 24 hours of their discovery.
#Swiss critical sector faces new 24-hour #cyberattack reporting rule
Silk Typhoon Hackers Indicted
Lots of interesting details in the story:
The US Department of Justice on Wednesday <a href="https://www.jus... https://www.schneier.com/blog/archives/2025/03/silk-typhoon-hackers-indicted.html
Elon Musk said a “massive cyberattack” disrupted X on Monday and pointed to “IP addresses originating in the Ukraine area” as the source of the attack. Security experts say that's not how it works. Read more at @WIRED. #X #ElonMusk #Malware #Cyberattack #Twitter #Tech #Technology https://flip.it/nwqrow
#Anonymous claims responsibility for shutting down the Nazi Bar for several hours today via a #cyberattack campaign they call Operation Dreadnought.
Yeah. Sure it was.
Elon Musk says a 'massive cyberattack' is to blame for X being down