Security researcher @GossiTheDog shared a TikTok video from Microsoft employees showing Microsoft Recall.
Rest assured that malware will not be able to access it and your privacy is safe (joking, it's super unsafe)
Today we spoke with multiple individuals privy to and involved in the alleged TicketMaster breach.
Sometime in April an unidentified Threat Group was able to get access to TicketMaster AWS instances by pivoting from a Managed Service Provider. The TicketMaster breach was not performed by ShinyHunters group. ShinyHunters is the individual and/or group which posted the auction of the data, they are acting as a proxy for the Threat Group responsible for the compromise.
Based on data provided to us by the Threat Group responsible for the compromise, we can assert with a high degree of confidence the data is legitimate. Date ranges in the database appear to go as far back as 2011. However, some dates show information from the mid-2000's. Data shared with us includes:
- Full name
- Email address
- Address
- Telephone number
- Credit card number (hashed)
- Credit card type, authentication type, etc
- All user financial transactions
NOTE: The data provided to us, even as a 'sample', was absurdly large and made it difficult to review in depth. We are unable to verify the authenticity of financial information. Briefly skimming the PII present in the dump, it appears authentic.
🚨Major Data For Sale🚨ShinyHunters is allegedly selling access to the Santander Bank database. Price: $2,000,000. One time buyer,
#DarkWeb#Cybersecurity#Security#Cyberattack#Cybercrime#Privacy#Infosec
ShinyHunters claims the data contains 30 million customers, 6 million account numbers and balances, 28 million credit card numbers, HR employee lists, and more.
"The cybersecurity reality we live in now is teenagers are running around in organized crime gangs with digital bazooka’s. They probably have a better asset inventory of your network than you, and they don’t have to wait 4 weeks for 38 people to approve a change request for patching 1 thing."
If you think that patching critical public facing infrastructure within 24hrs is not a realistic goal then tell me why!
Despite all the security awareness we have here in 2023, all the new fancy tools we have, and all the celebration of coordinated government take downs of threat actor groups, cybercrime gangs are still on the rise hitting more companies and making more money than ever this year.
You need to be able to identify and patch something like CitrixBleed within 24 hours — if you cannot, there is a very real possibility it isn’t the ideal product fit for your company due to the level of risk it poses, and you need to rethink if the architecture and look for a solution you can manage.
The LockBit ransomware group has assembled a strike team to breach banks, law firms and governments and I don't see this stopping anytime soon.
Follow this link for Kevin Beaumont's @GossiTheDog deeper dive into the topic:
https://t.co/uQsyDp4ALD
@RansomSpares - Are you aware that your contact us form doesn't work (neither does the Chat)?
I need to get in touch regarding a recent order issue. Thanks
Stunning views whilst cycling round North Wales 🏴
#lovethebike#triathlonlife#triathlon @ Talsarnau, Gwynedd, United Kingdom https://t.co/YaN9no0jOK
I usually make short-form satirical videos for fun, but never share them with the world. This time tho, I thought I'd make one for the infosec community. Some might even find it educational 😅
If you're in #infosec and you feel a little down this week, this video is for you💙
ᴡᴏʀʟᴅ ᴄʜᴀᴍᴘɪᴏɴ!!!!
This is just unbelievable. I started racing with my dad many years ago. We dreamed of becoming a World Champion and now we are.
(1/3)
There is no going back to the digital adoption levels of two years ago. There is only going forward, and the Microsoft Cloud is the most trusted and comprehensive cloud to help our partners deliver on this unprecedented opportunity.