Researchers at Cyberint have reported a significant increase in online discussions pertaining to LinkedIn account hacking. Users have reported cases of accounts being locked, hijacked, or permanently deleted. In some instances, attackers are asking for ransom payments to recover the compromised accounts.
[Read more…] about Researchers Report Increase in LinkedIn Account Hijacking AttacksDiscord.io Temporarily Shuts Down Following Data Breach
The Discord.io custom invite service has temporarily shut down following a data breach that exposed information for 760K users. While not an official Discord site, the third-party service allowed visitors to search for Discord servers based on content and for server owners to create custom invites to their channels.
On August 13, a hacker known as ‘Akhirah’ began selling the Discord.io database on the Breached hacking forums. According to the hacker, the database contains information for 760,000 members, including usernames, Discord IDs, email addresses, and billing addresses among other details.
The breach is believed to have been caused by a vulnerability in the Discord.io website that provided access to the database. The site recommends that users who joined before 2018 update their password if shared with other websites.
Microsoft Now Enabling Windows Kernel Fix for All Users
Microsoft has enabled a fix for a kernel disclosure vulnerability (CVE-2023-32019) that it had disabled in previous Windows updates. The vulnerability, discovered by Mateusz Jurczyk of Google Project Zero, allows an attacker to access the memory of privileged processes to obtain potentially sensitive information.
Microsoft previously provided instructions for administrators to enable the fix by manually editing the Windows registry, noting the “resolution described in this article introduces a potential breaking change.” The warning led to uncertainty for many administrators who held out on deploying the fix out of concern that it would interfere with their Windows installations.
Microsoft has enabled the fix by default in Windows updates wince August 8, 2023.
Cybersecurity Daily: August 15, 2023
Your daily dose of relevant cybersecurity advisories, industry news, and product updates for Tuesday, August 15, 2023.
Advisories
- New CVE-2023-3519 scanner detects hacked Citrix ADC, Gateway devices
- Hackers Use Weaponized PDFs and Chat Apps for C2 to Evade Detection
- Gigabud RAT Android Banking Malware Targets Institutions Across Countries
- Macs are getting compromised to act as proxy exit nodes
- Threat actors use beta apps to bypass mobile app store security
- North Korean Hackers Suspected in New Wave of Malicious npm Packages
- Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn
- Nine flaws in CyberPower and Dataprobe solutions expose data centers to hacking
- Almost all VPNs are vulnerable to traffic-leaking TunnelCrack attacks
- Hacking ATMs by exploiting flaws in ScrutisWeb ATM fleet software
Weekly Malware Roundup – August 11, 2023
This is the GreyKeep Security Malware Roundup for August 11, 2023. Here’s a summary of what’s in this week’s edition:
Organizations
Microsoft Apple Intel Salesforce Citrix | Barracuda CloudFlare TETRA CODESYS Zyxel |
Targets
Intel AMD Linux MacOS Windows Windows Defender Microsoft 365 | .NET Visual Studio Power Platform Kubernetes Redis Rust PaperCut |