News
Cisco warns of two more SD-WAN bugs under active attack
Just when network admins thought the Cisco SD-WAN patch queue might finally be shrinking, Switchzilla has confirmed miscreants are exploiting more vulnerabilities in its SD-WAN management software.…
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
A new twist on the long-running ClickFix scam is now tricking Windows users into launching Windows Terminal and pasting malware into it themselves – handing the credential-stealing Lumma infostealer the keys to their browser vault.…
Son of government contractor arrested after alleged $46M crypto heist from US Marshals
The son of a government contractor was arrested in the Caribbean after allegedly stealing more than $46 million in seized cryptocurrency from the US Marshals Service, the FBI says.…
Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October
Microsoft has finally fixed a Windows Recovery Environment (WinRE) bug it introduced in Windows 10's final update.…
Transport for London says 2024 breach affected 7M customers, not 5,000
Transport for London has confirmed that a 2024 breach exposed the data of more than 7 million people – a far larger crowd than the few thousand customers originally warned that their details might be at risk.…
Google says spyware makers and China-linked groups dominated zero-day attacks last year
Zero-day exploitation targeting enterprise tech products reached an all-time high last year, with China-linked cyber-espionage groups remaining the most prolific state-backed users, according to Google.…
Iran intelligence backdoored US bank, airport, software outfit networks
An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies' networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers.…
UK watchdog eyes Meta's smart glasses after workers say they 'see everything'
Britain's privacy watchdog is asking questions about Meta's AI-powered smart glasses after reports that human contractors reviewing recordings from the devices were exposed to extremely private moments captured by unsuspecting users.…
'Hundreds' of Iranian hacking attempts have hit surveillance cameras since the missile strikes
Multiple Iranian hacking crews have been targeting internet-connected surveillance cameras across Israel and other Middle Eastern countries since the war started on February 28, according to Check Point security researchers. …
Malware-laced OpenClaw installers get Bing AI search boost
OpenClaw, the AI agent that can manage just about anything, is risky all by itself, but now fake installers for it are wreaking havoc. Users who searched Bing’s AI results for “OpenClaw Windows” were directed to a malicious GitHub repository that delivered information stealers and GhostSocks onto their machines.…
LexisNexis confirms data breach at Legal & Professional arm, some customer records affected
Data analytics giant LexisNexis has confirmed its Legal & Professional division suffered a data breach days after the Fulcrumsec cybercrime crew claimed responsibility for the hack.…
Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation
Russian cybersecurity outfit Kaspersky is waving away claims that an iPhone exploit kit recently uncovered by Google was developed by the same people who were behind a group of zero-days that allegedly compromised thousands of Russian diplomats in a 2023 campaign.…
Google feels the need for security speed, so will ship Chrome updates every two weeks
Google will halve the time between releases of its Chrome browser to two weeks, across versions of the software for desktop operating systems, Android, and iOS.…
Dev stunned by $82K Gemini bill after unknown API key thief goes to town
A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours.…
Chat at your own risk! Data brokers are selling deeply personal bot transcripts
Your latest chat transcript could be bought and sold. Data brokers are selling access to sensitive personal data captured during chatbot conversations, despite claims that the data is anonymized and obtained with consent.…
Cyberwarriors elevated to big leagues in US war with Iran
In what may be the most public acknowledgment of its cyber operations capabilities to date, the Pentagon has admitted that cyber soldiers are playing a key role in its attacks on Iran. …
Turns out most cybercriminals are old enough to know better
Contrary to what some believe, cybercrime is not a kids' game. Middle-aged adults, not teenagers, now make up the biggest chunk of people getting busted.…
Until last month, attackers could've stolen info from Perplexity Comet users just by sending a calendar invite
If you wanted to steal local files from someone using Perplexity's Comet browser, until last month you could just schedule the theft by sending your victim a calendar event.…
Chrome Gemini panel became privilege escalator for rogue extensions
Security boffins have discovered a high-severity bug in Google Chrome that allowed malicious extensions to hijack its Gemini Live AI panel and inherit privileges they were never meant to have.…
Cybercriminals swipe 15.8M medical records from French doctors ministry
Around 15.8 million administrative files were stolen after attackers breached a software supplier to France's health ministry.…