Remove 11
Remove 2015 Remove Data Remove Information Security Remove Security
article thumbnail

FIN7 group leverages Windows 11 Alpha-Themed docs to drop Javascript payloads

Security Affairs

FIN7 cybercrime gang used weaponized Windows 11 Alpha-themed Word documents to drop malicious payloads, including a JavaScript backdoor. doc) containing a decoy image claiming to have been made with Windows 11 Alpha. “The specified targeting of the Clearmind domain fits well with FIN7’s preferred modus operandi.

Retail 114
article thumbnail

The Week in Cyber Security and Data Privacy: 16–22 October 2023

IT Governance

At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks. Publicly disclosed data breaches and cyber attacks City of Philadelphia discloses data breach after five months Date of breach: 24 May 2023 ( notice issued 20 October 2023).

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Security Affairs newsletter Round 241

Security Affairs

The best news of the week with Security Affairs. Crooks use carding bots to check stolen card data ahead of the holiday season. Tianfu Cup 2019 – 11 teams earned a total of 545,000 for their Zero-Day Exploits. Adobe announces end of support for Acrobat 2015 and Adobe Reader 2015. Pierluigi Paganini.

article thumbnail

Travel leisure company Carnival Corporation discloses data breach

Security Affairs

The world’s largest travel leisure company Carnival Corporation discloses a data breach that took place last year and which exposed the personal information of its customers. Carnival Corporation, the world’s largest travel leisure company, discloses a data breach that took place in 2019. Pierluigi Paganini.

article thumbnail

Talos experts found 11 flaws in Schneider Electric Modicon Controllers

Security Affairs

Talos experts discovered 11 security flaws affecting some models of Schneider Electric’s Modicon programmable logic controllers. CVE-2019-6848 is an uncaught exception issue that could be exploited to cause a Denial of Service condition by sending specific data on the REST API of the controller/communication module.

article thumbnail

AccorHotels subsidiary Gekko Group exposes hotels and travelers data in massive data leak

Security Affairs

Security experts from vpnMentor discovered that Gekko Group, an AccorHotels subsidiary, exposes hotels and travelers in a massive data leak. vpnMentor discovered a database exposed online that contained over 1 terabyte of data from Gekko Group brands and their clients. SecurityAffairs – AccorHotels subsidiary , data leak).

B2B 72
article thumbnail

Maze Ransomware operators claim to have stolen millions of credit cards from Banco BCR

Security Affairs

Maze Ransomware operators claim to have gained access to the network of Banco BCR of Costa Rica and stolen 11 million credit card credentials. Maze Ransomware operators claim to have hacked the network of the state-owned Bank of Costa Rica Banco BCR and to have stolen internal data, including 11 million credit card credentials.