Cybersecurity

Vans, Supreme owner VF Corp says hackers stole 35 million customers’ personal data | TechCrunch

VF Corp., the parent company of the popular apparel brands Vans, Supreme, and The North Face, said Thursday that hackers stole the personal data of 35.5 million customers in a December cyberattack. The Denver, Colorado-based company reported the data breach to regulators in a filing on Thursday. The filing did not say specifically what kinds […]

Cybersecurity

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

Jan 19, 2024NewsroomMalware / Endpoint Security Pirated applications targeting Apple macOS users have been observed containing a backdoor capable of granting attackers remote control to infected machines. “These applications are being hosted on Chinese pirating websites in order to gain victims,” Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said. “Once detonated, the malware […]

Cybersecurity

AHA: Rise in Scams Targeting IT Help Desks for Payment Fraud

Fraud Management & Cybercrime , Healthcare , Industry Specific American Hospital Association Warns of Social Engineering Schemes Marianne Kolbasuk McGee (HealthInfoSec) • January 18, 2024     Image: Getty Threat actors are targeting hospital IT help desks with elaborate social engineering scams to commit payment fraud by using stolen credentials from billing and payments employees, […]

Cybersecurity

Npm Trojan Bypasses UAC, Installs AnyDesk with “Oscompatible” Package

Jan 19, 2024NewsroomSoftware Security / Spyware A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines. The package, named “oscompatible,” was published on January 9, 2024, attracting a total of 380 downloads before it was taken down. oscompatible included a “few strange binaries,” according […]

Cybersecurity

CISA Warns Against New Androxgh0st Malware Attacks | Cyware Hacker News

Organizations across the globe have been warned against a new campaign leveraging Androxgh0st malware that steals credentials from various high-profile applications such as AWS, Microsoft 365, Twilio, and SendGrid. A joint advisory issued by the FBI and the CISA reveals that the campaign actively targets Apache servers and websites using the popular Laravel Web application […]