Security
Hacker claims global AT&T, Mercedes partner
Threat actors have claimed Credera, a global boutique consulting firm, saying they have stolen information related to major clients such as Mercedes, AT&T, Green Dot, Myze, and Spectrio.
Read more about Hacker claims global AT&T, Mercedes partner
Hackers nab FEMA, Customs and Border Protection staff data
Earlier this year, a hacker managed to gain access to the computer networks of the Federal Emergency Management Agency (FEMA) and stayed in them for several months, stealing data about FEMA and US Customs and Border Protection (CBP) employees.
Read more about Hackers nab FEMA, Customs and Border Protection staff data
Hackers exploiting critical sudo flaw: CISA wants five bugs gone by October 20th
CISA warns that the critical Linux Sudo flaw, unveiled in July, has been included in hackers’ arsenals and is now being actively exploited to gain superuser privileges on unpatched systems. The watchdog set aggressive deadlines for federal agencies to patch the flaws.
Read more about Hackers exploiting critical sudo flaw: CISA wants five bugs gone by October 20th
China’s new K visa aims to attract foreign stem graduates amid us rivalry
China's new visa programme aimed at attracting foreign tech talent kicks off this week, a move seen boosting Beijing's fortunes in its geopolitical rivalry with Washington
Read more about China’s new K visa aims to attract foreign stem graduates amid us rivalry
Japan's largest beer brewer stops production after cyberattack
It’s not yet known whether all 30 production facilities have been forced to pause their operations.
Read more about Japan's largest beer brewer stops production after cyberattack
Canada's WestJet notifies 1.2 million Americans data was hacked in June breach
Canada’s WestJet has begun notifying 1.2 million American customers whose sensitive data was impacted after hackers breached the airline’s systems in June.
Read more about Canada's WestJet notifies 1.2 million Americans data was hacked in June breach
Hackers claim data breach of Israeli satellite operator
Spacecom, the Israeli company operating the AMOS satellite fleet, has been claimed by a hacker gang, which claims it obtained access to the company’s ground control stations. However, researchers believe the attacker's claims are not entirely earthly.
Read more about Hackers claim data breach of Israeli satellite operator
As zero-day exploits rage, close to 200,000 Cisco devices are exposed online
Public scans have revealed that hackers can easily find 192,038 Cisco network devices exposed on the internet running a service vulnerable to a zero-day flaw. Attackers are actively targeting vulnerable systems, and many of them are likely still unpatched.
Read more about As zero-day exploits rage, close to 200,000 Cisco devices are exposed online
Friends of NRA spills supporter data on Google
A mailing list containing nearly 10,000 Colorado NRA supporters’ names and home addresses has been accidentally posted online, exposing sensitive data to anyone searching on Google.
Read more about Friends of NRA spills supporter data on Google
Dutch teens detained over alleged WiFi sniffing for Russia
Police in the Netherlands arrested two 17-year-olds last week over allegations that they were spying on the headquarters of European law enforcement agencies after being recruited by Russian intelligence.
Read more about Dutch teens detained over alleged WiFi sniffing for Russia
Meta AI chatbot outsmarted to instruct on incendiary device making
Meta’s personal assistant, which is integrated into Messenger, WhatsApp, Instagram, and other apps, can sometimes be too helpful, researchers have discovered. For example, the Llama 4-based chatbot was easily tricked into providing instructions on making a Molotov cocktail.
Read more about Meta AI chatbot outsmarted to instruct on incendiary device making
Chinese drone maker DJI loses appeal to get off Pentagon blacklist
A US federal judge has rebuffed drone maker DJI’s efforts to be removed from a Department of Defense list of Chinese military companies. The firm claims it’s not owned or controlled by the Chinese military.
Read more about Chinese drone maker DJI loses appeal to get off Pentagon blacklist
Was Medusa's claim on cable giant a PR stunt? Demanding $1.2 million for data likely belonging to another company
Notorious ransomware gang Medusa posted ransom demands of $1.2 million, extorting a multinational mass media, telecommunications, and entertainment conglomerate. There’s just one problem: the alleged victim doesn’t recognize the data.
Read more about Was Medusa's claim on cable giant a PR stunt? Demanding $1.2 million for data likely belonging to another company
Your questions, answered by Cybernews: Why do we still need CAPTCHAs?
Clicking Google CAPTCHA images can sometimes feel pointless. But are there other ways to secure your accounts from brute force attacks? Each week, our team selects one pressing and common reader issue and deconstructs it to help you stay safe online.
Read more about Your questions, answered by Cybernews: Why do we still need CAPTCHAs?
Fake farewells from Scattered LAPSUS$ hunters: gangs likely plotting new attacks
A short-lived hacker conglomerate uniting LAPSUS$, ShinyHunters, and Scattered Spider, responsible for breaching numerous companies through major platforms like Salesforce, abruptly announced its retirement. Security researchers from Resecurity warn that the farewell is likely a smokescreen: once the hackers regroup after recent arrests, they can launch fresh waves of attacks.
Read more about Fake farewells from Scattered LAPSUS$ hunters: gangs likely plotting new attacks
Your questions, answered by Cybernews: Why your weak passwords is Google’s problem too
Why is your weak password Google's problem too? Or why the platforms keep on insisting on a strong password while you might not care? Each week, our team selects one pressing and common reader issue and deconstructs it to help you stay safe online.
Read more about Your questions, answered by Cybernews: Why your weak passwords is Google’s problem too
Multiple Cisco zero-day vulnerabilities trigger "urgent" mass patching, CISA warns
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning of three previously unknown CISCO vulnerabilities being exploited in the wild, releasing an emergency directive on Thursday to patch affected devices in the next 24 hours.
Read more about Multiple Cisco zero-day vulnerabilities trigger "urgent" mass patching, CISA warns
Data leak puts 10% of Texas truckers in danger
A massive data leak from a driver compliance platform has exposed personal documents belonging to over ten thousand Texas truckers, including drug tests and other sensitive information.
Read more about Data leak puts 10% of Texas truckers in danger
Russia-linked hackers claim Port of Baltimore operator
The Maryland Department of Transportation (MDOT), which operates one of the largest ports in the USA, was breached by a Russia-linked hacking group, with attackers posting personal data as proof.
Read more about Russia-linked hackers claim Port of Baltimore operator
Fake Malwarebytes, LastPass, and dozens of other malware-containing apps found on GitHub
Malwarebytes has warned users to be wary of fake versions of legitimate software being disseminated on GitHub. Dozens of apps were found impersonating popular brands like password managers, Audacity, Dropbox, and others, to lure victims into downloading and running malware themselves.
Read more about Fake Malwarebytes, LastPass, and dozens of other malware-containing apps found on GitHub