News

IKEA posted on ransomware gang’s leak site

Ransomware cartel Vice Society added data stolen from IKEA Morocco and IKEA Kuwait to the gang’s website.
Read more about IKEA posted on ransomware gang’s leak site

FC Barcelona’s official website exploited for fraud

FC Barcelona, Europe‘s top football club, had its official website used by scammers in a third-party fraud.
Read more about FC Barcelona’s official website exploited for fraud

FBI lends helping hand in Continental breach investigation

The Federal Bureau of Investigations (FBI) has joined an ongoing investigation into a ransomware attack on Continental, a German tire and car parts company. The gang LockBit is behind the breach.
Read more about FBI lends helping hand in Continental breach investigation

RansomExx joins the ranks of ransomware gangs switching to Rust

While switching a programming language might sound trivial, the change indicates cybercriminals are carefully weighing the benefits of the swap.
Read more about RansomExx joins the ranks of ransomware gangs switching to Rust

UK bans Chinese cameras on government sites

The UK has introduced additional controls on sensitive government sites to enhance the security of their personnel, information, assets, and estate.
Read more about UK bans Chinese cameras on government sites

Pro-Kremlin group claims responsibility for cyberattack on EU Parliament

The European Parliament’s website was hit by a cyberattack after it had declared Russia “a state sponsor of terrorism.” The pro-Kremlin group Killnet has since claimed responsibility for the attack.
Read more about Pro-Kremlin group claims responsibility for cyberattack on EU Parliament

Russian zero-day firm offers $1.5m for a Signal RCE exploit

OpZero, a Russian zero-day company, has raised its prices for Signal RCE (remote code execution) exploits so much that it now pays three times more than Zerodium, its closest competitor. Why?
Read more about Russian zero-day firm offers $1.5m for a Signal RCE exploit

AirAsia hack: 5m customer records allegedly stolen

The Daixin ransomware gang claimed AirAsia Group as its victim, stealing data of over five million passengers and employees.
Read more about AirAsia hack: 5m customer records allegedly stolen

Hackers lift $300,000 in DraftKings credential stuffing attack

American sports betting company DraftKings announced on Monday it had suffered a credential stuffing attack that led to customer losses of up to $300,000. The firm soon said it would return money to clients’ accounts.
Read more about Hackers lift $300,000 in DraftKings credential stuffing attack

Threat actors behind Medicare and Medicaid fraud schemes face charges

Ten individuals are charged for their role in money laundering and wire fraud schemes targeting US state and private healthcare programs, which cost victims more than $11.1 million in total losses, the US Department of Justice announced.
Read more about Threat actors behind Medicare and Medicaid fraud schemes face charges

Chinese threat group spoofs Coca-Cola and McDonald’s in sophisticated phishing campaign

A new large-scale phishing campaign with over 42,000 unique domains impersonates popular brands to spread malware, threat intelligence company Cyjax discovered.
Read more about Chinese threat group spoofs Coca-Cola and McDonald’s in sophisticated phishing campaign

Criminals charge $350 for hacking WhatsApp and Viber accounts

Losing confidence in the anonymity offered by cybercrime forums, illicit marketplaces are increasingly turning to Telegram, cybersecurity company Positive Technologies PT said.
Read more about Criminals charge $350 for hacking WhatsApp and Viber accounts

Wickr Me messaging app is shutting down

Wickr opted to ditch its free messaging app Wickr Me and focus on business customers instead.
Read more about Wickr Me messaging app is shutting down

Cybercrime is being commercialized to mimic corporations

Ransomware operators have adopted best business practices, from bug bounties to career pages, from a subscription model to opportunities for entry-level newcomers.
Read more about Cybercrime is being commercialized to mimic corporations

Twitter might finally introduce encrypted DMs

Twitter source code shows that the social network might be introducing a security feature the company’s owner Elon Musk was craving months ago.
Read more about Twitter might finally introduce encrypted DMs

Iran-sponsored actor breached US federal agency

Threat actor penetrated an unnamed US agency exploiting Log4Shell vulnerability in an unpatched VMware Horizon server, the US cybersecurity agency said.
Read more about Iran-sponsored actor breached US federal agency

BreachForums website just had its domain suspended

Hacker marketplace BreachForums had its domain suspended. The website’s predecessor, RaidForums, suffered a similar fate just before being taken down.
Read more about BreachForums website just had its domain suspended

Suffolk police accidentally published victims’ data on its website

Suffolk police force revealed the names, dates of birth, and addresses of hundreds of victims of sexual assault on its website.
Read more about Suffolk police accidentally published victims’ data on its website

Government of Moldova shaken by big hack-and-leak operation

A weird newly-registered website called Moldova Leaks has been releasing damaging private exchanges of at least two prominent political figures in this small Eastern European country. The leaked Telegram conversations have caused a major political scandal.
Read more about Government of Moldova shaken by big hack-and-leak operation

FIFA World Cup apps have privacy experts on edge

Joy for football fans, a nightmare for their data security. The FIFA World Cup in Qatar starts in less than a week, and privacy experts are calling out the event organizers for planning to snoop on the participants’ devices.
Read more about FIFA World Cup apps have privacy experts on edge