Security

Microsoft alerts CyberLink to North Korean threat

Microsoft has alerted software company CyberLink to the misuse of its software by North Korean group Diamond Sleet.
Read more about Microsoft alerts CyberLink to North Korean threat

Thousands of exposed gas pumps invite cyberwarriors

Exposed gas pump controllers may tempt attackers to try and create fuel shortages. Worryingly, there are thousands of unprotected controllers worldwide, with the potential to impact millions.
Read more about Thousands of exposed gas pumps invite cyberwarriors

MacOS targeted by ClearFake malware campaign

A data-stealing program that targets Mac operating systems (OS) is being distributed to unsuspecting targets by means of fake web browser updates.
Read more about MacOS targeted by ClearFake malware campaign

Enterprise software provider Tmax leaks 2TB of data

A Korean IT company developing and selling enterprise software has leaked over 50 million sensitive records.
Read more about Enterprise software provider Tmax leaks 2TB of data

Best botnet ad? An attack on OpenAI

Anonymous Sudan supposedly hit ChatGPT at almost the same time it introduced a new botnet. Experts say the gang is commercializing to enhance operational resources.
Read more about Best botnet ad? An attack on OpenAI

Hive reborn: new ransomware group emerges from the ashes

Hive, one of the world’s most dangerous ransomware groups, disappeared from the scene after being infiltrated by the FBI. Hunters International, a new kid on the block using similar code, has recently emerged in its place. However, the gang claims to be unrelated.
Read more about Hive reborn: new ransomware group emerges from the ashes

Vietnam Post exposes 1.2TB of data, including email addresses

Vietnam Post Corporation, a Vietnamese government-owned postal service, left its security logs and employee email addresses accessible to outside cyber snoopers, Cybernews researchers have discovered. The exposed sensitive data could spell trouble if accessed by malicious actors.
Read more about Vietnam Post exposes 1.2TB of data, including email addresses

Hacking the sky: planes need patching, too – interview

Cyber assaults on the aviation sector carry more serious repercussions than mere data theft or DDoS attacks.
Read more about Hacking the sky: planes need patching, too – interview

San Francisco’s transport agency exposes drivers’ parking permits and addresses

A misconfiguration in the Metropolitan Transportation Commission (MTC) systems caused a leak of over 26K files, exposing clients’ parking permits and home addresses.
Read more about San Francisco’s transport agency exposes drivers’ parking permits and addresses

Over 3,000 apps leak Twitter API keys

Threat actors could use API keys to access or take over Twitter accounts.
Read more about Over 3,000 apps leak Twitter API keys

US lawmakers to crackdown on Feds buying and using Chinese-made drones

Top lawmakers have introduced two new measures aimed at stopping the US government from purchasing and operating drones made by China and other foreign adversaries with taxpayer funds.
Read more about US lawmakers to crackdown on Feds buying and using Chinese-made drones

Digital payment apps Paypal, Venmo, CashApp could soon be regulated like banks

The US Consumer Financial Protection Bureau (CFPB) wants to regulate all payment apps and digital wallets – such as Apple Pay, CashApp, Google Wallet, and Venmo – just as it would any other financial institution.
Read more about Digital payment apps Paypal, Venmo, CashApp could soon be regulated like banks

Experiment: anti-Pegasus box to keep spies away from my home

3
Journalists, activists, or minorities around the globe who are targeted by governments using high-tech spyware such as Pegasus have limited means to protect themselves. After recent revelations that ad networks are being utilized for spying and delivering payloads, one helpful solution could be DNS filtering, known as a Pi-Hole. Is it hard to set up, and how useful is it?
Read more about Experiment: anti-Pegasus box to keep spies away from my home

NSA forms central AI security hub

The US National Security Agency (NSA) will create a new AI Security Center to integrate AI technology with national defense, and maintain its edge among world powers.
Read more about NSA forms central AI security hub

Lithuania’s cyber chief unimpressed: attacks against NATO were PR stunts

Cybercriminals had promised to fight against the “doomsday clock” of world catastrophe, yet the NATO summit in Lithuania was uneventful from a cybersecurity standpoint
Read more about Lithuania’s cyber chief unimpressed: attacks against NATO were PR stunts

LockBit ransom gang behind mass exploitation of Citrix bug, researchers say

Security researchers are blaming a now-patched Citrix zero-day vulnerability for a recent spate of November ransomware attacks, said to be carried out by the notorious LockBit gang – and warn more are coming.
Read more about LockBit ransom gang behind mass exploitation of Citrix bug, researchers say

Gamblers’ data compromised after casino giant fails to set password

One of the biggest online casinos in Mexico has exposed sensitive user data, including home addresses and the amounts of money they spent on gambling. The data was likely compromised by unauthorized actors.
Read more about Gamblers’ data compromised after casino giant fails to set password

New malvertising campaign targets Windows geeks

A threat actor copied a legitimate Windows news website to deliver an infostealer for the CPU-Z processor tool.
Read more about New malvertising campaign targets Windows geeks

Data of 800K Chess.com players scraped and released

The most popular platform for chess players, Chess.com, has had some of its user data leaked in a fresh scraping attempt.
Read more about Data of 800K Chess.com players scraped and released

Allen & Overy law firm breached, LockBit takes credit

Top global law firm Allen & Overy (A&O) said some of its systems have been impacted due to a “data incident” claimed by the LockBit ransomware group.
Read more about Allen & Overy law firm breached, LockBit takes credit