#cybersecurity

2025-05-02

UK retailers are facing a surge in cyberattacks—with high-profile names like Marks & Spencer already hit. Are these threats the wake-up call the industry needed? Discover what’s behind the alarming trend.

thedefendopsdiaries.com/cybers

#ukretailers
#cybersecurity
#ransomware
#phishing
#ncsc

2025-05-02

3 hours.
That’s all it took for a fraudster to bypass 2FA and drain $38,000 from Justin Chan’s bank account.

The method? SIM swapping — a type of cyberattack where your phone number is hijacked and used to intercept one-time passwords.

Justin didn’t click a malicious link.
He didn’t fall for a phishing scam.
He simply trusted that his SMS-based 2FA would keep him safe.

It didn’t.

* The attacker called his mobile carrier and transferred his number.
* They used that number to receive 2FA codes.
* They accessed his bank and investment accounts.
* $38,000 gone before sunrise.

Most users still think “I’ve set up 2FA, so I’m safe.” But if that 2FA is tied to your phone number, it’s an open door for modern hackers.

Justin eventually got his money back — after months of stress and media pressure. But many victims don’t.

Let this be a reminder:

- Use app-based or hardware 2FA wherever possible.
- Audit your basic mobile privacy options.
- Rethink how much control your number gives others.

And if your mobile carrier doesn’t offer strong protections by default… maybe it’s time to switch.

#CyberSecurity #MobileSecurity #SIMSwap #2FA

urlDNA.io :verified:urldna@infosec.exchange
2025-05-02

Possible Phishing 🎣
on: ⚠️hxxps[:]//emailalert-107928[.]weeblysite[.]com
🧬 Analysis at: urldna.io/scan/6813a9a63b77500
#cybersecurity #phishing #infosec #urldna #scam #infosec

“[DOGE] haven’t been able to articulate why they want access to some of these data files other than broad ‘waste, fraud, and abuse.’ That, ethically, to me, points to it being a data breach.” #Doge #DataBreach #Cybersecurity #Privacy #Podcast

Did DOGE "breach" Americans' d...

2025-05-02

The wait is over: The VB2025 programme is here.

Three days of bold ideas, sharp minds, and real-world security insight - live in Berlin.

We’re incredibly proud of the speaker line-up and can't wait to welcome the VB community from around the world.

👀 Tickets? Coming very soon.

Follow us and be first to know when they go on sale!

🗓️ 24–26 September 2025
📍JW Marriott Hotel, Berlin

👉 virusbulletin.com/conference/v

#VB2025 #Cybersecurity #Infosec #Berlin

VB2025 programme is live
Three days. Many voices. One Berlin.
VB2025 Berlin 24-26 September 2025
Prof. Dr. Dennis-Kenji Kipkerkenji@chaos.social
2025-05-02

Einblicke in die #Cybercrime Industrie in #Nordkorea: Laut einem aktuellen Bericht sollen Hunderte von US "#Fortune 500" Firmen und damit die umsatzstärksten Unternehmen in den #USA von nordkoreanischen IT-Kräften infiltriert worden sein.

Als "Schläfer" verhalten sich diese zunächst unauffällig, zumeist mit Anstellung in mehreren Firmen gleichzeitig, um bei einer Entlassung die Firmen mit Datenlecks oder der Lahmlegung von Infrastrukturen zu erpressen:

cyberscoop.com/north-korea-wor #cybersecurity

Ankit BytecodeAnkitBytecode
2025-05-02

🛡️ Is Your Password Safe? 🔍
Mohit Yadav reveals how to quickly check if your password has been compromised online! 💻⚠️
Take control of your digital safety and stay protected from hackers.

Follow for more -
Website - craw.in
Call - +91-9513805401
.
.

urlDNA.io :verified:urldna@infosec.exchange
2025-05-02

Possible Phishing 🎣
on: ⚠️hxxp[:]//m-facebookz2b[.]gxscv[.]com
🧬 Analysis at: urldna.io/scan/681349b03b77500
#cybersecurity #phishing #infosec #urldna #scam #infosec

2025-05-02

Startups are prime hacker targets due to weak defenses; post-breach costs (forensics, legal, compliance) often exceed hundreds of thousands, leaving investors to absorb the damage. #CyberSecurity #Ransomware wsj.com/articles/deep-pocketed

While AI-generated code is speeding things up, it's also been shown to invent fake libraries. Introduce a bad actor, and the software supply chain can rapidly turn into a security nightmare. It's wild how quickly this can spiral. #AI #GenAI #CyberSecurity #SecDevOps #InfoSec #OpenSource #Security

AI-generated code could be a d...

2025-05-02

Ivanti Connect Secure Zero Day is Leveraged to Install DslogdRAT and Web Shell

Pulse ID: 6814bc0378f2bcf443e8277c
Pulse Link: otx.alienvault.com/pulse/6814b
Pulse Author: cryptocti
Created: 2025-05-02 12:35:15

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#ConnectSecure #CyberSecurity #DRat #InfoSec #Ivanti #OTX #OpenThreatExchange #RAT #bot #cryptocti

2025-05-02

Fake Vulnerability Phishing Exploits WooCommerce Users

Pulse ID: 6814bc395b5502fd4b73e4d7
Pulse Link: otx.alienvault.com/pulse/6814b
Pulse Author: cryptocti
Created: 2025-05-02 12:36:09

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #Vulnerability #bot #cryptocti

ForeNova Technologiesforenova
2025-05-02

👾 Most overlooked vulnerabilities related to attack surface management⚠️

🔓 Hackers now use AI-powered tools to automatically find these exact weaknesses, scanning your networks, applications and endpoints around the clock.

👇 Check out the link in the comments to learn more about how to reduce your attack surface.

2025-05-02

Lazarus Group’s “Operation SyncHole” Targeting Critical Industries

As part of a series of articles on cyber-security, we take a look at some of the key quotes from people who have contributed to this year's £1.3bn ransomware attack.

Pulse ID: 6814bc79ac1cf9155fe34c4e
Pulse Link: otx.alienvault.com/pulse/6814b
Pulse Author: cryptocti
Created: 2025-05-02 12:37:13

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #Lazarus #OTX #OpenThreatExchange #RAT #RansomWare #bot #cryptocti

2025-05-02

Commvault Confirms Hackers Exploited Zero Day to Breach Azure Environment

Pulse ID: 6814bceee4dec1825b696fe0
Pulse Link: otx.alienvault.com/pulse/6814b
Pulse Author: cryptocti
Created: 2025-05-02 12:39:10

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Azure #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst