Lapsus$ teen hackers convicted in the UK
The teens were charged with fraud, blackmail and violating the UK’s Computer Misuse Act.
The teens were charged with fraud, blackmail and violating the UK’s Computer Misuse Act.
Roman Storm and Roman Semenov allegedly created the core features of Tornado Cash and paid for critical infrastructure to operate the service.
The data was scraped using an exposed Duolingo API, which is still publicly available.
The company warned that “the majority of customers have lost all data with us.”
The campaign deployed the Korplug backdoor via a legitimate security software Cobra DocGuard.
The breach affected “certain corporate systems” in Australia and the UK.
The group shared screenshots of what appear to be internal documents, including watch blueprints and designs.
The bug could be exploited to bypass authentication process and execute arbitrary code on the system.
This appears to be the first time Cuba exploited the CVE-2023-27532 vulnerability.
As part of the operation, 14 suspected cybercriminals were arrested.
Showing elements 2011 - 2020