Security

Microsoft fixes zero-day flaw exploited by cybercrooks to elevate privileges

Microsoft warns that Windows is affected by a zero-day flaw that hackers are exploiting to deploy ransomware. The patch arrives with the latest monthly security update.
Read more about Microsoft fixes zero-day flaw exploited by cybercrooks to elevate privileges

17,000,000 GrubHub passwords and other data exposed, hackers claim

Attackers claim they have their hands on a whopping 70 million lines of GrubHub’s data, including millions of hashed passwords, phone numbers, and email addresses.
Read more about 17,000,000 GrubHub passwords and other data exposed, hackers claim

Bitwarden thinks rhyming passwords are secure

Redditors on the subreddit r/Bitwarden are debating whether passwords or passphrases that rhyme are less secure.
Read more about Bitwarden thinks rhyming passwords are secure

NASCAR massive data breach claimed by Medusa ransomware, over 1TB allegedly stolen

Medusa ransomware has claimed a massive data breach at NASCAR (The National Association for Stock Car Auto Racing). Hackers have released the organization’s internal file structure and 33 screenshots containing sensitive personal details and documents.
Read more about NASCAR massive data breach claimed by Medusa ransomware, over 1TB allegedly stolen

Biometric recognition systems aren't that safe, Europol says

Biometric technology isn’t without risks and has vulnerabilities that can be used for criminal abuse.
Read more about Biometric recognition systems aren't that safe, Europol says

Court orders Belgian ISPs to block illegal sports streams and IPTV platforms

Belgian internet service providers (ISPs) and public DNS resolver operators must block access to more than 130 pirate sports streaming domains and five illegal IPTV platforms.
Read more about Court orders Belgian ISPs to block illegal sports streams and IPTV platforms

US Treasury bank regulators' emails accessed for years in “major" hacking incident

The US Treasury’s Office of the Comptroller of the Currency (OCC) on Tuesday disclosed to Congress that hackers had access to the email accounts of top federal banking regulators and 150,000 staff emails for over a year.
Read more about US Treasury bank regulators' emails accessed for years in “major" hacking incident

Android affected by critical vulnerabilities: hackers can take control without any interaction

Google has patched severe Android vulnerabilities, some of which could allow attackers to gain control of a device without user interaction or execution privileges. Two zero-day vulnerabilities have already been exploited to unlock phones.
Read more about Android affected by critical vulnerabilities: hackers can take control without any interaction

300K vehicles and millions of trips exposed in fleet manager’s data leak

NexOpt, a vehicle tracking service provider, has leaked sensitive real-time and historic travel data.
Read more about 300K vehicles and millions of trips exposed in fleet manager’s data leak

Cannabis firm LFTD Partners buys $350K worth of USDC, loses it to hackers

LFTD Partners Inc., a publicly traded cannabis and psychedelics company, has fallen victim to digital asset theft after converting a substantial portion of its cash into stablecoin.
Read more about Cannabis firm LFTD Partners buys $350K worth of USDC, loses it to hackers

Hackers on WhatsApp can spoof executables as images or other files

WhatsApp has patched a dangerous spoofing issue that enabled attackers to send executables that appeared to receivers like images, PDFs, or other files.
Read more about Hackers on WhatsApp can spoof executables as images or other files

UMMC facing class action lawsuit for enabling cyberstalking campaign

The University of Maryland Medical Center (UMMC) is being sued by former and current employees over a security breach.
Read more about UMMC facing class action lawsuit for enabling cyberstalking campaign

Apple appealing against UK 'back door' order

Apple is appealing against a British government order to create a "back door" to its encrypted cloud storage systems, the Investigatory Powers Tribunal (IPT) confirmed on Monday.
Read more about Apple appealing against UK 'back door' order

Extremely dangerous malware spreading via YouTube: it comes with a password stealer

These RATs are not after crumbs. They're here for your passwords, crypto, and total control of your systems.
Read more about Extremely dangerous malware spreading via YouTube: it comes with a password stealer

Signalgate: did iPhone contact suggestion lead to national security chaos?

It seems that Jeffrey Goldberg, the editor of the Atlantic, may have Apple to thank for his brief inclusion in a sensitive White House Signal group chat discussing US strikes in Yemen.
Read more about Signalgate: did iPhone contact suggestion lead to national security chaos?

Kellogg discloses data breach, but it's not super cereal

WK Kellogg, the North American cereal giant, has suffered a data breach impacting an unknown number of victims.
Read more about Kellogg discloses data breach, but it's not super cereal

Port of Seattle notifies 90,000 people about data breach

The Port of Seattle has informed approximately 90,000 individuals about a data breach that happened last year.
Read more about Port of Seattle notifies 90,000 people about data breach

AI gone rogue? Unpacking Grok's provocative behaviors

The broader public is wondering what Grok's rebellious side says about both AI innovation and online conduct.
Read more about AI gone rogue? Unpacking Grok's provocative behaviors

Free VPN apps linked to Chinese military: over 70 million downloads

Millions of Americans are using free VPN apps that covertly proxy their traffic through Chinese companies, including several sanctioned firms linked to China’s military, a report by the Tech Transparency Project (TTP) reveals.
Read more about Free VPN apps linked to Chinese military: over 70 million downloads

Hackers use Booking.com scam to hijack hotels

Hotel staff who think they’re confirming a reservation might be booking themselves a front-row seat to a cyberattack instead.
Read more about Hackers use Booking.com scam to hijack hotels