Bill Toulas reports: A new cyber espionage campaign dubbed ‘No Pineapple!’ has been attributed to the North Korean Lazarus hacking group, allowing the threat actors to stealthily steal 100GB of data from the victim without causing any destruction. The campaign lasted between August and November 2022, targeting organizations in medical research, healthcare, chemical engineering, energy,…
Category: Of Note
Former Employee Ubiquiti Networks Pleads Guilty To Stealing Confidential Data And Extorting Company For Ransom
There’s an update to a previously reported case involving a former employee of Ubiquiti Networks, although as is their policy, the DOJ does not name the victim firm: Damian Williams, the United States Attorney for the Southern District of New York, announced that NICKOLAS SHARP pled guilty today in Manhattan federal court to multiple federal…
Auction Company Offers to Sell Unscrubbed Computers Back to San Benito Schools
Fernando Del Valle reports: A San Benito school district online auction sold thousands of computers and tablets, some of which contained employees’ and students’ personal data, a computer store owner said Wednesday. South Texas Auction Co.’s records show the district sold more than 2,000 computers and 1,500 tablets during a July 23 online auction, David…
FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Info for Advertising
The Federal Trade Commission has taken enforcement action for the first time under its Health Breach Notification Rule against the telehealth and prescription drug discount provider GoodRx Holdings Inc., for failing to notify consumers and others of its unauthorized disclosures of consumers’ personal health information to Facebook, Google, and other companies. In a first-of-its-kind proposed…
In 2023, Resolve to Fix Your Organization’s Meta Pixel Problem
In 2023, Resolve to Fix Your Organization’s Meta Pixel Problem It’s time to be proactive about user privacy. Find out if you’re sending too much data to Facebook—or if you need to send data at all By: Maria Puertas and Simon Fondrie-Teitler We all use the internet to complete increasingly sensitive tasks: book doctor’s appointments,…
GitHub revokes code signing certificates stolen in repo hack
Sergiu Gatlan reports: GitHub says unknown attackers have stolen encrypted code-signing certificates for its Desktop and Atom applications after gaining access to some of its development and release planning repositories. So far, GitHub has found no evidence that the password-protected certificates (one Apple Developer ID certificate and two Digicert code signing certificates used for Windows…