TMX loan data breach, Italy bans ChatGPT and WordPress Elementor Pro exploit

April 3, 2023 by Dan Virgillito

High-cost lender TMX announces data breach affecting millions of customers, hackers actively exploit vulnerability in the Elementor Pro WordPress plugin and Italy’s ChatGPT ban. Catch all this and more in this week’s edition of Cybersecurity Weekly.

1. Consumer lender TMX discloses data breach, nearly 5 million customers affected

High-cost lender TMX Finance and its affiliates announced they suffered a data breach that affects around 5 million customers. The breach was traced back to early December 2022, but was only discovered in February 2023. The hackers reportedly stole personal information, including passport and social security numbers. TMX Finance is offering affected customers credit monitoring and identity protection services. The incident highlights the ongoing threat of cyberattacks for companies handling sensitive information.

Read more »

2. Hackers exploit bug in the popular Elementor Pro WordPress plugin

Hackers are exploiting a vulnerability in the popular Elementor Pro WordPress plugin, used by over 11 million websites. The flaw, discovered on March 18, 2023, impacts version 3.11.6 and all previous versions, allowing authenticated users to change site settings and perform a complete site takeover. Security firm PatchStack reveals that adversaries exploit the bug to redirect visitors to malicious domains or upload backdoors to the breached site. Users should upgrade to version 3.11.7 or above as a safety measure.

Read more »

3. Italy bans ChatGPT, citing privacy concerns

Italy has banned and launched an investigation into OpenAI’s ChatGPT over privacy concerns, making it the first Western country to block the advanced chatbot. The model, backed by Microsoft, has millions of users and can answer questions in natural, human-like language using the internet as its database. There have been concerns over AI’s potential risks, including spreading misinformation and bias. OpenAI said it was committed to protecting people’s privacy and looked forward to making ChatGPT available in Italy again soon.

Read more »

4. New AlienFox malware spoofs credentials of 18 cloud services

Hackers are using the “AlienFox” modular toolkit to compromise the email and web hosting services of 18 companies, according to SentinelLabs researchers. The adaptable toolkit extracts sensitive information, such as API keys and secrets, from configuration files of service providers like Office365, AWS, and Google Workspace. AlienFox scripts are distributed mainly via Telegram and open-source repositories, leading to constant adaptation and variation in the wild. Researchers have uncovered two versions of the tools, with version 3.x containing the script, which automates the extraction of keys and secrets from a compromised web application framework called Laravel.

Read more »

5. Misconfigured Microsoft app leads to the hijacking of Bing search results

A misconfigured Microsoft application allowed unauthorized users to log in and modify Bing search results in real-time. Wiz Research discovered the issue, dubbed “BingBang,” and reported it to Microsoft on January 31, 2023. The attack affected multi-tenant apps that had been misconfigured, which accounted for around 25% of scanned apps. In addition to the modification, attackers could use an XSS attack to potentially compromise the accounts of Office 365 users. Microsoft confirmed the fix on March 28, 2023, and Wiz Research was awarded a bug bounty of $40,000.

Read more »

Posted: April 3, 2023
Dan Virgillito
View Profile

Dan Virgillito is a blogger and content strategist with experience in cyber security, social media and tech news. Visit his website or say hi on Twitter.