Tag: security

Hackers claim they stole 1.5 billion Salesforce records from hundreds of companies in major hack – but are they telling the truth?

ShinyHunters claim theft of 1.5 billion records from 760 global companies Attackers exploited GitHub secrets to access sensitive Salesforce object tables FBI issued warnings as hacker groups announced they were “going dark ShinyHunters have finally revealed how much data it stole in the Salesloft / Salesforce attack, claiming to have…

Read More

New Phoenix RowHammer attack cracks open DDR5 memory defenses in minutes

Phoenix RowHammer variant affects DDR5 desktop systems, bypassing all known mitigations on SK Hynix chips Attackers can gain root access and steal RSA keys within minutes using default system settings Researchers recommend tripling refresh rates, as DRAM devices cannot be patched and remain vulnerable long-term Standard, production-grade desktop systems were,…

Read More

Former FinWise employee may have stolen sensitive data on 689,000 American First Finance customers

A former FinWise employee accessed sensitive data on 689,000 people more than a year after leaving the company Victims likely include those with FinWise loans or accounts serviced by American First Finance, its technology partner FinWise hired security experts, notified authorities, and offered credit monitoring FinWise Bank, a Utah-based community…

Read More

CISA blasted by US watchdog for wasting funds and retaining the wrong employees

CISA mismanaged over $138 million in cybersecurity retention funds, awarding incentives to unqualified or unrelated personnel The agency lacked proper oversight, documentation, and compliance, undermining its ability to retain critical cybersecurity talent DHS OIG recommended eight corrective actions; seven have been implemented, with one unresolved concerning recovery of improper payments…

Read More

Salesforce platforms are being cracked open for data theft – FBI warns of UNC6040 and UNC6395 IOCs

Two threat groups, UNC6040 and UNC6395, are actively targeting Salesforce accounts to steal sensitive data UNC6395 exploits integrations like the Salesloft Drift chatbot, while UNC6040 uses phone-based social engineering to impersonate IT staff and gain access The FBI warns that follow-up extortion attacks are often carried out by ShinyHunters, linked…

Read More

Another massive DDoS attack that reached 1.5 Bpps has been thwarted

FastNetMon detected record 1.5 billion packet per second DDoS attack Traffic came from hijacked IoT devices and MikroTik routers across 11,000 networks FastNetMon warns ISP level filtering is essential to stop future large scale floods A distributed denial-of-service attack targeting a DDoS mitigation vendor somewhere in Western Europe has been…

Read More