Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
UtiliaCS 320x100
Banner Ancharia Desktop 1 1

Author: Pietro Melillo

New Group Ransomware ‘Pryx’ Compromises 30,000 College Enrollment Data!

A new player has emerged on the cybercrime landscape: the ransomware group “Pryx.” Pryx has claimed its first significant attack, announcing that it has compromised the systems of Rowan College at Burlington County (RCBC.edu) and stolen 30,000 university applications. Incident Details Pryx has claimed to have breached the IT systems of Rowan College and to be in possession of sensitive data from the institution. This announcement was made on their dataleak site, which is accessible both through the traditional internet and the dark web. According to the statement from Pryx, the stolen data includes: Rowan College’s Reaction As of now, Rowan College

Threat Actors Release 2022 Electronic Arts (EA) Employee Database

Recently, a threat actor allegedly leaked a database containing information on Electronic Arts (EA) employees from 2022. The data breach was confirmed by the threat actor himself, who explained the reasons behind his decision to make the data public. Currently, we are unable to accurately confirm the veracity of the breach, as no press release has been issued on the official website regarding the incident. Therefore, this article should be used as an “intelligence source.” The Leaker’s Motives The threat actor stated: “I recently noticed that a new burner account was created to try and sell this data breach, but it has

Possible Data Breach of the Internal Security Operations Command (ISOC)

A member of BreachForums has announced a significant data breach involving Thailand’s Internal Security Operations Command (ISOC), an agency known as the political arm of the Royal Thai Armed Forces. Currently, we are unable to accurately confirm the veracity of the breach, as no press release has been issued on the official website regarding the incident. Therefore, this article should be used as an “intelligence source.” Details of the Breach In early 2024, ISOC suffered a data breach that resulted in the compromise of 178 GB of secret documents, project files, video files, and more. This event represents one of the largest

Bulgarian Hacker “Emil Külev” Arrested

On June 30, 2024, the Sofia police arrested Teodor Iliev, a 21-year-old Bulgarian who called himself “Emil Külev” online. The announcement was made by the Prosecutor’s Office of the Republic of Bulgaria, which stated that they had charged and detained Iliev for up to 72 hours in connection with numerous computer crimes. The Charges Teodor Iliev, also known online as “MAGADANS,” is accused of illegally accessing the information systems of dozens of state institutions, commercial banks, insurance companies, and other legal entities between March 2020 and January 2024. In July 2023, a user on the BreachForums called “MAGADANS” revealed what they claimed

Possible Data Breach Affecting TÜV Rheinland AG

Recently, TÜV Rheinland AG, one of the leading global certification and inspection companies, has appeared on the data leak site of the ransomware group RansomEXX. At present, there are no official confirmations from the organization regarding the veracity of the breach, as TÜV Rheinland AG has not yet released any press statements on its website about the incident. Therefore, this article should be considered as an “intelligence source.” RansomEXX RansomEXX is a well-known group of cybercriminals specializing in ransomware attacks, targeting large organizations and companies across various sectors. The group is known for its modus operandi of encrypting victims’ data and subsequently

Juniper Networks Releases Security Updates for a Critical 10.0 Vulnerability

Juniper Networks has recently announced the release of out-of-band security updates to address a severe vulnerability that could lead to an authentication bypass in some of its routers. This vulnerability, identified as CVE-2024-2973, has received a CVSS score of 10.0, indicating the highest possible severity. The CVE-2024-2973 Vulnerability According to Juniper Networks, the vulnerability involves an authentication bypass using an alternate path or channel in Session Smart routers or conductors that operate with a redundant peer. This issue allows a network-based attacker to bypass authentication and take full control of the device. In an advisory issued last week, the company explained that

Allegedly Data Breach: Kemenkumham Email Credentials Compromised

A significant data breach has involved the Ministry of Law and Human Rights (Kemenkumham) in Indonesia. According to a post on a hacker forum, a threat actor under the pseudonym “Guzmanloeraxxx” has allegedly leaked the email login credentials of Kemenkumham employees. If confirmed, this breach would pose serious risks to national security and public trust. Currently, we are unable to accurately verify the reported information, as no official press release regarding the incident has been issued on the website. Kemenkumham Kemenkumham, short for Kementerian Hukum dan Hak Asasi Manusia, is the Ministry of Law and Human Rights of the Republic of Indonesia.

Coinbase USA: Threat Actor Claims to Sell Database of 600,000 Users

In the past few hours, a new and alarming cyber threat has emerged. A threat actor has claimed to possess and intends to sell a database containing information on 600,000 US users of the Coinbase platform. This news raises serious concerns about the security and privacy of users’ personal data. Database Details According to the announcement posted on a hacking forum, the database includes detailed user information, such as: These details, if they fall into the wrong hands, can be used for a variety of illegal activities, such as identity theft, financial fraud, and phishing attacks. Currently, we are unable to accurately

The Virginia Department of Elections database may have been hacked and is online on the dark web

A serious security incident appears to have hit the Virginia Department of Elections, causing the unauthorised dissemination of a large election database. The attack, claimed by a user known as IntelBroker, was made public through an online forum dedicated to data breaches. The Virginia Department of Elections is the body responsible for administering elections in the state of Virginia. This department ensures that all elections are conducted fairly, transparently, and in compliance with state and federal laws. It oversees voter registration, supervises local and state elections, and maintains the integrity of the electoral process through secure data management and election staff training.

Vietnam Hong Ngoc Hospital on Breach Forums: 112,621 Patient and Doctor Profiles Compromised

A serious data breach incident may have recently affected the Hong Ngoc Hospital, a renowned hospital located in Vietnam. The news was disseminated through the BreachForums, a platform known for the buying and selling of compromised data. The volume and sensitivity of the compromised information make this incident particularly alarming. Hong Ngoc General Hospital was founded in 2003, when private hospitals were not yet widespread in Vietnam. With continuous effort, Hong Ngoc earned its reputation as the first hospital-hotel in Hanoi and northern Vietnam. To date, after 17 years of foundation and development, Hong Ngoc has become a household name and a