Security
Dolly.com pays ransom, attackers release data anyway
Dolly.com, an on-demand moving and delivery platform, allegedly paid attackers not to publish stolen customer data.
Read more about Dolly.com pays ransom, attackers release data anyway
Google, Meta, Microsoft to join forces defending apps from hackers
The tech giants have formally partnered to improve app security across ecosystems under a newly formed structure.
Read more about Google, Meta, Microsoft to join forces defending apps from hackers
Marina Bay Sands Singapore luxury resort breached
Singapore’s iconic resort and casino Marina Bay Sands stated that the personal information of its loyalty members was found compromised in a recent data security incident.
Read more about Marina Bay Sands Singapore luxury resort breached
TikTok lagging behind rivals like Facebook in security
A new study shows TikTok trailing behind rival platforms in terms of security while Facebook and YouTube lead the way.
Read more about TikTok lagging behind rivals like Facebook in security
Kim’s cyber army has a new malware toy targeting Apple devices
BlueNorOff, a cybercrime group from North Korea, was found to be using a new, fairly simple yet very functional malware that helps attackers commit financial crimes targeting MacOS, the latest Jamf research has revealed.
Read more about Kim’s cyber army has a new malware toy targeting Apple devices
Royal Mail jeopardizes users with open redirect flaw
The British postal service and courier company has left an open redirect vulnerability on one of its sites, exposing its customers to phishing attacks and malware infections.
Read more about Royal Mail jeopardizes users with open redirect flaw
Sensitive military personnel data available for just a few cents online, research finds
Data brokers, feeding online advertising businesses, can easily obtain and sell sensitive military personnel data for as low as $0.12 per record, posing a risk to US national security, a study from Duke University has found. Researchers were able to buy thousands of records with details on health, credit, gambling, and religion, together with contacts.
Read more about Sensitive military personnel data available for just a few cents online, research finds
Headhunt for 4 million cybersecurity pros: current shortage is largest ever
The gap between the demand for cybersecurity professionals and their availability has widened to unprecedented levels, says a new report. The number of new cyber pros would need to nearly double to close it, and the existing workforce lacks competence.
Read more about Headhunt for 4 million cybersecurity pros: current shortage is largest ever
Boeing back on LockBit ransom list after confirming cyber incident
In another twist to the alleged Boeing ransomware attack, the global aerospace technology and defense contractor was put back on LockBit’s victim leak site Thursday – and then taken off again barely an hour later.
Read more about Boeing back on LockBit ransom list after confirming cyber incident
Enter the Puma: phishing link-shortening gang caught in the wild
A threat group believed to be from Ukraine went undetected for years, selling URL link-shortening services to other cybercriminals to help facilitate their malicious activities.
Read more about Enter the Puma: phishing link-shortening gang caught in the wild
Forty countries to pledge: no ransoms for cybercriminals
A US-led alliance of forty countries has committed to signing a pledge to never pay ransoms, leaving cybercriminals without one of their main funding mechanisms, according to a senior White House official.
Read more about Forty countries to pledge: no ransoms for cybercriminals
WiHD leak exposes details of all torrent users
World-in-HD, a French private video torrent community, left an open instance exposing the emails and passwords of all of its users and administrators.
Read more about WiHD leak exposes details of all torrent users
Massive DDoS attacks are the new normal
DDoS attackers shattered previous records with never-before-seen malicious activity during the third quarter. The 89 reported DDoS attacks bombarded Cloudflare’s servers with more than 100 million requests each second. The previous all-time high was below 71 million.
Read more about Massive DDoS attacks are the new normal
Microsoft: English-speaking ransom gang issuing death threats
Microsoft has detected a threat actor linked to the gang that recently launched high-profile cyberattacks on casinos in Las Vegas.
Read more about Microsoft: English-speaking ransom gang issuing death threats
Hello Alfred app exposes user data
Hello Alfred, an in-home hospitality app, left a database accessible without password protection, exposing almost 170,000 records containing private user data.
Read more about Hello Alfred app exposes user data
New England Biolabs leak sensitive data
Leaving environment files open to the public is one of the simplest mistakes that web admins can make, but it can have disastrous consequences. Despite leaving some of its sensitive credentials exposed, New England Biolabs seems to have dodged a bullet.
Read more about New England Biolabs leak sensitive data
International Criminal Court investigating “unprecedented” cyberattack
The International Criminal Court (ICC) has fallen victim to a sophisticated cyberattack, suspected to be an espionage operation.
Read more about International Criminal Court investigating “unprecedented” cyberattack
One app, two accounts: new WhatsApp feature raises security concern
WhatsApp will allow users to juggle two accounts at the same time, potentially eliminating the need to have separate phones for work and personal use. However, this is also a security risk, experts warn.
Read more about One app, two accounts: new WhatsApp feature raises security concern
Deepfaked African Union chief called European leaders
Threat actors used artificial intelligence to impersonate African Union Commission Chairperson Moussa Faki and place calls with various European leaders.
Read more about Deepfaked African Union chief called European leaders
I tried to revoke all Android app permissions but it was impossible
I tried to take complete control of all the apps and their permissions on my Android device, but I had to give up. Despite revoking all user-available permissions, apps can still run on startup, stay in the background, have full network access, access sensitive information, and use hardware. So, what can you do?
Read more about I tried to revoke all Android app permissions but it was impossible