article thumbnail

Phishing campaign aimed at stealing Office 365 logins abuses Google Cloud Services

Security Affairs

Cybercriminals are increasingly leveraging public cloud services such as Google Cloud Services in phishing campaigns against Office 365 users. Cybercriminals are increasingly abusing cloud services, such as Google Cloud Services, to arrange phishing campaign aimed at stealing Office 365 logins. com” to host the phishing page.

article thumbnail

Russia-linked APT28 and crooks are still using the Moobot botnet

Security Affairs

The threat actors used the botnet harvest credentials, collect NTLMv2 digests, proxy network traffic, and host spear-phishing landing pages and custom tools. The discovery underscores significant interest among different threat actors in compromising internet-facing routers. ” reported Trend Micro. ” concludes the report.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

E-commerce app 21 Buttons exposes millions of users’ data

Security Affairs

Researchers discovered that the popular e-commerce app 21 Buttons was exposing private data for 100s of influencers across Europe. Researchers from cybersecurity firm vpnMentor discovered that the e-commerce app 21 Buttons was exposing private data for 100s of influencers across Europe. 2020 Dates vendors contacted: 5th Nov.,

article thumbnail

Mailchimp discloses a new security breach, the second one in 6 months

Security Affairs

The company also notified the primary contacts for all affected accounts less than 24 hours after the initial discovery. According to TechCrunch, one of the compromised accounts belongs to e-commerce giant WooCommerce. ” reads the post published by TechCrunch. WooCommerce is said to have more than five million customers.”

article thumbnail

Companies impacted by Mailchimp data breach warn their customers

Security Affairs

The company also notified the primary contacts for all affected accounts less than 24 hours after the initial discovery. TechCrunch first reported that one of the compromised accounts belongs to e-commerce giant WooCommerce. “In The list of the impacted companies includes WooCommerce, FanDuel, and the Solana Foundation.

article thumbnail

Fintech Giant Fiserv Used Unclaimed Domain

Krebs on Security

If you have received this email in error, please send an e-mail to customersupport@defaultinstitution.com.” At first, only a few wayward emails arrived. Ironically enough, one was from a “quality assurance” manager at Fiserv.

article thumbnail

Wannacry, the hybrid malware that brought the world to its knees

Security Affairs

Reflecting on the Wannacry ransomware attack, which is the lesson learnt e why most organizations are still ignoring it. Indeed, every discovery is worthless if it is not made available to others. The infection chain.

IT 98