Hacking operation ShinyHunters has claimed to have compromised nine major brands, including fast fashion retailer Zara, convenience store chain 7-Eleven, and cruise line operator Carnival Corporation, while warning that it would release over 9 million records with personally identifiable information and internal data should the demanded ransom remain unpaid by Apr. 21, Cybernews reports.
The Payouts King ransomware operation is leveraging the QEMU emulator to create hidden virtual machines and establish reverse SSH backdoors on compromised systems, allowing them to bypass endpoint security measures.
The vulnerability allowed unauthorized access to order confirmation pages, revealing customer names, phone numbers, email addresses, postal and billing addresses, and details of purchased items.
Tennessee-based Cookeville Regional Medical Center had information from 337,917 patients compromised following a ransomware attack last July that has been claimed by the Rhysida ransomware-as-a-service operation, according to Infosecurity Magazine.
TechCrunch reports that major U.S. clothing retailer Express has fixed a vulnerability in its website, which exposed at least a dozen customers' sensitive data, including names, email addresses, postal, billing, and delivery addresses, order details, partial card information, and phone numbers, in search engine results.
Major U.S. insurance provider Kemper Corporation had more than 29 GB of data from its Salesforce account claimed to have been stolen by the ShinyHunters hacking group, which leaked more than 13 million records following failed negotiations, reports Cybernews.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.