Cybersecurity

DPRK Exploits 2 MITRE Sub-Techniques: Phantom DLL Hijacking, TCC Abuse

This month, MITRE will be adding two sub-techniques to its ATT&CK database that have been widely exploited by North Korean threat actors. The first, not entirely new, sub-technique involves manipulation of Transparency, Consent, and Control (TCC), a security protocol that regulates application permissions on Apple’s macOS. The other — called “phantom” dynamic link library (DLL) […]

Cybersecurity

Persistent Magento backdoor hidden in XML

Oops, your XML now contains shell code The following XML code was found in the layout_update database table and is responsible for periodic reinfections of your system. Attackers combine the Magento layout parser with the beberlei/assert package (installed by default) to execute system commands. Because the layout block is tied to the checkout cart, this […]

Cybersecurity

Hackers Leak Alleged Partial Facebook Marketplace Database

The alleged partial Facebook Marketplace database has been leaked on Breach Forums by the infamous threat actor IntelBroker. They claim that another actor, using the alias “algoatson,” stole the database from a contractor responsible for managing cloud services for Facebook. The infamous threat actor known as IntelBroker has claimed responsibility for leaking a partial database […]

Cybersecurity

Threat Actors Selling 1.8TB Database of Indian Mobile Users

The database holds personal records of over 750 million Indian citizens, accounting for nearly half of the country’s 1.4 billion population. A massive yet alleged data breach has reportedly exposed the personal information of millions worldwide, encompassing 85% of the Indian population, marking it as the largest-ever breach of its kind. Indian cybersecurity firm CloudSEK […]

Cybersecurity

Global Retailer BuyGoods.com Leaks 198GB of Internal and User PII, KYC data

The staggering 198.3 gigabytes of misconfigured database contained more than 260,000 records including customer selfies with unredacted credit cards. Cybersecurity researcher Jeremiah Fowler recently uncovered a misconfigured cloud database that had left a wealth of sensitive data exposed. The affected database contained records attributed to customers of BuyGoods.com, alternatively recognized in the industry as Softwareproject. […]

Cybersecurity

Aussie Travel Agency Data Leak Puts Thousands of Tourists at Risk

Melbourne-based travel agency, Inspiring Vacations, left a massive 26.8 GB database publicly exposed, devoid of any security measures like authentication or passwords. A data leak at a Melbourne-based travel agency has exposed the personal information of thousands of tourists, raising concerns about online security and privacy in the travel industry.  The leak was discovered by […]

Data Center

What Is a Configuration Management Database (CMDB)? | Definition from TechTarget

What is a configuration management database (CMDB)? A configuration management database (CMDB) is a file — usually in the form of a standardized database — that contains all relevant information about the hardware and software components used in an organization’s IT services and the relationships among those components. A CMDB stores information that provides an […]