476 words
2 minutes
GUARD 23.03.2025
2025-03-23

Data Breaches/Leaks#

  1. Hardcoded Secrets on GitHub

    • Date: throughout 2024
    • Source: https://cybernews.com/security/developers-hardcoding-secrets-github-risk/
    • Reason: Developers hardcoding sensitive information in public repositories.
    • Leaked Data: API keys, credentials, authentication tokens.
    • Summary: Security researchers warn that developers continue to expose sensitive information in GitHub repositories, increasing risks of unauthorized access.
  2. NASIMS Government Data Leak

    • Date: October 20th, 2024
    • Source: https://cybernews.com/security/government-data-leak-nasims-citizen-records/
    • Reason: Misconfigured database (S3 Bucket).
    • Leaked Data: Personal details of citizens, including names, addresses, and identification number, 23 million files.
    • Summary: A government database containing sensitive citizen records was found exposed, highlighting poor security practices in public sector organizations.
  3. California Cryobank Data Breach

  4. Oberlin Marketing Medicare Data Leak

Vulnerabilities#

  1. Facebook Font Rendering Library Exploit

  2. Apache Tomcat RCE Vulnerability

  3. Fortinet Critical Vulnerability

AI#

  1. DeepSeek and AI Malware Generation

  2. ChatGPT Bug Puts Organizations at Risk

Risk#

  1. Nation-State Groups Exploiting Windows Shortcut Flaw

Cybercrime#

  1. Juniper Routers Compromised with TinyShell Malware
  1. Ukraine Defense Sector Attacked by DarkCrystal RAT
  1. Denmark Warns of Increased Cyber Espionage in Telecom Sector

Malware#

  1. Medusa Ransomware Spreading Rapidly
  1. Stilachirat Trojan Used for Spying
  1. VSCode Extensions Used to Deploy Ransomware

Titbits#

  1. Snowden Warns About New Ransomware Extortion Tactics
  1. Microsoft Fixes Windows Update Bug That Wiped Out Copilot
GUARD 23.03.2025
https://typetherapy.blog/posts/guard/guard_23_03_2025/
Author
Type Therapy Blog
Published at
2025-03-23
License
CC BY-NC-SA 4.0