Security

This sucks: dev finds backdoor in his robot vacuum, potentially giving full control to spies

This software engineer was a happy user of an iLife A11 vacuum cleaner for nearly a year, until he discovered a constant stream of data being beamed to China. But that wasn’t the worst of it.
Read more about This sucks: dev finds backdoor in his robot vacuum, potentially giving full control to spies

Germany publishes checklist on how to act when your online account is hacked

The Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany’s cybersecurity agency, and the Federal and State Police Crime Prevention Program (ProPK) have published a checklist outlining steps that victims should take when one of their online accounts has been compromised.
Read more about Germany publishes checklist on how to act when your online account is hacked

Nation-state attackers infiltrate Ribbon, a major telecom services provider also used by the US DoD

Nation-state attackers have infiltrated Ribbon Communications, one of the telecom industry’s leading providers of cloud services, communications software, and network solutions – including for clients such as BT, Verizon, Deutsche Telekom, Tata, and more.
Read more about Nation-state attackers infiltrate Ribbon, a major telecom services provider also used by the US DoD

Google Chrome will switch to HTTPS by default and alert users about unencrypted visits

Google is changing its default Chrome settings to always try an HTTPS-encrypted connection first. Users will see warnings when visiting HTTP sites that do not support this secure connection.
Read more about Google Chrome will switch to HTTPS by default and alert users about unencrypted visits

Reputation.com exposes 120 million logs in major data leak

Major online reputation management company Reputation.com, which serves hundreds of major brands, has exposed 120 million records containing backend system data. The leak includes session cookies that could lead to the abuse of customer social media accounts.
Read more about Reputation.com exposes 120 million logs in major data leak

LG Uplus joins three major South Korean telecoms hacked this year

LG Uplus has confirmed a data breach, adding to a wave of cyberattacks on major South Korean telecom providers.
Read more about LG Uplus joins three major South Korean telecoms hacked this year

Employee data from advertising giant Dentsu leaked in hacker attack

Dentsu, one of the largest advertising agencies on the planet, has had its UK employee data exposed via a data breach in its trading divisions. Thousands of people were likely exposed.
Read more about Employee data from advertising giant Dentsu leaked in hacker attack

The US refuses to sign UN’s cybercrime treaty

The United States declined to sign the United Nations’ Convention against Cybercrime in Hanoi this weekend, stating that it continues to review the treaty.
Read more about The US refuses to sign UN’s cybercrime treaty

Massive risk: 92% of Exchange servers in Germany unprotected after Microsoft support ends

Microsoft flipped the switch on October 14th, ending security updates for deprecated Exchange Server 2016 and 2019. However, network admins have seemingly ignored the memo, and now tens of thousands of servers are potentially vulnerable in Germany alone.
Read more about Massive risk: 92% of Exchange servers in Germany unprotected after Microsoft support ends

Swedish power grid operator confirms it was hit by hacker attack

Svenska kraftnät, Sweden’s primary electricity grid operator, has confirmed that it suffered a data breach after the Russia-linked Everest ransomware gang claimed to have syphoned hundreds of gigabytes of the company’s data.
Read more about Swedish power grid operator confirms it was hit by hacker attack

Hackers put 8M records of Mexicans’ debt data up for sale

A cybercriminal claims to be selling a massive database of over eight million records containing personal details of Mexican debtors.
Read more about Hackers put 8M records of Mexicans’ debt data up for sale

Qilin claims large pharmacy benefit manager MedImpact

Qilin has already claimed responsibility for more than 700 ransomware attacks this year alone but the gang isn’t stopping there. It’s just claimed that it has exfiltrated data from the large US pharmacy benefit manager, MedImpact.
Read more about Qilin claims large pharmacy benefit manager MedImpact

Google pushed to publicly deny false reports of massive Gmail breach

After a series of sensational stories claiming that a Gmail data breach had impacted hundreds of millions of accounts began appearing online, Google was pushed to publicly deny the reports.
Read more about Google pushed to publicly deny false reports of massive Gmail breach

Kremlin’s airspace game: drones fuel disinformation campaigns, undermining support for Ukraine

An increasing number of drone incursions in EU airspace are quickly exploited by the pro-Russia information campaigns to shape public perception. Google Threat Intelligence Team (GTIG) observed multiple campaigns sowing distrust in local governments and reducing public support for Ukraine.
Read more about Kremlin’s airspace game: drones fuel disinformation campaigns, undermining support for Ukraine

Major crypto exchange leak exposes user wallets, passwords

The unprotected database revealed millions of records ranging from two-factor authentication codes and hashed passwords to wallet addresses. What’s worse, the data has been accessible for months.
Read more about Major crypto exchange leak exposes user wallets, passwords

US sanctions backfire: Huawei thrives while American companies lose revenue

Huawei has developed its own operating system, built its own chips, has independent supply chains, and boosted its global market share in telecom equipment while entering new markets. Meanwhile, the US tech companies lost $33 billion in sales, and the Chinese government's retaliation is hurting the American economy, says think tank ITIF.
Read more about US sanctions backfire: Huawei thrives while American companies lose revenue

Ex-CISA head Easterly thinks AI will unalive the cybersecurity industry

Jen Easterly, former director of the Cybersecurity and Infrastructure Security Agency (CISA), has used the last couple of weeks to spread her idea that AI could spell the end of the cybersecurity industry. Why?
Read more about Ex-CISA head Easterly thinks AI will unalive the cybersecurity industry

HSBC USA data breach exposes client transactions, hackers claim

Cybercrooks have uploaded data allegedly revealing the personal details of HSBC USA bank customers, including bank account numbers and transaction details. The Cybernews research team says there are indications that the leaked data is legitimate.
Read more about HSBC USA data breach exposes client transactions, hackers claim

Dublin Airport under fire after devastating attack on European airports

Hackers threatening Dublin Airport to spill the data of over a million passengers unless ransomware is paid.
Read more about Dublin Airport under fire after devastating attack on European airports

Hackers exploiting Windows updates: Microsoft urges users to patch

Hackers are exploiting a Windows Server vulnerability that can turn system updates into a malware delivery machine. Microsoft is urging users to download patches.
Read more about Hackers exploiting Windows updates: Microsoft urges users to patch