CoW Swap admits to over 550 BNB theft after a contract exploit

CoW Swap, a decentralized exchange, was the recent victim of a hacking exploit. The contract exploit on the DeFi protocol led to the loss of around 550 BNB. The exploit led to the hacker approving fund transfers from the protocol without authorization….

Atlassian fixed critical authentication vulnerability in Jira Software

Atlassian fixed a critical flaw in Jira Service Management Server and Data Center that can allow an attacker to impersonate another user and gain access to a Jira Service Management instance. Atlassian has released security updates to address a critical vulnerability in Jira Service Management Server and Data Center, tracked as CVE-2023-22501 (CVSS score: 9.4), […]

The post Atlassian fixed critical authentication vulnerability in Jira Software appeared first on Security Affairs.

Average IT person vs Organised Fraud

So let’s say there’s this average IT person who was personally affected by this organised ‘financial’ group of fraudsters. One day, he gets access to their website (owing to some incapable element within the Organised crime group who made a mistake) and finds information about thousands of other people currently affected and hundreds of thousands more who’d been affected in the past, what should he do?

The access to the website does not allow him to delete the data, he finds out that the data is held outside the country and he clearly knows that there’s no jurisdiction for his government’s authorities to even do anything. He’s unable to ‘export’ the data to even try and notify everyone affected how to escape these thugs. And when I say crime/thugs, they have all the information that’s on the affected common man’s phone and threaten to ruin their life with it unless they get the meagre amount of money that they’re blackmailing the person for.

Does he go to the media? Does he try and hack their website to expose them? What can a common man do?

submitted by /u/the4amfriend
[link] [comments]

Russia-linked Gamaredon APT targets Ukrainian authorities with new malware

Russia-linked threat actor Gamaredon employed new spyware in cyber attacks aimed at public authorities and critical information infrastructure in Ukraine. The State Cyber Protection Centre (SCPC) of Ukraine warns of a new wave of targeted attacks conducted by the Russia-linked APT group Gamaredon (aka Shuckworm, Actinium, Armageddon, Primitive Bear, UAC-0010, and Trident Ursa). The attacks aimed at public authorities and critical information […]

The post Russia-linked Gamaredon APT targets Ukrainian authorities with new malware appeared first on Security Affairs.

Are the Russian ransomware outfits protected by the FSB?

There’s a frequent pattern in a lot of the malware I analyze that it checks system language for Russian speakers and some other languages and doesn’t activate unless the check fails. Now none of these were authored by any sort of APT, they were very u…

Tips on embedding script for reverse scam

I know nooby title, whatever – if I get one helpful answer I’ll be one step closer.

I’ve got a scammer ready to open a jpeg or a pdf, at first I thought a fun first time thing to try would be to just do a one liner windows executable with the extension of a jpeg.

rm -rf /

But then I thought… It’d be nice to get some dirt, soo thinking scp everything in home directory to a clean I own, remove the file after copying.

So it won’t be this easy, help me along the way?

submitted by /u/rebs92
[link] [comments]

Where’s the Epstine/Maxwell list?

I would expect these documents would be a prime target to hackers, from foreign governments, to buisness rivals, to activist hackers. Just curious of your guys take on it. I mean something like that gets out it is world changing. And it is obviously ve…