Search/hcl
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
domino appdev pack
Connections
6 relationships
Crook hawks millions of records allegedly plundered from corporate Azure tenants
A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name "TheHatman," according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs. Another 800,000 records supposedly come from Tata Consultancy Services, 425,000 from Vodafone, and 250,000 from HCL Technologies, with IHG Hotels & Resorts, Kyndryl, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts rounding out the haul. Hudson Rock assessed the data as "highly likely authentic," citing corporate email addresses and structures consistent with exports from Microsoft Azure directory services. The records allegedly contain considerably more than names and work email addresses. Samples reviewed by the security shop reportedly include phone numbers, physical addresses, employee IDs, job titles, departments, office locations, reporting structures, group memberships, and service account details. Some records also reportedly identify accounts with Global Administrator privileges, potentially handing attackers a useful map of whom to target next. Even if the passwords aren't included, knowing who holds the keys to the kingdom makes for a handy phishing shortlist. How TheHatman allegedly obtained the information remains unclear. The attacker claims to have used compromised credentials, but Hudson Rock could not independently establish the initial access vector. It floated several possibilities, including credentials or session cookies stolen by infostealer malware, phishing, weak or absent multifactor authentication, and overly permissive third-party applications. Hudson Rock said its infostealer database contained compromised Microsoft cloud credentials associated with most of the named companies, although it could not link those credentials to TheHatman's alleged access. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," said Hudson Rock. "If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises." The Register contacted all the organizations named by Hudson Rock to ask whether they were breached, whether the advertised data is authentic, and how any unauthorized access occurred. We've also asked Microsoft whether it is aware of a wider campaign targeting Azure or Entra customers. Tata Services sent The Register the statement it made to India's stock exchange [PDF] saying that the “Company has received threat-intelligence alerts alleging possible exposure of certain employee information." It added: The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments. The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted. “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years. Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely." It said: “The Company will continue to assess any new information that becomes available and take appropriate action, if required. The Company remains committed to maintaining the security and resilience of its systems and to protecting the information entrusted to us.” TheHatman claims to have the data. How it might have walked out of nine corporate directories is the part nobody has explained yet. ®
theregister.comAug 17, 2026extracted
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®
theregister.comAug 17, 2026extracted
HCL AppScan 360º 2.0 protects software supply chains
HCL AppScan 360º 2.0 protects software supply chains HCLSoftware launched HCL AppScan 360º version 2.0, a next-generation application security platform designed to help organizations regain control over their software supply chains. As open-source adoption accelerates and global data regulations tighten, HCL AppScan 360º delivers a cloud-native solution that enables enterprises to secure their applications, without compromising visibility, compliance, or sovereignty. High-profile incidents like Log4Shell have exposed the fragility of software supply chains and the lack of visibility many organizations have into their own codebases. Organizations are relying on open-source software (OSS) components from a patchwork of fragmented repositories which leaves systems exposed to newly discovered vulnerabilities and creates a tangled web of dependencies that is tough to track and maintain. It is not uncommon for companies to rely on hundreds ,or even thousands, of open-source components, many of which come with little visibility into their origins, licensing, or security posture. At the same time, governments are tightening the reins. Over 70 percent of countries have introduced or are drafting data sovereignty laws (Gartner), and regulations like the EU’s Cyber Resilience Act and the U.S. Executive Order on Improving the Nation’s Cybersecurity are mandating greater transparency, faster patching, and full lifecycle oversight of software components. “The global move towards data sovereignty is changing the ecosystem in which secure development happens—but not the increasing pace, which is driven, to a large degree, by open-source adoption and AI tooling,” said Rajesh Iyer, EVP and Portfolio Manager, HCLSoftware. “These pressures are forcing organizations to rethink how they manage open-source software, track vulnerabilities, and control where and how their data is stored and processed.” HCL AppScan 360º version 2.0 is purpose-built to meet this moment. It delivers full-stack application security testing, including high density Software Composition Analysis (SCA) and automated Software Bill of Materials (SBOM) generation, within a secure, on-prem or sovereign cloud environment. “IDC research shows that nearly 85% of organizations currently deploy at least some application security tools on premises, even as cloud adoption grows,” said Katie Norton, Research Manager for DevSecOps at IDC. “The availability of on-premises SCA in AppScan 360º Version 2.0 addresses a critical gap for enterprises that require deep open-source visibility while maintaining full control over their infrastructure and data locality.” This new release adds a number of core technologies to the platform to create a suite of AI-enabled testing and remediation tools including DAST, SAST, IAST, SCA, API, IaC and secrets. Some key capabilities include: Real-time open-source vulnerability detection across the entire application stack with high-density SCA. Automated SBOM creation to provide visibility into dependencies, versions, and sources, make it easier to spot vulnerabilities, stay compliant with licensing, and respond quickly when issues arise. Deployment flexibility in air-gapped or sovereign environments for full infrastructure control. Correlation (IAST, DAST, SAST) to prove exploitability and confirm fixes with findings from a mix of technologies. Beyond regulatory compliance, AppScan 360º helps organizations build trust with customers and partners. A recent Cisco survey found that 92% of consumers prefer their personal data to be stored within their home country, a signal that data sovereignty is now a business differentiator, not just a legal checkbox. “We are delivering on a promise to our customers with a fully on-prem platform that provides up-to-the-minute open-source visibility and AI-enablement, all without exposing their data to the public cloud,” concluded Rajesh Iyer.
helpnetsecurity.comSep 12, 2025extracted
Naval Group Denies Hack Claims, Alleges "Reputational Attack"
Naval Group, a leading defense contractor majority-owned by the French government, has denied claims of a cyber-attack. On July 23, a member of a dark web cybercrime forum using the moniker ‘Neferpitou’ claimed to possess 1TB of data after gaining access to the defense giant’s IT systems. The compromised data allegedly included: A classified content management system (CMS) for submarines and frigates, including source code and deployment documentation Network data related to submarines and frigates Technical documents from DCN, DCNS, and Naval Group, with various classification levels such as "Restricted Distribution" and "Special France" Virtual machines used by developers, containing various simulators related to the French Navy Internal communications intercepted from the organization’s messaging system (HCL Notes) According to the individual's statement, they provided a substantial data sample (approximately 13 GB) as proof of their claims. They issued a 72-hour ultimatum for Naval Group to establish contact through Session, an encrypted messaging platform known for its anonymity and reportedly favored by cybercriminals. The full dataset would be publicly released at no cost if a response was not issued within the given timeframe. Photo credits: HJBC / Aleksandrkozak / Shutterstock.com Complaint Filed to Shed Light on Malicious Acts Speaking to Infosecurity, Naval Group confirmed that on July 23 that several of its services, including the group’s own Computer Emergency Response Team (CERT), began investigating the claims in collaboration with French government agencies. On July 25, a new sample of the alleged stolen data was published, which reportedly included more components of a classified naval CMS (such as binaries, training materials and logs), detailed screenshots, performance test results and restricted documents related to its use on French frigates. However, Naval Group told Infosecurity that no intrusion into the company’s IT environments had been detected and no impact on its operations had been reported. “In an international, commercial and informational context marked by heightened tensions and an increase in destabilization attempts, Naval Group has observed that it is the target of a reputational attack, characterized by claims of cyber malfeasance,” a Naval Group spokesperson said to Infosecurity. The company has filed a complaint with the Paris Public Prosecutor's Office to “shed light on these malicious acts,” the spokesperson added. Older Claim of Naval Group Data Leak From NoName057(16) A social media account allegedly linked to NoName057(16), a pro-Russian hacktivist group, claimed on X on July 7 that it had infiltrated Naval Group’s internal perimeter. “We were able to obtain a lot of interesting data, which we have already handed over to the appropriate parties,” the post read. There is currently no evidence to support these assertions and their legitimacy has not been established. Between July 14 and 17, NoName057(16)’s attack infrastructure was disrupted and a major part of the group's central server infrastructure taken offline in an international operation dubbed Operation Eastwood, coordinated by Europol and Eurojust. Naval Group is France’s largest shipbuilder, employing over 15,000 people with a yearly revenue exceeding €4.3bn ($5bn). The French State holds a majority stake in the company (62.25%), and Thales, a French multinational company specializing in aerospace, defense and security, owns 35%.
infosecurity-magazine.comJul 28, 2025extracted