Ax Sharma :verified:

On @ax | This account now legacy.
---------------------------------------

Security Researcher, Editor, Tech Reporter

Bylines & contributions: BleepingComputer, BBC, TechCrunch, WIRED, CSOOnline, Security Report

British Association of Journalists (BAJ),
Canadian Association of Journalists (CAJ)
📍🇬🇧🇮🇳🇨🇦

🦋 Bluesky bsky.app/axsharma.com
🌐 axsharma.com

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-04-28

This Friday morning—which is payday for most in the UK, starts with a widespread outage affecting Lloyds Bank, TSB, Bank of Scotland and Halifax customers.

Customers report issues logging in to Internet banking and mobile apps.
bleepingcomputer.com/news/tech

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-04-24

Yellow Pages Canada confirms cyber attack as Black Basta #ransomware gang posts private business, customer and employee data on its data leak site.

bleepingcomputer.com/news/secu

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-24

TELUS, Canada's second-largest telco, is investigating a potential #databreach after sample sets of company's employee data, payroll records, and private GitHub repos appeared on a data breach forum this week.
bleepingcomputer.com/news/secu

Too early to conclude that an incident indeed occurred at TELUS or rule out a third-party vendor breach.

Employee names do check out though and correspond to present-day technical staff, like devs.

Screenshots further show many folders within GitHub repo, with TA claiming to even sell the company's "sim-swap-api," and calling this a "FULL breach."

TELUS says it is investigating and has thus far not seen corporate/retail customers impacted.

Ax Sharma :verified: boosted:
2023-02-14

Check out today's Metacurity for the latest infosec news you might have missed over the weekend. Lead items via @axsharma @jgreig @kevinvaline @chriskingspain @billtoulas @jagmeetsingh @AmondoZhou 1/2
metacurity.substack.com/p/new-

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-14

NEW: #Eurostar is forcing 'password reset' for everyone in a mass email sent out this week. But, when you actually try to reset password, 'technical problems' make it impossible, effectively locking passengers out of their accounts.

bleepingcomputer.com/news/secu

Observed the problem yesterday and it continues well into today. This has left passengers around the world frustrated with some even mistaking this for a #phishing attempt or worse, a data breach.

Eurostar had last enforced password resets in 2018 following a data breach. Have reached out to them with a set of questions as to what's prompting this. Their advice to clear cookies or 're-register' with the same email does not work.

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-13

Pepsi Bottling Ventures, PepsiCo's largest independent U.S. manufacturer and seller of Pepsi-Cola beverages discloses a data breach after an info-stealing malware infection that lasted 27-days.

Reporting by Bill Toulas.

bleepingcomputer.com/news/secu
#databreach

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-13

New 'DarkBit' #ransomware gang has hit Technion - Israel's Institute of Technology 🇮🇱

From attacking the Israeli "regime" to calling out tech layoff, the gang's motives seem multifaceted.
bleepingcomputer.com/news/secu

The ransom note, that has #DarkBit demanding roughly $1.7 million, implies the group's members were part of university's tech layoffs, with the attack being a way to avenge the firing.

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-12

Microsoft's WinGet package manager is failing today after an SSL/TLS certificate used by its CDN expired over the weekend.

bleepingcomputer.com/news/secu

Until Microsoft renews the cert, a viable solution identified by developers is to use an alternate WinGet source, such as winget.azureedge[.]net.

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-10

Reddit suffered a cyberattack Sunday evening, allowing hackers to access internal business systems and steal internal documents and source code.

bleepingcomputer.com/news/secu

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-07

The #ransomware attack on Royal Mail that had caused heavy disruptions to its international shipping ops has been claimed by #LockBit gang.
bleepingcomputer.com/news/secu

LockBit had earlier denied being behind the cyber attack and blamed the mishap on an affiliate. They are now, however, threatening to leak the allegedly stolen data on its leak site. Like earlier, they still haven't explained exactly what data was stolen, if any.

This adds to a series of chaotic developments at Royal Mail—from the ongoing CWU strikes from workers, to multiple IT outages of last year, at least one of which led to Tracking services being unavailable for days.

h/t @AlvieriD. Reporting by
@serghei

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-04

Bermuda hit by a major island-wide power outage last night that impacted much of the region's internet connectivity. Some customers additionally reported losing phone connection.
bleepingcomputer.com/news/tech

Bermudian government has called the "mass-outage" at BELCO, Bermuda's sole electricity provider, a "serious incident"

Both NetBlocks and Cloudflare Radar confirmed seeing a noticeable dip in the island's internet connectivity following the power cut.

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-01

RubyInstaller[.]org's Wikis poisoned since Nov 29th, 2022 with links to malware and IP tracing/logging site, IPlogger.

Malware ZIP: e811cea654c10c0efe2618bf9d20e60c15497e8207cf5d8096aa75bab1e28573

Looks like they just fixed these today. The wiki homepage too.
Nov 29: github.com/oneclick/rubyinstal
Dec 1: github.com/oneclick/rubyinstal
#opensource

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-01

Confirmed: U.S. No Fly List posted publicly on hacking forum last week is the same list discovered recently on CommuteAir's misconfigured AWS server, news of which was first reported by Daily Dot reporter Mikael Thalen!

bleepingcomputer.com/news/secu

#dataleak #databreach

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-02-01

Catch me with legendary Alexis Conran on Channel 5's "Phone Scams" — hour long episodes run Wednesdays at 8 PM🇬🇧 where we dive into a variety of scams 🙌📸

➡️ TOMORROW, Feb 1 @ 8pm: Ep 2
➡️ Next week, Feb 8: Ep 3

Playing catch up? Just log in with your (free) Channel 5 account from within the UK.
channel5.com/show/phone-scams-

#scams #tech #channel5

Ax Sharma :verified: boosted:
2023-01-30

Don't miss today's packed Metacurity for the latest infosec developments you need to know. Lead items via @josephmenn @jesseahamilton @lawrenceabrams @serghei @axsharma @IonutArghire 1/2 metacurity.substack.com/p/fbi-

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-01-23

Threat actors are abusing Google Ads to deliver bogus email invites enticing users to visit sex and adult dating websites.

The feature is otherwise used by Google Ads account administrators to add new users to admin interface.

Reporting the email as spam would likely block legitimate emails from Google as well 😬

No way to fix the issue just yet. Still waiting to hear back from Google.

bleepingcomputer.com/news/secu

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-01-06

Ever since the publication of this piece, "noindex" has magically disappeared from ALL versions of Slack's 31st December security update -- US, UK, Spain, Australia, what have you 🙂 with the entry now clearly visible on the company's (international) news blogs too.

bleepingcomputer.com/news/secu

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-01-01

JUST IN: In a statement, the creator of counterfeit PyTorch dependency (''torchtriton') has apologized and stressed that their intent wasn't malicious.

They claim collecting sensitive data, including keys and secrets—which they call a "wrong decision," was to better identify victims.

Either way, the end result is just that - those targeted will need to rotate their secrets/keys and treat this like any other intrusion. A lesson in ethical hacking and where to stop.

bleepingcomputer.com/news/secu

Ax Sharma :verified: boosted:
Ax Sharmaax@c.im
2023-01-01

PyTorch reveals malicious dependency chain compromise between Dec 25th & 30th.

The counterfeit 'torchtriton' stole SSH keys, first 1000 files in $HOME, .gitconfig and other secrets. But the attacker claims they are only collecting "metadata," and wrongly implying that this is ethical research.

2,300+ downloads seen so far on PyPI.

Uninstall now 👇👇👇

bleepingcomputer.com/news/secu
#opensource

Ax Sharma :verified:axsharma@infosec.exchange
2022-12-22

Would y'all kill me if I moved to @ax ? Shorter than @axsharma :D

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst