Security

Californian IT company leaks private mobile phone data

Hundreds of thousands of clients who opted-in for a screen warranty were exposed when DNA Micro leaked data from its systems.
Read more about Californian IT company leaks private mobile phone data

FTC warning: no crypto is FDIC insured, period

Authorities have issued a stern reminder following recent false advertising by some crypto companies: funds deposited with a crypto-based financial services provider will never be insured by the Federal Deposit Insurance Corporation (FDIC).
Read more about FTC warning: no crypto is FDIC insured, period

Don’t call it quishing: QR code phishing on the rise

There’s a new trend emerging in cybercrime, AT&T warns – embedding malicious QR codes into phishing attempts. The attack has been dubbed “quishing,” but the term isn’t getting any love among the cybersecurity community on Reddit.
Read more about Don’t call it quishing: QR code phishing on the rise

LinkedIn smart links leveraged in credential phishing campaign

Attackers are on the hunt for Microsoft Office logins. A recent phishing campaign is leveraging newly created or compromised LinkedIn business accounts.
Read more about LinkedIn smart links leveraged in credential phishing campaign

Facebook copyright scam intensifies, users left stranded

16
The Facebook copyright infringement scam appears to have intensified, with users reporting being locked out of their accounts with little help from the Meta-owned social media platform to restore their access.
Read more about Facebook copyright scam intensifies, users left stranded

Telegram, AWS users targeted by hidden malware code

Telegram, AWS, and Alibaba Cloud users are being targeted by a fresh malware campaign that strategically buries malicious code within specific software functions to make it harder to detect.
Read more about Telegram, AWS users targeted by hidden malware code

Europol scrutinized hundreds of platforms and devices for human trafficking

In the Netherlands, 85 law enforcement investigators from 26 countries coordinated a three-day-long operational action targeting online criminal activities that enable human trafficking. That led to 371 platforms being checked, including social media and dating platforms, web forums, marketplaces, and online applications.
Read more about Europol scrutinized hundreds of platforms and devices for human trafficking

Air Canada responds to BianLian ransom attack claims

Air Canada responds to Wednesday’s claims by the BianLian ransomware group that it was responsible for a September breach of the airline – and to have stolen more than 200 GB of data from the carrier on its dark leak site.
Read more about Air Canada responds to BianLian ransom attack claims

Android financial apps too greedy for permissions

Android apps usually require excessive permissions. But financial apps go a step further into dangerous territory, asking for even more access and posing heightened risks to privacy and security, a Cybernews research team investigation into 50 apps reveals.
Read more about Android financial apps too greedy for permissions

Space cybersecurity takes center stage in Estonia

By 2040, the global space industry could be worth as much as one trillion dollars. Securing space-based systems is crucial.
Read more about Space cybersecurity takes center stage in Estonia

Air Europa cyberattack leaks credit card data

Spain’s Air Europa has fallen victim to a cyberattack on its payment system exposing some customer credit card information.
Read more about Air Europa cyberattack leaks credit card data

Google mitigates largest DDoS attack to date

Google said that it mitigated the largest DDoS attack ever in August, peaking at 398 million requests per second, or more than the total number of article views Wikipedia reported in a month.
Read more about Google mitigates largest DDoS attack to date

Exposed security cameras in Israel and Palestine posing significant risks

Many poorly configured security cameras are exposed to hacktivists in Israel and Palestine, placing the owners using them and the people around them at substantial risk.
Read more about Exposed security cameras in Israel and Palestine posing significant risks

Titans in crisis: unraveling the MGM and Caesars ransomware timeline

MGM Resorts International and Caesars Entertainment made headlines in Las Vegas, stealing the spotlight in 2023 as the new poster child for corporate ransomware attack victims. How did this incident unfold, who is responsible, and what are the future implications?
Read more about Titans in crisis: unraveling the MGM and Caesars ransomware timeline

Ten most common cyber security misconfigurations, as revealed by the NSA and CISA

According to an advisory by the US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), systemic weaknesses in large organizations are “all too common” and leveraged by multiple malicious actors. The agencies have compiled a list of the top ten cybersecurity misconfigurations.
Read more about Ten most common cyber security misconfigurations, as revealed by the NSA and CISA

MGM cyberattack cost over $100M in losses

MGM Resorts International is estimating last month's cyberattack – which forced the hotel and gaming giant to completely shut down its systems for nearly a week – will take a $100m dollars hit to its third-quarter results, but expects no impact on yearly profits.
Read more about MGM cyberattack cost over $100M in losses

Zero-day bugs: what they are and how to defend against them

The MOVEit Transfer attacks have made it abundantly clear that zero-day vulnerabilities and other flaws can cause millions of dollars in damage. However, the only way to avoid bugs is to properly understand them.
Read more about Zero-day bugs: what they are and how to defend against them

Blue teams on the edge: cyber pros seem to hate their jobs

4
If you’re interested in cybersecurity and looking for information online, chances are you’ll end up in the Reddit community of cyber pros. Users in the forums are known to openly share frustrations about their jobs, companies, and colleagues – highlighting the fact that “blue” teams have many common problems.
Read more about Blue teams on the edge: cyber pros seem to hate their jobs

Seaports in India were left vulnerable to takeover by hackers

The National Logistics Portal (NLP), a newly launched platform to manage all port operations in India, left public access to sensitive data, posing the risk of a potential takeover by threat actors.
Read more about Seaports in India were left vulnerable to takeover by hackers

Misconfigured WBSC server leaks thousands of passports

The World Baseball Softball Confederation (WBSC) left open a data repository exposing nearly 50,000 files, some of which were highly sensitive, the Cybernews research team has discovered.
Read more about Misconfigured WBSC server leaks thousands of passports