Security

Russia-linked hackers attack Texas electric cooperatives

Hackers claim to have breached Texas electric power cooperatives, exposing sensitive financial documents.
Read more about Russia-linked hackers attack Texas electric cooperatives

“Empty shelves and stalled production lines:” UK suffering four major cyberattacks a week

“Nationally significant” cyberattacks in the UK more than doubled compared to last year. Disruptions at Marks & Spencer, the Co‑op Group, and Jaguar Land Rover grabbed the headlines, and over 200 other major breaches occurred in one year, NCSC said in a report.
Read more about “Empty shelves and stalled production lines:” UK suffering four major cyberattacks a week

Hackers can snoop on Android screens and steal sensitive data with zero permissions

One pixel at a time, hackers can peer into Android screens and steal one-time passwords (OTP), private messages, or other sensitive data. Researchers have disclosed a high-severity “Pixnapping” attack method, demonstrating that likely all modern Android devices are affected.
Read more about Hackers can snoop on Android screens and steal sensitive data with zero permissions

Dutch government takes control of chipmaker Nexperia due to “national and economic security”

The Dutch Department of Economic Affairs is taking over management of the semiconductor manufacturer Nexperia. The government is concerned that the knowledge and capabilities of crucial technology are being transferred to its Chinese parent company, Wingtech.
Read more about Dutch government takes control of chipmaker Nexperia due to “national and economic security”

Clever woman exposes Wise scam - scammer loses it

Phishing attacks are becoming more sophisticated by the day, and one recent case that reached the Cybernews newsroom raised serious eyebrows.
Read more about Clever woman exposes Wise scam - scammer loses it

“Inflation Refund” scam texts spread among thousands of New Yorkers

New Yorkers are getting thousands of text messages claiming they need to fill out documents to be eligible for the state’s “Inflation Refunds.” But this is, in fact, an ongoing smishing campaign.
Read more about “Inflation Refund” scam texts spread among thousands of New Yorkers

Drones over Europe: when airspace is the new frontline

When European lawmakers call drone flights over the region’s critical infrastructure “hybrid warfare,” that’s probably an overstatement: drones are nothing new, actually, if only, well, there are millions of them, and everyone can buy one. Nevertheless, the possibility of a catastrophic event is growing, an expert says.
Read more about Drones over Europe: when airspace is the new frontline

How to tell if your mobile number has been hacked and what to do next

What would you do if your phone suddenly showed "No Service" while everyone around you had a full signal? For many people, that is the first warning sign that their mobile number has been hacked.
Read more about How to tell if your mobile number has been hacked and what to do next

Report: LockBit, Qilin, DragonForce join forces as ransomware cartel

It’s not exactly clear what the impact is going to be, but the announcement by LockBit, DragonForce, and Qilin – three of the biggest names in the world of ransomware and data extortion – certainly sounds menacing.
Read more about Report: LockBit, Qilin, DragonForce join forces as ransomware cartel

Texas police accused of using surveillance data to hunt woman over abortion

Authorities in Texas used surveillance data to track down a woman who performed a self-managed abortion. Deputies and the surveillance companies then tried to cover their tracks.
Read more about Texas police accused of using surveillance data to hunt woman over abortion

All SonicWall firewall cloud backups stolen, admins urged to act immediately

A threat actor has accessed all firewall cloud backups belonging to customers of SonicWall, a major VPN, firewall, and other network security solutions provider. The firm has updated its advisory, which previously claimed the data breach affected less than 5% of its firewall install base.
Read more about All SonicWall firewall cloud backups stolen, admins urged to act immediately

Cl0p found exploiting Oracle EBS zero-day months before critical patch release

Google threat researchers have revealed that the Cl0p ransom gang, which is said to have compromised hundreds of companies in a zero-day spree targeting Oracle E Business Suite (EBS), likely began its exploit campaign back in July.
Read more about Cl0p found exploiting Oracle EBS zero-day months before critical patch release

Casino giant sued by employee over data breach that exposed Social Security numbers

Boyd Gaming, a Las Vegas Casino chain, is being sued for a previous data breach that exposed the sensitive data of its employees.
Read more about Casino giant sued by employee over data breach that exposed Social Security numbers

Quebec schools app leaks kids' data, sparking outrage

Hundreds of schools and daycares in Quebec used an app that exposed children's data, putting them at risk. And while fingers pointed in multiple directions, looking for someone to blame, schools continued to use the application despite the dangerous data leak.
Read more about Quebec schools app leaks kids' data, sparking outrage

Microsoft Windows 10 approached its expiration date. What should you do?

Users who still use the operating system that was first launched in 2015 are encouraged to take action to ensure that their devices continue to receive technical assistance, features, and security updates from Windows.
Read more about Microsoft Windows 10 approached its expiration date. What should you do?

AI girlfriend can’t keep a secret: app leaks intimate conversations of 400K+ users

Two AI character apps by the same developer, “Chattee Chat” and “GiMe Chat,” have exposed millions of intimate conversations, over 600K images, and other private data. Leaked purchase logs reveal that some users spend thousands of dollars on their AI girlfriends.
Read more about AI girlfriend can’t keep a secret: app leaks intimate conversations of 400K+ users

Hackers leveraging Teams to drop malware, steal data, Microsoft warns

Microsoft has warned about hackers taking advantage of its collaboration platform, Teams. Attackers use Teams to gather information, trick users into sharing sensitive data, impersonate trusted sources, deliver malware through messages and calls, and even steal credentials, exfiltrate data, and maintain persistence.
Read more about Hackers leveraging Teams to drop malware, steal data, Microsoft warns

Foreign threat actors adopting ChatGPT to bolster “old playbook” of attacks, OpenAI finds

Foreign adversaries are now building AI into their existing workflows – from crafting phishing campaigns, tweaking malware, and generating propaganda, to researching ways to automate their cyber kill chain, according to a new report by OpenAI.
Read more about Foreign threat actors adopting ChatGPT to bolster “old playbook” of attacks, OpenAI finds

Attacker says they breached Huawei, source code sold online

A hacker claims to have stolen Huawei’s internal source code and sold it on an underground cybercriminal forum.
Read more about Attacker says they breached Huawei, source code sold online

Millions of shoppers exposed ahead of the Black Friday

Global e-commerce giant VTEX has leaked the data of six million people, exposing everything from their home addresses to their purchases.
Read more about Millions of shoppers exposed ahead of the Black Friday