Security

FBI warns bad actors are spoofing the IC3 cybercrime reporting website

The FBI has warned that cybercriminals are creating fake versions of its Internet Crime Complaint Center (IC3) website, a site used by the public to report online cyber scams.
Read more about FBI warns bad actors are spoofing the IC3 cybercrime reporting website

Amateur porn website users’ data leaked online, hackers claim

Attackers claim they’ve obtained a trove of personal details from MyHomemadePorn, an amateur adult content platform. However, the Cybernews research team believes the data could be fake.
Read more about Amateur porn website users’ data leaked online, hackers claim

Hackers say they’ve jacked SK Telecom’s source code

Hackers claim to have infiltrated SK Telecom’s systems, allegedly stealing source code and exposing sensitive internal projects. It could be the company’s second cyber blow this year.
Read more about Hackers say they’ve jacked SK Telecom’s source code

Hackers claim attack on the US's biggest sushi supplier – again?

A church-run sushi supplier, the biggest in the US, may be facing its second major cyberattack in a year, with new leaked data raising questions about another breach.
Read more about Hackers claim attack on the US's biggest sushi supplier – again?

Hackers claim breach of Italian post, researchers disagree

The Cybernews research team says the supposed leak looks a lot like old data with made-up details.
Read more about Hackers claim breach of Italian post, researchers disagree

iOS malicious deepfakes put Apple users and banks at risk

Security researchers have found a malicious new tool that can inject deepfake videos straight into iOS devices. The tool presents a major risk for identity theft, so Apple users should be wary.
Read more about iOS malicious deepfakes put Apple users and banks at risk

Hackers now going straight to the source – company data backups

A fifth of organizations in the UK report attacks on backups as the main cause of data breaches.
Read more about Hackers now going straight to the source – company data backups

Hackers can flip bits in RAM to escalate privileges and take over systems

Even if hackers don’t have access to the specific DDR5 memory cells that store critical information, they can manipulate electrical charges and reliably cause bit flips, corrupting the data or even elevating their privileges, new Google-backed research has revealed.
Read more about Hackers can flip bits in RAM to escalate privileges and take over systems

Baltimore hospital network victim of major data breach, hackers claim

Baltimore Medical System (BMS), a federally funded US health system, has been claimed by a hacker gang. The attackers claim they’ve stolen several terabytes of data from the healthcare provider, which mostly operates in underserved areas.
Read more about Baltimore hospital network victim of major data breach, hackers claim

Android apps with millions of downloads stealing ad money right under Google’s nose

Security researchers have uncovered a huge ad fraud scheme involving 224 apps on the Google Play Store, downloaded more than 38 million times. The apps generated fake ad views in the background, stealing money from advertisers.
Read more about Android apps with millions of downloads stealing ad money right under Google’s nose

Scattered Spider not dark after all: researchers see signs of life in new attacks

Scattered Spider and a bunch of other hacking groups recently announced that they were closing up shop. However, it seems they haven’t actually ceased activity.
Read more about Scattered Spider not dark after all: researchers see signs of life in new attacks

Data breach at Tiffany’s exposes gift card numbers

The American luxury jewelry behemoth, Tiffany & Co., has suffered a data breach that exposed thousands of clients, revealing their identities and gift card numbers.
Read more about Data breach at Tiffany’s exposes gift card numbers

Hundreds of NPM packages compromised as ongoing supply chain attack snowballs out of control

Hundreds of compromised NPM packages have already been found, and the list continues to grow as a major supply chain attack spreads malware. Developers are urged to be extremely cautious after hackers planted malicious scripts in CrowdStrike’s NPM packages and other widely used libraries.
Read more about Hundreds of NPM packages compromised as ongoing supply chain attack snowballs out of control

Does Nothing Phone pass our cybersecurity test? Here’s what we found

Nothing Phone 3a smartphone is one of the best value-for-money propositions on the market, but how secure is it? Our researchers analyzed the device and found some exposed weaknesses that could be abused to deny services, and the same privacy concerns as with all Android phones.
Read more about Does Nothing Phone pass our cybersecurity test? Here’s what we found

Vibe coders lose crypto after installing extensions on popular marketplaces

Dozens of malicious extensions have infiltrated the major IDE (integrated development environment) marketplaces favored by vibe coders over the past month. Major crypto figures have reported falling victim to this fraud campaign.
Read more about Vibe coders lose crypto after installing extensions on popular marketplaces

Russian gang claims breach of US broadcaster, executive exposed

A Russia-linked ransomware gang has claimed an attack on an American broadcaster. The owner's passport was allegedly exposed.
Read more about Russian gang claims breach of US broadcaster, executive exposed

Hackers setting traps for vibe coders: AI assistants can deliver malware

AI code assistants have already transformed most workflows, but they’ve also brought hidden dangers. Unit 42 security researchers warn that hackers can compromise these tools when they pull data from external sources.
Read more about Hackers setting traps for vibe coders: AI assistants can deliver malware

Finance apps are much more interested in you than you think

Most people download finance apps to check their balances, transfer money, and maybe pay a bill. But it turns out these apps are interested in much more than just finance-related activities.
Read more about Finance apps are much more interested in you than you think

Cybercriminals steal 160 million records from Vietnamese financial system, exposing entire population

Cybercriminals attacked Vietnam’s financial system and are selling over 160 million records of sensitive financial data.
Read more about Cybercriminals steal 160 million records from Vietnamese financial system, exposing entire population

Hackers stuffed malware into fake Signal, WhatsApp, and Chrome apps

Hackers are tricking Google search results, luring users into downloading malicious apps pretending to be Signal, WhatsApp, and Chrome.
Read more about Hackers stuffed malware into fake Signal, WhatsApp, and Chrome apps