Security
LockBit uses Starlink to avoid detection
LockBit ransomware syndicate has intimate ties with other major cybercrime groups, employs smear campaigns to stay on top, and subscribes to Starlink internet connection to avoid detection.
Read more about LockBit uses Starlink to avoid detection
Norton Password Manager breach: nearly one million users targeted
Norton LifeLock – the company that promises to keep you 'cyber safe' – said it discovered an unauthorized third party trying to log into a large swath of customer accounts during a recent December 2022 breach.
Read more about Norton Password Manager breach: nearly one million users targeted
Social marketplace exposes nearly half a million users
Security loopholes on social marketplace website trustanduse.com exposed data of around 439,000 users including many businesses for at least six months.
Read more about Social marketplace exposes nearly half a million users
Threat actors can use ChatGPT to create deployable malware
New research shows hackers are exploiting ChatGPT to write usable malware and sharing their results on the dark web.
Read more about Threat actors can use ChatGPT to create deployable malware
Facebook users targeted in copyright infringement scam
Hackers are sending fake copyright infringement notices to Facebook users to steal their credentials, a new research by Avanan has found.
Read more about Facebook users targeted in copyright infringement scam
LastPass hack aftermath: can we trust password managers?
Hackers stole copies of LastPass customers' vaults and might attempt to decrypt them. The incident has undoubtedly shaken an online community that has repeatedly been asked to trust password managers.
Read more about LastPass hack aftermath: can we trust password managers?
Gotta catch ‘em all: cybercriminals target victims with fake Pokémon game
Threat actors capitalize on the popularity of a Pokémon franchise and a buoyant NFT card trading market to spread malware.
Read more about Gotta catch ‘em all: cybercriminals target victims with fake Pokémon game
Russian threat group using other crooks’ malware to target Ukraine, says watchdog
A suspected Russian threat group is believed to have begun targeting victims in Ukraine, piggybacking off previously deployed malware to install backdoors of its own and siphon off data, cybersecurity watchdog Mandiant reports.
Read more about Russian threat group using other crooks’ malware to target Ukraine, says watchdog
How hackers might be exploiting ChatGPT
The viral AI chatbot ChatGPT might advise threat actors how to hack into networks with ease.
Read more about How hackers might be exploiting ChatGPT
Slack admits security breach
A popular workspace platform Slack disclosed a security incident that took place as the new year drew near.
Read more about Slack admits security breach
Cricket-oriented platform ‘drops a dolly’ exposing user data
Social platform for the cricket community exposed over 100k entries of private customer data and admin credentials.
Read more about Cricket-oriented platform ‘drops a dolly’ exposing user data
Researchers discover critical vulnerabilities in Ferrari, BMW, Toyota, and other automotive giants
Security researchers, including Web application security researcher Sam Curry, discovered severe vulnerabilities in Ferrari, BMW, Toyota, Ford, and other automotive companies.
Read more about Researchers discover critical vulnerabilities in Ferrari, BMW, Toyota, and other automotive giants
AI startup spills employee data and corporate secrets
An Indian startup focusing on artificial intelligence (AI) solutions leaked sensitive corporate data, including extensive information about its projects and employees.
Read more about AI startup spills employee data and corporate secrets
MailChimp, Mailgun, and Sendgrid API leak endangered over 54m users
Leaked API keys of three popular email service providers allowed threat actors to perform various unauthorized actions such as sending emails, accessing mailing lists and personal data, deleting API keys, and modifying two-factor authentication, hence putting 54 million users at risk.
Read more about MailChimp, Mailgun, and Sendgrid API leak endangered over 54m users
Shoemaker Ecco leaks over 60GB of sensitive data for 500+ days
Ecco, a global shoe manufacturer and retailer, exposed millions of documents, potentially opening itself up to large cyberattack.
Read more about Shoemaker Ecco leaks over 60GB of sensitive data for 500+ days
3.5m IP cameras exposed, with US in the lead
The number of internet-facing cameras in the world is growing exponentially. Some of the most popular brands don't enforce a strong password policy, meaning anyone can peer into their owners' lives.
Read more about 3.5m IP cameras exposed, with US in the lead
How to avoid hacking hangover at the airport this holiday season
Cyber con artists are hitting consumers with an endless barrage of online eavesdropping, phishing scams, and fake websites – many of them travel-related – designed to catch you off guard and allow hackers access to your personal and financial data.
Read more about How to avoid hacking hangover at the airport this holiday season
Amazon shoppers warned of holiday scams
It's beginning to look a lot like… scam season. With holidays up around the corner, it's busy days for cyber Grinches ready to empty your bank account.
Read more about Amazon shoppers warned of holiday scams
India’s foreign ministry leaks expat passport details
The Global Pravasi Rishta Portal, India’s government platform for connecting with its overseas population, leaked sensitive data, including names and passport details.
Read more about India’s foreign ministry leaks expat passport details
US Health Department warns healthcare industry of new Royal ransomware
The US Department of Health and Human Services (HHS) warned the healthcare community about human-operated Royal ransomware that has been used to attack the sector since 2022.
Read more about US Health Department warns healthcare industry of new Royal ransomware