Software bug exposed Peloton users private account data
A vulnerability in Peloton's API allowed anyone access users' private information, such as age, gender, city, weight, workout statistics and more.
A vulnerability in Peloton's API allowed anyone access users' private information, such as age, gender, city, weight, workout statistics and more.
The attack hindered access to government websites, as well as websites of universities and research institutions.
The bugs allow a remote attacker to take over vulnerable systems.
The campaign hit at least 50 organizations from a wide variety of industries.
The company did not provide information on the nature of the zero-day attacks, or the victims that may have been targeted.
The attackers used the RoyalRoad weaponizer to deliver the previously undocumented PortDoor malware.
The provider did not share details on the nature of the cyberattack, but said that there is no evidence that any information was stolen.
By exploiting any of these bugs an attacker can cause widespread disruption to the services.
Phishing emails attempt to trick users into installing an updated version of the Moserware malware.
The hacker group abused legitimate software to side-load the second-stage backdoor called Nebulae.
Showing elements 3201 - 3210