Security

Massive research into iOS apps uncovers widespread secret leaks, abysmal coding practices

1
Most apps on Apple’s App Store seem to leak at least one hard-coded secret. Many high-sensitivity secrets were found, including keys to cloud storage, various APIs, and even payment processors. Some endpoints are left completely unprotected, putting users at risk.
Read more about Massive research into iOS apps uncovers widespread secret leaks, abysmal coding practices

How Apple App Store apps can expose your data: hard-coded secrets explained

Your data can be exposed to bad actors because of poor programming practices.
Read more about How Apple App Store apps can expose your data: hard-coded secrets explained

How do malicious apps end up on official app stores?

While you may think that downloading apps from official app stores is entirely secure, you can still catch malware that will steal your private data.
Read more about How do malicious apps end up on official app stores?

Multiple vulnerabilities in Mozilla products could put governments and businesses at risk

Mozilla has patched multiple vulnerabilities that could have enabled attackers to hijack user devices.
Read more about Multiple vulnerabilities in Mozilla products could put governments and businesses at risk

Jaguar Land Rover’s source code, tracking data leaked, attackers claim

Britain’s luxury car maker Jaguar Land Rover (JLR) allegedly has had its tracking data, source code, and employee details stolen and leaked.
Read more about Jaguar Land Rover’s source code, tracking data leaked, attackers claim

Critical Apple vulnerability enables “extremely sophisticated” attacks

Apple has urgently patched a zero-day vulnerability in WebKit, the engine powering the Safari web browser and many other apps.
Read more about Critical Apple vulnerability enables “extremely sophisticated” attacks

Russian YouTubers blackmailed into spreading crypto miner

“A massive malware campaign” has been uncovered, with Russian YouTubers being forced to spread crypto-mining malware.
Read more about Russian YouTubers blackmailed into spreading crypto miner

Google coughed up $12M in bug bounties in 2024

Google’s Vulnerability Reward Program paid $11.8 million to the security research community last year to make the company and its products safer.
Read more about Google coughed up $12M in bug bounties in 2024

“Script kiddie” hackers behind Dark Storm cyberattack on Musk's X, security researcher says

A French security researcher on Tuesday claims to have uncovered the identity of the Dark Storm hacker behind the hours-long DDoS cyberattack on Elon Musk’s X social media platform – and it looks as if an Egyptian college student was behind the entire operation.
Read more about “Script kiddie” hackers behind Dark Storm cyberattack on Musk's X, security researcher says

Government leaks nearly two million citizens’ documents

India’s Ministry of Housing and Urban Affairs left an open AWS bucket revealing nearly two million IDs, bank statements, and other files with sensitive citizens’ data.
Read more about Government leaks nearly two million citizens’ documents

Rackspace files allegedly published by Cl0p ransom gang

The Cl0p ransomware gang on Monday claims to have published a slew of files belonging to US-based cloud storage company Rackspace Technology.
Read more about Rackspace files allegedly published by Cl0p ransom gang

Fraudulent DocuSign email seeks to steal credentials

Nearly unstoppable phishing sites are tricking victims into giving access to their corporate networks.
Read more about Fraudulent DocuSign email seeks to steal credentials

Web cameras behind latest ransomware, DDoS incidents serving hackers a launchpad

A series of recent reports have highlighted web and IP cameras as key enablers of devastating cyberattacks, acting as springboards for hackers to deploy malware.
Read more about Web cameras behind latest ransomware, DDoS incidents serving hackers a launchpad

Switzerland mandates 24-hour cyberattack reporting for critical sector

In view of the “increasing threat of cyber incidents,” Switzerland is aiming to bolster cybersecurity defenses by introducing a reporting obligation for cyberattacks on critical infrastructure, effective April 1st.
Read more about Switzerland mandates 24-hour cyberattack reporting for critical sector

A hacker’s ideology on censorship, political social engineering, and Anonymous

Since hackers saw their first dawn in the digital age, we have always fought in various ways to secure and preserve freedom of speech and the free flow of information.
Read more about A hacker’s ideology on censorship, political social engineering, and Anonymous

Hack your way into a paycheck with OSINT skills

Cybersecurity and IT roles within the industry are largely regulated through training and certification courses. Getting certified not only proves you've trained but also that you possess enough knowledge to pass the required exam.
Read more about Hack your way into a paycheck with OSINT skills

Critical bug turns Kibana into potential malware host

Software giant Elastic rolled out security updates, warning users of a critical vulnerability in Kibana’s data visualization dashboard.
Read more about Critical bug turns Kibana into potential malware host

“Free” movie streams expose a million pirates to malware and data theft

Illegal streaming site users risk being infected with dangerous malware and losing all their data, crypto, and accounts, the Microsoft Threat Intelligence team warns. While pirates watch videos, a chain of events unfolds behind the scenes, leading to info stealers being downloaded from GitHub, Discord, or Dropbox.
Read more about “Free” movie streams expose a million pirates to malware and data theft

BianLian ransomware wanna-bes are targeting business execs using the actual mail, FBI says

In a ransomware first, threat actors claiming to be from the BianLian ransomware gang have been found using the regular US postal service to try and extort money from corporate executives, the FBI warned on Thursday.
Read more about BianLian ransomware wanna-bes are targeting business execs using the actual mail, FBI says

Telegram Android flaw enables hackers to disguise malware as videos

Attackers on Telegram are disguising malicious scripts as videos and tricking users into running them. Accidental clicking will leak some user data and may lead to forced malicious app installations.
Read more about Telegram Android flaw enables hackers to disguise malware as videos