About half of 6 million internet-connected systems using the legacy File Transfer Protocol continue to lack encryption, making them vulnerable to cyberattacks, according to SecurityWeek.
Major Dutch online store Bol, which also operates in Belgium, had information from more than 400,000 of its Belgian users allegedly compromised by the hacker using the alias "Jeffrey Epstein," reports Cybernews.
The French Interior Ministry has disclosed a cyberattack against the country's National Agency for Secure Documents' ANTS platform, which is being used for driver's license, passport, and ID issuance, according to Security Affairs.
A security researcher, operating under the handle @weezerOSINT, reported that a simple free account on Lovable provided access to other users' source code and database credentials.
The attackers asserted they breached Seiko USA's Shopify backend, exfiltrating sensitive customer data including names, email addresses, phone numbers, order history, shipping addresses, and account details.
Hacking operation ShinyHunters has claimed to have compromised nine major brands, including fast fashion retailer Zara, convenience store chain 7-Eleven, and cruise line operator Carnival Corporation, while warning that it would release over 9 million records with personally identifiable information and internal data should the demanded ransom remain unpaid by Apr. 21, Cybernews reports.
The Payouts King ransomware operation is leveraging the QEMU emulator to create hidden virtual machines and establish reverse SSH backdoors on compromised systems, allowing them to bypass endpoint security measures.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.