Security
Most wanted hackers hide in plain sight – and there's nothing police can do
When we think of hackers, we usually picture shadowy figures operating beyond the reach of law enforcement agencies. The moment agencies get a whiff of who and where they are, they vanish into the shadows again.
Read more about Most wanted hackers hide in plain sight – and there's nothing police can do
BuddyBoss platform compromised, hundreds of websites already hacked
Cybernews has discovered an ongoing attack against live servers running BuddyBoss, a premium WordPress platform for e-learning and online communities. Hundreds of websites have been compromised, and thousands remain in danger. Admins are advised to take immediate action: disable updates, revert any recent changes, and assume compromise.
Read more about BuddyBoss platform compromised, hundreds of websites already hacked
Wrong kind of spark: Innova Energie ex-employee steals customer IBANs in insider breach
Dutch energy company Innova Energie has sent an email to affected customers to inform them of a recent data breach carried out by a former employee.
Read more about Wrong kind of spark: Innova Energie ex-employee steals customer IBANs in insider breach
CISA issues urgent Microsoft Intune security warning
The Cybersecurity and Infrastructure Security Agency (CISA) is strongly encouraging businesses and organizations to improve the security of their Microsoft environment, starting with Microsoft Intune.
Read more about CISA issues urgent Microsoft Intune security warning
Scam protection company Aura just got scammed: 900,000 records stolen
A company promising to protect you from scams just got scammed itself. Over 900,000 records are now floating on the dark web after attackers dropped an entire dataset.
Read more about Scam protection company Aura just got scammed: 900,000 records stolen
Companies now required to reveal AI use to get cyber insurance
Insurers in India are pressing companies to reveal how they use AI as part of stricter cyber insurance assessments. The move reflects growing concern that opaque AI deployments could introduce new security gaps and complicate risk modelling.
Read more about Companies now required to reveal AI use to get cyber insurance
China working on encryption that can't be cracked by tomorrow's computers
China will likely develop national standards for post-quantum cryptography in the next three years as it pours funds into research, according to a leading expert in the field.
Read more about China working on encryption that can't be cracked by tomorrow's computers
Telegram executes record number of takedowns, but cyber crooks still stand tall
Telegram bans and takedowns are now extremely massive and frequent. Pavel Durov, the CEO, is apparently trying to clean up his act, but cybercriminal ecosystems aren’t shrinking – they’re adapting. And quickly.
Read more about Telegram executes record number of takedowns, but cyber crooks still stand tall
Ubiquiti rushes out emergency fix for critical bug in UniFi Network Application
Ubiquiti has disclosed a maximum severity vulnerability in its UniFi Network Application, the software for managing WiFi access points, switches, and gateways. Hackers can break in without any credentials.
Read more about Ubiquiti rushes out emergency fix for critical bug in UniFi Network Application
Ten major tech companies ordered to hand over all communications with EU regulators
The US Committee on the Judiciary is demanding all communications from ten major American tech companies with so-called “foreign censors,” including the European Commission and EU Member States.
Read more about Ten major tech companies ordered to hand over all communications with EU regulators
Stryker cyberattack delays surgeries as CISA warns to harden Microsoft systems
Stryker said Wednesday that last week’s cyberattack has now delayed some surgeries, as CISA warns attackers are targeting Microsoft endpoint management systems used by US organizations.
Read more about Stryker cyberattack delays surgeries as CISA warns to harden Microsoft systems
Millions of Crime Stoppers tips exposed, challenging the anonymity promise
Hacktivists have leaked millions of anonymous tips submitted by Crime Stoppers informants. A massive 91.53GB dataset, dubbed BlueLeaks 2.0, has been made available to journalists and researchers by transparency collective DDoSecrets, which says tipsters were never anonymous.
Read more about Millions of Crime Stoppers tips exposed, challenging the anonymity promise
Hackers are doing their homework – and your VPN is first on the list, report warns
New findings from Hewlett Packard Enterprise (HPE) show that cybergangs like Akira are diligently doing their market research on VPN technologies to identify weak entry points before launching attacks.
Read more about Hackers are doing their homework – and your VPN is first on the list, report warns
Hackers turn GitHub’s favourite OpenWebUI AI servers into crypto mining zombie army
Popular open-source AI servers were secretly hijacked for more than a year and turned into a silent army of crypto mining machines.
Read more about Hackers turn GitHub’s favourite OpenWebUI AI servers into crypto mining zombie army
Japan to launch “hack back” powers this October
During a press briefing on Tuesday, Chief Cabinet Secretary Minoru Kihara said that the time was right to allow offensive cyber operations as the country faced its “most complicated national security environment” since the Second World War.
Read more about Japan to launch “hack back” powers this October
Hundreds of code repos falling like dominoes, infected by new wave of self-replicating malware
Hundreds of GitHub and npm repositories, and dozens of extensions for VS Code and other code editors, have been compromised in a new massive wave of the GlassWorm supply chain attack. Thousands of developers are at risk, with the latest victims being popular React Native packages with over 130,000 monthly downloads.
Read more about Hundreds of code repos falling like dominoes, infected by new wave of self-replicating malware
CISA flags actively exploited vulnerability of file transfer software used by US Air Force and Sony
The US Cybersecurity and Infrastructure Security Agency (CISA) has officially urged US federal agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that could be chained in remote code execution (RCE) attacks.
Read more about CISA flags actively exploited vulnerability of file transfer software used by US Air Force and Sony
Chinese chatbots fooled into recommending nonexistent health gadget
A fake fitness tracker in China has revealed how easily chatbots can be misled by poisoned data. The incident raises fresh concerns about the reliability of chatbot outputs.
Read more about Chinese chatbots fooled into recommending nonexistent health gadget
Dutch telecom's bid to keep Chinese kit fails as court backs spy agency fears
Telecom provider Odido has lost an appeal regarding the replacement of network components from Huawei and ZTE in critical parts of its mobile network.
Read more about Dutch telecom's bid to keep Chinese kit fails as court backs spy agency fears
Russia found sharing drone technology, battlefield tactics with Iran to boost strike capabilities
Russia is now sharing satellite imagery, upgraded drone technology, and tactical guidance with Iran – likely improving Tehran’s ability to strike US and allied targets in the Middle East.
Read more about Russia found sharing drone technology, battlefield tactics with Iran to boost strike capabilities