Security

Invasion of the infostealers: meet the malware stealing your cookies

Threat actors are leveraging a new tactic to help them access your credentials without knowing them already or launching a multi-factor authentication challenge.
Read more about Invasion of the infostealers: meet the malware stealing your cookies

Rent Go exposes over 160K customer passports, driver’s licenses

The Turkey-based car rental service left an open Azure Blob Storage, revealing hundreds of thousands of document images that customers submitted to use the company’s service.
Read more about Rent Go exposes over 160K customer passports, driver’s licenses

Shopify plugins leaked data from nearly 2K stores

A vast amount of sensitive data of unsuspecting shoppers was exposed to threat actors by the e-commerce giant’s plugin developer, with millions of orders being leaked.
Read more about Shopify plugins leaked data from nearly 2K stores

Privacy consultant convicted of cyberstalking

A federal jury has convicted a former computer privacy consultant from Seattle for a cyberstalking campaign threatening sexual assault and other violence against multiple victims.
Read more about Privacy consultant convicted of cyberstalking

Alarming: researchers can fingerprint and block eight out of ten top VPN providers

OpenVPN, a widely used open-source VPN software for secure and private connections, can “be reliably detected and blocked at scale by network-based adversaries,” research has found.
Read more about Alarming: researchers can fingerprint and block eight out of ten top VPN providers

M-series Macs can leak secrets due to inherent vulnerability

A feature that makes Apple M-series processors faster also leaves them vulnerable to a new side-channel attack that cannot be patched, according to research. Hackers, in theory, could extract secret encryption keys and then access sensitive data.
Read more about M-series Macs can leak secrets due to inherent vulnerability

Millions of hotel doors vulnerable to attack, researchers find

Security researchers have discovered vulnerabilities in dormakaba’s Saflok electronic locks, which would allow hackers access to rooms and residences in a matter of seconds.
Read more about Millions of hotel doors vulnerable to attack, researchers find

Russia unleashes dangerous new wiper

Russia is using a new malware variant with expanded capabilities to target Ukrainian telecommunication networks, cybersecurity threat intelligence platform SentinelLabs has discovered. The launch coincides with enduring disruptions experienced by the country’s internet service providers (ISPs).
Read more about Russia unleashes dangerous new wiper

Anti-scam firm exposes OpenAI API key

Certy AI’s anti-scam moderation system left an exposed environment file and revealed sensitive information such as its OpenAI API key, Cybernews researchers have discovered.
Read more about Anti-scam firm exposes OpenAI API key

North Korean hackers use “nuclear lure” to trick and run new attack

North Korea’s nuclear threats are now being exploited by North Korean hackers known as Kimsuky as a lure for victims to open malicious payloads. Here’s how the threat actor updated their playbook.
Read more about North Korean hackers use “nuclear lure” to trick and run new attack

US officials warn of hackers disrupting the “critical lifeline” of drinking water

China and Iran-linked threat actors are targeting water and wastewater systems throughout the United States. Cyberattacks on infrastructure can disrupt “the critical lifeline of clean and safe drinking water, as well as impose significant costs on affected communities,” officials from the Environmental Protection Agency (EPA) and the White House have warned.
Read more about US officials warn of hackers disrupting the “critical lifeline” of drinking water

Famous Indian brands exposed in massive marketing firm data leak

Customers of Swiggy, Redbus, Nykaa, BigBasket, TataMotors, ICICIPruLife, Axis Direct, and other brands in India have been put at risk. Cybersecurity neglect resulted in a tremendous amount of their personal data being exposed.
Read more about Famous Indian brands exposed in massive marketing firm data leak

Keyboard strokes may reveal your password – research

Keyboard keystroke sounds can be exploited to reveal sensitive user data. For example, it can reveal text that users are typing into a password box.
Read more about Keyboard strokes may reveal your password – research

US vs TikTok: could VPNs be the answer

TikTok faces a total ban from the US market after the company was told to sever ties with Chinese owner ByteDance.
Read more about US vs TikTok: could VPNs be the answer

Most UK orgs vulnerable to attacks – Microsoft

A large majority of UK organizations are entering the age of artificial intelligence but are woefully unprepared for new attack vectors that AI provides.
Read more about Most UK orgs vulnerable to attacks – Microsoft

TV company exposes over 100K records

Zapping.com, a Chilean online television company, has leaked sensitive data.
Read more about TV company exposes over 100K records

Another English city, another cyberattack, British gov to blame say critics

A British National Security report warns of ‘a catastrophic ransomware attack that could take down the government at any moment – this as another English city authority struggles to recover after a week-long cyberattack.
Read more about Another English city, another cyberattack, British gov to blame say critics

Data leak at Spanish home rental service exposes three million customers

Privacy in a countryside getaway is no longer a guarantee. Escapada Rural, a local Spanish short-term rental service akin to Airbnb, left large amounts of private customer data exposed for half a year. Hackers got hold of the data and posted it on BreachForums, an illicit marketplace.
Read more about Data leak at Spanish home rental service exposes three million customers

Massive data leak in Irish Health Service Executive uncovered

The Health Service Executive (HSE) in Ireland accidentally exposed the private information of an estimated one million citizens in December 2021, a researcher has shared. The leak happened seven months after a major ransomware attack on the same organization.
Read more about Massive data leak in Irish Health Service Executive uncovered

Financial company leaks user passports

IKF Finance, an Indian non-banking finance company, leaked over three terabytes of sensitive customer and employee data, potentially exposing its entire user base.
Read more about Financial company leaks user passports