In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
Briefly

In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
Trump Mobile confirmed exposure of customer personal data to the internet, including names, addresses, email addresses, and phone numbers, attributing the issue to a third-party platform provider. Documents from a Freedom of Information Act lawsuit showed Russian state-sponsored activity tied to the 2019–2020 SolarWinds supply chain attack had access to Treasury emails, focusing on eight email accounts connected to hundreds of others. A remote code execution vulnerability in the VS Code Remote-SSH extension could let attackers pivot to remote systems by modifying a bootstrap shell script written to the Temp directory before execution. UK Visa Portal publicly exposed more than 100,000 visa application documents, affecting applicants’ records.
"Phone provider Trump Mobile has confirmed that customers' names, addresses, email addresses, phone numbers, and other data was exposed to the internet. The company reportedly said a third-party platform provider was responsible for the exposure."
"Documents presented in a Freedom of Information Act lawsuit filed by Bloomberg News against the US government show that the Russian state-sponsored APT responsible for the 2019-2020 SolarWinds supply chain attack had deep access to Treasury emails. The hackers reportedly focused on only eight email accounts linked to 300 other email addresses. The Treasury had roughly 94,000 people at the time."
"A remote code execution (RCE) vulnerability in the Visual Studio Code (VS Code) Remote‑SSH extension could allow attackers to pivot to remote systems, security researcher Suman Kumar Chakraborty warns. The issue exists because, upon initiating a Remote SSH connection, the extension writes a bootstrap shell script to the Temp directory. An attacker with access to the system can modify the script before it is transmitted and executed on the remote server, to deploy a reverse shell."
"Immigration portal UK Visa Portal publicly exposed over 100,000 documents of people who applied for a UK visa, TechCrunch reports. Not affiliated with the UK government, the w"
Read at SecurityWeek
Unable to calculate read time
[
|
]