Security

Three serious vulnerabilities enabling attackers to break out of Docker, Kubernetes containers

Three severe vulnerabilities have been identified in the container runtime environment runC, which is used by Docker, Kubernetes, and other solutions. Attackers can exploit the flaws to escape the containers and ultimately gain root access to the host system.
Read more about Three serious vulnerabilities enabling attackers to break out of Docker, Kubernetes containers

Previously unseen spyware targets Samsung Galaxy owners

A powerful new Android spyware family, dubbed Landfall, has emerged, exploiting several zero-day vulnerabilities to target Samsung Galaxy and likely other devices. The tool was likely used by government entities and other commercial surveillance buyers.
Read more about Previously unseen spyware targets Samsung Galaxy owners

Doctor Alliance breach allegedly exposes patients’ health data

Attackers are threatening the healthcare tech firm to pay ransom or they will release over a million records. The alleged stolen data includes sensitive medical data ranging from diagnoses to checkup summaries.
Read more about Doctor Alliance breach allegedly exposes patients’ health data

Domino effect: after Norway, UK now also probing Chinese Yutong e-buses

Following Norway's announcement last week that Oslo’s Chinese electric buses could be remotely disabled by their manufacturer, the United Kingdom, which also operates hundreds of these vehicles, has launched its own investigation.
Read more about Domino effect: after Norway, UK now also probing Chinese Yutong e-buses

Android built-in security features won’t protect from stalkerware, EFF warns

Android built-in security and antivirus apps often fail to protect users from stalkerware – malicious surveillance tools installed on a device without the owner’s knowledge by harassers and other stalkers.
Read more about Android built-in security features won’t protect from stalkerware, EFF warns

Texas sues Roblox over operating “as a digital playground for predators”

Texas Attorney General Ken Paxton has filed a lawsuit against the online gaming platform Roblox, accusing it of putting children in danger and ignoring online safety laws.
Read more about Texas sues Roblox over operating “as a digital playground for predators”

Belgium introduces mandatory drone and UAV pilot registration after airport threats

Belgium’s National Security Council has advised that all drones and drone pilots must be registered. This way, the Belgian government hopes to gain control over drones that have been spotted around airports and military bases in recent days.
Read more about Belgium introduces mandatory drone and UAV pilot registration after airport threats

Washington Post is latest victim of Oracle-hacking Cl0p gang

The Washington Post on Thursday said it is the latest victim of a Cl0p ransomware group and its ongoing Oracle attack spree, which has impacted hundreds of organizations and counting.
Read more about Washington Post is latest victim of Oracle-hacking Cl0p gang

Attackers drop terrabytes of US manufacturing giant’s data

The Rhysida ransomware gang has leaked nearly 2TB of sensitive data from US manufacturing giant Gemini Group, exposing employee and client records across North America.
Read more about Attackers drop terrabytes of US manufacturing giant’s data

“We will sell your data:” Spanish top radio station held hostage by Russian hackers

A popular Spanish radio station with over a million listeners has been hit by attackers who are known for causing chaos and demanding huge amounts of money.
Read more about “We will sell your data:” Spanish top radio station held hostage by Russian hackers

iPhone thieves are using this trick to unlock devices: beware of fake “Find My” messages

People who have lost their iPhones are receiving fake text messages claiming that their device has been found abroad. The false hope is leading to the removal of Activation Lock and compromised Apple ID credentials, Swiss authorities warn.
Read more about iPhone thieves are using this trick to unlock devices: beware of fake “Find My” messages

I wanted a cloud at home, but AI assistants kept sabotaging my efforts

I just wanted to make my home network simpler and more secure – use nice domain names and the encrypted TLS (Transport Layer Security) protocol for my services instead of plain text HTTP.
Read more about I wanted a cloud at home, but AI assistants kept sabotaging my efforts

State-sponsored hackers named as culprits in SonicWall cyber hit

SonicWall, a major VPN, firewall, and other network security solutions provider, has formally blamed state-sponsored threat actors for the September security breach, when all firewall cloud backups belonging to customers were illegally accessed.
Read more about State-sponsored hackers named as culprits in SonicWall cyber hit

Claude Desktop users in danger: any question can lead to complete compromise

AI chatbot apps can be tricked by malicious websites into fetching and running malware on user devices. A massive security oversight has been discovered in Claude Desktop.
Read more about Claude Desktop users in danger: any question can lead to complete compromise

Belgium convenes National Security Council due to various drone sightings at airports and military bases

Belgium’s National Security Council will meet on Thursday to discuss several incidents involving drones crossing airspace at airports and military bases.
Read more about Belgium convenes National Security Council due to various drone sightings at airports and military bases

Crooks now using AI to generate convincing pharmaceutical scams

Scammers are now impersonating licensed physicians and medical clinics to promote counterfeit or unsafe medications. They frequently leverage AI and deepfake technology to generate convincing fake photos, videos, and endorsements, putting people’s lives at risk.
Read more about Crooks now using AI to generate convincing pharmaceutical scams

Third-party leak exposes Stanford Health Care staff details, passwords

Names, payroll data, hashed passwords, and thousands of other sensitive records belonging to Stanford Health Care’s staff were exposed after a third-party contractor, Perfectshift, left an unprotected database accessible to the public.
Read more about Third-party leak exposes Stanford Health Care staff details, passwords

Swiss bank’s data stolen in cyberattack, hackers claim

A notorious group of Russian hackers are claiming to be behind an attack on a Swiss international bank, allegedly stealing customer data and the bank’s source code.
Read more about Swiss bank’s data stolen in cyberattack, hackers claim

Russian hackers sneak a full Linux virtual machine inside Windows to run undetected

You can’t detect malware on Windows if it’s not running on Windows. Russian hackers are exploiting Microsoft’s Hyper-V virtualization feature to create a hidden Linux virtual machine within a target’s host, allowing them to covertly install secret implants on the victim's computer.
Read more about Russian hackers sneak a full Linux virtual machine inside Windows to run undetected

Attackers breach nuclear waste plant, allegedly stealing its entire database

Radon, a nuclear waste management plant operated by Russia’s nuclear energy behemoth Rosatom, allegedly had its systems breached with attackers stealing testing data and user information.
Read more about Attackers breach nuclear waste plant, allegedly stealing its entire database