Security

Tencent DMCA takedowns on GitHub raise questions over who owns user data

Tencent has filed a sweeping set of DMCA complaints with GitHub, leading to the removal of dozens of open-source projects that enable users to export or analyze their own WeChat chat histories.
Read more about Tencent DMCA takedowns on GitHub raise questions over who owns user data

Germany to boost federal service hacking, cut US intel reliance

Germany is drafting a law to massively expand its federal service hacking and internet surveillance, including full-content interception and six-month data retention. Berlin says the overhaul will cut reliance on US intel and bring the agency in line with European peers.
Read more about Germany to boost federal service hacking, cut US intel reliance

US hotel giant Hyatt allegedly attacked as stolen data appears online

A ransomware gang claims it broke into Hyatt’s global hotel empire, saying it stole internal logins and financial data that could be downloaded for free.
Read more about US hotel giant Hyatt allegedly attacked as stolen data appears online

Apple, Nvidia, and Tesla confidential files allegedly exposed in supplier breach

Luxshare, one of Apple’s key partners in assembling iPhones, AirPods, Apple Watches and Vision Pro allegedly suffered a data breach, orchestrated by a ransomware cartel. Attackers threaten the company to leak Apple, Nvidia and LG data.
Read more about Apple, Nvidia, and Tesla confidential files allegedly exposed in supplier breach

Off-grid messaging on the rise as alternative to internet shutdowns and surveillance

Mass surveillance gave rise to encrypted, increasingly decentralized messaging apps. Now, extreme internet shutdowns in Iran are driving demand for even more robust tools: messengers that function entirely offline. People are experimenting with Briar, Bitchat, and other mesh-based apps that rely on Bluetooth and WiFi to stay connected.
Read more about Off-grid messaging on the rise as alternative to internet shutdowns and surveillance

Google shows how easy it is to crack old Microsoft Windows logins

Google just dropped a dataset proving that a decades-old Windows login system can be cracked in hours, putting corporate networks at risk.
Read more about Google shows how easy it is to crack old Microsoft Windows logins

North Korea-linked hackers weaponize Google ads in malware campaign

A North Korea-linked hacking group has been found abusing online advertising infrastructure operated by Google and South Korea’s Naver to distribute malware while evading security controls, according to a new report by cybersecurity firm Genians Security Center.
Read more about North Korea-linked hackers weaponize Google ads in malware campaign

145K exposed after hacker hit of Maine’s largest health systems

Attackers roamed Central Maine Healthcare for over two months, rummaging through sensitive patient data, which in some cases included treatment information and health insurance data.
Read more about 145K exposed after hacker hit of Maine’s largest health systems

Tech hero releases tool that disables AI, ads, and other junk in Chrome, Edge, and Firefox

Can’t a browser be just a browser? A new tool will adjust Chrome, Firefox, and Edge configurations, removing AI features, telemetry data reporting, sponsored content, product integrations, and other annoyances.
Read more about Tech hero releases tool that disables AI, ads, and other junk in Chrome, Edge, and Firefox

Your company most probably can't recover from a cyberattack and doesn't know it

Many organizations are probably overestimating their ability to recover from cyberattacks. Researchers from Dell have highlighted the “resilience debt,” the gap between how ready to recover from a cyberattack companies think they are, and their actual readiness. It’s bigger than most companies think and creates an extra layer of risk.
Read more about Your company most probably can't recover from a cyberattack and doesn't know it

AWS dodges massive cyber disaster: every account was in danger

Cybersecurity researchers at Wiz Research managed to gain admin access to key AWS GitHub repositories. The disclosed critical bug could've had massive repercussions, potentially threatening “The AWS Console itself” and every AWS account.
Read more about AWS dodges massive cyber disaster: every account was in danger

Attackers claim theft of 183M records from major oil company

TotalEnergies, a French energy and petroleum behemoth, has supposedly suffered a data breach, exposing tens of millions of records. While the perpetrators' claims are hardly trustworthy, they have started posting customer data on the social platform X.
Read more about Attackers claim theft of 183M records from major oil company

Poland avoids blackout as PM blames Russia-linked attackers for massive cyberattack

Poland is recovering from a cyberattack that nearly knocked out the country’s power grid. PM Donald Tusk has blamed groups linked to Russian intelligence services and is preparing additional defenses.
Read more about Poland avoids blackout as PM blames Russia-linked attackers for massive cyberattack

Google Bluetooth flaw puts millions of audio devices at risk

Researchers are warning of a new vulnerability in Google’s Fast Pair Service that allows hackers to eavesdrop on hundreds of millions of Bluetooth audio devices. Is yours one of them?
Read more about Google Bluetooth flaw puts millions of audio devices at risk

End may be near for massive botnet controlling over 2 million Android devices

In an ongoing effort to tame the Aisuru and Kimwolf botnets, responsible for the largest DDoS attacks to date and powering massive proxy services, Lumen severed 550 command-and-control centers, disrupting the malicious activity.
Read more about End may be near for massive botnet controlling over 2 million Android devices

320K+ exposed in Monroe University hacker attack

The New York-based University had somebody roaming its systems for two weeks, accessing a trove of sensitive information, which includes everything from passport numbers to financial account information.
Read more about 320K+ exposed in Monroe University hacker attack

Microsoft hits cybercriminals where it hurts: notorious infrastructure provider disrupted

Many hackers woke up on Wednesday to find a critical part of their operations suddenly gone. They could no longer access the disposable virtual machine provider, which powers fraud, phishing, and other cybercrimes.
Read more about Microsoft hits cybercriminals where it hurts: notorious infrastructure provider disrupted

1M+ customer records stolen from Orange, attackers claim

The leaked Orange database supposedly includes full customer names, national ID numbers, and other personally identifiable information (PII) belonging to the mobile carrier’s customers.
Read more about 1M+ customer records stolen from Orange, attackers claim

South Korea’s Kyowon investigates ransomware attack as millions of accounts face exposure

South Korean authorities are investigating a suspected ransomware attack at Kyowon Group that could affect millions of user accounts. The company states that it is still assessing whether personal data was actually compromised.
Read more about South Korea’s Kyowon investigates ransomware attack as millions of accounts face exposure

Hackers could access data of 71,000 patients at Belgian hospitals

A Belgian cybersecurity expert and his team discovered that three hospitals in Flanders, the northern part of Belgium, were susceptible to a data breach. The vulnerabilities have been patched.
Read more about Hackers could access data of 71,000 patients at Belgian hospitals