Ross Kelly reports: Russian tech company Yandex has issued an apology after racial slurs were discovered in source code leaked in a recent data breach. Several references to racial slurs, including the ‘N-word’, were found in the company’s source code last week. A researcher first revealed the use of offensive terminology in a series of…
GitHub revokes code signing certificates stolen in repo hack
Sergiu Gatlan reports: GitHub says unknown attackers have stolen encrypted code-signing certificates for its Desktop and Atom applications after gaining access to some of its development and release planning repositories. So far, GitHub has found no evidence that the password-protected certificates (one Apple Developer ID certificate and two Digicert code signing certificates used for Windows…
Microsoft disables verified partner accounts used for OAuth phishing
Bill Toulas reports: Microsoft has disabled multiple fraudulent, verified Microsoft Partner Network accounts for creating malicious OAuth applications that breached organizations’ cloud environments to steal email. In a joint announcement between Microsoft and Proofpoint, Microsoft says the threat actors posed as legitimate companies to enroll and successfully be verified as that company in the MCPP…
Google Fi Customers Caught Up in T-Mobile Data Breach
Matthew Humphries reports: Google is in the process of telling Google Fi customers that their data was stolen as part of the T-Mobile breach earlier this month. On Jan. 5, a hacker breached T-Mobile’s network and stole data from 37 million customer accounts. Google Fi uses T-Mobile’s network for the majority of its connections, and it seems the…
Hacker finds bug that allowed anyone to bypass Facebook 2FA
Lorenzo Franceschi-Bicchierai reports: A bug in a new centralized system that Meta created for users to manage their logins for Facebook and Instagram could have allowed malicious hackers to switch off an account’s two-factor protections just by knowing their phone number. Gtm Mänôz, a security researcher from Nepal, realized that Meta did not set up a limit…
Morgan Hill Unified School District discloses data breach
Morgan Hill Unified School District in California has disclosed a breach that occurred when an employee’s email account was accessed without authorization between September 11 and October 11, 2022. While the district’s investigation was able to confirm connections to the employee’s account during those dates, the investigation was not able to determine which specific emails…