Security
Telegram, AWS users targeted by hidden malware code
Telegram, AWS, and Alibaba Cloud users are being targeted by a fresh malware campaign that strategically buries malicious code within specific software functions to make it harder to detect.
Read more about Telegram, AWS users targeted by hidden malware code
Europol scrutinized hundreds of platforms and devices for human trafficking
In the Netherlands, 85 law enforcement investigators from 26 countries coordinated a three-day-long operational action targeting online criminal activities that enable human trafficking. That led to 371 platforms being checked, including social media and dating platforms, web forums, marketplaces, and online applications.
Read more about Europol scrutinized hundreds of platforms and devices for human trafficking
Air Canada responds to BianLian ransom attack claims
Air Canada responds to Wednesday’s claims by the BianLian ransomware group that it was responsible for a September breach of the airline – and to have stolen more than 200 GB of data from the carrier on its dark leak site.
Read more about Air Canada responds to BianLian ransom attack claims
Android financial apps too greedy for permissions
Android apps usually require excessive permissions. But financial apps go a step further into dangerous territory, asking for even more access and posing heightened risks to privacy and security, a Cybernews research team investigation into 50 apps reveals.
Read more about Android financial apps too greedy for permissions
Space cybersecurity takes center stage in Estonia
By 2040, the global space industry could be worth as much as one trillion dollars. Securing space-based systems is crucial.
Read more about Space cybersecurity takes center stage in Estonia
Air Europa cyberattack leaks credit card data
Spain’s Air Europa has fallen victim to a cyberattack on its payment system exposing some customer credit card information.
Read more about Air Europa cyberattack leaks credit card data
Google mitigates largest DDoS attack to date
Google said that it mitigated the largest DDoS attack ever in August, peaking at 398 million requests per second, or more than the total number of article views Wikipedia reported in a month.
Read more about Google mitigates largest DDoS attack to date
Exposed security cameras in Israel and Palestine posing significant risks
Many poorly configured security cameras are exposed to hacktivists in Israel and Palestine, placing the owners using them and the people around them at substantial risk.
Read more about Exposed security cameras in Israel and Palestine posing significant risks
Titans in crisis: unraveling the MGM and Caesars ransomware timeline
MGM Resorts International and Caesars Entertainment made headlines in Las Vegas, stealing the spotlight in 2023 as the new poster child for corporate ransomware attack victims. How did this incident unfold, who is responsible, and what are the future implications?
Read more about Titans in crisis: unraveling the MGM and Caesars ransomware timeline
Ten most common cyber security misconfigurations, as revealed by the NSA and CISA
According to an advisory by the US National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), systemic weaknesses in large organizations are “all too common” and leveraged by multiple malicious actors. The agencies have compiled a list of the top ten cybersecurity misconfigurations.
Read more about Ten most common cyber security misconfigurations, as revealed by the NSA and CISA
MGM cyberattack cost over $100M in losses
MGM Resorts International is estimating last month's cyberattack – which forced the hotel and gaming giant to completely shut down its systems for nearly a week – will take a $100m dollars hit to its third-quarter results, but expects no impact on yearly profits.
Read more about MGM cyberattack cost over $100M in losses
Zero-day bugs: what they are and how to defend against them
The MOVEit Transfer attacks have made it abundantly clear that zero-day vulnerabilities and other flaws can cause millions of dollars in damage. However, the only way to avoid bugs is to properly understand them.
Read more about Zero-day bugs: what they are and how to defend against them
Blue teams on the edge: cyber pros seem to hate their jobs
If you’re interested in cybersecurity and looking for information online, chances are you’ll end up in the Reddit community of cyber pros. Users in the forums are known to openly share frustrations about their jobs, companies, and colleagues – highlighting the fact that “blue” teams have many common problems.
Read more about Blue teams on the edge: cyber pros seem to hate their jobs
Seaports in India were left vulnerable to takeover by hackers
The National Logistics Portal (NLP), a newly launched platform to manage all port operations in India, left public access to sensitive data, posing the risk of a potential takeover by threat actors.
Read more about Seaports in India were left vulnerable to takeover by hackers
Misconfigured WBSC server leaks thousands of passports
The World Baseball Softball Confederation (WBSC) left open a data repository exposing nearly 50,000 files, some of which were highly sensitive, the Cybernews research team has discovered.
Read more about Misconfigured WBSC server leaks thousands of passports
DarkBeam leaks billions of email and password combinations
The leaked logins present cybercriminals with almost limitless attack capabilities.
Read more about DarkBeam leaks billions of email and password combinations
MGM and Caesars-like phishing campaign continues targeting luxury hotels
Luxury hotels remain the major target of a “well-crafted and innovative” social engineering campaign, cybersecurity experts warn.
Read more about MGM and Caesars-like phishing campaign continues targeting luxury hotels
Canadian Flair Airlines left user data leaking for months
Canadian Flair Airlines left credentials to sensitive databases and email addresses open for at least seven months, the Cybernews research team has discovered. This increases the risk of passengers’ personal information, such as emails, names, or addresses, ending up in the wrong hands.
Read more about Canadian Flair Airlines left user data leaking for months
Facebook live streaming fakes used as lure by phishers
The World Sailing Championships were recently spoofed by scammers on Facebook, who used fake offers of free live streaming to fool the unwary.
Read more about Facebook live streaming fakes used as lure by phishers
Space and defense tech maker Exail Technologies exposes database access
Exail Technologies, a high-tech manufacturer whose clients include the US Coast Guard, exposed sensitive company data that could’ve enabled attackers to access its databases.
Read more about Space and defense tech maker Exail Technologies exposes database access