Security
Everest claims Travel Club, Spain’s largest coalition loyalty program
Air Miles España, a company operating Travel club, a well-known coalition loyalty platform, has reportedly fallen victim to a ransomware attack by the Everest group.
Read more about Everest claims Travel Club, Spain’s largest coalition loyalty program
Germany encourages enabling of 2FA by default for webmail providers
The Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany’s cybersecurity agency, argues that providers of email services should enable two-factor authentication (2FA) by default, rather than leaving this up to their users.
Read more about Germany encourages enabling of 2FA by default for webmail providers
Shai-Hulud supply chain attacks back with a vengeance, impacting 28k GitHub repositories
The Shai-Hulud supply chain attack campaign, already responsible for compromising hundreds of CrowdStrike’s NPM packages in September, is back with a vengeance, according to a new warning by cybersecurity firm Aikido.
Read more about Shai-Hulud supply chain attacks back with a vengeance, impacting 28k GitHub repositories
Hackers target WhatsApp, Signal apps with spyware, compromising personal devices, CISA warns
Threat actors have been on a tear, using encrypted messaging apps like WhatsApp and Signal to deliver spyware and phishing attacks – all to compromise the personal devices of high-profile individuals, from government officials to non-profit CEOs.
Read more about Hackers target WhatsApp, Signal apps with spyware, compromising personal devices, CISA warns
Increased security and employee productivity: Why are more companies going with passwordless authentication?
Increased employee productivity is one of the “perks” of passwordless authentication.
Read more about Increased security and employee productivity: Why are more companies going with passwordless authentication?
Crooks breach major US contractor, Amazon data center plans for sale
A threat actor is claiming to have breached Cooper Steel Fabricators, a major Tier-1 structural steel fabricator based in the US. A “complete mirror” of the company’s FTP server has been listed for sale.
Read more about Crooks breach major US contractor, Amazon data center plans for sale
Customer data from Wall Street banks breached, JPMorgan and Citi affected
A hacker attack on SitusAMC, a popular vendor for elite Wall Street banks, may have exposed JPMorgan, Morgan Stanley, Citi, and other financial institutions’ customer details.
Read more about Customer data from Wall Street banks breached, JPMorgan and Citi affected
Another major airline hacked, customer data exposed
Another day, another airline hit. This time, it’s the Spanish flag carrier Iberia notifying customers of a data security incident, allegedly caused by a compromise at one of its suppliers.
Read more about Another major airline hacked, customer data exposed
FCC rolls back ISP cybersecurity rules despite looming threat from China-linked hackers
The Federal Communications Commission (FCC) has rolled back several security measures for internet service providers (ISPs). These measures were implemented after Chinese hackers successfully gained access to ISP networks for several months.
Read more about FCC rolls back ISP cybersecurity rules despite looming threat from China-linked hackers
Millions of Americans exposed after automotive platform breach, hackers say
Cybercrooks claimed an attack on Revolution Parts, alleging they have siphoned details of over 5 million of the company’s customers, including their emails and IP addresses.
Read more about Millions of Americans exposed after automotive platform breach, hackers say
North Korea now targeting applicants to major US AI and crypto firms, and there’s a twist
North Korean agents have created a fake job-application platform picking out applicants to major US AI and crypto firms, researchers said in a new report. Pyongyang has been at it for years, of course, but this time, there’s a catch.
Read more about North Korea now targeting applicants to major US AI and crypto firms, and there’s a twist
Trump could allow China to import Nvidia H200 chips, despite national security concerns
The White House may soon allow Beijing to import Nvidia's H200 GPUs into the communist nation, sources told Reuters on Friday – despite US lawmakers' grave concerns for national security, prompting a renewed push to pass the CHIPS Act.
Read more about Trump could allow China to import Nvidia H200 chips, despite national security concerns
Hacking spree continues with Mazda, Canon, and NHS added to the list
The Russia-linked Cl0p ransomware cartel claims it has the data of numerous companies, with the UK's health system NHS, Mazda, Mazda USA, and Canon recently added to the gang’s ever-growing victim list.
Read more about Hacking spree continues with Mazda, Canon, and NHS added to the list
US, UK, and Australia impose sanctions on Russian bulletproof hosting company
The United States, the United Kingdom, and Australia have imposed sanctions against a Russian bulletproof hosting service provider, three of its subsidiaries, and two of its staff members.
Read more about US, UK, and Australia impose sanctions on Russian bulletproof hosting company
US citizens, Chinese nationals busted exporting "cutting-edge" Nvidia AI chips to China
Two American citizens and two Chinese nationals now face 50 years behind bars each for illegally exporting at least four shipments of Nvidia’s cutting-edge GPU chips and their AI technology to the People’s Republic of China, the US Justice Department said.
Read more about US citizens, Chinese nationals busted exporting "cutting-edge" Nvidia AI chips to China
Burj Khalifa’s fire security firm claimed by hackers
A notorious ransomware gang claims to have stolen a terabyte of NAFFCO’s internal data, putting one of the Gulf’s biggest fire-safety giants under intense scrutiny.
Read more about Burj Khalifa’s fire security firm claimed by hackers
Exclusive interview with IGEL's Jason Mafera. Why endpoint security is still the weakest link in cyber defense
Endpoint security is often overlooked, costing companies millions in revenue when recovering from a cyberattack.
Read more about Exclusive interview with IGEL's Jason Mafera. Why endpoint security is still the weakest link in cyber defense
Palo Alto boss says nation states will soon weaponize quantum computing
Businesses will soon commercialize quantum computing, but nation states might weaponize the technology even sooner, Palo Alto Networks CEO Nikesh Arora has suggested.
Read more about Palo Alto boss says nation states will soon weaponize quantum computing
Hackers claim SAS Institute, but researchers are not so sure
Attackers are claiming that they’ve obtained source code from analytic software maker SAS Institute. However, the Cybernews research team believes the data sample the attackers shared is likely outdated.
Read more about Hackers claim SAS Institute, but researchers are not so sure
Researchers pull 100M WhatsApp phone numbers in an hour
While many focus on messaging security, researchers have revealed how using one of WhatsApp’s features could lead to the collection of users’ metadata.
Read more about Researchers pull 100M WhatsApp phone numbers in an hour