07/04

Microsoft denies data breach, theft of 30 million customer accounts

https://www.bleepingcomputer.com/news/security/microsoft-denies-data-breach-theft-of-30-million-customer-accounts/
Microsoft denies data breach, theft of 30 million customer accounts

疑似摩诃草组织利用WarHawk后门变种Spyder窥伺多国

https://mp.weixin.qq.com/s/ewGyvlmWUD45XTVsoxeVpg
疑似摩诃草组织利用WarHawk后门变种Spyder窥伺多国

The suspected Maha grass organization uses the WarHawk backdoor variant Spyder to spy on many countries

https://mp-weixin-qq-com.translate.goog/s/ewGyvlmWUD45XTVsoxeVpg?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
The suspected Maha grass organization uses the WarHawk backdoor variant Spyder to spy on many countries

Swedish Data Protection Authority Warns Companies Against Google Analytics Use

https://thehackernews.com/2023/07/swedish-data-protection-authority-warns.html
Swedish Data Protection Authority Warns Companies Against Google Analytics Use

Mexico-Based Hacker Targets Global Banks with Android Malware

https://thehackernews.com/2023/07/mexico-based-hacker-targets-global.html
Mexico-Based Hacker Targets Global Banks with Android Malware

Threads, an Instagram app on the App Store

https://apps.apple.com/us/app/threads-an-instagram-app/id6446901002
Threads, an Instagram app on the App Store

New Python tool checks NPM packages for manifest confusion issues

https://www.bleepingcomputer.com/news/security/new-python-tool-checks-npm-packages-for-manifest-confusion-issues/
New Python tool checks NPM packages for manifest confusion issues

Alert: 330,000 FortiGate Firewalls Still Unpatched to CVE-2023-27997 RCE Flaw

https://thehackernews.com/2023/07/alert-330000-fortigate-firewalls-still.html
Alert: 330,000 FortiGate Firewalls Still Unpatched to CVE-2023-27997 RCE Flaw

Hunting for Nginx Alias Traversals in the wild

https://labs.hakaioffsec.com/nginx-alias-traversal/
Hunting for Nginx Alias Traversals in the wild

Getting email address of any HackerOne user worth $7,500 | by Japz Divino | Pinoy White Hat | Jul, 2023 | Medium

https://medium.com/pinoywhitehat/getting-email-address-of-any-hackerone-user-worth-7-500-afb8076ee395
Getting email address of any HackerOne user worth $7,500 | by Japz Divino | Pinoy White Hat | Jul, 2023 | Medium

DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

https://thehackernews.com/2023/07/ddosia-attack-tool-evolves-with.html
DDoSia Attack Tool Evolves with Encryption, Targeting Multiple Sectors

AiTM/ MFA phishing attacks in combination with "new" Microsoft protections (2023 edition)

https://jeffreyappel.nl/aitm-mfa-phishing-attacks-in-combination-with-new-microsoft-protections-2023-edt/
AiTM/ MFA phishing attacks in combination with "new" Microsoft protections (2023 edition)

Hackers stole millions of dollars worth of crypto assets from Poly Network platformSecurity Affairs

https://securityaffairs.com/148129/cyber-crime/poly-network-platform-hacked.html
Hackers stole millions of dollars worth of crypto assets from Poly Network platformSecurity Affairs

draw.io

http://draw.io
draw.io

Google Analytics data transfer to U.S. brings $1 million fine to Swedish firms

https://www.bleepingcomputer.com/news/security/google-analytics-data-transfer-to-us-brings-1-million-fine-to-swedish-firms/
Google Analytics data transfer to U.S. brings $1 million fine to Swedish firms

Technical Analysis of Bandit Stealer | Zscaler

https://www.zscaler.com/blogs/security-research/technical-analysis-bandit-stealer
Technical Analysis of Bandit Stealer | Zscaler