Over 390M impacted by Russian social network breach
Included in the leaked 27.6 GB archive belonging to VK — which was co-founded by recently arrested Telegram CEO Pavel Durov before being relinquished to Russian state-owned firms in December 2021 — were individuals' names, sex, ID numbers, profile...
The incident was reported by the BBC to have involved the targeting of the TfL corporate headquarters' backroom systems, which Propel Tech co-owner and Managing Director Andrew Brown said indicated the potential severity of system vulnerabilities.
After obtaining initial network access through the exploitation of the VMware vulnerability, tracked as CVE-2023-38831, Head Mare proceeds with the deployment of the PhantomDL and PhantomCore backdoors that facilitate additional payload delivery.
California Approves Privacy Bill Requiring Opt-Out Tools
This bill requires Web browsers to have an easy-to-find (and use) setting for consumers to send an opt-out preference signal by default to every site and app they interact with.
North Korea's 'Citrine Sleet' APT Exploits Zero-Day Chromium Bug
Microsoft warned that the DPRK's latest innovative tack chains together previously unknown browser issues, then adds a rootkit to the mix to gain deep system access and steal crypto.