Security

Guess who’s getting rich off ransomware? The usual suspects

Ransomware victims paid an estimated $813 million in 2024, and nearly 40% of that amount went to actors in Russia, China, and North Korea, a new analysis has found.
Read more about Guess who’s getting rich off ransomware? The usual suspects

Rhysida exploits Microsoft certificates to infect Teams, Zoom, PuTTY

Rhysida is now taking advantage of users on Microsoft platforms to deliver malware, while abusing Microsoft code-signing certificates to make their files appear legitimate. The tech giant has revoked more than 200 certificates tied to the group, but researchers warn that the gang continues to find a way to slip past the cracks in security controls.
Read more about Rhysida exploits Microsoft certificates to infect Teams, Zoom, PuTTY

Hackers caught hiding malware instructions and data in OpenAI accounts

Hackers are exploiting OpenAI accounts to relay encrypted commands to compromised devices and store stolen data. A sophisticated new backdoor has been discovered that abuses public AI infrastructure.
Read more about Hackers caught hiding malware instructions and data in OpenAI accounts

Iconic Italian newspaper accidentally exposes its own readers

A decades-old newspaper has accidentally exposed its readers, leaving an unprotected database with millions of logs without a password.
Read more about Iconic Italian newspaper accidentally exposes its own readers

Google’s new reCAPTCHA only appears when a visitor is flagged as risky

Google is making reCAPTCHA – its free service for protecting sites from spam and abuse – a lot more intelligent. It can now distinguish between risky users, such as bots, and trustworthy ones, and give developers control over when to trigger the security guard.
Read more about Google’s new reCAPTCHA only appears when a visitor is flagged as risky

Hackers leak alleged US gas station memos threatening staff

Super Quik, a US regional gas station chain, has been hit by Russia-linked attackers, who leaked security camera footage and a tranche of internal documents on the dark web.
Read more about Hackers leak alleged US gas station memos threatening staff

Ransomware gang cracks the whip on US horse gear giant

The cyber cartel has just added an unlikely victim to its growing hitlist – a California-based horse sport equipment giant.
Read more about Ransomware gang cracks the whip on US horse gear giant

Enterprises are ditching VMware for Proxmox, but forget to apply updates, security firm warns

Broadcom pricing hikes are triggering an exodus from VMware, with an open-source alternative, Proxmox, gaining serious traction within enterprise organizations. However, rushed migrations often result in outdated deployments, which have raised security concerns.
Read more about Enterprises are ditching VMware for Proxmox, but forget to apply updates, security firm warns

SIM farms expose weaknesses in telecom and authentication ecosystems

The recent crackdown on SIM farm networks in Europe has once again exposed deep flaws in telecom security and identity verification.
Read more about SIM farms expose weaknesses in telecom and authentication ecosystems

Norway discovers that its Chinese electric buses can be remotely disabled

Oslo’s public transportation agency, Ruter, decided to conduct a security audit of the city’s electric buses and found that the Chinese ones could be remotely disabled by their manufacturer. Security experts aren’t even surprised.
Read more about Norway discovers that its Chinese electric buses can be remotely disabled

AWS postmortem: a first-hand account of the outage

The AWS outage dealt a massive blow to companies worldwide. To understand the full effects, Cybernews spoke to engineering experts who were directly impacted.
Read more about AWS postmortem: a first-hand account of the outage

Vibe coders targeted with Pokémon, Minecraft-themed add-ons: malware steals crypto

Looking at plain code feels too boring, so you add a little animated sidekick to keep you entertained or a new theme to keep you focused? Pwned. Security researchers are flagging a wave of VS Code extensions that quietly mine cryptocurrency or potentially worse.
Read more about Vibe coders targeted with Pokémon, Minecraft-themed add-ons: malware steals crypto

Canadian cybersecurity agency recommends enabling 2FA after cyberattack reports on vital infrastructure

The Canadian Center for Cyber Security is warning businesses and organizations involved in vital infrastructure to implement additional security measures, as they’ve become a target for hacktivists.
Read more about Canadian cybersecurity agency recommends enabling 2FA after cyberattack reports on vital infrastructure

The US government just got closer to banning popular TP-Link routers

Top US federal agencies are backing a proposal to ban future sales of popular TP-Link home routers because the vendor is allegedly still closely tied to its former Chinese parent company.
Read more about The US government just got closer to banning popular TP-Link routers

WhatsApp announces passkey-encrypted backups

WhatsApp has disclosed that its messaging platform is launching passkey-encrypted backups, offering both Android and iOS users the option to secure their stored messages with facial recognition, fingerprint, or screen lock code.
Read more about WhatsApp announces passkey-encrypted backups

The evil masterminds behind Meduza infostealer malware are…kids in Hello Kitty pants

The latest bust by Russian authorities has destroyed the familiar image of the hacker as a villain who wears a black hoodie. The Meduza Infostealer malware developers appear to be more like kids who play Roblox.
Read more about The evil masterminds behind Meduza infostealer malware are…kids in Hello Kitty pants

CISA releases security best practices guide for on-site Microsoft Exchange Servers

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a 15-page best practices guide – all so that organizations still using the now-outdated Microsoft Exchange Servers can properly harden their systems against known threats.
Read more about CISA releases security best practices guide for on-site Microsoft Exchange Servers

Naruto, Sailor Moon US publisher’s Google Drive breached, attackers claim

The attack allegedly resulted in hackers downloading hundreds of gigabytes of corporate data, including employee credentials.
Read more about Naruto, Sailor Moon US publisher’s Google Drive breached, attackers claim

Over 3 billion Chromium users vulnerable to browser crash bug

Chrome, Edge, Brave, Opera, and Vivaldi – all Chromium-based browsers – are currently vulnerable to a critical bug that allows attackers to crash the app in 15 to 60 seconds. All it takes is to open a malicious (or educational) website.
Read more about Over 3 billion Chromium users vulnerable to browser crash bug

Hacker gang claims raid on Japanese grocery store chain

A prolific Russia-linked ransomware gang has allegedly struck again. This time, it is claiming the Japanese supermarket chain Super Value Co. and leaking employee and financial data on the dark web.
Read more about Hacker gang claims raid on Japanese grocery store chain