Security

Major leak exposes users from Russian crypto exchanges

Customers at nine crypto exchanges in Russia have had their anonymity shattered, with private user data being exposed for more than two months now, the Cybernews Research team has discovered.
Read more about Major leak exposes users from Russian crypto exchanges

Attackers prey on leaked crypto leads

While crypto leads are essential for businesses, attackers may use leaked crypto-related data to perform a variety of attacks.
Read more about Attackers prey on leaked crypto leads

Dubai’s largest taxi app exposes 220K+ users

The Dubai Taxi Company (DTC) app, which provides taxi, limousine, and other transport services, left a database open to the public, exposing sensitive customer and driver data.
Read more about Dubai’s largest taxi app exposes 220K+ users

Leaked nudes emerging as top cyber risk of 2024

Dark web forums are abuzz with discussions centering around nude images and videos leaked from platforms like OnlyFans and Instagram.
Read more about Leaked nudes emerging as top cyber risk of 2024

Android barcode scanner app exposes user passwords

An Android app with over 100k Google Play downloads and a 4.5-star average rating has let an open instance go unchecked, leaving sensitive user data up for grabs.
Read more about Android barcode scanner app exposes user passwords

Green Card Lottery agency exposes applicants’ data

Thousands of applicants for the Diversity Immigrant Visa Program, widely known as Green Card Lottery, got their private data leaked by the US GREEN CARD OFFICE LIMITED (USGCO), a limited liability company registered in the UK that helps to prepare the documents, the Cybernews research team has found.
Read more about Green Card Lottery agency exposes applicants’ data

Adobe’s InDesign exploited in new wave of phishing attacks

Hackers are getting creative, literally, by utilizing Adobe’s popular graphic design program, InDesign, to target corporations in the latest surge of phishing attacks, new research shows.
Read more about Adobe’s InDesign exploited in new wave of phishing attacks

Beware: predatory Android loan apps spy, harass, and blackmail users

Deceptive loan apps charging excessive interest rates can also be malicious. SpyLoan apps circumvent Google Play requirements to track their users’ data and then use it to blackmail them.
Read more about Beware: predatory Android loan apps spy, harass, and blackmail users

GST Invoice Billing Inventory exposes sensitive data to threat actors

A business accounting app for small and medium businesses with over 1M downloads has left a database open, exposing sensitive personal and corporate data up for grabs.
Read more about GST Invoice Billing Inventory exposes sensitive data to threat actors

Russian state-sponsored hackers exploiting Outlook vulnerability, Microsoft warns

Microsoft is urging Outlook users to patch and update their systems to mitigate a new threat from Russia. Hackers associated with the Kremlin’s military intelligence agency GRU are exploiting the vulnerability to access victim’s emails.
Read more about Russian state-sponsored hackers exploiting Outlook vulnerability, Microsoft warns

The future of phone scams: bots that sound like your loved ones

Every fifth unknown call in the US is spam. Despite a meager success rate, millions fall victim to fraudsters due to the sheer volume of attempts. Now, scammers have a dangerous new innovation that will make them even more productive and convincing.
Read more about The future of phone scams: bots that sound like your loved ones

Bluetooth connections no longer private with new BLUFFS attacks

Bluetooth, a low-power wireless technology connecting our devices, has a new vulnerability to iron out. Attackers in the middle could easily snoop on your communications using a new BLUFFS attack.
Read more about Bluetooth connections no longer private with new BLUFFS attacks

Hacktivism and its impacts on mental health

I get it. Like me, you’re wired in. Maybe your vice is social media or gaming. Perhaps you’re an Infosec researcher, or a hacker, or OSINT investigator. Whatever your function is, what began as a romance with technology ultimately evolves into a bitter love/hate relationship, taking a toll on your emotions and your overall psychological well-being.
Read more about Hacktivism and its impacts on mental health

Fortune-telling website exposes 13M+ user records

WeMystic, a website on astrology, numerology, tarot, and spiritual orientation, left an open database exposing 34GB of sensitive data about the platforms' users.
Read more about Fortune-telling website exposes 13M+ user records

Russia-linked Black Basta ransomware has extorted at least $100 million

Black Basta, which is believed to be a faction of the notorious Russian Conti ransomware gang, has raked in at least $107 million in Bitcoin ransom payments since its inception in early 2022, joint research by Elliptic and Corvus Insurance has revealed.
Read more about Russia-linked Black Basta ransomware has extorted at least $100 million

Digital wallets and the rise of the identity trojan

Just when we thought it was safe to open our wallets, here comes the identity trojan.
Read more about Digital wallets and the rise of the identity trojan

KidSecurity’s user data compromised after app failed to set password

KidSecurity, a popular parental control app that’s used to track children, has exposed its activity logs, leaving users' private data in the hands of threat actors.
Read more about KidSecurity’s user data compromised after app failed to set password

Pennsylvania water facility hit by Iranian hackers

CISA warns an Iranian hacktivist group targeting water and energy facilities in Israel has now attacked the water authority of two townships in Pennsylvania over the weekend by compromising industrial control devices that are made in Israel.
Read more about Pennsylvania water facility hit by Iranian hackers

Thousands of secrets lurk in app images on Docker Hub

Thousands of secrets have been left exposed on Docker Hub, a platform where web developers collaborate on their code for web applications. While some are harmless API keys, others could lead to unauthorized access, data breaches, or identity theft, the latest Cybernews research reveals.
Read more about Thousands of secrets lurk in app images on Docker Hub

Almost two million affected by data company Zeroed-In Technologies breach

HR data analytics company Zeroed-In Technologies was hacked in August this year. Three months after discovering the breach, the firm has now notified Maine’s authorities, saying that the data of nearly two million people was exposed.
Read more about Almost two million affected by data company Zeroed-In Technologies breach