Security

WiHD leak exposes details of all torrent users

World-in-HD, a French private video torrent community, left an open instance exposing the emails and passwords of all of its users and administrators.
Read more about WiHD leak exposes details of all torrent users

Massive DDoS attacks are the new normal

DDoS attackers shattered previous records with never-before-seen malicious activity during the third quarter. The 89 reported DDoS attacks bombarded Cloudflare’s servers with more than 100 million requests each second. The previous all-time high was below 71 million.
Read more about Massive DDoS attacks are the new normal

Microsoft: English-speaking ransom gang issuing death threats

Microsoft has detected a threat actor linked to the gang that recently launched high-profile cyberattacks on casinos in Las Vegas.
Read more about Microsoft: English-speaking ransom gang issuing death threats

Hello Alfred app exposes user data

Hello Alfred, an in-home hospitality app, left a database accessible without password protection, exposing almost 170,000 records containing private user data.
Read more about Hello Alfred app exposes user data

New England Biolabs leak sensitive data

Leaving environment files open to the public is one of the simplest mistakes that web admins can make, but it can have disastrous consequences. Despite leaving some of its sensitive credentials exposed, New England Biolabs seems to have dodged a bullet.
Read more about New England Biolabs leak sensitive data

International Criminal Court investigating “unprecedented” cyberattack

The International Criminal Court (ICC) has fallen victim to a sophisticated cyberattack, suspected to be an espionage operation.
Read more about International Criminal Court investigating “unprecedented” cyberattack

One app, two accounts: new WhatsApp feature raises security concern

WhatsApp will allow users to juggle two accounts at the same time, potentially eliminating the need to have separate phones for work and personal use. However, this is also a security risk, experts warn.
Read more about One app, two accounts: new WhatsApp feature raises security concern

Deepfaked African Union chief called European leaders

Threat actors used artificial intelligence to impersonate African Union Commission Chairperson Moussa Faki and place calls with various European leaders.
Read more about Deepfaked African Union chief called European leaders

I tried to revoke all Android app permissions but it was impossible

I tried to take complete control of all the apps and their permissions on my Android device, but I had to give up. Despite revoking all user-available permissions, apps can still run on startup, stay in the background, have full network access, access sensitive information, and use hardware. So, what can you do?
Read more about I tried to revoke all Android app permissions but it was impossible

Californian IT company leaks private mobile phone data

Hundreds of thousands of clients who opted-in for a screen warranty were exposed when DNA Micro leaked data from its systems.
Read more about Californian IT company leaks private mobile phone data

FTC warning: no crypto is FDIC insured, period

Authorities have issued a stern reminder following recent false advertising by some crypto companies: funds deposited with a crypto-based financial services provider will never be insured by the Federal Deposit Insurance Corporation (FDIC).
Read more about FTC warning: no crypto is FDIC insured, period

Don’t call it quishing: QR code phishing on the rise

There’s a new trend emerging in cybercrime, AT&T warns – embedding malicious QR codes into phishing attempts. The attack has been dubbed “quishing,” but the term isn’t getting any love among the cybersecurity community on Reddit.
Read more about Don’t call it quishing: QR code phishing on the rise

LinkedIn smart links leveraged in credential phishing campaign

Attackers are on the hunt for Microsoft Office logins. A recent phishing campaign is leveraging newly created or compromised LinkedIn business accounts.
Read more about LinkedIn smart links leveraged in credential phishing campaign

Facebook copyright scam intensifies, users left stranded

16
The Facebook copyright infringement scam appears to have intensified, with users reporting being locked out of their accounts with little help from the Meta-owned social media platform to restore their access.
Read more about Facebook copyright scam intensifies, users left stranded

Telegram, AWS users targeted by hidden malware code

Telegram, AWS, and Alibaba Cloud users are being targeted by a fresh malware campaign that strategically buries malicious code within specific software functions to make it harder to detect.
Read more about Telegram, AWS users targeted by hidden malware code

Europol scrutinized hundreds of platforms and devices for human trafficking

In the Netherlands, 85 law enforcement investigators from 26 countries coordinated a three-day-long operational action targeting online criminal activities that enable human trafficking. That led to 371 platforms being checked, including social media and dating platforms, web forums, marketplaces, and online applications.
Read more about Europol scrutinized hundreds of platforms and devices for human trafficking

Air Canada responds to BianLian ransom attack claims

Air Canada responds to Wednesday’s claims by the BianLian ransomware group that it was responsible for a September breach of the airline – and to have stolen more than 200 GB of data from the carrier on its dark leak site.
Read more about Air Canada responds to BianLian ransom attack claims

Android financial apps too greedy for permissions

Android apps usually require excessive permissions. But financial apps go a step further into dangerous territory, asking for even more access and posing heightened risks to privacy and security, a Cybernews research team investigation into 50 apps reveals.
Read more about Android financial apps too greedy for permissions

Space cybersecurity takes center stage in Estonia

By 2040, the global space industry could be worth as much as one trillion dollars. Securing space-based systems is crucial.
Read more about Space cybersecurity takes center stage in Estonia

Air Europa cyberattack leaks credit card data

Spain’s Air Europa has fallen victim to a cyberattack on its payment system exposing some customer credit card information.
Read more about Air Europa cyberattack leaks credit card data