> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets 10/06/2025

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 06/10/2025 12:37] [LANGUAGE: EN]
Oracle says hackers are trying to extort its customers Oracle said on Thursday that customers of its E-Business Suite of products “have received extortion emails,” confirming a warning first issued on Wednesday, opens new tab by Alphabet’s Google. In a blog post, opens new tab, the California-based tech company said its investigation found that hackers had made potential use of previously identified software vulnerabilities and urged customers to upgrade their products. Oracle did not immediately respond when asked how many clients were affected. Google has described the hacking campaign as “high volume,” but declined to go into detail.   That CISO job offer could be a ‘pig-butchering’ scam The recent experience of a seasoned security leader illustrates how fake job offers are increasingly being used as entry points for “pig-butchering” scams. Pig-butchering scams are a form of investment fraud that exploit social engineering to build a relationship with a prospective mark before butchering them financially, often through cryptocurrency or other fake investments. Fraudsters purportedly representing Gemini Crypto, a US-based cryptocurrency trading platform, tried to leave US CISO Walter Williams at a minimum of $1,000 out of pocket through a sustained campaign that lasted more than three months between May and September 2025. The pretext of a confidential job search for a CISO was plausible enough for Williams to play along despite quickly realizing the approach was suspect.   Japan’s most popular beer is running low after cyberattack Japan is facing a potential shortage of Asahi beer after a cyberattack against the beverage maker forced its systems offline. Asahi Group issued a statement on Monday announcing that order, shipment, and call center operations at the company had been suspended due to the systems outage, and that the disruption was limited to Japan. The company has now started to manually process orders, according to an updated notice published today, but system-based orders and wide-scale shipments remain suspended. Asahi said it was targeted by a ransomware attack, but is withholding specifics “to prevent further damage.” The company is unable to provide a clear timeline for system recovery.   Red Hat Confirms GitLab Instance Hack, Data Theft Red Hat on Thursday confirmed that one of its GitLab instances was hacked after a threat actor claimed to have stolen sensitive data belonging to the company and its customers.  It was initially reported that the hackers had targeted a GitHub instance, but the enterprise software giant clarified that it was actually a GitLab instance, specifically one used by the Red Hat Consulting team. The hackers, calling themselves Crimson Collective, claimed to have stolen 570 Gb of compressed data from 28,000 private repositories. The obtained data allegedly includes source code, credentials, secrets, and configurations, as well as customer engagement reports (CERs).   ParkMobile pays… $1 each for 2021 data breach that hit 22 million ParkMobile has finally wrapped up a class action lawsuit over the platform’s 2021 data breach that hit 22 million users. But there’s a catch: victims are receiving compensation in the form of a $1 in-app credit, which they must claim manually. And, it comes with an expiration date. Great news! If you were affected by ParkMobile’s 2021 data breach, there’s serious money to be made: a whopping dollar. The popular mobile and web parking payments platform, headquartered in Atlanta, began sending emails last week to class action plaintiffs, advising them on how to claim their portion of the settlement fund. Upon receiving this email, I was, like many others, understandably skeptical and struggled with its wording. Was it legitimate or a trolling (or even phishing) attempt?   LinkedIn sues software company allegedly scraping data from millions of profiles Social media giant LinkedIn on Thursday filed a lawsuit against a company which it says operates a network of millions of fake accounts used to scrape data from LinkedIn members before selling the information to third parties without permission. ProAPIs, a software company, and its CEO Rahmat Alam allegedly run an operation which LinkedIn says charges customers up to $15,000 per month for scraped user data taken from the social media platform. With the rise of artificial intelligence, companies which scrape user data at scale are proliferating and are increasingly undermining consumer privacy. The post InfoSec News Nuggets 10/06/2025 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →