Software

Industry

Location Tracking Life360 App Consumer Data is Leaked Online

March 15, 2024

A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API. Life360 is a family networking app designed to provide location and safety services.

Known only by their ’emo’ handle, they said the unsecured API endpoint used to steal the data provided an easy way to verify each impacted user’s email address, name, and phone number. “When attempting to login to a life360 account on Android the login endpoint would return the first name and phone number of the user, this existed only in the API response and was not visible to the user,” emo said.

Life360 did not disclose how the threat actor breached its platform, but the company stated that it had taken steps to protect its systems from further attack.

read more

TeamViewer Reports Databreach

June 26, 2024

Software company TeamViewer says that a compromised employee account is what enabled hackers to breach its internal corporate IT environment and steal encrypted passwords in an incident attributed to the Russian government.

TeamViewer said a Kremlin-backed group tracked as APT29 was able to copy employee directory data like names, corporate contact information and the encrypted passwords, which were for the company’s internal IT environment. The company reaffirmed that the hackers were not able to gain access to the company’s product environment or customer data, and that the breach appears to be contained.

read more

Ransomware Attack Affects Cultural Organizations in France

June 28, 2024

Forum Sirius, a ticketing software provider was informed on June 28 that it had been the target of a cyberattack. Forum Sirius serves more than 400 cultural organisations.

The Forum Sirius database contains 5,986,188 records including user IDs, names, addresses, phone numbers, emails, and other personal information although bank details are claimed to have been protected. It is claimed that those behind last month’s attack are offering to sell the database to a single buyer for $2,000 (£1,500/€1,850).

read more

Cyberattack Causes Serious Fallout for French Online Retailers

August 16, 2024

Friday, August 16, 2024 was a dark day for Octave, specializing in ERP solutions and e-commerce services. A ransomware attacked knocked out half of the company’s information system. The company is doing everything it can to restore its services as soon as possible, but the situation remains complex and delicate. All Octave customers , whether they use ERP solutions, e-commerce site services or any other service of the company, are directly affected by this attack. “The complexity of the actions required to restore the systems securely adds uncertainty as to the rapid resolution of the situation.”

. Octave set up a crisis unit, called on a cybersecurity specialist and filed a complaint.

Some of Octave’s customers, mostly independent physical stores that have an online shopping site such as cobra.fr, agripartner.fr, ardent-peche.fr, kazed.fr or 3as-racing.com, remain inaccessible this Wednesday, September 11, 2024.

read more

Cyber Incident at Software co. Formpipe’s Danish Subsidiary

October 17, 2024

Formpipe has reported a computer security incident within its Danish subsidiary. The incident resulted in a data security breach, but details on the extent and consequences of the incident are not yet available. The investigation is ongoing to determine the causes and implications of the incident.

read more

Giant Latin American Software Company TOTVS Hit by Cyberattack

October 1, 2024

“TOTVS was the target of a cyberattack and reacted quickly. The attack was carried out by the BlackByte group, known for its double extortion tactic. Although TOTVS has indicated that encryption is under control, there is evidence that *data exfiltration* was significant, with samples already circulating on the dark web.

This suggests that confidential information may have been compromised, increasing the challenge of containing the impact of the attack.

read more

Swedish IT Logistics Company Aurdel Hit by Cyberattack

September 26, 2024

Aurdel, a subsidiary of an IT company, Dist IT, was the victim of a cyberattack that caused a financial impact. The attack began on Thursday and the systems were taken offline to minimize the damage, resulting in delays in deliveries. The perpetrators of the attack had access to data, but it is too early to assess the extent of the violation.

Aurdel was created by merging two of the Nordic regions’ biggest distributors – Aurora Group and Deltaco.

read more

Axido Said “Return to Production Will Be very Long”

June 14, 2024

(auto-translated) Axido isolated its information system and mandated a third party to conduct the investigations. Part of the production environment of its hosted customers has been compromised by the attackers.

Axido is unable to move forward “on specific deadlines for restarting the environments of [its] customers”. The company said that “the return to production will be very long”. “in the interest of the security of our customers and their data, we will take the time to carry out all these operations”.

“In accordance with the recommendations of the ANSSI, we have chosen not to come into contact with the attackers.”

read more

DDoS Attack Took Down TankerTrackers Online Service

January 15, 2024

A DDoS attack has taken down the TankerTrackers online service, that tracks and report shipment of crude oil. This was timed to coincide with a simultaneous kinetic attack by the Houthis against the Marshall Island flagged, US-owned, Greek-operated tanker MV CHEM RANGER. If the information is valid, this is the first time a coordination of cyber and kinetic attacks has occurred.

read more

Big Ripple Effects after AI-driven Supply Chain Software Supplier Blue Yonder Cyberattack

November 21, 2024

A ransomware attack targeted Blue Yonder, a major supply chain technology provider, affecting several retailers including Starbucks and Sainsbury’s. The attack disrupted operations, including scheduling and inventory management, prompting the companies to trigger backup plans to manage inventories and other essential systems. The incident highlights the potential consequences of cyber attacks on supply chain technology providers and the need for robust cybersecurity measures to prevent and respond to such incidents.

Morrisons, a U.K.-based grocery chain, said the Blue Yonder incident impacted delivery of goods to stores in the UK. Availability of some product lines at wholesale and convenience locations could drop to as low as 60% of normal availability. Sainsbury’s added that it was putting contingency processes in place. Starbucks is reverting to manual operations after back-end process for employing scheduling and time-tracking was affected by the attack.

Blue Yonder describes itself as a world leader in digital supply chain transformation with an AI-driven platform that helps with everything from fulfillment to delivery logistics.

read more