Security
Millions installed these AI apps, but researchers warn of leaked user locations
Popular AI photo identification apps with 2 million downloads have exposed their users' GPS coordinates. Researchers found that attackers have already compromised the data.
Read more about Millions installed these AI apps, but researchers warn of leaked user locations
Epstein’s files expose valid passwords, Redditors hacking into accounts
Passwords from several Jeffrey Epstein accounts, including Outlook, Yahoo, Apple ID, and other services, were found in the latest Epstein files release. Reddit users claim to have accessed multiple accounts and are wreaking havoc in the Outlook inbox.
Read more about Epstein’s files expose valid passwords, Redditors hacking into accounts
One of the most extensive Android spyware campaign hits 45,000 devices
The Arsink RAT exploits legitimate Google cloud services to steal SMS messages, contacts, call logs, and audio while giving operators complete remote control of compromised devices.
Read more about One of the most extensive Android spyware campaign hits 45,000 devices
From scam parks to execution chambers: China’s hardline tactics against cross-border cyber fraud
China’s recent executions of alleged cybercriminals connected to scam centres in Myanmar underscore a widening shift in how Beijing treats cross-border fraud.
Read more about From scam parks to execution chambers: China’s hardline tactics against cross-border cyber fraud
US senator demands AT&T and Verizon CEOs testify over Salt Typhoon telecom hack
A US senator is pushing AT&T and Verizon CEOs to testify after telecom giants allegedly blocked Salt Typhoon security assessments — raising new concerns about US network safety.
Read more about US senator demands AT&T and Verizon CEOs testify over Salt Typhoon telecom hack
January’s biggest data breaches exposed
From ICE agents and Tinder for Nazis, to the cars we drive, and even the sneakers on our feet, January’s biggest data breaches touched nearly every corner of daily life – pulling consumers, corporations, and US government agencies alike into the same cybersecurity mess.
Read more about January’s biggest data breaches exposed
M&S attackers hit German insurance giant – HanseMerkur
A 3-billion-dollar German insurance giant has been allegedly breached in a ransomware attack by a Russia-aligned Dragonforce gang.
Read more about M&S attackers hit German insurance giant – HanseMerkur
SharePoint phishing campaign rages: fake invitations lead to compromised Microsoft accounts
It might seem that someone you know is sharing a file stored on SharePoint. Swiss authorities have issued an alert about a global SharePoint phishing wave, tricking users into handing their credentials to cybercriminals.
Read more about SharePoint phishing campaign rages: fake invitations lead to compromised Microsoft accounts
Former Trump CISA leader slams current state of play as “hot mess”
Donald Trump has already entered the second year of his presidency, but the Cybersecurity and Infrastructure Security Agency (CISA) still doesn’t have a permanent boss. One of the former ones has something to say about it – and it’s bad.
Read more about Former Trump CISA leader slams current state of play as “hot mess”
DDoSecrets.com is gone: domain squatter snatched the URL, the project migrates to .ORG
DDoSecrets, a major whistleblower website, successor to WikiLeaks, has moved to a new domain, ddosecrets.org. The migration was forced after the old .com domain was lost due to registrar mishaps. DDoSecrets urges users to update all links and email addresses to the .org domain immediately.
Read more about DDoSecrets.com is gone: domain squatter snatched the URL, the project migrates to .ORG
Fancy Bear’s latest dance: Microsoft Office flaw fuels cyberattacks in Ukraine and EU
To conduct cyberattacks against organizations in Ukraine and the European Union, the Russian state-sponsored hacking group Fancy Bear (APT28) has been exploiting a recently disclosed vulnerability in Microsoft Office.
Read more about Fancy Bear’s latest dance: Microsoft Office flaw fuels cyberattacks in Ukraine and EU
8.7 billion records spilled: Inside the massive Chinese data leak
The exposed Elasticsearch cluster, which contained over 160 indices, held billions of primarily Chinese records, ranging from national citizen ID numbers to various business records.
Read more about 8.7 billion records spilled: Inside the massive Chinese data leak
ShinyHunters tease Coinbase by flashing allegedly stolen data on Telegram
Infamous for their audacity, hackers from the threat actor known as ShinyHunters are not only escalating their operations but also flashing alleged data from Coinbase, a major crypto exchange, which disclosed the breach in May last year.
Read more about ShinyHunters tease Coinbase by flashing allegedly stolen data on Telegram
Microsoft Windows moves to disable NTLM, a common attack vector for hackers
After decades on life support, Microsoft is finally flipping the kill switch for NTLM (New Technology LAN Manager), a built-in authentication system. Hackers favor NTLM for its weak security and vulnerability to relay attacks.
Read more about Microsoft Windows moves to disable NTLM, a common attack vector for hackers
Hackers share chip photos allegedly stolen from HP subsidiary, Poly
Telecommunications giant Poly was posted on a dark web forum, which attackers use to showcase their latest victims. HP says it's investigating attacker claims.
Read more about Hackers share chip photos allegedly stolen from HP subsidiary, Poly
Notepad++ hit by Chinese state-sponsored group, injecting malware into updates
For months, hackers abused hijacked Notepad++ update infrastructure to infect selected users with malicious packages. The investigation reveals a massive hosting-level compromise and likely Chinese state-sponsored group involvement.
Read more about Notepad++ hit by Chinese state-sponsored group, injecting malware into updates
Hackers who hit OkCupid, Bumble, and Crunchbase bypass security with a simple trick: a phone call
A hail of major recent cyberattacks have one thing in common – hackers call employees to ask for access. Google alerts about “a significant expansion and escalation in the operations” of ShinyHunters.
Read more about Hackers who hit OkCupid, Bumble, and Crunchbase bypass security with a simple trick: a phone call
Epstein allegedly had a “personal hacker,” was into cyberwar and malware
Financier, child sex offender, serial rapist, human trafficker – Jeffrey Epstein had many faces. Now, a new batch of files suggests he was interested in hacking and malware, and might even have had a personal hacker.
Read more about Epstein allegedly had a “personal hacker,” was into cyberwar and malware
Hackers claim 1.4 TB theft from Iron Mountain, major data management company
A Russia-linked attacker group says they accessed a huge database of the S&P 500 company, allegedly accessing company and client data. The attached data sample provides some insight into the claimed data breach.
Read more about Hackers claim 1.4 TB theft from Iron Mountain, major data management company
Hugging Face platform abused to spread Android malware variants
Hugging Face is considered a trusted platform unlikely to trigger security warnings but a new Android malware campaign is using it as a repository for thousands of variations of an APK payload that collects sensitive credentials.
Read more about Hugging Face platform abused to spread Android malware variants