Security

Attack of drones: airborne cybersecurity nightmare

Once a niche technology, drones are about to explode in terms of market growth and enterprise adoption. Naturally, threat actors follow the trend and exploit the technology for surveillance, payload delivery, kinetic operations, and even diversion.
Read more about Attack of drones: airborne cybersecurity nightmare

Rise of deepfakes: who can you trust in the metaverse?

In this new virtual world of the metaverse, people may not always be who they seem.
Read more about Rise of deepfakes: who can you trust in the metaverse?

Conversation hijacking: when trusted person becomes your worst enemy

Given the tremendous growth in phishing attacks in recent years, many of us have become wary of suspicious-looking emails that contain links designed to encourage us to share passwords and allow criminals to deliver malware or steal money.
Read more about Conversation hijacking: when trusted person becomes your worst enemy

Weakest passwords of 2022

Despite all the warnings, shockingly high numbers of people are still using easily guessable passwords such as swear words, celebrity names, cities, animals, or keyboard sequences, with half of those observed consisting of just one word.
Read more about Weakest passwords of 2022

How to fight back if your government shuts internet down

In a digital world where the lines between online and offline are disappearing, life without internet access is unimaginable. But the rise of internet shutdowns and online censorship during political instability is a trend that nobody can afford to ignore.
Read more about How to fight back if your government shuts internet down

Ransom gangs function just like McDonald's, researchers find

As more organizations fall victim to ransomware, we dive into the anatomy of modern ransomware gangs, dissecting their operations.
Read more about Ransom gangs function just like McDonald's, researchers find

Magecart attacks: how your credit card data gets stolen from e-commerce sites

Threat actors continue to conduct Magecart attacks to steal financial data and personal information from e-commerce platforms. Let’s look at the attack chain and taxonomy for this illegal practice and countermeasures to mitigate them.
Read more about Magecart attacks: how your credit card data gets stolen from e-commerce sites

Thomson Reuters collected and leaked at least 3TB of sensitive data

2
Thomson Reuters left an open database with sensitive customer and corporate data, including third-party server passwords in plaintext format.
Read more about Thomson Reuters collected and leaked at least 3TB of sensitive data

Playing with fire: millions of .git folders exposed to public

Nearly two million .git folders containing vital project information are exposed to the public, the Cybernews research team found.
Read more about Playing with fire: millions of .git folders exposed to public

TikTok's top hacker enjoys account takeovers

Yusuf, a 23-year-old bug bounty hunter from Kurdistan, Iraq, is one of TikTok's top contributors. Hacking big tech companies started as a hobby, Yusuf told Cybernews.
Read more about TikTok's top hacker enjoys account takeovers

Curb your access privileges, Microsoft tells system admins

Microsoft’s recent security update might be good news for the computer industry, but some system administrators might be reluctant to enable it – as it entails curtailing their unlimited access privileges.
Read more about Curb your access privileges, Microsoft tells system admins

Retailer hit with ransomware after leaving customer data exposed

Online retailer Esquimal leaked the data of thousands of users via an open server. Threat actors apparently noticed this and hit the company with ransomware.
Read more about Retailer hit with ransomware after leaving customer data exposed

Hackable factory robots could injure workers, warns cyber expert

A low-skilled hacker could be just five easy steps away from remotely controlling heavy industry machines, putting workers at risk of injury or worse – that’s the verdict from one cybersecurity firm.
Read more about Hackable factory robots could injure workers, warns cyber expert

Harvard Business Publishing licensee hit by ransomware

Threat actors got to a database with over 152,000 customer records before its owner, the Turkish branch of Harvard Business Review, closed it. Crooks left a ransom note, threatening to leak the data and inform authorities of the EU’s General Data Protection Regulation (GDPR) violations.
Read more about Harvard Business Publishing licensee hit by ransomware

Protecting infrastructure: it’s impossible to stay alert all the time – interview

Unlike computers, humans grow tired of being “always alerted” – even in the face of the gravest of dangers.
Read more about Protecting infrastructure: it’s impossible to stay alert all the time – interview

Ransomware as a self-sustaining industry in criminal underworld

Ransomware affected 12 million employees and cost companies over $4 trillion dollars in six months of 2020 alone, a survey by Nordlocker finds.
Read more about Ransomware as a self-sustaining industry in criminal underworld

US streaming platform leaks admin credentials and source code

1
CarbonTV, a US-based streaming service, left a server with its source code open, risking user safety and the company’s reputation.
Read more about US streaming platform leaks admin credentials and source code

Cyberwar against Russia is creating a risky legal precedent, says expert

While hitting Russia with cyberattacks helps ease the pressures Moscow has put on Ukraine, what will happen if hackers use the cyberwar as a pretext to focus on another, unrelated, target?
Read more about Cyberwar against Russia is creating a risky legal precedent, says expert

Procurement as an unguarded attack surface

With cyberattacks such as SolarWinds receiving so much publicity, the threat vector in the procurement and contracting sector has become well documented.
Read more about Procurement as an unguarded attack surface

Deepfakes could facilitate real estate fraud, experts warn

Algorithms capable of creating hyper-realistic images have been available for several years. Now, AI-powered image generators are also easily accessible to all. Experts warn that it is only a matter of time before the technology is used to commit real estate fraud.
Read more about Deepfakes could facilitate real estate fraud, experts warn