Security
FCC closes loophole making Verizon phones harder to steal
The FCC is waiving a 2007 “handset unlocking” rule that regulators say helped fuel phone theft and fraud, allowing cybercriminals to exploit Verizon cell phone users for years.
Read more about FCC closes loophole making Verizon phones harder to steal
Manchester United captain’s X account hacked, club asks fans not to interact
Manchester United footballer Bruno Fernandes’s X account has been hacked. The Premier League club has confirmed the breach and told fans not to interact with the account.
Read more about Manchester United captain’s X account hacked, club asks fans not to interact
Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway
Millions of Instagram users panicked over sudden password reset emails and claims that 17.5 million user data records had been stolen, while Meta denied any breach allegations.
Read more about Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway
“Nissan has 5 days before we leak their data,” attackers threaten
A Russia-linked ransomware gang is threatening to expose 900GB of Japanese auto manufacturing giant Nissan’s internal data.
Read more about “Nissan has 5 days before we leak their data,” attackers threaten
Attackers claim PayPal credential leak, but researchers doubt the data’s useful
Users of a data leak forum claim that they’ve obtained over 100,000 stolen PayPal credentials, including emails and passwords.
Read more about Attackers claim PayPal credential leak, but researchers doubt the data’s useful
Telegram built-in proxy exposes real IPs using single-click flaw, researchers warn
A one-click vulnerability in the Telegram app for Android and iOS enables attackers to obtain users’ real IP addresses, even when they use a built-in proxy, security researchers warn.
Read more about Telegram built-in proxy exposes real IPs using single-click flaw, researchers warn
Scammers trap investors in fake Truman Show, where portfolio grows, money disappears
Investment scams in the AI era are becoming indistinguishable from reality, researchers warn. Fraudsters trap victims in a “Truman Show” world, complete with fake apps, websites, news coverage, personalities, followers, and false regulatory references.
Read more about Scammers trap investors in fake Truman Show, where portfolio grows, money disappears
Public exploit just put Cisco’s identity systems on edge
Cisco has patched a security flaw in its Identity Services Engine after a public proof-of-concept exploit was dropped. The vulnerability could have enabled hackers to attack corporate identity systems.
Read more about Public exploit just put Cisco’s identity systems on edge
WhatsApp’s free pass may be ending as Brussels considers tougher oversight
EU considers making WhatsApp more responsible for tackling harmful content, spokesperson says
Read more about WhatsApp’s free pass may be ending as Brussels considers tougher oversight
Prosura attackers put insurer's customer data up for sale
Prosura attackers claim to have obtained nearly 100 million lines of data from the VroomVroomVroom partner earlier this month.
Read more about Prosura attackers put insurer's customer data up for sale
“Militant pro-trans organization” hacks UK Free Speech Union and exposes its backers
Individuals who donated £50 ($67) or more to the Free Speech Union (FSU), a UK-based membership organization, have had their names publicly listed online. The organization was hacked by trans activists, who blame it “for defending bigots.”
Read more about “Militant pro-trans organization” hacks UK Free Speech Union and exposes its backers
Billions of Chrome users at risk: Google confirms another zero-day vulnerability
Google has fixed a vulnerability in the new Chrome versions 143.0.7499.192/193 for Windows and macOS and 143.0.7499.192 for Linux. According to the firm, the vulnerability hasn’t yet been exploited for attacks in the wild.
Read more about Billions of Chrome users at risk: Google confirms another zero-day vulnerability
Years online, but no safeguards: How Illinois exposed 700,000 health records
The Illinois Department of Human Services (IDHS) has disclosed a massive data breach, which affects over 700,000 of its customers.
Read more about Years online, but no safeguards: How Illinois exposed 700,000 health records
Italian diving legend Cressi hit by cyberattack, claim Russian hackers
A Russia-linked ransomware gang has claimed responsibility for an attack on Cressi, a historic Italian diving equipment manufacturer, potentially signaling a data breach.
Read more about Italian diving legend Cressi hit by cyberattack, claim Russian hackers
17-year-old PowerPoint flaw still actively exploited by attackers, CISA warns
Someone has likely fallen victim to attackers exploiting an old PowerPoint vulnerability that dates back to 2009. The US cybersecurity authority, CISA, is urging federal agencies to immediately remediate the decades-old flaw.
Read more about 17-year-old PowerPoint flaw still actively exploited by attackers, CISA warns
“There will be no patch” says D-Link, as hackers exploit old routers
A newly discovered vulnerability has been exploited in the wild to target outdated D-Link routers and hijack them, cybersecurity researchers have warned.
Read more about “There will be no patch” says D-Link, as hackers exploit old routers
Chinese hackers breach emails of US congress staffers
A Chinese hacking group has compromised emails used by staff members of powerful committees in the US House of Representatives, the Financial Times reported on Wednesday, citing people familiar with the matter.
Read more about Chinese hackers breach emails of US congress staffers
Chrome hits scammers with rate limiting for push notifications
Google is rolling out rate limiting for the Chrome Push API, capping delivery to 1,000 push notifications per minute. The change primarily affects websites that target users individually – a pattern often exploited by scammers who use small pop-ups to alert users of fake viruses, urgent updates, or oversensational breaking news.
Read more about Chrome hits scammers with rate limiting for push notifications
Your domain, their bait: Microsoft warns businesses on internal email phishing loopholes
Threat actors are abusing routing configurations and improperly set spoofing protections to impersonate an organization’s own domain, sending phishing emails that appear to originate from internal sources, Microsoft has warned.
Read more about Your domain, their bait: Microsoft warns businesses on internal email phishing loopholes
Cybercrooks find a simple trick to bypass malicious QR code detection – HTML tables
Cybercriminals have discovered a way to bypass detection engines for malicious QR codes, which are designed to protect email users. Now, they’re spamming inboxes with fraudulent QR codes generated with HTML code, instead of attached images.
Read more about Cybercrooks find a simple trick to bypass malicious QR code detection – HTML tables