Security
Microsoft, Google and Apple logins targeted by new phishing kit using real websites
A newly identified phishing platform Starkiller gives cybercriminals a more convincing way to steal login details – using the real websites victims trust instead of fake copies.
Read more about Microsoft, Google and Apple logins targeted by new phishing kit using real websites
Data breach at media behemoth RTL Group exposes employee data, attackers claim
The attackers claim to have access to personal phone numbers, email addresses, and other sensitive personal data. The company says customer data is unlikely to be impacted.
Read more about Data breach at media behemoth RTL Group exposes employee data, attackers claim
Another bombshell in France: hacker pilfers data from 1.2 million bank accounts
A hacker stole credentials from a single government official and gained access to data from 1.2 million French bank accounts, according to the country’s Economy Ministry. Yes, it was that simple, and even though authorities are calling for calm, the pilfered information could indeed be used in extremely targeted cyberattacks.
Read more about Another bombshell in France: hacker pilfers data from 1.2 million bank accounts
Nearly 1 million accounts exposed in Figure data breach tied to ShinyHunters
Nearly 1 million customer accounts tied to leading fintech lender Figure Technology Solutions were exposed in a breach linked to the ShinyHunters hacker gang, newly published breach database records reveal.
Read more about Nearly 1 million accounts exposed in Figure data breach tied to ShinyHunters
Deutsche Bahn suspects Russian meddling behind recent IT outage
A recent major outage at Deutsche Bahn, Germany’s state-owned railway company, has been linked to a large-scale botnet attack.
Read more about Deutsche Bahn suspects Russian meddling behind recent IT outage
VPN crackdown in Spain, as LaLiga raises against pirates
A Spanish court just told NordVPN and ProtonVPN to start blocking pirate football streaming. Neither company got a prior warning.
Read more about VPN crackdown in Spain, as LaLiga raises against pirates
Eurail admits breach: alleged passenger data spills onto the dark net
Europe’s iconic rail pass is facing a different kind of journey after hackers threatened to auction off what they claim is 1.3TB of passenger data.
Read more about Eurail admits breach: alleged passenger data spills onto the dark net
IDMerit data breach: 1 billion records of personal data exposed in KYC data leak
An unprotected database, likely containing know-your-customer (KYC) data, has spilled vast amounts of personal records across multiple countries, including the USA, Germany, France, China, Brazil, and many more.
Read more about IDMerit data breach: 1 billion records of personal data exposed in KYC data leak
Docs reveal significant increase in ICE data stored on Microsoft cloud: What info is it collecting?
An increase in ICE’s budget has enabled the organization to ensure it doesn’t run out of cloud storage.
Read more about Docs reveal significant increase in ICE data stored on Microsoft cloud: What info is it collecting?
Hacker claims access to $120B insurer, but experts see credibility red flags
A malicious actor is claiming to have stolen a database containing customer data and employee access credentials from French insurance behemoth AXA.
Read more about Hacker claims access to $120B insurer, but experts see credibility red flags
Threat actor posts allegedly sensitive data related to Safran Group, company denies cyberattack
A threat actor claims to have leaked the database and internal files of Safran Group, a major French multinational aerospace and defense company. The dataset being sold seems to include extremely sensitive data.
Read more about Threat actor posts allegedly sensitive data related to Safran Group, company denies cyberattack
Notepad++ releases another patch following recent cyberattacks
Notepad++ has implemented additional security enhancements and cryptographic checks to strengthen its update process, which was recently exploited in a sophisticated espionage campaign that infected targeted users with malware.
Read more about Notepad++ releases another patch following recent cyberattacks
Dutch man receives wrong link from police, downloads secret files and gets arrested
Dutch police arrested a 40-year-old man for hacking after one of their own officers inadvertently gave him access to confidential files. The suspect refused to part with the documents unless given “something in return.”
Read more about Dutch man receives wrong link from police, downloads secret files and gets arrested
Hackers claim Canada Goose breach but researchers reveal data is “several years old”
Canada Goose, a major luxury winter clothing maker, has been targeted by hackers. The company’s data was shared on a popular data-leak forum, but Cybernews researchers believe it is several years old.
Read more about Hackers claim Canada Goose breach but researchers reveal data is “several years old”
Barron's top investment advisors threatened with 48-hour ultimatum "don't be the next headline”
ShinyHunters, an infamous extortion gang, is giving two elite US investment advisors 48 hours before it dumps millions of allegedly sensitive client records online.
Read more about Barron's top investment advisors threatened with 48-hour ultimatum "don't be the next headline”
Palo Alto sets a dangerous precedent: are we now so scared of China?
Some are calling out cowardice, others say it’s all very pathetic. One thing is clear, though: Palo Alto’s decision not to tie Beijing to a hacking campaign for fear of retaliation shows how firm China’s grip is. Is the West now so scared of angering the Chinese government?
Read more about Palo Alto sets a dangerous precedent: are we now so scared of China?
Shelly to release firmware update to address flaw in smart home devices
Smart home manufacturer Shelly says it will release a firmware update next week to automatically disable unsecured setup access points on its Gen 4 devices, following scrutiny from security researchers, who still believe this amounts to a “flaw.”
Read more about Shelly to release firmware update to address flaw in smart home devices
Developer drops tool for spying on neighbors’ Bluetooth signals
One privacy enthusiast has built a tool to monitor your neighbors' nearby Bluetooth signals, demonstrating how easily everyday convenience can be exploited for covert spying. Having Bluetooth enabled is like constantly broadcasting your name to anyone within roughly 50 meters.
Read more about Developer drops tool for spying on neighbors’ Bluetooth signals
Lapsus$ gang claims Adidas breach, company confirms investigation
The Lapsus$ hacking gang claims to have breached Adidas Extranet, accessing data such as user names, passwords, and extensive technical information. The threat actor also said that “something bigger” is coming soon. Adidas confirmed it was investigating the incident.
Read more about Lapsus$ gang claims Adidas breach, company confirms investigation
Odido hackers pretended to be an IT employee to breach corporate system
The attackers who stole the personal data of 6.2 million Odido customers used social engineering and phishing attacks to gain access to the company’s relationship management system, according to anonymous sources.
Read more about Odido hackers pretended to be an IT employee to breach corporate system