iOS apps that cater to sugar dating, BDSM, and LGBTQ+ communities – where privacy is critical – have leaked highly sensitive content, putting users of these apps at risk. Cybernews researchers discovered that apps from BDSM People, CHICA, TRANSLOVE, PINK, and BRISH had publicly accessible secrets published together with the apps’ code, including API keys, passwords, and encryption keys. It is highly dangerous to expose these, as credentials in client applications are accessible to anyone, and can be abused by malicious actors to gain a foothold on systems. In this instance, the most dangerous of leaked secrets granted access to…
Kirsten Doyle
A new cybersecurity report from Forescout Technologies has unveiled significant vulnerabilities in solar power systems that could potentially destabilize power grids and compromise consumer data privacy. The report, titled “SUN:DOWN – Destabilizing the Grid via Orchestrated Exploitation of Solar Power Systems,” details several key findings: According to Barry Mainz, Forescout CEO, “The collective impact of residential solar systems on grid reliability is too significant to ignore – hospitals could lose access to critical equipment, families could go without heat in the winter or AC in a heatwave, and businesses could shut down. Threat actors increasingly target critical infrastructure, making it…
The Qualys Threat Research Unit (TRU) has uncovered three security bypasses in Ubuntu’s unprivileged user namespace restrictions. Researchers disclosed these vulnerabilities to the Ubuntu Security Team on 15 January this year, has been working with then ever since. Researchers found three distinct bypasses of these namespace restrictions, each of which would allow bad actors to create user namespaces with full administrative capabilities. “These bypasses facilitate exploiting vulnerabilities in kernel components requiring powerful administrative privileges within a confined environment. The restrictions on unprivileged user namespaces were initially introduced in Ubuntu 23.10 and enabled by default in Ubuntu 24.04,” Qualys explained. The…
Cybersecurity analyst Jeremiah Fowler has discovered an unprotected Amazon S3 database that wasn’t encrypted or password protected and contained some 27,000 records. The records included highly personal information such as driver’s licenses, Medicaid cards, work statements, and bank statements that held account numbers and partial credit card numbers. The name of the database and the internal files names suggest that the database was owned by Australian fintech company Vroom by YouX (formerly Drive IQ). In addition, Fowler discovered an internal screenshot that showed another instance of MongoDB storage with 3.2 million documents. However, he did not examine its content and…
A new ransomware gang, Arkana Security, is claiming responsibility for an enormous breach at WideOpenWest (WoW), one of the largest cable operators and ISPs in the US. The malicious actors boasted they had full backend control and even put a music video montage together to illustrate exactly how much access they had. Threat researchers from Hudson Rock traced the origins or the attack to an infostealer infection back in September last year. It has allegedly compromised over 403,000 including names, emails, passwords and other data, and an additional file allegedly containing 2.2 million records. It has also given the malefactors…
Despite Oracle’s denial of a breach affecting its Oracle Cloud federated SSO login servers, Bleeping Computer has confirmed with multiple companies that data samples shared by the threat actor are authentic. Recently, a threat actor, “rose87168,” claimed to be selling six million records, including sensitive account data, on dark web forums. CloudSEK’s investigation suggests the breach may have exploited a known security flaw, possibly allowing unauthorized access and data exfiltration. The vulnerable Oracle Cloud subdomain, which has subsequently been removed. Oracle dismissed the claims, although cybersecurity firm CloudSEK and independent researchers found evidence supporting the breach. As further proof, the…
A powerful new attack tool, Atlantis AIO, is making it easier than ever for cybercrooks to access online accounts. Designed to perform credential stuffing attacks automatically, Atlantis AIO enables hackers to test millions of stolen usernames and passwords in rapid succession. In new research, Abnormal Security has described how, by offering pre-configured modules to target a wide range of platforms—especially email providers—this tool allows attackers to take over accounts with minimal effort. Credential stuffing remains one of the most common cyber threats today. It exploits a common security vulnerability: people reusing the same passwords across multiple websites. Cyber attackers exploit…
Rhino Security researchers have identified multiple critical vulnerabilities in Appsmith, an open-source developer platform commonly used for building internal applications. The most severe of these is CVE-2024-55963, which enables unauthenticated attackers to execute arbitrary system commands on servers running default installations of Appsmith versions 1.20 through 1.51. Remote Code Execution as PostgreSQL User Appsmith ships with a local PostgreSQL database for practice and learning purposes, but the researchers discovered a critical misconfiguration in its default setup. The PostgreSQL authentication configuration file (pg_hba.conf) allowed any local user to connect as any PostgreSQL user without needing a password. The vulnerability became exploitable…
Five critical security vulnerabilities have been found in the Ingress NGINX Controller for Kubernetes, potentially enabling unauthenticated remote code execution. This exposure puts over 6,500 clusters at immediate risk by making the component accessible via the public internet. The vulnerabilities, CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974, are a series of unauthenticated Remote Code Execution vulnerabilities in Ingress NGINX Controller for Kubernetes, discovered by Wiz Research, who collectively named them “IngressNightmare.” According to the researchers, exploitation of these vulnerabilities could lead to “unauthorized access to all secrets stored across all namespaces in the Kubernetes cluster by attackers, which can result in cluster…
Troy Hunt, a security consultant who runs the popular data-breach search service Have I Been Pwned?, has disclosed that he has become a victim of a phishing attack that exposed the email addresses of 16,000 subscribers to his blog troyhunt.com. “Every active subscriber on my list will shortly receive an email notification by virtue of this blog post going out,” he said. The export also included people who have unsubscribed, and Hunt questioned why Mailchimp would keep these in the first place. “I’ll need to work out how to handle those ones separately. I’ve been in touch with Mailchimp but don’t have a reply…
