任意のGoogleユーザーの電話番号を漏洩させる
IPv6の膨大なアドレス空間と巧妙なBotGuard回避により、レート制限が無効化され、すべてのGoogleユーザーの電話番号が脆弱な状態に置かれました。このセキュリティ問題は、Googleの認証システムにおける重大な欠陥を明らかにしています。
IPv6の膨大なアドレス空間と巧妙なBotGuard回避により、レート制限が無効化され、すべてのGoogleユーザーの電話番号が脆弱な状態に置かれました。このセキュリティ問題は、Googleの認証システムにおける重大な欠陥を明らかにしています。
DDoSecrets has released 410 GB of heap dump data obtained from a hack of TeleMessage's archive server. The data includes information from the company's customers, which reportedly include law enforcement agencies and financial institutions.
A new phishing-as-a-service called Starkiller uses disguised links to load real login pages from target brands. It acts as a relay between victims and legitimate sites, forwarding usernames, passwords, and MFA codes to bypass security measures.
An analysis of the Android Telegram client Telega found that it routes network traffic through a Man-in-the-Middle (MitM) infrastructure located in Russia, raising serious security and privacy concerns for users.
TeleMessage's customer list includes DC Police, Andreessen Horowitz, JP Morgan, and hundreds of other organizations, according to analysis of 410 GB of Java heap dumps from the company's archive server.
An investigation uncovered a large network of fake support groups on Telegram that spread cryptocurrency stealers and drainers. The network was found to be actively promoting malicious tools designed to drain crypto wallets.