A not-so-private anonymous video chat app has compromised credentials, including usernames, emails, and network information, thanks to a misconfigured Kibana dashboard.
…
Malicious actors are not targeting vote counters, but rather the voters themselves.
A flaw fixed last month is now being used in real-life attacks, and security researchers are urging users to patch.
Security researchers spotted a new campaign using the same methods as TeamPCP.
Initial Access Brokers are removing a major pain point helping ransomware operators steal more.
SilentPush is warning about an Intial Access Broker campaign called DriveSurge that uses thousands of websites to deploy a backdoor.
…
A tool started benign and turned sour after a little while, stealing tokens and granting persistent access.
If you’re using Linux, make sure you patch up and disable unnecessary file sharing features.
Thousands of attacks were seen in a single day as a patch is rolled out.
The botnet is theorized to be related to Asocks, with the possibility the proxy network has bitten the dust.