ASOS app users report spam messages following security breach

UK fashion retailer ASOS is facing a security incident after users reported receiving unauthorized pop-up notifications within the company's official mobile app. The messages, which appear to originate from a group calling itself the "Xuanye Group," claim that the company's Snowflake data instance has been compromised and threaten to leak information if demands are not met. While ASOS has not yet issued an official statement, the incident has triggered widespread concern among customers. Security experts advise users to avoid interacting with the app and to refrain from clicking any links contained in the suspicious pop-up messages, as these lead to external Telegram channels used by the attackers. The breach highlights ongoing vulnerabilities in third-party data integrations and the potential for attackers to leverage internal communication channels to reach end users directly.
This is a summary. Read the full article at the original source:
MashableRelated stories
Online fashion retailer ASOS has confirmed that some of its app users received unauthorized push notifications. The messages, which appeared on users'…
Windows IR: A Systematic Approach. Part 2 — Isolation, Processes, and Services
The second part of the Windows Incident Response series focuses on practical methods for responding to security incidents. The author examines the pro…
Researchers from the Netherlands and Italy have unveiled a new attack that expands the Spectre-v2 class of vulnerabilities. Unlike the original 2018 a…



