At least 91 dark web sites suffered a breach after a malicious actor accessed their hosting provider's server and apparently managed to export files and possibly linked databases as well, BleepingComputer reported on Monday.
The hackers responsible for breaching the systems of multiple U.S. energy operators since May 2017 employed a phishing scheme that used malicious attachments to download a template file via an SMB connection, in order to silently harvest credentials, according to a blog post from Cisco Talos.
Bob Dyachenko, the Kromtech security researcher who discovered the data leak of 3 million WWE fans, says it was most likely accessible thanks to a misconfiguration by either WWE or a contractor.