Security
Misconfigured WBSC server leaks thousands of passports
The World Baseball Softball Confederation (WBSC) left open a data repository exposing nearly 50,000 files, some of which were highly sensitive, the Cybernews research team has discovered.
Read more about Misconfigured WBSC server leaks thousands of passports
DarkBeam leaks billions of email and password combinations
The leaked logins present cybercriminals with almost limitless attack capabilities.
Read more about DarkBeam leaks billions of email and password combinations
Canadian Flair Airlines left user data leaking for months
Canadian Flair Airlines left credentials to sensitive databases and email addresses open for at least seven months, the Cybernews research team has discovered. This increases the risk of passengers’ personal information, such as emails, names, or addresses, ending up in the wrong hands.
Read more about Canadian Flair Airlines left user data leaking for months
MGM and Caesars-like phishing campaign continues targeting luxury hotels
Luxury hotels remain the major target of a “well-crafted and innovative” social engineering campaign, cybersecurity experts warn.
Read more about MGM and Caesars-like phishing campaign continues targeting luxury hotels
Facebook live streaming fakes used as lure by phishers
The World Sailing Championships were recently spoofed by scammers on Facebook, who used fake offers of free live streaming to fool the unwary.
Read more about Facebook live streaming fakes used as lure by phishers
Space and defense tech maker Exail Technologies exposes database access
Exail Technologies, a high-tech manufacturer whose clients include the US Coast Guard, exposed sensitive company data that could’ve enabled attackers to access its databases.
Read more about Space and defense tech maker Exail Technologies exposes database access
Proton Pass security flaw exposed: Firefox users at risk
A password manager by Swiss-based company Proton is still storing data in plaintext. Patch is on the way.
Read more about Proton Pass security flaw exposed: Firefox users at risk
PwC Nigeria tech bootcamp IDs exposed
Participants in PricewaterhouseCooper’s (PwC) Nigeria Tech Talent Bootcamp are at risk of identity theft after private data was leaked from a misconfigured Amazon Web Services account, a Cybernews investigation reveals.
Read more about PwC Nigeria tech bootcamp IDs exposed
Microsoft AI research team allegedly leaks 38TB of private data
A disk backup of two employees’ workstations were also included in the leaked data, researchers at cloud security company Wiz said.
Read more about Microsoft AI research team allegedly leaks 38TB of private data
Brits in dark about dark web, study shows
One in seven Brits have had personal data leaked in the past year but few can tell what the dark web is, according to new research.
Read more about Brits in dark about dark web, study shows
Dangerous permissions detected in top Android health apps
Leading Android health applications expose users to avoidable threats like surveillance and identity theft, due to their risky permissions. Cybernews has the story.
Read more about Dangerous permissions detected in top Android health apps
Third of Americans use password managers
Increased cybersecurity risks may have sharpened some Americans’ attention to password management – but most still rely on memorization or handwritten notes, a practice criticized by many cybersecurity experts.
Read more about Third of Americans use password managers
Caesars ransom attack linked to MGM, tens of millions paid to hackers
New sources are naming Caesars Entertainment as the first victim to be hit by a massive cyberattack on the Las Vegas strip – making MGM Resorts the second.
Read more about Caesars ransom attack linked to MGM, tens of millions paid to hackers
China-linked malware spotted in national power grid
A national grid in an undisclosed Asian country was compromised for up to six months earlier this year, a study says. Evidence suggests a threat actor was using Chinese-linked malware called ShadowPad Trojan.
Read more about China-linked malware spotted in national power grid
MGM cyberattack claimed by ALPHV/BlackCat ransom gang
New information has surfaced claiming the ALPHV/BlackCat ransomware group is responsible for Monday’s debilitating cyber attack on the Las Vegas-based MGM Resorts Internationa. With rumors about a large ransom payment swirling, some insiders say MGM may not even be able to pay its employees come Friday.
Read more about MGM cyberattack claimed by ALPHV/BlackCat ransom gang
Ethereum’s Buterin says X account hacked in T-Mobile SIM swap
Ethereum co-founder Vitalik Buterin said someone “socially engineered” T-Mobile to take over his phone number, which was enough to hack into his X (Twitter) account.
Read more about Ethereum’s Buterin says X account hacked in T-Mobile SIM swap
IBM: Janssen health database breached in cyber incident
IBM announces that an unauthorized party breached the patient healthcare database it manages for the Johnson & Johnson-owned Janssen CarePath platform.
Read more about IBM: Janssen health database breached in cyber incident
LADbible Group leaks internal data
LADBible group, a popular viral media publisher, has leaked employee email addresses, links to its social media, a list of advertisers, and data on articles, among other information of high value to attackers.
Read more about LADbible Group leaks internal data
Large companies unprepared for cyberattacks, boards say
Board members in Singapore, Canada, and Japan feel their organizations are most exposed, according to a new report from cybersecurity company Proofpoint.
Read more about Large companies unprepared for cyberattacks, boards say
Flaw in AtlasVPN Linux clients discovered, update released
A simple code snippet in a webpage could disconnect instances of AtlasVPN’s Linux Client, exposing a user’s IP address. The zero-day flaw was discovered and shared by a user on Reddit, the company has released a patch.
Read more about Flaw in AtlasVPN Linux clients discovered, update released