News
Apple squashes kernel bug used by TriangleDB spyware
Whoever is infecting people's iPhones with the TriangleDB spyware may be targeting macOS computers with similar malware, according to Kaspersky researchers.…
FTC accuses DNA testing company of lying about dumping samples
The Federal Trade Commission has alleged that genetic testing firm 1Health.io, also known as Vitagene, deceived people when it said it would dispose of their physical DNA sample as well as their collected health data.…
Training in Spanish for cyber security pros
Sponsored Post Cybercrime is a global phenomenon, but the effectiveness of measures put in place to fight it varies considerably from one region to another.…
Oreo cookie maker says crooks gobbled up staff info
Mondelez International has warned 51,000 of its past and present employees that their personal information has been stolen from a law firm hired by the Oreo and Ritz cracker giant.…
Reddit confirms BlackCat gang pinched some data
Reddit this week confirmed ransomware gang BlackCat, aka AlphaV, broke into its corporate systems in February.…
Over 100,000 compromised ChatGPT accounts found for sale on dark web
Singapore-based threat intelligence outfit Group-IB has found ChatGPT credentials in more than 100,000 stealer logs traded on the dark web in the past year.…
Data leak at major law firm sets Australia's government and elites scrambling
An infosec incident at a major Australian law firm has sparked fear among the nation's governments, banks and businesses – and a free speech debate.…
Guess what happened to this US agency using outdated software?
Infosec in brief Remember earlier this year, when we found out that a bunch of baddies including at least one nation-state group broke into a US federal government agency's Microsoft Internet Information Services (IIS) web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution?…
Outsource to infill on cyber security
Sponsored Feature Life is tougher than ever for security pros facing a rising tide of cyberattacks. And adversaries are becoming more adept than ever at using diverse methods and technologies to scale up assaults on their selected targets.…
With dead-time dump, Microsoft revealed DDoS as cause of cloud outages
In the murky world of political and corporate spin, announcing bad news on Friday afternoon – a time when few media outlets are watching, and audiences are at a low ebb – is called "taking out the trash." And that’s what Microsoft appears to have done last Friday.…
Third MOVEit bug fixed a day after PoC exploit made public
Progress Software on Friday issued a fix for a third critical bug in its MOVEit file transfer suite, a vulnerability that had just been disclosed the day earlier.…
LockBit suspect's arrest sheds more light on 'trustworthy' gang
FBI agents have arrested a Russian man suspected of being part of the Lockbit ransomware gang. An unsealed complaint alleges the 20-year-old was an Apple fanboy, an online gambler, and scored 80 percent of at least one ransom payment given to the criminals.…
Capita faces first legal Letter of Claim over mega breach
Capita is facing its first legal claim over the high profile digital burglary in late March that exposed some customer data to intruders and will cost the outsourcing biz around £20 million ($26 million) to clean up.…
Microsoft: Russia sent its B team to wipe Ukrainian hard drives
Here's a curious tale about a highly destructive yet flaky Kremlin-backed crew that was active during the early days of Russia's invasion of Ukraine, then went relatively quiet – until this year.…
EU boss Breton: There's no Huawei that Chinese comms kit is safe to use in Europe
European commissioner Thierry Breton wants Huawei and ZTE barred throughout the EU, and revealed plans to remove kit made by the Chinese telecom vendors from the Commission's internal networks.…
US government hit by Russia's Clop in MOVEit mass attack
The US Department of Energy and other federal bodies are among a growing list of organizations hit by Russians exploiting the MOVEit file-transfer vulnerability.…
Chinese spies blamed for data-harvesting raids on Barracuda email gateways
Chinese spies are behind the data-stealing malware injected into Barracuda's Email Security Gateway (ESG) devices globally as far back as October 2022, according to Mandiant.…
North Korea created very phishy evil twin of Naver, South Korea's top portal
North Korea has created a fake version of South Korea's largest internet portal, Naver, in a large scale phishing attempt, Seoul's National Intelligence Service (NIS) said on Wednesday.…
Decision to hold women-in-cyber events in abortion-banning states sparks outcry
Global nonprofit Women in Cybersecurity (WiCyS), despite months of controversy over the cities named to host its 2024 and 2025 conferences, says it will move forward as planned with the events in Nashville, Tennessee, and Dallas, Texas, respectively.…
LockBit victims in the US alone paid over $90m in ransoms since 2020
Seven nations today issued an alert, plus protection tips, about LockBit, the prolific ransomware-as-a-service gang.…
Pages
