The Apache Software Foundation has released a security advisory for Java logging library Apache Log4j. This vulnerability may be exploited over a network without the need for a username and password. This is logged in the National Vulnerability Database (NVD) as CVE-2021-44228. Multiple server and cloud software vendors will be releasing security updates.
Robinhood has reported that some of its financial app’s customer data was leaked in November 2021. This includes at least two million full names and 5 million email addresses. A much smaller amount of customers had additional data leaked. Social security numbers and bank account numbers were not affected.
T-Mobile has notified its customers that there was unauthorized access to some of its company data in August of 2021, and that the entry point for the intrusion was closed. The company is still researching this event.
Update: T-Mobile has released more details as well as recommendations for its customers, as well as former and prospective customers.
ParkMobile, a vehicle parking app which is used in several major cities in the U.S. under various names, has released details for a security incident with its vehicle parking app in March of 2021. License plate numbers and some email addresses and/or phone numbers were included in this incident, but not credit cards or drivers license numbers.
Facebook has released a response to recent reports of 530 million user accounts made publicly available in an unsecured database. Facebook states that their systems were not hacked, but user data was scraped from its platform prior to September 2019. Facebook also states that the issue was corrected at that time and should not happen again.
Microsoft released several urgent security updates for Exchange Server based on cyber attacks believed to be from HAFNIUM and other groups starting March 2, 2021. This includes Microsoft Exchange Server 2019, 2016, 2013 and 2010, but not Exchange Online. Microsoft recommends installation of security updates and running tests to see if Exchange servers have already been compromised.
The U.S. Justice Department has also executed a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers in the United States in relation to this security issue. The FBI will attempting to provide notice of the court-authorized operation to all owners or operators of these computers.
SolarWinds issued a security advisory in December 2020 regarding recent cyberattacks on its Orion Platform of products and an FAQ page. Microsoft has also created a list of resources regarding this security incident.
Marriott Hotels has reported a data breach in 2020 that affected the data for approximately 5.2 million guests. Customers can request more information at mysupport.marriott.com
Convenience store chain Wawa has disclosed a data breach that occurred from March 2019 to December 2019. Malware was detected and then removed from its payment processing servers by their information security team. Payment information, including credit and debit card numbers, expiration dates, and cardholder names were included in this breach. Wawa is offering one year of identity theft protection for affected cardholders.