Red Hot Cyber. The Cybersecurity Blog

Threat Actors 888 claimed a compromise at Credit Suisse
A malicious actor, known by the alias 888, has recently claimed to be selling sensitive data belonging to Credit Suisse, one of the leading institutions in private banking and asset management. Details of the Alleged Breach According to 888, the

Cyber catastrophe in sight? The new Bug on MOVEit has an Online PoC Exploit
In the realm of cybersecurity, vulnerabilities constantly represent a significant risk for businesses and institutions. Many system administrators may recall CVE-2023-34362 from last year, a catastrophic vulnerability in Progress MOVEit Transfer that shook the industry, affecting high-profile victims like the

KillSec Announces New Ransomware-as-a-Service (RaaS) Platform
June 25, 2024 – KillSec, a well-known hacktivist group, has announced the launch of their latest offering on their Telegram channel: KillSec RaaS (Ransomware-as-a-Service). This new platform promises to enhance the capabilities of aspiring cybercriminals by providing advanced tools and

UNZIPPED DATA – LEVI STRAUSS COMPROMISED ACCOUNTS
The legendary Jeans retailer Levi Strauss & Co. identified a significant data breach that affected over 72,000 customers. The incident was discovered on June 13th, 2024 and it was the result of a credential stuffing attack, where attackers used combination

LockBit: The Bluff of Double Extortion Against the Federal Reserve
In recent years, the cybersecurity landscape has been dominated by the growing threat posed by ransomware groups. Among these, LockBit has emerged as one of the most notorious and feared. However, a recent event has called their credibility into question:

Xehook Stealer: The Rise and Sale of a Formidable Stealer Malware
Introduction Xehook Stealer is a sophisticated malware targeting Windows operating systems, first discovered in January 2024. Within a year, Xehook has rapidly gained notoriety for its advanced data collection capabilities and support for over 110 cryptocurrencies and 2FA extensions. Starting

IntelBroker Takes Control of BreachForums: A New Chapter in Cybercrime Management
Pietro Melillo - August 22nd, 2024
IntelBroker Takes Control of BreachForums: A New Chapter in Cybercrime Management IntroductionThe recent acquisition of BreachForums by IntelBroker marks a significant shift in the landscape of cybercrime. This transition of...

Donald Trump’s campaign under attack! Documents and internal communications exfiltrated
Alessio Stefan - August 11th, 2024
After the European elections unfolded, geopolitical attentions shifted to the U.S. election campaign, one of the most dynamic in recent years recently with the Democrats' recent changeover with Harris as...

RipperSec claims DDoS attack on Ferrari
Inva Malaj - August 11th, 2024
Recently the Hacktivist Group "RipperSec" claimed to have attacked Ferrari's global site in the name of justice for Palestine. The hacktivist group known as 'RipperSec' claimed responsibility for a DDoS...

NSO Group targeted! BlackMeta attacks Spyware maker’s central domain
Alessio Stefan - August 4th, 2024
The Pro-Palestinian group BlackMeta (or DarkMeta) announced on August 1, 2024, on their official telegram channel that they conducted a destructive attack on the NSO group's infrastructure, including the central...
Sign up for the newsletter