Connect with us

Press Release

FlexBooker reports a data breach, affecting more than 3.7 million accounts.

Published

on

FlexBooker reports a data breach, affecting more than 3.7 million accounts.

In an attack just before the holidays, the accounts of over three million customers of the American appointment scheduling service FlexBooker were taken, and they are now being exchanged on hacker forums.

The same hackers are also selling databases they claim to be from two other organisations: the Australian case management system rediCASE and the racing media outlet Racing.com.

Holiday breaches before
A few days before Christmas, there were supposedly three breaches, and the intruder posted the information on a hacking forum.

A popular programme for booking appointments and syncing employee calendars, FlexBooker, appears to be the source of the most recent data dump.

Owners of any company that needs to plan appointments, such as accountants, barbers, doctors, mechanics, lawyers, dentists, gyms, salons, therapists, trainers, spas, and the list goes on, are among FlexBooker’s clients.

The group claiming responsibility for the attack appears to go by the name of Uawrongteam, and they published links to files and archives containing personal information, including pictures, driver’s licences, and other IDs.

The database, according to Uawrongteam, has a table with 10 million lines of client data, including everything from payment forms and charges to pictures taken for driver’s licences.

Names, emails, phone numbers, password salt, and hashed passwords are among the database’s “juicy columns,” according to the actor.

Customers of FlexBooker have received a data breach notification that confirms the attack and that data on the service’s Amazon cloud storage system was “accessed and downloaded” by the intruders.

The letter states that “our account on Amazon’s AWS servers was compromised on December 23, 2021, starting at 4:05 PM EST,” adding that the attackers did not obtain “any credit card or other payment card information.”

FlexBooker advised consumers to be on the lookout for strange or fraudulent activities, and to monitor account statements and credit reports.

For further information, the developer also directed users to a report on a distributed denial-of-service (DDoS) attack. It was then determined that some customers’ personal information had been obtained by the hackers.

The FlexBooker assault exposed email addresses, names, partial credit card information, passwords, and phone numbers for more than 3.7 million users, according to the data breach reporting service Have I Been Pwned.

Prior to FlexBooker, the threat actor known as Uawrongteam distributed links to material that was purportedly taken from Racing.com, a digital television station that broadcasts horse racing and offers news, stats, and event calendars associated with the sport.

The data from the Redbourne Gang’s rediCASE Case Management Software, which is utilised by numerous enterprises in addition to health and community agencies, looks to be another target of the same group.

Continue Reading

Press Release

NVIDIA resolves critical issues affecting Windows and Linux devices.

Published

on

NVIDIA resolves critical issues affecting Windows and Linux devices.

NVIDIA has released security upgrades to fix ten more bugs impacting the NVIDIA Virtual GPU (vGPU) management software in addition to six security holes discovered in Windows and Linux GPU display drivers.

The flaws make Windows and Linux systems vulnerable to attacks that could cause a denial of service, privilege escalation, data manipulation, or information disclosure.

Because all of these security flaws need local user access, potential attackers must first get access to susceptible targets via a different attack method.

Patching of eleven high severity vulnerabilities
Attackers can simply escalate privileges to obtain permissions above those provided by the OS after successfully exploiting one of the vulnerabilities fixed today.

Denial-of-service attacks or gaining access to otherwise inaccessible information can also be used to temporarily disable workstations running vulnerable drivers or software.

With the exception of the security flaws identified as CVE-2021-1052, CVE-2021-1053, and CVE-2021-1056 affecting the Linux GPU Display Driver for Tesla GPUs, which will start receiving an updated driver version on January 18, 2021, NVIDIA has patched all impacted software products and platforms.

The flaws have CVSS V3 base ratings ranging from 5.3 to 8.4, and NVIDIA has classified 11 of them as high-risk.

The risk assessment “is based on an average of risk across a broad set of deployed systems and may not represent the true risk of your local installation,” according to NVIDIA’s security alert.

To accurately assess the risk these vulnerabilities represent to your particular system configuration, the business further suggests speaking with an IT or security specialist.

The January 2021 Security Bulletin is a complete list of security problems that NVIDIA patched this month.

Several driver updates are accessible from hardware vendors.
NVIDIA advises users to use the security updates offered on the NVIDIA Driver Downloads page to upgrade their GeForce, NVIDIA RTX, Quadro, NVS, and Tesla GPU display drivers, as well as Virtual GPU Manager and guest driver software.

According to the business, certain consumers who choose not to manually fix the weaknesses might also get security upgrades bundled with Windows GPU display driver 460.84, 457.49, and 452.66 versions from their computer hardware vendors.

Users of the NVIDIA vGPU enterprise software must sign into the NVIDIA Enterprise Application Hub in order to download updates from the NVIDIA Licensing Center.

Continue Reading

Press Release

Internet Explorer 11 support will no longer be offered by WordPress.

Published

on

Internet Explorer 11 support will no longer be offered by WordPress.

WordPress, the most well-known and widely used blogging platform, is thinking about removing support for Internet Explorer 11 when its usage falls below 1%.

WordPress has discovered that the cumulative usage of IE 11 is less than 1% using the following three metrics:

according to StatCounter’s GlobalStats, 0.71%.
from W3 Counter, 1.2%
from WordPress.com, 0.46%
When WordPress stopped supporting Internet Explorer 8, 9, and 10 in 2017, these usage figures were comparable.

WordPress plans to discontinue support for Internet Explorer 11 in the future due to the low number of users and the significant expense of maintaining the browser.

“Regarding the present WordPress user experience, the majority of WordPress users ought to be aware by now that a flag was introduced to BrowseHappy around 13 months ago to not recommend IE. In connection with this, the entire IE11 experience is subpar and comes with a significant maintenance cost for developers “Last week, WordPress clarified in a blog post.

WordPress is requesting feedback from individuals and organisations that still use the browser by March 18th in order to formulate their strategies for ceasing support.

WordPress is not the only platform to stop supporting IE 11.

Microsoft Teams’ web app will no longer be supported by Internet Explorer, and Microsoft 365 would stop supporting it on August 17, 2021, according to a 2020 August Microsoft announcement.

Continue Reading

Press Release

Major Canadian banks experience a bizarre, hours-long outage

Published

on

Major Canadian banks experience a bizarre, hours-long outage

Major Canadian banks fell unavailable for several hours, denying consumers access to e-transfers, online and mobile banking, and other services.

The Canadian Imperial Bank of Commerce, Scotiabank, Bank of Montreal, and Royal Bank of Canada (RBC) are among the institutions apparently affected by the outage (CIBC).

For many, online banking and e-Transfers are not working.
Yesterday, the main banks in Canada went offline, making it difficult for many people to access e-Transfers, online, and mobile banking services.

The number of reports of people experiencing problems accessing their online banking peaked on Wednesday between 5 and 6 p.m. Eastern time, while BleepingComputer is still receiving an influx of these reports today:

 

An RBC spokesman acknowledged that “we are currently having technical challenges with our online and mobile banking, as well as our phone services.”

“We have no ETA to offer at this time, but our specialists are looking into it and striving to fix it as soon as they can. We value your tolerance.”

Customers continued to report problems a few hours later, within 30 minutes of RBC declaring that all systems were operating normally:

Andrew Currie, an RBC client, stated that the disruption left him without “access to my money at the grocery store” and forced him to wait in line for the cash register for 30 minutes.

Customers of BMO also noticed that the bank’s “Global Money Transfer service” was unavailable “all day” and that transfers were being automatically denied without any apparent cause. Such customers were advised to contact customer care by a BMO representative.

Inconsistencies with their internet banking were not acknowledged by CIBC.

Customers were apparently locked out of the TD Bank mobile banking app, and customer support agents said they “haven’t been told of recent concerns with our online service through EasyWeb.”

According to a TD Bank representative speaking to BleepingComputer, the bank had no significant system issues or outages.

It’s unclear at this moment whether some people’s difficulties at the ATMs were caused by the outage. According to an RBC staffer, the customer experiencing ATM problems is using an old debit card:

Some transfers are subject to rules under the Emergencies Act.

Although the reason for the outage is unknown, its timing is very intriguing because it comes only a few days after Canadian Prime Minister Justin Trudeau used the Emergencies Act in the midst of ongoing “Freedom Convoy” rallies.

Deputy Prime Minister Chrystia Freeland detailed the new rules that payment service providers must follow in accordance with the recently implemented Emergencies Act on Monday during a press briefing on Parliament Hill.

Additionally, without a court ruling and without risking civil liability, the Emergencies Act gives banks the power to freeze the accounts of people and companies they believe to be connected to the illegal blockades.

However, as the Deputy PM notes, since banks are currently required to report to FINTRAC, it is still unclear how new legislation will cause a planned or unanticipated outage.

Continue Reading

Trending