Security

Massive supply chain attack hits NPM as hackers target 18 packages downloaded 2B times weekly

What has been dubbed the largest supply chain attack in history has hit NPM, one of the most prolific JavaScript package managers.
Read more about Massive supply chain attack hits NPM as hackers target 18 packages downloaded 2B times weekly

Wealthsimple hackers gained access to customer account numbers, government IDs, and more

Online investment management firm Wealthsimple admits that customer data, including financial account numbers and government IDs, has been accessed by cybercriminals during a recent third-party breach.
Read more about Wealthsimple hackers gained access to customer account numbers, government IDs, and more

China is blurring the lines between civilian AI and military power

China is turning everyday AI like voice apps, drones, and satellites into military tools, blurring the line between civilian tech and the People Liberation Army (PLA).
Read more about China is blurring the lines between civilian AI and military power

America’s second largest egg producer breached, claim hackers

Rose Acre Farms, a top US egg producer, has been claimed by a prominent cybercrime cartel, with the attackers saying that they’ve encrypted the company’s data. Past attacks on major agricultural producers led to shortages and price hikes.
Read more about America’s second largest egg producer breached, claim hackers

China aims for domination in another key semiconductor material: undercutting the silicon supply chain

China, already a dominant player in rare earth mineral supply chains, has been heavily backing its domestic polysilicon industry, a critical material for semiconductor manufacturing. It is flooding the market with the substrate at below-fair prices, pushing companies out of business and positioning Chinese firms to dominate the global market, analysts warn.
Read more about China aims for domination in another key semiconductor material: undercutting the silicon supply chain

Expedia’s chatbot instructs on how to make a Molotov cocktail

Travel agency Expedia has launched a ChatGPT-based AI travel planner that does far more than its initial purpose. For example, it instructs users on how to make a Molotov cocktail.
Read more about Expedia’s chatbot instructs on how to make a Molotov cocktail

How the Salesforce breaches unfolded: root causes identified

New details have emerged regarding the massive Salesforce compromise campaign, which impacted hundreds of companies, including major tech and cybersecurity firms.
Read more about How the Salesforce breaches unfolded: root causes identified

The dumbest employee tech hacks that nearly broke companies

From medical data being shared on Dropbox to an industrial control system connected to a food truck’s hotspot, what are the dumbest employee IT decisions?
Read more about The dumbest employee tech hacks that nearly broke companies

Data breach at American credit union exposes financial data

Not only did hackers penetrate Carter Credit Union’s network, but they also got their hands on virtually every possible data point the financial institution had on its customers.
Read more about Data breach at American credit union exposes financial data

Fake recruiters from North Korea plot attacks on Slack, abuse Western cyber intelligence

Hundreds of people were hacked between March and June this year by North Korean hackers posing as recruiters or job seekers, cybersecurity researchers warn. They abuse Western cyber intelligence platforms and other commercial tools when carrying out cyberattacks.
Read more about Fake recruiters from North Korea plot attacks on Slack, abuse Western cyber intelligence

Major airline inflight service providers' hack exposes Starlink users

Anuvu, an in-flight entertainment and connectivity (IFEC) service provider, has allegedly fallen victim to a hacker attack.
Read more about Major airline inflight service providers' hack exposes Starlink users

Instagram exposes teens to gruesome content despite pledges to protect them

Let’s say a 15-year-old boy creates a new Instagram account and follows celebrities recommended by the platform. He searches for the word “fight” and ultimately ends up scrolling through an array of violent and gory videos, despite Meta’s pledges to restrict unsafe content.
Read more about Instagram exposes teens to gruesome content despite pledges to protect them

Bridgestone hacked same day as Jaguar Land Rover, also disrupting operations

Bridgestone Americas on Thursday confirms the company has suffered what it calls a “limited cyber incident” – ironically, on the same day luxury carmaker Jaguar Land Rover was breached by the publicity-hungry Scattered Spider-led trio of ransomware gangs.
Read more about Bridgestone hacked same day as Jaguar Land Rover, also disrupting operations

Surge in malicious scans for outdated routers: hackers hunting for old Cisco, Linksys gear

Researchers are warning of a surge in malicious scans for old, outdated, and vulnerable network equipment. Hackers are likely succeeding because these probes often come from compromised end-of-life Cisco, Linksys, and Araknis Networks devices.
Read more about Surge in malicious scans for outdated routers: hackers hunting for old Cisco, Linksys gear

Online chess players’ data leaked in third-party breach

The most popular platform for chess players, Chess.com, has informed thousands of users that their personal details were exposed after hackers breached the company’s data storage vendor.
Read more about Online chess players’ data leaked in third-party breach

AI blockade: websites are putting up fences to protect their content

Website owners, from global banks to prestigious universities and leading law firms, are cracking down on AI bots pillaging their online content. Firms are increasingly blocking AI crawlers using various methods, from including them in robots.txt files to implementing server-side anti-bot protections.
Read more about AI blockade: websites are putting up fences to protect their content

Jaguar Land Rover cyberattack claimed by Salesforce, M&S hacking gangs

The hacking group said to be behind the devastating rash of Salesforce supply chain attacks is claiming responsibility for this week's cyberattack on luxury automaker Jaguar Land Rover.
Read more about Jaguar Land Rover cyberattack claimed by Salesforce, M&S hacking gangs

Cybercrime revolutionized with an AI “brain” that unleashes automated cyberattack mayhem

Instead of hacking themselves, attackers are increasingly deploying a free AI weapon that hacks for them. Twelve autonomous AI agents juggle 150 highly specialized security tools, from reconnaissance to zero-day exploitation, and it seems to be working.
Read more about Cybercrime revolutionized with an AI “brain” that unleashes automated cyberattack mayhem

PayPal users targeted by stealthy phishing scam

A polished and sophisticated scam is targeting PayPal users. Like most scams, it has telltale signs of deception, which can be easily spotted if you look hard enough.
Read more about PayPal users targeted by stealthy phishing scam

Hackers exploiting popular TP-Link WiFi device, WhatsApp also affected

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are actively exploiting two vulnerabilities: one affects very popular TP-Link WiFI extenders, and another is a recent WhatsApp flaw exploited by highly sophisticated attackers.
Read more about Hackers exploiting popular TP-Link WiFi device, WhatsApp also affected